Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “vulnerability analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Firmware Tampering Detection in Heavy-Duty Vehicles through J1939 CAN Analysis

Modern heavy-duty vehicles rely on complex networks of Electronic Control Units (ECUs) that communicate using the J1939 protocol. While this system makes it easier to update and configure vehicle components, it also opens the door to serious cybersecurity risks if not properly secured. This work investigates the potential for firmware tampering through the J1939 communication protocol, which enables ECU configuration and reprogramming over the Controller Area Network (CAN) bus. By monitoring CAN traffic during legitimate maintenance operations and reverse-engineering OEM diagnostic software, we identified common and proprietary J1939 message identifiers, authentication patterns, and vulnerabilities within Unified Diagnostic Services (UDS). These findings demonstrate that inadequate authentication mechanisms can allow malicious actors to alter ECU firmware or disable safety functions, posing severe operational and safety risks. Our analysis contributes to the development of vehicle intrusion detection systems capable of recognizing abnormal reprogramming activity and future firmware fingerprinting methods to verify software integrity across ECUs. This work highlights the importance of standardizing secure firmware authentication across manufacturers to strengthen cyber resilience in heavy-duty vehicle systems.

33 ADVANCED PROPULSION SYSTEMS↗

Uncertainty quantification and reliability assessment for intermodal freight transportation

Intermodal freight optimization models support cost-effective, low-emission, and timely goods movement by coordinating trucks, rail, and barges. These models determine optimal flows, routing, and modal switches while respecting infrastructure and operational constraints. However, their real-world utility is often undermined by pervasive uncertainties-such as fluctuating transportation costs and emissions, variable terminal capacities, and uncertain freight demand-that distort key performance outcomes, including total system cost, carbon footprint, and transit time reliability. This study presents a structured framework for quantifying uncertainty in intermodal freight transportation (IFT) optimization. The framework evaluates how input uncertainty affects system performance and reliability, a critical need for ensuring that model-based decisions remain robust under real-world variability, especially amid volatile fuel prices, shifting demand, and growing disruptions. It integrates three complementary methods: (1) Sobol-based global sensitivity analysis to identify influential parameters affecting cost, emissions, and transit time, (2) Monte Carlo-based capacity perturbation analysis to assess robustness under probabilistic facility disruptions, and (3) Monte Carlo filtering with Bayesian inference to detect threshold-based performance vulnerabilities. The results highlight diesel truck unit cost as the dominant driver of variability. To improve system resilience, planners should prioritize uncertainty in fuel-related parameters when designing intermodal strategies.

Intermodal freight transportation↗

Science priorities for the human dimensions of global change

The topics covered include the following: defining research needs; understanding land use change; improving policy analysis -- research on the decision-making process; designing policy instruments and institutions to address energy-related environmental problems; assessing impacts, vulnerability, and adaptation to global changes; and understanding population dynamics and global change.

Source record↗

RADAMS: Resilient and adaptive alert and attention management strategy against Informational Denial-of-Service (IDoS) attacks

Attacks exploiting human attentional vulnerability have posed severe threats to cybersecurity. In this work, we identify and formally define a new type of proactive attentional attacks called Informational Denial-of-Service (IDoS) attacks that generate a large volume of feint attacks to overload human operators and hide real attacks among feints. Here, we incorporate human factors (e.g., levels of expertise, stress, and efficiency) and empirical psychological results (e.g., the Yerkes-Dodson law and the sunk cost fallacy) to model the operators’ attention dynamics and their decision-making processes along with the real-time alert monitoring and inspection. To assist human operators in dismissing the feints and escalating the real attacks timely and accurately, we develop a Resilient and Adaptive Data-driven alert and Attention Management Strategy (RADAMS) that de-emphasizes alerts selectively based on the abstracted category labels of the alerts. RADAMS uses reinforcement learning to achieve a customized and transferable design for various human operators and evolving IDoS attacks. The integrated modeling and theoretical analysis lead to the Product Principle of Attention (PPoA), fundamental limits, and the tradeoff among crucial human and economic factors. Experimental results corroborate that the proposed strategy outperforms the default strategy and can reduce the IDoS risk by as much as 20%. Besides, the strategy is resilient to large variations of costs, attack frequencies, and human attention capacities. We have recognized interesting phenomena such as attentional risk equivalency, attacker’s dilemma, and the half-truth optimal attack strategy.

97 MATHEMATICS AND COMPUTING↗

Additional design studies of the NASA/Navy lift/cruise fan

Additional preliminary design studies were performed for a turbotip lift/cruise fan propulsion system for a Navy multimission aircraft. The LCF459/J97 propulsion system was previously designed for this application. These studies extended the analysis in areas of (1) scroll commonality, (2) increased engine-out contingency ratings, (3) mounting systems, (4) manufacturing cost reductions, and (5) vulnerability.

