Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability Research”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Development of the Contamination Distribution Centered Toxics Mobility Vulnerability Index in the Beaumont–Port Arthur Region of Texas

This study advances the Toxics Mobility Inventory (TMI) and the Toxics Mobility Vulnerability Index (TMVI) to develop a new tool to assess the movement of hazardous substances and their implications for vulnerable communities. It emphasizes the need to include contamination distribution variables in such indices to address disproportionate impacts and more accurately reflect vulnerability. The study uses the TMI framework and TMVI methodology in the Beaumont–Port Arthur region of Texas, also integrating contamination distribution considerations into the analysis to develop a new framework and process. The new Contamination Distribution Centered Toxics Mobility Vulnerability Index (CDC-TMVI) consolidates climate change and topography variables into a broader built environment vulnerability category while introducing a contamination sources category. Using ArcGIS Pro and ToxPi tools, the study evaluates 27 geospatial variables across four categories: built environment vulnerability, social vulnerability, health outcomes, and contamination sources. The results indicate significant contributions from contamination and social vulnerability variables, highlighting areas with higher risks of flooding and air pollution. This article advocates for future research and policy efforts to enhance the integration of contamination sources and their spatial distributions into toxics mobility assessments to better protect vulnerable populations. Furthermore, the unique methodology and findings serve as a basis for developing targeted measures and strategic planning to improve environmental health.

contamination↗

Geologic Seawater Air Conditioning (GeoSWAC) System: Resource Assessment and Techno-Economic Evaluation in Puerto Rico

Puerto Rico's hot, humid climate drives a high and persistent demand for cooling, straining an aging and fuel-dependent energy grid while increasing peak electricity loads. Much of this challenge stems from inefficient air-conditioning systems operating in buildings without passive cooling design, making cooling both costly and vulnerable to disruption - especially during hurricanes. To address these issues, researchers evaluated a new alternative called Geologic Seawater Air Conditioning (GeoSWAC), which uses inland wells connected to naturally cold, deep seawater. By avoiding long offshore pipelines and energy-intensive refrigeration cycles, GeoSWAC can cut electricity use by 75-90%, reduce environmental impacts, and operate more reliably during power outages. A case study at the University of Puerto Rico's Rio Piedras campus found that GeoSWAC could deliver significantly lower levelized costs of cooling, reduced operational expenses, and improved water conservation compared to the campus's existing chilled-water plant. The system offers key advantages - including access to a constant cold heat sink, low pumping requirements, and enhanced resilience - for coastal regions such as Puerto Rico, the broader Caribbean, and Florida. However, its effectiveness depends heavily on site-specific geological conditions, such as subsurface connectivity and aquifer characteristics, which require detailed investigation. Future research should refine hydrogeological models, conduct performance and economic analyses, and address regulatory and permitting frameworks to support broader adoption of this promising technology.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Roadmap for the future of extreme wildfire events

Background Extreme wildfire events (EWEs) represent a growing threat globally, posing substantial risks to ecosystems, human communities, and infrastructure. Despite increased recognition of their ecological, social, and economic significance, current definitions of EWEs vary widely, reflecting disciplinary biases and regional contexts. This article emerges from an interdisciplinary workshop convened to reassess and refine the definition of EWEs, examine their impacts across ecological and social dimensions, and identify critical knowledge gaps impeding our understanding of these infrequent but important events. Results Our synthesis highlights significant limitations with existing definitions, particularly their reliance on subjective thresholds and their emphasis on extreme fire behavior alone. EWEs encompass a spectrum of complex, multi-dimensional phenomena that extend beyond immediate biophysical characteristics to include cumulative social, economic, and ecological impacts. These impacts often manifest over extended timeframes and include hazardous environmental contamination, severe geomorphic disturbances, ecosystem transformations, and unintended consequences of post-fire management actions. Current wildfire modeling frameworks inadequately capture these compounding factors, particularly the interactions among social systems, ecological conditions, and extreme fire behavior. To overcome these issues, we advocate for an interdisciplinary and context-sensitive approach to defining and studying EWEs. This revised definition emphasizes wildfires exhibiting anomalies in fire behavior, ecological outcomes, or social impacts relative to historically observed baselines, accommodating variability across different geographic regions and ecological settings. Conclusions Adopting an interdisciplinary framework that integrates biophysical and social sciences will enhance the predictive capability of wildfire models and improve resilience planning and response strategies. Filling identified knowledge gaps—such as limited high-quality empirical fire behavior data and insufficient integration of social dynamics into modeling—will better prepare communities and ecosystems to cope with and adapt to EWEs. This inclusive approach underscores the necessity for collaboration across disciplines and sectors, essential to managing extreme wildfires in an era of increasing climatic and ecological uncertainty.

