Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

The Nuclear Digital I&C System Supply Chain Cyber-Attack Surface

The nuclear supply chain attack surface is a large, complex network of interconnected stakeholders and activities. The global economy has widened and deepened the supply chain, resulting in larger numbers of geographically dispersed locations and increased difficulty ensuring the authenticity and security of digital assets. Although the nuclear industry has made significant strides in securing facilities from cyber-attacks, the supply chain remains vulnerable. This paper outlines supply chain threats and vulnerabilities and provides a Digital I&C System Supply Chain Cyber-Attack Surface diagram to illustrate the complexity of securing hardware, firmware, software, and system information throughout the entire supply chain lifecycle. The knowledge presented in this paper provides a foundation to use in cybersecurity supply chain risk analysis and to guide future supply chain research and development efforts leading to enhancement of a nuclear facility’s overall security posture.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

First Results from Nanoindentation of Vapor Diffused Nb3Sn Films on Nb

The mechanical vulnerability of the Nb3Sn-coated cavities is identified as one of the significant technical hurdles toward deploying them in practical accelerator applications in the not-so-distant future. It is crucial to characterize the material's mechanical properties in ways to address such vulnerability. Nanoindentation is a widely used technique for measuring the mechanical properties of thin films that involves indenting the film with a small diamond tip and measuring the force-displacement response to calculate the film's elastic modulus, hardness, and other mechanical properties. For the first time, the nanoindentation analysis was performed on multiple vapor-diffused Nb3Sn samples coated at Jefferson Lab and Fermilab coating facilities. This contribution will discuss the first results obtained from the nanoindentation of Nb3Sn-coated Nb samples prepared via the Sn vapor diffusion technique.

Pudasaini, Uttar↗

First Results from Nanoindentation of Vapor Diffused Nb3Sn Films on Nb

The mechanical vulnerability of the Nb3Sn-coated cavities is identified as one of the significant technical hurdles toward deploying them in practical accelerator applications in the not-so-distant future. It is crucial to characterize the material's mechanical properties in ways to address such vulnerability. Nanoindentation is a widely used technique for measuring the mechanical properties of thin films that involves indenting the film with a small diamond tip and measuring the force-displacement response to calculate the film's elastic modulus, hardness, and other mechanical properties. For the first time, the nanoindentation analysis was performed on multiple vapor-diffused Nb3Sn samples coated at Jefferson Lab and Fermilab Nb3Sn coating facilities. This contribution will discuss the first results obtained from the nanoindentation of Nb3Sn-coated Nb samples prepared via the Sn vapor diffusion technique.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

Surface structure studies in 2D and 3D Nb resonators using GI-XRD

Superconductor radio frequency (SRF) Nb-resonators are a key element in the development of new generations of particle accelerators as well as in the fabrication of 3D circuit QED architecture for quantum computing. Nevertheless, Niobium is extremally reactive to light elements such as C, N, O and H, and therefore to the impurities ordering under special conditions, e.g., cryogenic temperatures. Since these resonators are put through a series of metallurgical and chemical processes, the number of impurities in the solid increases in tens of ppm. Upon operational conditions ~1.6 K, Nb become vulnerable to H atoms ordering, which leads to the nucleation of secondary phases such as Nb-hydrides. Thereupon to the energy dissipation and eventually to the superconductivity breakdown known as Q-disease and potentially High-Field Q-slope. In this contribution, we present a detailed structural analysis by high-energy grazing-incidence X-ray diffraction of specimens extracted from 3D Nb resonators to shed light on the kinetic formation of the resulting secondary phases and their crystal phase identification upon cooling and heating cycles. To our knowledge, this is the first study carried out in resonators samples using a light source, shallow angles and temperatures near ~4 K. Consequently, this work opens new routes to understand the chemical and phase composition, crystal and electronic structure of the Nb surface at temperatures near the operating conditions as a strategy to improve the physical and functional properties of Nb superconducting resonators.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