Source record↗

Integrated Water-Power System Resilience Analysis in a Southeastern Idaho Irrigation District: Minidoka Case Study

This study investigates the joint water–power system resilience of an irrigation district in southeastern Idaho. Irrigation districts face difficulties in the delivery of water to farmers under drought conditions, during equipment failures, or unplanned infrastructure disruptions. The resilience of interconnected water and power systems can be better analyzed and understood through an integrated approach, using a model that connects the dependencies between the two halves of the system. Using a multi-agent system model capturing both water and power system components, as well as their linkages, we capture the interdependencies of these systems and highlight opportunities for improvement when faced with disruptions. Through simulation scenarios, we examine the system resilience using system performance, quantified as the percentage of met demand of the power and water system, when subjected to drought water year, an unforeseen water demand increase, power outage and dam failure. Scenario results indicate that the effects of low flow years are mostly felt in the power system; unexpected increases in water demand marginally impact irrigation system performance; dams and pumps present vulnerabilities of the system, causing substantial unmet demand during disruptions. Noting the interdependencies between the water–power system halves while leveraging an integrated simulation allows for an insightful analysis of the system impacts during disruptions.

13 HYDRO ENERGY↗

The Role of Alerting System Failures in Loss of Control Accidents CAST SE-210 Output 2

This report is part of a series of reports that address flight deck design and evaluation, written as a response to loss of control accidents. In particular, this activity is directed at failures in airplane state awareness in which the pilot loses awareness of the airplane's energy state or attitude and enters an upset condition. In a report by the Commercial Aviation Safety Team, an analysis of accidents and incidents related to loss of airplane state awareness determined that hazard alerting was not effective in producing the appropriate pilot response to a hazard (CAST, 2014). In the current report, we take a detailed look at 28 airplane state awareness accidents and incidents to determine how well the hazard alerting worked. We describe a five-step integrated alerting-to-recovery sequence that prescribes how hazard alerting should lead to effective flight crew actions for managing the hazard. Then, for each hazard in each of the 28 events, we determine if that sequence failed and, if so, how it failed. The results show that there was an alerting failure in every one of the 28 safety events, and that the most frequent failure (20/28) was tied to the flight crew not orienting to (not being aware of) the hazard. The discussion section summarizes findings and identifies alerting issues that are being addressed and issues that are not currently being addressed. We identify a few recent upgrades that have addressed certain alerting failures. Two of these upgrades address alerting design, but one response to the safety events is to upgrade training for approach to stall and stall recovery. We also describe issues that are not being addressed adequately: better alert integration for flight path management types of hazards, airplanes in the fleet that do not meet the current alerting regulations, a lack of innovation for addressing cases of channelized attention, and existing vulnerabilities in managing data validity.

aviation safety↗

Predicting System Accidents with Model Analysis During Hybrid Simulation

Standard discrete event simulation is commonly used to identify system bottlenecks and starving and blocking conditions in resources and services. The CONFIG hybrid discrete/continuous simulation tool can simulate such conditions in combination with inputs external to the simulation. This provides a means for evaluating the vulnerability to system accidents of a system's design, operating procedures, and control software. System accidents are brought about by complex unexpected interactions among multiple system failures , faulty or misleading sensor data, and inappropriate responses of human operators or software. The flows of resource and product materials play a central role in the hazardous situations that may arise in fluid transport and processing systems. We describe the capabilities of CONFIG for simulation-time linear circuit analysis of fluid flows in the context of model-based hazard analysis. We focus on how CONFIG simulates the static stresses in systems of flow. Unlike other flow-related properties, static stresses (or static potentials) cannot be represented by a set of state equations. The distribution of static stresses is dependent on the specific history of operations performed on a system. We discuss the use of this type of information in hazard analysis of system designs.

Malin, Jane T.↗

Convex Relaxations of Maximal Load Delivery for Multi-Contingency Analysis of Joint Electric Power and Natural Gas Transmission Networks

Recent increases in gas-fired power generation have engendered increased interdependencies between natural gas and power transmission systems. These interdependencies have amplified existing vulnerabilities in gas and power grids, where disruptions can require the curtailment of load in one or both systems. Although typically operated independently, coordination of these systems during severe disruptions can allow for targeted delivery to lifeline services, including gas delivery for residential heating and power delivery for critical facilities. To address the challenge of estimating maximum joint network capacities under such disruptions, we consider the task of determining feasible steady-state operating points for severely damaged systems while ensuring the maximal delivery of gas and power loads simultaneously, represented mathematically as the nonconvex joint Maximal Load Delivery (MLD) problem. To increase its tractability, we present a mixed-integer convex relaxation of the MLD problem. Then, to demonstrate the relaxation’s effectiveness in determining bounds on network capacities, exact and relaxed MLD formulations are compared across various multi-contingency scenarios on nine joint networks ranging in size from 25 to 1191 nodes. The relaxation-based methodology is observed to accurately and efficiently estimate the impacts of severe joint network disruptions, often converging to the relaxed MLD problem’s globally optimal solution within ten seconds.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Milwaukee Urban Development: Assessing Climate Vulnerability through the InVEST Model on Urban Cooling in Milwaukee Using NASA Earth Observations

