Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Techniques for fire detection

An overview is given of the basis for an analysis of combustable materials and potential ignition sources in a spacecraft. First, the burning process is discussed in terms of the production of the fire signatures normally associated with detection devices. These include convected and radiated thermal energy, particulates, and gases. Second, the transport processes associated with the movement of these from the fire to the detector, along with the important phenomena which cause the level of these signatures to be reduced, are described. Third, the operating characteristics of the individual types of detectors which influence their response to signals, are presented. Finally, vulnerability analysis using predictive fire modeling techniques is discussed as a means to establish the necessary response of the detection system to provide the level of protection required in the application.

Bukowski, Richard W.↗

Cybersecurity for Electric Vehicle Fast-Charging Infrastructure

The integration of electric vehicles (EVs) into electric grid operations can potentially leave the grid vulnerable to cyberattacks from both legacy and new equipment and protocols, including extreme fast-charging infrastructure. This paper introduces a co-simulation platform to perform cyber vulnerability analysis of EV charging infrastructure and its dependencies on communications and control systems. Grid impact scenarios through linkages to power system simulation tools such as OpenDSS and vehicle infrastructure-specific attack paths are discussed. An adaptive platform that assists with predicting and solving evolving cybersecurity challenges is demonstrated with a cyber-energy emulation that accelerates the analysis of cyberattacks and system behavior.

47 OTHER INSTRUMENTATION↗

Novel Geometric Operations for Linear Programming

This report summarizes the work performed under the project "Linear Programming in Strongly Polynomial Time." Linear programming (LP) is a classic combinatorial optimization problem heavily used directly and as an enabling subroutine in integer programming (IP). Specifically IP is the same as LP except that some solution variables must take integer values (e.g. to represent yes/no decisions). Together LP and IP have many applications in resource allocation including general logistics, and infrastructure design and vulnerability analysis. The project was motivated by the PI's recent success developing methods to efficiently sample Voronoi vertices (essentially finding nearest neighbors in high-dimensional point sets) in arbitrary dimension. His method seems applicable to exploring the high-dimensional convex feasible space of an LP problem. Although the project did not provably find a strongly-polynomial algorithm, it explored multiple algorithm classes. The new medial simplex algorithms may still lead to solvers with improved provable complexity. We describe medial simplex algorithms and some relevant structural/complexity results. We also designed a novel parallel LP algorithm based on our geometric insights and implemented it in the Spoke-LP code. A major part of the computational step is many independent vector dot products. Our parallel algorithm distributes the problem constraints across processors. Current commercial and high-quality free LP solvers require all problem details to fit onto a single processor or multicore. Our new algorithm might enable the solution of problems too large for any current LP solvers. We describe our new algorithm, give preliminary proof-of-concept experiments, and describe a new generator for arbitrarily large LP instances.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity for Electric Vehicle Fast-Charging Infrastructure: Preprint

The integration of electric vehicles (EVs) into electric grid operations can potentially leave the grid vulnerable to cyberattacks from both legacy and new equipment and protocols, including extreme fast-charging infrastructure. This paper introduces a co-simulation platform to perform cyber vulnerability analysis of EV charging infrastructure and its dependencies on communications and control systems. Grid impact scenarios through linkages to power system simulation tools such as OpenDSS and vehicle infrastructure-specific attack paths are discussed. An adaptive platform that assists with predicting and solving evolving cybersecurity challenges is demonstrated with a cyber-energy emulation that accelerates the analysis of cyberattacks and system behavior.

47 OTHER INSTRUMENTATION↗

Cybersecurity for Fast Charging EV Infrastructure

The integration of electric vehicles (EVs) into electric grid operations can potentially leave the grid vulnerable to cyberattacks from both legacy and new equipment and protocols, including extreme fast-charging infrastructure. This paper introduces a co-simulation platform to perform cyber vulnerability analysis of EV charging infrastructure and its dependencies on communications and control systems. Grid impact scenarios through linkages to power system simulation tools such as OpenDSS and vehicle infrastructure-specific attack paths are discussed. An adaptive platform that assists with predicting and solving evolving cybersecurity challenges is demonstrated with a cyber-energy emulation that accelerates the analysis of cyberattacks and system behavior.