First Results from Nanoindentation of Vapor Diffused Nb3Sn Films on Nb

The mechanical vulnerability of the Nb3Sn-coated cavities is identified as one of the significant technical hurdles toward deploying them in practical accelerator applications in the not-so-distant future. It is crucial to characterize the material's mechanical properties in ways to address such vulnerability. Nanoindentation is a widely used technique for measuring the mechanical properties of thin films that involves indenting the film with a small diamond tip and measuring the force-displacement response to calculate the film's elastic modulus, hardness, and other mechanical properties. For the first time, the nanoindentation analysis was performed on multiple vapor-diffused Nb3Sn samples coated at Jefferson Lab and Fermilab Nb3Sn coating facilities. This contribution will discuss the first results obtained from the nanoindentation of Nb3Sn-coated Nb samples prepared via the Sn vapor diffusion technique.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

Instantaneous difference frequency locking observed during toroidicity-induced Alfvén eigenmode coupling in the DIII-D tokamak

In magnetic confinement fusion, toroidicity-induced Alfvén eigenmodes (TAEs) are well-studied, weakly stable solutions of the linearized ideal magnetohydrodynamic equations. Driven unstable by suprathermal populations of energetic particles, TAE pose a key vulnerability to the confinement of high-energy alpha particles generated by fusion reactions. Hence, it is paramount to understand TAE dynamics if a working reactor is to be realized. In this work, we detect and characterize signatures of nonstationary nonlinear coupling between TAE using a novel, time-resolved bispectral analysis; results are supported by analytic signal of band-passed data. Crucially, a stationary phase relationship between two TAE and a nascent low frequency fluctuation is observed precisely when the triple product of magnetic fluctuation amplitudes is enhanced. Local mode number and frequency spectrum, gleaned from beam-emission spectroscopy, corroborates simultaneous satisfaction of nonlinear matching conditions, and provides a tool to identify theorized pathways of energy transfer, e.g. TAE parametric instability.

bispectral analysis↗

Cyber Security Analysis for Nuclear Reactor Control Systems (Final Technical Report)

This project investigated the cyber-security impacts of moving from an all analog, point-to-point, instrumentation and control (I&C) system to a digital I&C system based on Modbus and a shared communication medium. A formalism called a hybrid attack graph was expanded to support the nuclear research reactor system. The hybrid attack graph allows one to check a system for vulnerabilities, in this case cyber-security vulnerabilities, and to document the attack vectors (scenarios) causing those vulnerabilities. In parallel, a simulation of the system was developed to model both the physical reactor parameters and operations, as well as the network interconnects and communications. This simulation platform was modeled on the nuclear research reactor located at Washington State University. The simulation platform provided a sandbox to evaluate and quantify the impact of identified and proposed vulnerabilities in the system and to determine the effectiveness of countermeasures at stopping these attacks. The simulation and hybrid attack graph tools were integrated to provide a streamlined process of generating attack scenarios, playing those scenarios out in the simulation, and then analyzing the results to correlate system state to states in the hybrid attack graph. This process was used to (1) quantify the impact of attack scenarios and (2) to determine if the system moved through the hybrid attack graph as anticipated. The hybrid attack graph tool was extended and customized to produce a tool to automatically identify critical assets (CAs) and critical digital assets (CDAs) as defined by NRC Regulatory Guide 5.71. This tool was verified using the nuclear research reactor at Washington State University. Finally, a series of educational modules covering the findings of the different aspects of this research have been created.

97 MATHEMATICS AND COMPUTING↗

Uncertain Spatial Pattern of Future Land Use and Land Cover Change and Its Impacts on Terrestrial Carbon Cycle Over the Arctic–Boreal Region of North America