54 ENVIRONMENTAL SCIENCES↗

Blueprint: Coordinated Vulnerability Disclosure (CVD) Adaption and Adoption Guide for Industry To Create Their Own CVD Program

This guide provides a series of steps and guidance for electric vehicle supply equipment (EVSE) industry members to set up their own coordinated vulnerability disclosure (CVD) program by utilizing the Software Engineering Institute/Computer Emergency Response Team (SEI/CERT)’s CVD how-to guide. Due to the complexity of CVD, and with the existing resources out there, this guide is intended that this portion of the blueprint is an extension of the CVD how-to guide, not meant as a replacement. This guide is meant to outline a process for what to do when you discover a vulnerability on EVSE equipment. It is written for developers, vendors and security researchers as well as management. This is not a technical document. It is meant to be accessible for both technical and non-technical roles.

33 ADVANCED PROPULSION SYSTEMS↗

Nanoporous Wood Chips Based Sizable, Robust, and Low-Cost Honeycomb Vacuum Insulation Panels (DOE BENEFIT Final Research Performance Progress Report (RPPR))

Conventional vacuum insulation panels (VIPs) suffer from severe limitations including high cost, vulnerability to perforation, and significant performance degradation over time due to vacuum loss. InventWood Inc. (IW) and partnering teams completely re-engineered the VIP structure by constructing arrays of isolated vacuum-cells to enable limited cutting at designated areas (in between vacuum cells) and reduced consequential vacuum loss due to puncture. The teams also replaced the expensive vacuum insulation core materials with a low-cost commercial wood pulp and recycled long fiber. The wood pulp derived VIP can deliver an overall panel insulation of R15 (<0.01W/m·K) with over 90% thermal resistance retention after cutting (R13.5 overall, R5 along the cut edges). In addition, the vacuum-cell-array design minimizes edge losses, resulting in more durable performance, longer service life (>50 years), and higher R-value per dollar towards a cost target of <$1/ft 2 ·in. It is anticipated that the Nanochip-VIP will attract strong market interest and become an affordable insulation solution for energy efficient buildings and retrofits, leading to significant reductions in energy usage.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

The Effects of Compounded Model Size Reductions on Adversarial Robustness

Recent advances in Edge AI and Tiny Machine Learning (TinyML) have enabled the deployment of machine learning models on resource-constrained environments. However, deploying these models on edge devices, such as micro-controllers, requires significant model footprint reduction through a variety of techniques such as quantization, pruning, and clustering. While these optimization methods offer considerable advantages, they potentially introduce AI-related security vulnerabilities, particularly concerning model robustness with respect to adversarial AI attacks. Prior research has extensively examined the impact of quantization on adversarial robustness; however, the effects of alternative reduction techniques and their combinations remain understudied. This paper investigates the impact of model size reduction techniques on adversarial robustness, when applied individually and combined. We utilized Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) attacks to generate adversarial perturbations for both training and testing data, and then evaluated the models' accuracy under adversarial training conditions. Our findings revealed that reduction techniques generally diminished robustness; although, combining techniques was not found to make robustness any worse than when applied individually. Moreover, specific techniques can potentially enhance resistance to small size perturbations. This research provides insights into the trade-offs between model size reduction and security, establishing a foundation for future investigations into improving adversarial training techniques and methodologies for maintaining robustness while preserving memory footprint benefits.

