Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Incident response”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

RCT Module 2.13: Radiological Incidents and Emergencies [Slides]

Emergency and incident response planning requires a detailed plan be in place. Each incident may be unique, and no plan can be expected to give an exact solution to every problem; however, a step-by-step approach for responding to a problem will ensure appropriate response.

61 RADIATION PROTECTION AND DOSIMETRY↗

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Canada-US Blended Cyber-Physical Security Exercise (Final Report)

The Canada-US Blended Cyber-Physical Exercise was a successful, first of its kind, multiorganization and multi-laboratory exercise that culminated years of complex system development and planning. The project aimed to answer three driving research questions, (1) How do cyberattacks support malicious acts leading to theft or sabotage [at a nuclear site]? (2) What are aspects of an effective combined cyber-physical response? (3) How to evaluate effectiveness of that response? Which derived the following primary objectives, 1. The May 2023 Cyber-Physical Exercise shall present a cyber-attack scenario that supports malicious acts leading to theft or sabotage. 2. The May 2023 Cyber-Physical Exercise shall define aspects of an effective combined cyber-physical response. 3. Analysis of the May 2023 Cyber-Physical Exercise shall evaluate the effectiveness of the incident response against pre-established exercise evaluation criteria. 4. Analysis of the May 2023 Cyber-Physical Exercise shall assess the effectiveness of the evaluation criteria itself. 5. Exercises shall be performed in a real-life environment. The team believes these objectives were met, and the evidence will be presented in this report. Due to the novelty of the exercise, there were several lessons learned that will be presented in this report.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Validating Protection System Behavior with Machine Learning in a Master State Overseer

As power system protection devices continue the widespread transition from analog to digital, they become increasingly intricate. The internal functions and communication between critical grid components must now be significantly more complex to keep up with the demands of the modern smart grid. This brings increased difficulty in maintenance and monitoring, making it harder to identify potential misoperation, power anomalies, and cyber threats. Such issues are often only pinpointed after an exhaustive and costly post-mortem analysis, when a major outage or damage has already occurred. A solution is needed for validating protection systems as they operate, independently evaluating grid state and confirming whether the protection system is behaving accordingly. As opposed to incident response, this acts as a constant verification mechanism that raises a flag when subtler issues are noticed, catching them earlier and preventing larger incidents. This work presents the implementation of such a system, expanding on the prototype developed by the authors in a previous paper. This is accomplished with a machine learning (ML) system capable of validating the performance of protection systems by classifying anomalous events and characterizing protection system responses based solely on available current and voltage measurements. Additionally, this system is contextualized within a larger, modular Master State awareness Overseer (MSO) framework, responsible for monitoring, analyzing, and managing an electric grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

A Software/Hardware Framework for Efficient and Safe Emergency Response in Post-Crash Scenarios of Battery Electric Vehicles

The adoption rate of battery electric vehicles (EVs) is rapidly increasing. Electric vehicles differ significantly from conventional internal combustion engine vehicles and vary widely across different manufacturers. Emergency responders (ERs) and recovery personnel may have less experience with EVs and lack timely access to critical information such as the extent of the stranded energy present, high-voltage safety hazards, and post-crash handling procedures in a user-friendly manner. This paper presents a software/hardware interactive tool named Electric Vehicle Information for Incident Response Solutions (EVIRS) to aid in the quick access to emergency response and recovery information. The current prototype of EVIRS identifies EVs using the VIN or Make, Model, and Year, and offers several useful features for ERs and recovery personnel. These features include integration and easy access to emergency response procedures tailored to an identified EV, vehicle structural schematics, the quick identification of battery pack specifications, and more. For EVs that are not severely damaged, EVIRS can perform calculations to estimate stranded energy in the EV’s battery and discharge time for various power loads using either EV dashboard information or operational data accessed through the CAN interface. Knowledge of this information may be helpful in the post-crash handling, management, and storage of an EV. The functionality and accuracy of EVIRS were demonstrated through laboratory tests using a 2021 Ford Mach-E and associated data acquisition system. The results indicated that when the remaining driving range was used as an input, EVIRS was able to estimate the pack voltage with an error of less than 3 V. Conversely, when pack voltage was used as an input, the estimated state of charge (SOC) error was less than 5% within the range of 30–90% SOC. Additionally, other features, such as retrieving emergency response guides for identified EVs and accessing lessons learned from archived incidents, have been successfully demonstrated through EVIRS for quick access. EVIRS can be a valuable tool for emergency responders and recovery personnel, both in action and during offline training, by providing crucial information related to assessing EV/battery safety risks, appropriate handling, de-energizing, transport, and storage in an integrated and user-friendly manner.