Land use and land cover change (LULCC) represents a key process of human-Earth system interaction and has profound impacts on terrestrial ecosystem carbon cycling. As a key input for ecosystem models, future gridded LULCC data is typically spatially downscaled from regional LULCC projections by integrated assessment models, such as the Global Change Analysis Model (GCAM). The uncertainty associated with the different spatial downscaling methods and its impacts on the subsequent model projections have been historically ignored and rarely examined. This study investigated this problem using two representative spatial downscaling methods and focused on their impacts on the carbon cycle over the Arctic-Boreal Vulnerability Experiment (ABoVE) domain, where extensive LULCC is expected. Specifically, we used the Future Land Use Simulation model (FLUS) and the Demeter model to generate 0.25° gridded LULCC data (i.e., LULCC FLUS and LULCC Demeter , respectively) with the same input of regional LULCC projections from GCAM, under both the low (i.e., SSP126) and high (i.e., SSP585) greenhouse gas emission scenarios. The two sets of downscaled LULCC were used to drive the Community Land Model version 5 and prognostically simulate the terrestrial carbon cycle dynamics over the 21st century. The results suggest large spatial-temporal differences between LULCC FLUS and LULCC Demeter , and the spatial distributions of the needleleaf evergreen boreal tree, broadleaf deciduous boreal tree, broadleaf deciduous boreal shrub, and C3 arctic grass are particularly different under both SSP126 and SSP585. Additionally, the spatiotemporal differences are larger under SSP126 than SSP585, due to more intensive LULCC under SSP126 than SSP585 from GCAM projection. The differences in LULCC further lead to large discrepancies in the spatial patterns of projected gross primary productivity, ecosystem respiration, and net ecosystem exchange, which represent more than 79% of the contributions of future LULCC in 2100. Additionally, the difference in carbon flux under SSP126 is generally larger than those under SSP585. This study highlights the importance of considering the uncertainties induced by the spatial downscaling process in future LULCC projections and carbon cycle simulations.

54 ENVIRONMENTAL SCIENCES↗

Electromagnetic Pulse – Resilient Electric Grid for National Security: Research Program Executive Summary

Sandia National Laboratories sponsored a three-year internally funded Laboratory Directed Research and Development (LDRD) effort to investigate the vulnerabilities and mitigations of a high-altitude electromagnetic pulse (HEMP) on the electric power grid. The research was focused on understanding the vulnerabilities and potential mitigations for components and systems at the high voltage transmission level. Results from the research included a broad array of subtopics, covered in twenty-three reports and papers, and which are highlighted in this executive summary report. These subtopics include high altitude electromagnetic pulse (HEMP) characterization, HEMP coupling analysis, system-wide effects, and mitigating technologies.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Substation Configuration Survey for Electromagnetic Coupling Analysis

Impacts of a high-altitude electromagnetic pulse (HEMP) on the power grid are a growing concern due to the increased reliance on the power grid. A critical area of research is quantifying power system equipment response to HEMP since this is not known in general. Substation site surveys were performed at seven high voltage substations across the United States to gather substation layout and construction details pertinent to HEMP coupling calculations and component vulnerability assessments. The primary objective for the survey was to gather information on cable layouts and cable construction within substations. Additional information was also gathered on equipment present within the substations and control house layouts. This report provides information gathered from the substation surveys.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense (Final)