Austria, Phillipe [ORNL] (ORCID:0000000236223973)↗

Investigating Resiliency of Transportation Network under Targeted and Potential Climate Change Disruptions

Ensuring robustness and resilience in intermodal transportation systems is essential for the continuity and reliability of global logistics. These systems are vulnerable to various disruptions, including natural disasters and technical failures. Despite significant research on freight transportation resilience, investigating the robustness of the system after targeted and climate-change-driven disruption remains a crucial challenge. Drawing on network science methodologies, this study models the interdependencies within the rail and water transport networks and simulates different disruption scenarios to evaluate system responses. Here, we use the data from the U.S. Department of Energy Volpe Center for network topology and tonnage projections. The proposed framework quantifies deliberate, stochastic, and climate-driven infrastructure failure, using higher resolution downscaled multiple Earth System Models’ simulations from Coupled Model Intercomparison Project Phase version 6. We show that the disruptions of a few nodes could have a larger impact on the total tonnage of freight transport than on network topology. For example, the removal of targeted 20 nodes can bring the total tonnage carrying capacity to 30% with about 75% of the rail freight network intact. This research advances the theoretical understanding of transportation resilience and provides practical applications for infrastructure managers and policymakers. By implementing these strategies, stakeholders and policymakers can better prepare for and respond to unexpected disruptions, ensuring sustained operational efficiency in transportation networks.

Climate Change Disruptions↗

Electric Vehicle Charging Data Falsification Attacks Utilizing Behavioral Models

A charging station (CS) and its associated electric vehicle supply equipment (EVSE) and charging electric vehicle (EV) interactions are potential targets for data falsification attacks since CSs are typically unmanned public facilities that are connected to the internet and EVs incorporate the vulnerable CAN bus network, which are both susceptible to remote attacks. The research question being addressed is how is the EV owner and CS negatively affected by CAN bus EV battery current sensor and battery temperature sensor data falsification attacks. Negative effects include economic losses from reduced life span of the battery, battery thermal runaway and fire (and potential loss of surrounding structure), and reduced utilization of the CS due to delayed departure time (longer charging times).

25 ENERGY STORAGE↗

The UCAR Africa Initiative: Recent insights, challenges, and opportunities to foster collaborative research for environmental sustainability

Africa is increasingly being exposed to the negative impacts of climate and environmental change, while having less capacity to respond compared to other continents. The vulnerability partially results from unprecedented demographic growth, urbanization, and industrialization. However, the continent has still largely been underserved by the broader Earth System Science (ESS) community, as evidenced by the limited amount of ESS data and research that cover Africa compared to other areas of the world. Here we present the recent University Corporation for Atmospheric Research (UCAR) Africa Initiative that aims to enhance environmental sustainability in Africa by fostering international collaborative research partnerships co-led by African scientists. Specifically, we outline urgent challenges and opportunities identified through an international workshop in six areas of ESS namely (1) air quality and health, (2) weather, (3) climate, (4) land and water, (5) social science perspectives, and (6) developing equitable collaboration and sustainable infrastructure. We highlight examples of successful partnerships and conclude with recommendations to advance collaborative, actionable ESS research that addresses Africa’s critical environmental challenges.