25 ENERGY STORAGE↗

Radiological Data Assessment Guidance for Emergency Response

This document provides guidance on how to apply data quality practices to measurements and information collected during the response and recovery to a radiological release. The process of applying data quality practices to measurement data is called data assessment. All data quality practices applied during a radiological incident response must balance the rigorous and time-consuming process normally applied to, for example, site decommissioning and decontamination, with the time- and resource-constraints present during emergency response. The guidance in this document presents the application of data quality practices for data assessment in a graded approach, where the recommended rigor increases as the response continues through its phases and as time and resource constraints relax.

54 ENVIRONMENTAL SCIENCES↗

Oakland University Cybersecurity Center (Final Scientific/Technical Report)

This report summarizes the outcomes of Award DE-CR0000023, “Oakland University Cybersecurity Center,” a 31-month project funded by the U.S. Department of Energy Office of Cybersecurity, Energy Security, and Emergency Response (CESER). The project addressed cybersecurity risks facing small and medium-sized manufacturers (SMMs) transitioning to Industry 4.0. The project integrated customer discovery, applied research, and cybersecurity training development. A total of 51 cybersecurity assessments identified significant gaps in baseline practices, incident response, and workforce capability. Research efforts produced a scalable mitigation framework tailored to SMM environments, and workforce analysis identified persistent talent gaps. Eight cybersecurity training modules were developed and deployed via Oakland University’s Professional and Continuing Education (PACE) platform. All objectives were completed, with 98.93% federal budget utilization and cost share exceeding requirements. The project establishes a scalable model for strengthening cybersecurity resilience and workforce capacity across U.S. manufacturing supply chains.

24 POWER TRANSMISSION AND DISTRIBUTION↗

From Count Rates to Quantifying Isotopic Activities – Field Analysis of Radiation Monitoring Data

The Nevada National Security Site (NNSS) provides a comprehensive bicoastal radiological and nuclear emergency response to United States Department of Energy/National Nuclear Security Administration. A major part of the support is to provide systematic radiological search for lost or stolen sources, Radiological search is a core competency of the NNSS with its origin dating back to nuclear weapons test era. Search operations from multiple platforms is the common thread among the various NNSS assets, which include Aerial Measuring System (AMS), Maritime Support Team (MST), National Capitol Response (NCR), National Search Team (NST) and Radiological Assistance Program (RAP). Information collected and analyzed during search operations add to the actionable intelligence for the law enforcement agencies and provide valuable guidance for the tactical resolution of a nuclear or radiological crisis. Search is an intelligence and situational awareness driven operation and most often called upon during a radiological emergency, however it can be brought into play to thwart a potential threat by providing monitoring and surveillance support. The Office of Nuclear Incident Response (NA-84) serves as the technical leader in responding to and resolving nuclear and radiological threats worldwide and integrates its efforts with other NNSA stakeholders (e.g., NNSA office of Defense Nuclear Non-proliferation NA-22). The response includes expertise in the areas of radiological search, render safe, and consequence management. This article will discuss the methodologies, tools, procedures, and techniques to extract maximum radiological characterization information (isotopic composition, activities for individual isotopes, threat assessment etc.) from field monitoring or Search operation data.