In the world of ever-advancing technology, Autonomous Systems (AS) find extensive application, bolstering functionalities of critical infrastructures such as nuclear power plants. These systems, however, are increasingly becoming a target for nefarious activities, namely through inference attacks, trojan attacks, and adversarial reprogramming. This paper delves into a comprehensive exploration of machine learning (ML)-driven autonomous control systems within advanced nuclear reactor designs, revealing the vulnerabilities and proposing strategies for defense against potential cyber-attacks. Advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)- based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber-physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems. As global reliance on generation III reactors begins to be critically assessed, the evolution towards advanced reactor systems utilizing digital instrumentation and controls (I&C) becomes not merely preferable, but essential. The integration of semi and fully autonomous control systems (ACS), powered by digital I&C and machine learning (ML)-based digital twinning (DT) technologies, emerges as a potent strategy to mitigate operations and maintenance costs, thereby enhancing the economic feasibility of novel reactor designs. However, with a staggering 500% and 380% increase in cyber-attacks reported against the energy sector by the United States Department of Energy (DoE) and the European Union respectively, a surge in cyber vulnerabilities specifically targeting the nuclear industry has been 2 markedly observed. Notable incidents, such as the W32.Ramnit spyware infiltration at the Gundremmingen nuclear power plant in Germany and the Dtrack spyware intrusion at the Kudankulam nuclear power plant in India, while not directly compromising core industrial control systems (ICS), underscore a compelling necessity to fortify cybersecurity protocols in safeguarding reactor systems against increasingly adept digital adversaries. In light of this, our investigation extends beyond conventional cybersecurity parameters, diving into the intricate web of potential vulnerabilities woven into ML-based DTs and ACS in advanced reactor systems. A crafted cyber-physical testbed and preliminary ACS were devised to act as a mirror, reflecting potential configurations of advanced reactor control designs. Moreover, this study is intertwined with a scrutinization of ML models, developed either through conventional, manually tuned methodologies or via automated means through AutoML, probing into their cyber-risk profiles within operational technology (OT) environments. Expanding on this, two distinct ACS blueprints were forged – one navigating through the corridors of traditional ML and the other traversing the path of AutoML – in an effort to holistically encapsulate the considerations pivotal to ML-based DT control system design. Employing the SANS Institute Industrial Control System (ICS) Kill Chain and the MITRE ATT&CK Tactics, Techniques, and Procedures (TTP) framework, a structured analysis was conducted, launching three targeted attacks against the training dataset, real-time dataset, and ML models, therein dissecting the potential cyber-attack implications against both ML frameworks within an ACS milieu. It is essential to note that three distinct categories of attacks were conducted against both ACS configurations, each encompassing three distinct ML-based DTs, cumulating in a total of 18 varied attacks. This exploration extends into the realms of Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense, unraveling vulnerabilities, and opportunities for fortified defenses against such intrusions, particularly where ML-driven technologies, and by extension, ACS, are deployed. Final recommendations, articulated through a lens of security, safeguard, and implementation considerations, are presented for both traditional and AutoML models, anchoring upon the existing knowledge landscape and ML-based DT modeling for ACS, and are offered as a beacon to guide the nuclear industry through the intricate cybersecurity challenges that lie ahead.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Displacement of carbon atoms in few-layer graphene

Molecular dynamics simulations were performed to study the susceptibility of carbon atom displacement under electron irradiation. The mapping of threshold displacement energies at different recoiling directions showed that the energies are very sensitive to the layer configurations and positions of neighboring atoms. Carbon atoms on the top and the bottom layers of few-layer graphene are most vulnerable to irradiation damage due to lack of constraints from the neighboring graphene layers. As indirect experiment evidence, transmission electron microscopy was performed on the edge of folded few-layer graphene, which made it possible to reveal “the inside” and compare irradiation tolerance of atoms at different layers, by using an electron analysis beam for both displacement creation and in situ characterization.

74 ATOMIC AND MOLECULAR PHYSICS↗

Bridge Seismic Screening Tool (BSST), Version 2.0

The Regional Resiliency Assessment Program (RRAP) is a cooperative assessment of specific critical infrastructure within a designated geographic area and a regional analysis of the surrounding infrastructure that addresses a range of infrastructure resilience issues that could have regionally and nationally significant consequences. In 2018, DHS’s Cybersecurity and Infrastructure Security Agency (CISA) sponsored the Oregon Transportation Systems RRAP project in coordination with the Office of the Governor (under the oversight of the state resilience officer), the Oregon Office of Emergency Management (OEM), the Oregon Department of Transportation (ODOT), and other regional stakeholders (CISA 2021). This project focuses on assessing the impacts of a Cascadia Subduction Zone (CSZ) earthquake on state transportation systems and, in particular, how those impacts may affect the ability of emergency response efforts to move supplies into the region. The intended outcome of this analysis is the prioritization of transportation routes and modes for additional planning, investment, hardening, or other activities to enhance their resilience—and therefore, to enhance their ability to support response and recovery efforts following a CSZ earthquake. An important part of this transportation system-level assessment has been to assess the seismic vulnerability of the state highway system. In doing so, the RRAP project team used the Bridge Seismic Screening Tool (BSST) to assess, at a system-level, the potential impacts that a CSZ earthquake could have on state highway bridges (Bergerson et al. 2019).1 Argonne National Laboratory (Argonne), in collaboration with the Washington State Department of Transportation (WSDOT), originally developed the BSST as part of the 2017 Washington State Transportation Systems RRAP project, a sister project to the 2018 Oregon Transportation Systems RRAP project. Argonne updated the BSST during this more recent project in Oregon based on feedback from stakeholders and subject matter experts (SMEs) on the original version of the tool. The first step in the BSST is to assess the seismic vulnerability of roadway bridges following a CSZ earthquake to determine a projected or potential damage state. Damage states then help determine approximate reopening times for bridge crossings.2 This document provides details on the BSST methodology, the implementation of that tool to analyze the projected damage incurred in a CSZ earthquake scenario, and the determination of corresponding reopening times of interstate, state highway, and local bridges following such an event.