African weather and land variability↗

PSInet: a new global water potential network

Abstract Given the pressing challenges posed by climate change, it is crucial to develop a deeper understanding of the impacts of escalating drought and heat stress on terrestrial ecosystems and the vital services they offer. Soil and plant water potential play a pivotal role in governing the dynamics of water within ecosystems and exert direct control over plant function and mortality risk during periods of ecological stress. However, existing observations of water potential suffer from significant limitations, including their sporadic and discontinuous nature, inconsistent representation of relevant spatio-temporal scales and numerous methodological challenges. These limitations hinder the comprehensive and synthetic research needed to enhance our conceptual understanding and predictive models of plant function and survival under limited moisture availability. In this article, we present PSInet (PSI—for the Greek letter Ψ used to denote water potential), a novel collaborative network of researchers and data, designed to bridge the current critical information gap in water potential data. The primary objectives of PSInet are as follows. (i) Establishing the first openly accessible global database for time series of plant and soil water potential measurements, while providing important linkages with other relevant observation networks. (ii) Fostering an inclusive and diverse collaborative environment for all scientists studying water potential in various stages of their careers. (iii) Standardizing methodologies, processing and interpretation of water potential data through the engagement of a global community of scientists, facilitated by the dissemination of standardized protocols, best practices and early career training opportunities. (iv) Facilitating the use of the PSInet database for synthesizing knowledge and addressing prominent gaps in our understanding of plants’ physiological responses to various environmental stressors. The PSInet initiative is integral to meeting the fundamental research challenge of discerning which plant species will thrive and which will be vulnerable in a world undergoing rapid warming and increasing aridification.

Forestry↗

Safe Operations at Roadway Junctions: Intelligent Roadway Infrastructure as Functional Interlocking

Automated vehicle (AV) technology is quickly maturing, and the corresponding infrastructure systems that evaluate traffic and communicate to vehicles requires sophisticated sensing and perception technologies, referred to as intelligent roadway infrastructure (IRI), to complement emerging AV capabilities. IRI provides signals to vehicles, indicating right-of-way for vehicles and communicating to approaching AVs that no other vehicle is failing to yield. This capability, denoted as safety-affirmative signaling, provides a green light or a green arrow as appropriate and affirms through communication links to connected vehicles when it is safe to proceed. About 36% of collisions occur at intersections, with most occurring upon left turns (22.2%) or crossing over (12.6%), and only a small percentage (1.2%) while turning right at an intersection. Of all intersection crashes about half (52.5%) of those vehicles were traveling through a signalized intersection 2. Safety-affirmative signaling would guarantee safety of AV fleet vehicles, by providing the interlocking principle, a term from automated train control that only allows progression through a railway intersection after affirming no opportunity for a crash exists. IRI through safety-affirmative signaling would bring performance and safety to complex roadway intersections where AV transit fleet service is most needed, as well as safety benefits to traditional, non-automated vehicles and vulnerable road users. The implementation of IRI has functional, programmatic, and technical challenges. Research work performed at the National Renewable Energy Laboratory (NREL) in an integrative approach encapsulating these themes, and termed infrastructure perception and control (IPC) is motivated by improved performance (travel time), improved safety (reduced collisions), and improved energy efficiency (less fuel burned and minimized production of greenhouse gases). IPC is intended not only for roadway and intersection applications but also in extension to inform complementary buildings and grid systems to enable better co-management, as vehicles and their charging needs become increasingly integrated into the built environment. The NREL IPC project presents an open-source framework, architecture, and supporting technology to implement IRI, addressing critical issues such as fusion of data, reliability, standardization of data interfaces, and confidence of detection. The framework is informed by previous experience in U.S. Department of Defense research technology, specifically in the use of radar to detect, identify, and track aerial threats. These principles combined with multi-sensor fusion provides for a complete digital twin with known and measurable confidence and accuracy from which safety-affirmative signaling can be developed and deployed.

ADVANCED PROPULSION SYSTEMS,MATHEMATICS AND COMPUT↗

Distribution System Resilience Assessment Considering PV Vulnerabilities for Hurricane Events

Distribution networks are increasingly vulnerable to damage and outages from extreme weather events. The integration of solar photovoltaics (PVs) further complicates resilience analysis due to its weather-dependent nature. However, limited research has examined the impacts of weather on PVs under severe events like hurricanes. This paper proposes a probabilistic framework to assess distribution system resilience considering PV vulnerabilities during hurricanes. The framework incorporates (i) a spatiotemporal fragility model to evaluate failure probabilities for distribution lines and PVs, and (ii) resilience indices at both system and component levels. The approach offers valuable insights into the resilience of modern distribution grids under extreme weather conditions. Numerical results on the unbalanced IEEE 123-bus test system validate the effectiveness of the framework.