61 RADIATION PROTECTION AND DOSIMETRY↗

NIRP Core Software Suite v.5.1

SAND2023-06610O The Nuclear Incident Response Program (NIRP) Core Software Suite is a set of code that supports multiple applications. It includes miscellaneous base code for data objects, mathematic equations, and user interface components that are used for developing large applications, including those used for data management. Among the types of applications: • Analyst Manager is used for managing contact information, which is also often included in reports and identifies the owners of calculations. • Radionuclide Viewer provides access to the Dose Coefficient File Package (DCFPAK) radiological data, and it complements the Mixture Manager tool. • Mixture Manager creates and manages radionuclides mixtures that are commonly used in other applications. • High Explosive Manager manages explosives and properties. • Chart Viewer is used for data charts such as meteorology charts and other charts specific to data needs. • Unit Converter converts numeric values to/from different units. This package includes object-oriented base code such as data objects describing the date, time, and location of an event; weather conditions; data types that support predefined ranges of values; a unit library, and others. The package also includes mathematic equations such as determining the distance between two points; erf functions; factorial functions; incidence fractions of probit curves; and others. Other features are customized user interface components for text fields; unit selectors (combo boxes); menus; panels; bug-tracking; and automated checks for software updates. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Collins, Ian↗

Ransomware Exercise Phase 2 Executive Briefing [Slides]

In 2021: Los Alamos National Laboratory (LANL) conducted a Technical Ransomware Event (Phase 1). Phase 1 activities to restore to operations were successful, mission essential functions were restored. All incident response notifications derived during Phase 1 were completed.

97 MATHEMATICS AND COMPUTING↗

Dose Exceedance Distance Sensitivity Based on Parametric Uncertainty

Sandia National Laboratories (SNL) collaborated with the US Nuclear Regulatory Commission's (NRC) Office of Nuclear Security and Incident Response (NSIR) and Office of Nuclear Regulatory Research (RES) to investigate the reasonable variability in the estimation of dose exceedance distances. SNL performed calculations using the MACCS code to elucidate the sensitivity of dose exceedance distances to variations in user input parameters.

61 RADIATION PROTECTION AND DOSIMETRY↗

Compendium of Cyber Incident Notification Requirements for Critical Infrastructure Utilities by State

Cyber attacks targeting critical infrastructure in the United States are on the rise and pose serious risks to the economy and health and safety of its citizens. Experts suggest a sound cyber risk mitigation strategy includes constant monitoring for signs of cyber intrusions and rapid reporting of incidents so that other critical infrastructure operators may benefit from early warnings. Reporting incidents to Public Utility Commissions (PUCs) and other state agencies who have roles in energy emergency planning and incident response and recovery is essential for them to maintain situational awareness and provide necessary support to ensure rapid restoration of utility services, should disruptions occur.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Application of multi-criteria decision analysis techniques and decision support framework for informing plant select agent designation and decision making

The United States Department of Agriculture (USDA) Division of Agricultural Select Agents and Toxins (DASAT) established a list of biological agents (Select Agents List) that threaten crops of economic importance to the United States and regulates the procedures governing containment, incident response, and the security of entities working with them. Every 2 years the USDA DASAT reviews their select agent list, utilizing assessments by subject matter experts (SMEs) to rank the agents. We explored the applicability of multi-criteria decision analysis (MCDA) techniques and a decision support framework (DSF) to support the USDA DASAT biennial review process. The evaluation includes both current and non-select agents to provide a robust assessment. We initially conducted a literature review of 16 pathogens against 9 criteria for assessing plant health and bioterrorism risk and documented the findings to support this analysis. Technical review of published data and associated scoring recommendations by pathogen-specific SMEs was found to be critical for ensuring accuracy. Scoring criteria were adopted to ensure consistency. The MCDA supported the expectation that select agents would rank high on the relative risk scale when considering the agricultural consequences of a bioterrorism attack; however, application of analytical thresholds as a basis for designating select agents led to some exceptions to current designations. A second analytical approach used agent-specific data to designate key criteria in a DSF logic tree format to identify pathogens of low concern that can be ruled out for further consideration as select agents. Both the MCDA and DSF approaches arrived at similar conclusions, suggesting the value of employing the two analytical approaches to add robustness for decision making.