ADVANCED PROPULSION SYSTEMS,POWER TRANSMISSION AND↗

Cyber–physical vulnerability and resiliency analysis for DER integration: A review, challenges and research needs

High penetration of renewable and sustainable Distributed Energy Resources (DER) into the traditional distribution system requires a well-coordinated control strategy for the improvement of system-wide reliability and resiliency. Implementation of such a holistic control architecture requires a flexible, near real-time, and bi-directional communication framework for facilitating the participation of various agents in a multi-vendor heterogeneous smart grid. While the sustainability of energy generation is ensured, this exposes the smart grid to extrinsic cyber threats, and appropriate defense mechanism(s) must be deployed to guarantee continued reliability and resiliency of the power grid. Further, the comprehensive literature review presented in this paper discusses the latest trends in the DER control schemes with fast communication requirements and their accompanying cyber–physical vulnerabilities. These control schemes are compared and contrasted for various traits. A three-level DER system architecture has been depicted, facilitating the deployment of these control schemes. The current developments of standard communication protocols, key security mechanisms, and best practices along major standards and guidelines are explored. The impacts of different attack types with miscellaneous DER functions based on various control schemes and associated mitigation solutions are also provided. Finally, challenges and future research directions for limiting cyber-power susceptibility to enhance resiliency are summarized. The work presented here will help us enabling a cyber-resilient and sustainable smart electric grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Utilizing Open-Source Earth Observations to Inform the Toa Baja Municipality’s Flood Risk Mitigation Efforts and Educate the Public

Global climate changes contribute to more intense and frequent tropical storms, subjecting places like Toa Baja, Puerto Rico to critical damage. Known as “the underwater city” due to its propensity to flood, residents of Toa Baja face constant flood risk. During extreme tropical storm events, such as Hurricane Maria in 2017, residents experienced up to 20 feet of inundation. The NASA DEVELOP National Program collaborated with the Municipio Autónomo de Toa Baja, ResilientSEE-PR, and the MIT Urban Risk Lab to supplement 2018 FEMA HEC-RAS flood maps that designate 63% of Toa Baja as a flood plain. This analysis provides a high-resolution interpretation of flood risk through two lenses; susceptibility and vulnerability. For this analysis, susceptibility consists of nine weighted layers: NDVI, landcover, slope, elevation, topographic wetness index, height above nearest drainage, saturated hydraulic conductivity, distance to water, and storm surge. These factors are consistently used to evaluate susceptibility to flood, but their weights vary by analysis. Vulnerability consists of population, informal settlements, and building density, which were given equal weight. Susceptibility and vulnerability were combined to map flood risk. This analysis used a bivariate legend to understand the different levels of risk along a spectrum from low susceptibility and low vulnerability (low risk) to high susceptibility and high vulnerability (high risk). Data processed in Google Earth Engine, which identified historical inundation on various occasions, were used to validate the flood susceptibility layers. Results showed 89% of areas designated as high susceptibility are located within the floodway designated by the FEMA HEC-RAS maps. The eastern region of Toa Baja is most at risk for flooding due to high susceptibility to flooding along with a high density of population, buildings, and informal settlements. The resulting map also reveals the presence of smaller high-risk areas all around the municipality. This analysis provides scientific evidence for flood risk mitigation in Toa Baja by highlighting areas that might be impacted by strong floods in the future. Additionally, these results are communicated in an Esri ArcGIS StoryMap, an accessible platform that can easily inform the public about the flood risk in their neighborhood.

Adriana Le Compte↗

Cyber Security for the Spaceport Command and Control System: Vulnerability Management and Compliance Analysis

With the rapid development of the Internet, the number of malicious threats to organizations is continually increasing. In June of 2015, the United States Office of Personnel Management (OPM) had a data breach resulting in the compromise of millions of government employee records. The National Aeronautics and Space Administration (NASA) is not exempt from these attacks. Cyber security is becoming a critical facet to the discussion of moving forward with projects. The Spaceport Command and Control System (SCCS) project at the Kennedy Space Center (KSC) aims to develop the launch control system for the next generation launch vehicle in the coming decades. There are many ways to increase the security of the network it uses, from vulnerability management to ensuring operating system images are compliant with securely configured baselines recommended by the United States Government.

Cyber Security↗

Forensic Analysis of SOHO Router Binaries

Small Office/Home Office (SOHO) routers are used by millions of consumers across the United States, and are commensurately vulnerable. Forensic analysis of SOHO router firmware helps to understand and mitigate those vulnerabilities. This poster focused particularly on analysis of BusyBox executables, a software suite that provides several Unix utilities in a single file. Three main tools were used to analyze the binaries. BinWalk was used to extract the files, but also to build entropy graphs, extract Linux kernel images, and identify CPU architectures; WiiBin processed the binaries to find endianness, architecture, the percent compressed/encrypted, and compiler data; and @DisCo, a machine learning tool used to determine function similarity in disassembled binaries, analyzed similarities and determined versions of extracted BusyBox files from each router. These tools found that venders from all five routers utilized the same version of the BusyBox software across different firmware updates, demonstrating the importance of constant firmware scrutiny to protect against security vulnerabilities.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A probabilistic analysis of electrical equipment vulnerability to carbon fibers

The statistical problems of airborne carbon fibers falling onto electrical circuits were idealized and analyzed. The probability of making contact between randomly oriented finite length fibers and sets of parallel conductors with various spacings and lengths was developed theoretically. The probability of multiple fibers joining to bridge a single gap between conductors, or forming continuous networks is included. From these theoretical considerations, practical statistical analyses to assess the likelihood of causing electrical malfunctions was produced. The statistics obtained were confirmed by comparison with results of controlled experiments.