58 GEOSCIENCES↗

Health Care Usage During the COVID-19 Pandemic and the Adoption of Telemedicine: Retrospective Study of Chronic Disease Cohorts

Background: The COVID-19 pandemic accelerated telehealth adoption across disease cohorts of patients. For many patients, routine medical care was no longer an option, and others chose not to visit medical offices in order to minimize COVID-19 exposure. In this study, we take a comprehensive multidisease approach in studying the impact of the COVID-19 pandemic on health care usage and the adoption of telemedicine through the first 12 months of the COVID-19 pandemic. Objective: We studied the impact of the COVID-19 pandemic on in-person health care usage and telehealth adoption across chronic diseases to understand differences in telehealth adoption across disease cohorts and patient demographics (such as the Social Vulnerability Index [SVI]). Methods: We conducted a retrospective cohort study of 6 different disease cohorts (anxiety: n=67,578; depression: n=45,570; diabetes: n=81,885; kidney failure: n=29,284; heart failure: n=21,152; and cancer: n=35,460). We used summary statistics to characterize changes in usage and regression analysis to study how patient characteristics relate to in-person health care and telehealth adoption and usage during the first 12 months of the pandemic. Results: We observed a reduction in in-person health care usage across disease cohorts (ranging from 10% to 24%). For most diseases we study, telehealth appointments offset the reduction in in-person visits. Furthermore, for anxiety and depression, the increase in telehealth usage exceeds the reduction in in-person visits (by up to 5%). We observed that younger patients and men have higher telehealth usage after accounting for other covariates. Patients from higher SVI areas are less likely to use telehealth; however, if they do, they have a higher number of telehealth visits, after accounting for other covariates. Conclusions: The COVID-19 pandemic affected health care usage across diseases, and the role of telehealth in replacing in-person visits varies by disease cohort. Understanding these differences can inform current practices and provides opportunities to further guide modalities of in-person and telehealth visits. Critically, further study is needed to understand barriers to telehealth service usage for patients in higher SVI areas. A better understanding of the role of social determinants of health may lead to more support for patients and help individual health care providers improve access to care for patients with chronic conditions.

60 APPLIED LIFE SCIENCES↗

Validating a Dynamic PWR Safety and Security Model?

Nuclear power plants (NPPs) are assessed for safety and security using separate models that cannot capture how an attacker's decisions and a plant's response unfold together in real time, leaving regulators and operators without a complete picture of true plant vulnerability. Traditional probabilistic risk assessment (PRA) methods treat adversarial events as fixed initiators with predetermined outcomes, and are structurally incapable of representing the time-dependent interplay between physical security events, safety system response, and operator mitigative actions. At Idaho National Laboratory (INL), I contributed to the development and validation of Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF). Where static PRA relies on event-tree logic that cannot evolve mid-scenario, MASS-DEF couples a time-dependent dynamic PRA tool EMRALD (Event Modeling Risk Assessment using Linked Diagrams) with attack simulation software, allowing attacker behavior, plant system states, and operator actions to interact across time. My work focused on validating a general Pressurized Water Reactor (PWR) model. I traced model logic against PWR plant to identified errors in logic and confirm accuracy. I then built and tested attack scenarios against a general PWR model to verify that the model produced expected outcomes across all logical pathways. I also contributed a section to a related technical paper applying the same EMRALD platform to radiation dose modeling. Results show that MASS-DEF can quantitatively demonstrate that many plants exceed their regulatory security thresholds. This demonstrated margin provides a technically defensible basis for reducing the number of guards without compromising regulatory compliance. Physical security costs represent roughly 10% of annual operating budgets, making such reductions directly meaningful to INL's mission of sustaining existing commercial NPPs. This internship strengthened my understanding of nuclear systems, probabilistic modeling, and technical writing, and has solidified my pursuit of a career at a national laboratory.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Hydraulic architecture explains species moisture dependency but not mortality rates across a tropical rainfall gradient