Milwaukee’s neighborhoods experience increased social, health, and ecological stress from the Urban Heat Island (UHI) effect due to changing land cover and climate. Extreme urban heat disproportionately affects Black and Latine communities due to systematic disinvestment in infrastructure and lack of resources to cope with heat. Our partner, Groundwork Milwaukee, supports Environmental Justice organizing around urban heat in historically redlined neighborhoods. This study explores heat mitigation in Metcalfe Park, one such neighborhood that is a focus area for our partner, as well as across the city and county of Milwaukee. Our team utilized the Natural Capital Project’s Integrated Valuation of Ecosystem Services and Tradeoffs (InVEST) Model for urban cooling to model heat mitigation scenarios for Milwaukee in support of Groundwork’s climate resilience and heat mitigation work. The data inputs used in our analysis were Land Use Land Cover (LULC), evapotranspiration, and surface temperature derived from NASA Earth observations, as well as a biophysical table containing land cover class attributes. We developed a heat vulnerability index from American Community Survey datasets and satellite imagery to identify areas in most need of heat mitigation intervention. We found that central and northwest city areas, home to a majority of Milwaukee’s Black and Latine population, have low heat mitigation and high vulnerability to heat impacts compared to the rest of the county. We also found that tree canopy increases across scales are effective in promoting heat mitigation. Our results and end products will bolster the efforts of our partners to make decisions on heat mitigation strategies, build community resilience, and reverse legacies of environmental racism in the face of extreme heat and climate change.

urban heat island↗

Cali Urban Development II: Investigating the Impacts of Land Use Change on Urban Heat and Social Vulnerability in Cali, Colombia

The surface urban heat island (SUHI) effect is an environmental phenomenon resulting in cities with higher temperatures than rural areas due to increased pavement and decreased cooling from vegetation. The city of Santiago de Cali in Colombia faces SUHI challenges exacerbated by land use change. The Cali municipal government agency, Departamento Administrativo de Gestión del Medio Ambiente, and the community organization Fundacion Dinamizadores Ambientales partnered with NASA DEVELOP to evaluate communities in Cali most vulnerable to urban heat. This project illustrated the utility of using NASA Earth observations to evaluate the relationship between land use, temperature, and social factors in Cali, Colombia between 2013 and 2023. The team used Landsat 7 Enhanced Thematic Mapper Plus (ETM+), Landsat 8 Operational Land Imager (OLI) and Thermal Infrared Sensor (TIRS), and Landsat 9 OLI-2/TIRS-2 to generate land surface temperature (LST) maps in Google Earth Engine through NASA DEVELOP’s Urban Heat Exposure Assessment Tempe 2.0 tool. Cloud cover limited the project feasibility, but it improved with Landsat 9 data. In ArcGIS Pro, the team found that LST was significantly higher in urban areas than in wetlands or forests. Using R Studio, the team ran a principal component analysis and found that health care and green space access were negatively correlated, and Afro-Colombian ethnicity was positively correlated with LST. With knowledge of the most impacted and vulnerable regions, the partner organizations can prioritize establishing healthcare facilities and green spaces in those areas to reduce the impacts of urban heat.

vegetation loss↗

Machine Learning-based Intrusion Detection for Smart Grid Computing: A Survey

Machine learning (ML)-based intrusion detection system (IDS) approaches have been significantly applied and advanced the state-of-the-art system security and defense mechanisms. In smart grid computing environments, security threats have been significantly increased as shared networks are commonly used, along with the associated vulnerabilities. However, compared to other network environments, ML-based IDS research in a smart grid is relatively unexplored, although the smart grid environment is facing serious security threats due to its unique environmental vulnerabilities. In this article, we conducted an extensive survey on ML-based IDS in smart grids based on the following key aspects: (1) The applications of the ML-based IDS in transmission and distribution side power components of a smart power grid by addressing its security vulnerabilities; (2) dataset generation process and its usage in applying ML-based IDSs in the smart grid; (3) a wide range of ML-based IDSs used by the surveyed papers in the smart grid environment; (4) metrics, complexity analysis, and evaluation testbeds of the IDSs applied in the smart grid; and (5) lessons learned, insights, and future research directions.

SCADA↗

Adapting Traditional Hazards Analysis Methods to Address Cyber Risks

Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.

42 ENGINEERING↗

Adapting Traditional Hazards Analysis Methods to Address Cyber Risks

Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.