Elber, W.↗

Security Vulnerability Profiles of Mission Critical Software: Empirical Analysis of Security Related Bug Reports

While some prior research work exists on characteristics of software faults (i.e., bugs) and failures, very little work has been published on analysis of software applications vulnerabilities. This paper aims to contribute towards filling that gap by presenting an empirical investigation of application vulnerabilities. The results are based on data extracted from issue tracking systems of two NASA missions. These data were organized in three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified security related software bugs and classified them in specific vulnerability classes. Then, we created the security vulnerability profiles, i.e., determined where and when the security vulnerabilities were introduced and what were the dominating vulnerabilities classes. Our main findings include: (1) In IVV issues datasets the majority of vulnerabilities were code related and were introduced in the Implementation phase. (2) For all datasets, around 90 of the vulnerabilities were located in two to four subsystems. (3) Out of 21 primary classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, they contributed from 80 to 90 of vulnerabilities in each dataset.

Goseva-Popstojanova, Katerina↗

Geospatial Capabilities to Couple Hazard and Social Vulnerability Data in Water Distribution Criticality Analysis

A resilience analysis of a water distribution system is greatly enhanced by the integration of up-to-date geospatial data describing the water system, hazards, and surrounding community. The Water Network Tool for Resilience (WNTR), an open-source Python package designed to simulate and analyze the resilience of water distribution systems, was recently updated to incorporate geographic information system (GIS) data into the resilience analysis. This paper describes the GIS capabilities and includes a case study using the drinking water distribution system model for a large city in Pennsylvania. The case study focuses on potential pipe damage from landslides and on pipes that are particularly difficult to repair. The analysis couples data on hazards, social vulnerability, and the location of emergency services to identify and prioritize high-impact critical infrastructure for mitigation. Results demonstrate that pipes can be prioritized for mitigation based on water shortage and vulnerable populations that are affected. In conclusion, the methods can be adopted for general use and are available as part of the WNTR software.

GIS, landslide↗

FIND: A Synthetic weather generator to control drought Frequency, Intensity, and Duration

Water systems worldwide are experiencing climate change-induced shifts in drought properties like frequency, intensity, and duration, affecting water security and reliability. To develop and test effective drought preparedness plans, researchers often use synthetic weather generators to create hydrological scenarios that explore drought variability beyond historical records. Existing weather generators typically allow users to adjust streamflow statistics like percentiles or temporal correlation but do not directly control drought properties of frequency, intensity, and duration. To fill this gap, we propose FIND (Frequency, INtensity, and Duration) synthetic weather generator. FIND incorporates a standardized drought index to directly and in dependently control drought frequency, intensity, and duration in generated streamflow time series while preserving observed hydrological variability. Use cases for FIND include i) water systems analysis applications that seek to train and test drought strategies under historical and plausible future drought conditions, and ii) bottom-up vulnerability studies relating system vulnerability outcomes to specific changes in drought properties of frequency, intensity, and duration. Here, we demonstrate FIND’s versatility through three experiments: replicating historically observed drought properties, generating streamflow scenarios for multiple sites preserving correlation between their drought conditions, and generating a set of scenarios with direct and independent changes in drought properties. FIND source code is openly available for applications beyond the scope of this paper.

42 ENGINEERING↗

Supporting U.S. National Security Through Cybersecurity Partnerships

At NLR, we're studying energy evolutions and threats to understand the challenges they pose and uncover ways to leverage grid advancements to achieve more secure, defensible, and reliable systems. Our integrated research approach bridges the gap between cyber threats and real-world consequences to deliver actionable solutions that reduce vulnerabilities and help strengthen U.S. national security.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Standards for Distributed Energy Resources: Gaps and Harmonization Strategy

This report examines cybersecurity standards for Distributed Energy Resources (DERs) in light of their rapid growth and increasing integration into energy systems. It identifies critical gaps in existing frameworks, including inadequate coverage of DER-specific challenges, complexities in implementing comprehensive standards, integration issues with legacy systems, adoption hurdles for newer standards, and a lack of harmonization across regulatory landscapes. The analysis highlights vulnerabilities such as data integrity risks, unauthorized device control, and denial-of-service attacks across various DER technologies like solar PV, wind turbines, energy storage systems, and hydrogen fuel cells. The report proposes a harmonization strategy to address these deficiencies by developing unified cybersecurity requirements, certification programs, and training resources while fostering collaboration among stakeholders such as government agencies, industry groups, DER operators, manufacturers, and research institutions. A phased roadmap is outlined to refine and implement these measures through pilot testing and widespread adoption. Ultimately, the report underscores the urgent need for coordinated efforts to enhance DER cybersecurity and ensure the reliable operation of future energy systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