Aim Intensified droughts are affecting tropical forests across the globe. However, the underlying mechanisms of tree drought response and mortality are poorly understood. Hydraulic traits and especially hydraulic safety margins (HSMs), i.e. the extent to which plants buffer themselves from thresholds of water stress, provide insights into species-specific drought vulnerability. Methods We investigated hydraulic traits during an intense drought triggered by the 2015-2016 El Niño on 27 canopy trees across three tropical forest sites with differing precipitation. We capitalized on the drought event as a time when plant water status might approach or exceed thresholds of water stress. We investigated the degree to which these traits varied across the rainfall gradient, as well as relationships amongst hydraulic traits and species-specific optimal moisture and mortality rates. Results There were no differences among sites for any measured trait. There was strong coordination among traits, with a network analysis revealing two major groups of coordinated traits. In one group there were water potentials, turgor loss point, sapwood capacitance and density, HSMs, and mortality rate. In the second group there was leaf mass per area, leaf dry matter content, hydraulic architecture (leaf area to sapwood area ratio), and species-specific optimal moisture. Conclusion These results demonstrated that while species with greater safety from turgor loss had lower mortality rates, hydraulic architecture was the only trait that explained species’ moisture dependency. Species with a greater leaf area to sapwood area ratio were associated with drier sites and reduced their transpirational demand during the dry season via deciduousness.

Hydraulic Saftey Margins, drought, tropical forest↗

Resilience Assessment: Cape Cod National Seashore

The NPS partnered with the National Renewable Energy Laboratory (NREL) in 2019 to develop resilience plans at specific high-risk parks as well as a resilience planning guide to inform resilience planning decisions by NPS and other federal land management agencies. The purpose of this project is to further examine the vulnerability of coastal park infrastructure specific to energy, communications, transportation, and water systems, for future operational resilience across the NPS portfolio. Leveraging previously compiled vulnerability assessments and renewable energy analyses, NREL has completed resilience plans at specific high-risk pilot parks to serve as a foundation for more comprehensive assessments and resilience planning activities. This report is a summary of the efforts at Cape Cod National Seashore (CACO), which outlines the methodology used and the results of the analysis, with the intention of serving as a case study for other parks interested in replicating the process.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Towards a New Supply Chain Cybersecurity Risk Analysis Technique

Supply chain cyber-attacks, such as the SolarWinds Orion attack, are occurring with greater frequency. These attacks compromise a digital device before it is sent to customers, bypassing traditional security controls to remain persistent and undetected in operational environments. While supply chain attacks are prevalent, methods for analyzing the risk of these attacks are currently unavailable. This paper proposes new supply chain cyber-attack difficulty and risk metrics to evaluate the relative risk of an attack throughout the supply chain lifecycle. Difficulty metrics for each stakeholder in a digital device’s supply chain (e.g., hardware manufacturing, firmware development, software development, storage, and distribution entities) are calculated using scores from cybersecurity maturity questionnaires in a Bayesian Network leaky Noisy-MAX model. These difficulty metrics are then used to calculate an overall supply chain cyber-attack risk. Vulnerability and recoverability metrics are also proposed to evaluate the relative stakeholder influence in the attack risk. These proposed relative risk metrics enable continuous supply chain monitoring, provide decision-makers with information necessary for improved supplier selection, and help drive improvements in the cybersecurity posture of the stakeholders in their supply chain.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