Vahedi, Soroush [University of Connecticut, Storrs↗

Capabilities for Water Sector Infrastructure Resilience - Prioritizing RD&D in a Target Rich, Resource Poor Sector

WSTB & Water Sector Security Program Expansion Objective: Incubate and shepherd a public-private consortium of joint seal US government sponsors and industry stakeholders to build out industrial control system (ICS) and operational technology (OT) architecture of the Idaho National Laboratory (INL) Water Security Test Bed (WSTB) asset to enable research, testing, and cyber workforce training related to evolving cyber-physical and physical vulnerabilities and threats in the water sector.

99 - GENERAL AND MISCELLANEOUS↗

Advanced Research on Integrated Energy Systems Cyber Range

As digital technologies expand to meet the needs of a more autonomous, interconnected, and advanced power system, new cybersecurity complexities and vulnerabilities arise. The ARIES Cyber Range enables the energy sector to evaluate these evolutions and validate cybersecurity solutions without impacting live systems. Combining power grid-scale hardware with emulation and simulation approaches, the ARIES Cyber Range can faithfully replicate modern energy systems - from grid physics to communication networks, and everything in between - with real-world fidelity. At NLR, researchers and partners are answering complex power system cybersecurity questions, examining emerging threats to the electric sector, and de risking new security technologies, all at a mission-relevant speed that keeps pace with rapidly evolving systems and hazards.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Hardware Fuzzing with An Emulator

Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.

42 ENGINEERING↗

V-INT: Automated Vulnerability Intelligence and Risk Assessment

The project team, including the University of Arkansas (UA) as the lead, the University of Arkansas at Little Rock (UALR), Network Perception (NP), and Bastazo, has successfully researched, developed, and demonstrated the V-INT toolset, and also integrated it into the commercial products of NP (i.e., NP-View) and Bastazo (i.e., Spartan). The end product is a cybersecurity software tool for energy utilities that can automatically assess the risks of software vulnerabilities in an organization’s assets considering the organization’s firewall policies. It allows security operators to identify the small portion of vulnerabilities that poses true threats to their system (i.e., those that are not protected by firewall policies) and prioritize the mitigation of these vulnerabilities to minimize risks. It also allows security operators to identify the vulnerability-induced attack paths under their organization’s firewall policy, providing effective decision supports for mitigating potential attacks.

97 MATHEMATICS AND COMPUTING↗

A distributed voltage inference framework for cyber-physical attacks detection and localization in active distribution grids

The transition to active distribution grids with real-time monitoring and control depends on the proliferation of advanced communication networks and devices. This paradigm shift towards a cyber-physical architecture also introduces new vulnerabilities for adversaries to exploit and launch sophisticated cyber-physical attacks targeting grid observability. Current research highlights the challenges in distinguishing attacks on voltage phasor or nodal injection measurements and isolating multi-source attack locations in a multiphase distribution grid. The attack detection and localization methods in literature face accuracy issues, applications across diverse attack scenarios, or scalability limits. Here, to bridge these gaps, this paper proposes a distributed Voltage Inference framework for real-time detection and localization of cyber-physical attacks, addressing scalability, adaptability, and accuracy challenges in state-of-the-art methods. The proposed methodology leverages the distributed nature of the Voltage Inference framework through a two-step process of prediction and correction, together with a tractable graph partitioning approach, providing a reliable solution to identify compromised measurement sources and facilitate isolation. Extensive testing on IEEE 13 and 123-node distribution feeders underscores the algorithm’s efficacy, enhancing the security and resilience of active distribution grids against evolving cyber threats. Additionally, Hardware-in-the-Loop (HIL) implementation validates the proposed strategy’s practical applicability in real-world scenarios.

active distribution grids↗