59 BASIC BIOLOGICAL SCIENCES↗

Exercise Design Guidance for Solar Cybersecurity

The intent of this resource is to provide recommendations on how State Energy Offices and Public Utility Commissions might design an energy emergency exercise, drill, or other simulation focused on solar cybersecurity scenarios . Exercise practitioners, planners, or facilitators interested in exploring solar cybersecurity incident response, preparedness, recovery, or mitigation may find this a valuable resource . This is an advanced supplementary resource for persons or entities with prior exercise experience and knowledge . It should not be used as a baseline educational resource for how to conduct and evaluate an exercise . It is based on a set of standard concepts, terms, and procedures that are common among the exercise community . This tool may be referenced in conjunction with the Hypothetical Solar Cyberattack Scenarios and Impacts tool within the CATSS Toolkit

14 SOLAR ENERGY↗

Software Bill of Materials in the Nuclear Industry

Nuclear power plants (NPP) have thousands of digital assets throughout their facility. Typically, NPPs have asset and configuration management programs that capture the make, model, and version of a component. This information, however, usually only includes first- or second-tier components and does not capture the complete enumeration of software components and their dependencies within operational technology (OT) equipment. As seen with recent cyberattacks, this level of detail is insufficient for identifying if and where an exploitable vulnerability exists within a facility. A software bill of materials (SBOM) provides this detailed enumeration. Further, integrating SBOMs with vulnerability data sources and vulnerability attestation reports can provide improved awareness leading to better cyber risk management and incident response. Preferably, SBOMs are provided by the supplier; however, when an NPP already owns a device, it is less likely they will have a supplier provided-SBOM. Fortunately, SBOMs can be generated on installed digital assets. This paper provides an introduction to the U.S. Department of Energy Office of Nuclear Energy paper titled “Towards Software Bill of Materials in the Nuclear Industry,” which describes the SBOM ecosystem and provides a suggested approach to methodically and seamlessly integrate an SBOM program in an NPP.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Investigation of Theoretical Solutions to a Bottom-Raised Oscillating Surge Wave Energy Converter (OSWEC) Through Experimental and Parametric Studies

Experiments were conducted on a wave tank model of a bottom raised oscillating surge wave energy converter (OSWEC) model in regular waves. The OSWEC model shape was a thin rectangular flap, which was allowed to pitch in response to incident waves about a hinge located at the intersection of the flap and the top of the supporting foundation. Torsion springs were added to the hinge in order to position the pitch natural frequency at the center of the wave frequency range of the wave maker. The flap motion as well as the loads at the base of the foundation were measured. The OSWEC was modeled analytically using elliptic functions in order to obtain closed form expressions for added mass and radiation damping coefficients, along with the excitation force and torque. These formulations were derived and reported in a previous publication by the authors. While analytical predictions of the foundation loads agree very well with experiments, large discrepancies are seen in the pitch response close to resonance. These differences are analyzed by conducting a sensitivity study, in which system parameters, including damping and added mass values, are varied. The likely contributors to the differences between predictions and experiments are attributed to tank reflections, standing waves that can occur in long, narrow wave tanks, as well as the thin plate assumption employed in the analytical approach.

analytical↗

Demonstrating the β-Ga 2 O 3 Schottky diodes for alpha radiation detection

Schottky barrier diodes were fabricated on (001) monoclinic β-Ga 2 O 3 wafers with low doped epitaxial layers of 7.0 × 10 15 cm −3 . Circular Ni Schottky contacts with area 2 mm 2 were deposited by electron beam evaporation. Devices were characterized electrically by performing forward and reverse current-voltage sweeps with a range of −100 V–2 V, as well as capacitance-voltage sweeps to −30 V. The breakdown voltage was also determined to be −180 V for the devices. Experiments measuring the electrical response from incident X-ray radiation was performed. A response time to X-ray radiation of less than 1 s was recorded and a decay time of approximately 2 s after removing X-ray source, which primarily attribute to X-ray switching on and off time. Energy spectra of alpha particles from a 0.9 μCi 241 Am button source was collected at various voltage biases using devices with the lowest measured leakage current while reverse biased. The total count rate was observed to increase linearly with increasing device bias. In conclusion, the peak channel number was observed to increase with increasing bias with the best resolution of 9.5% at −100 V reverse bias.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