42 - ENGINEERING↗

Port Impedance Measurement and Current Injection Response Analysis for PLCs

Programmable Logic Controllers (PLCs) are used to control devices throughout the power system since they have fast control capabilities and can utilize multiple types of communication interfaces. Therefore, studying and mitigating their vulnerabilities to electromagnetic pulse is important for the reliability of PLC operations. Here, in this paper, an effective impedance measurement scheme is proposed and demonstrated for three PLCs to estimate their susceptibility to an electromagnetic pulse. The equivalent non-uniform transmission line model is established to eliminate the impact of the fixture in the de-embedding process. Then different parameters of the impedance measurement setup are explored. Based on the measured impedance, the equivalent circuit is established to calculate the response of the device when subjected to the electromagnetic pulse. The voltage and current responses of different interfaces are compared utilizing the developed pulsed Current Injection (CI) method. Finally, the impedance measurement scheme is verified through testing using three measuring instruments. And the CI simulation experiments reveal the characteristics and susceptibilities of different PLCs interfaces, indicating that some protection measures are required for the reliable operation of the PLC.

42 ENGINEERING↗

Linkages between riverine flooding risk and economic damage over the continental United States

Economic damages from riverine flooding are expected to grow because of climate change. Yet, there are few 7 studies analyzing flooding damages in the U.S. that clearly measure the roles of hazard, exposure, and vulnerability 8 separately and locally. A lack of this knowledge prohibits spatially detailed predictions of future damages. By being 9 able to separate into these three risk factors, we provide all necessary inputs for uncertainty analysis of the flooding-10 damages forecasts that can incorporate new predictive scenarios for each component. To analyze the flooding risk 11 factors of non-coastal counties within the contiguous U.S. between 1999-2018, we gathered information on (1) 12 property and human damages from flooding, (2) maximum annual river discharge, (3) the number of housing units 13 and the years in which they were built, and (4) the incidence of flooding events. We used the method of trimmed 14 least absolute deviated and trimmed least square estimators to obtain the individual impact of hazard, exposure, and 15 vulnerability in the context of censored flooding damages for panel data. The resulting estimates indicate that 16 exposure has been the main driver of flooding risk for most counties in the U.S. Here, we use these estimates to describe 17 the main source of flooding risk for non-coastal counties for the 1999-2018 period.

54 ENVIRONMENTAL SCIENCES↗

Navigating United States Standards and Regulation for Digital Energy Systems

This report provides an analysis of the U.S. standards and regulatory landscape for digital energy systems, focusing on cybersecurity, safety, and reliability requirements. It examines the interplay between federal mandates, state regulations, voluntary industry standards, and utility-specific policies, highlighting critical gaps between compliance and real-world risk mitigation. While NERC CIP standards enforce cybersecurity for Bulk Electric System assets, distribution-level infrastructure and emerging technologies often fall outside mandatory oversight, creating vulnerabilities. The report identifies systemic challenges such as reliance on self-attestation, uneven state adoption of safety codes, and lagging standards for advanced technologies like battery energy storage and inverter-based resources. Through a detailed gap analysis, it underscores the urgency of proactive risk-based approaches, independent verification, and strategic engagement with state and federal entities. Recommendations include adopting tiered security frameworks, strengthening procurement practices, and addressing emerging technology risks to ensure resilient and secure digital energy infrastructure. This guidance is intended for utilities, regulators, and stakeholders navigating compliance obligations and seeking to enhance cybersecurity and safety beyond minimum standards.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Defining and Measuring Forest Dependence in the United States: Operationalization and Sensitivity Analysis

This manuscript helps bridge a gap between theoretical work that advocates for a broad view of forest dependence, and empirical work that has focused narrowly on economic measures. Background: Forest dependence has been widely recognized as a valuable concept for understanding human communities’ well-being and vulnerability to shocks and changes. Past theoretical literature has highlighted the importance of recognizing various types of dependence—environmental, economic, and social—yet past empirical literature on the topic in the United States has almost exclusively relied on measures of economic dependence such as employment and earnings from the traditional forest products sector. Objective and Methods: As a first step to bridge the gap between the theoretical and empirical, we reviewed the existing, publicly available, reliable, wall-to-wall data sources to identify alternate proxy measures for forest dependence. Data availability made the analysis feasible only at the county level—the administrative subdivisions of the state—or higher. Results and Conclusions: We created environmental, economic, and social criteria based on threshold levels of the following proxy variables: forest area, earnings, employment, and indigenous population. Using these criteria, we identified 524 counties to be potentially forest-dependent of 3140 total counties in the United States. The largest concentration was in the Pacific Northwest and Southeast regions, and a higher proportion were non-metro counties than metro. Varying the threshold levels significantly changes the number of counties identified but does not alter the overall geographic trends.

54 ENVIRONMENTAL SCIENCES↗