Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “vulnerability analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Cybersecurity for Fast Charging EV Infrastructure

The integration of electric vehicles (EVs) into electric grid operations can potentially leave the grid vulnerable to cyberattacks from both legacy and new equipment and protocols, including extreme fast-charging infrastructure. This paper introduces a co-simulation platform to perform cyber vulnerability analysis of EV charging infrastructure and its dependencies on communications and control systems. Grid impact scenarios through linkages to power system simulation tools such as OpenDSS and vehicle infrastructure-specific attack paths are discussed. An adaptive platform that assists with predicting and solving evolving cybersecurity challenges is demonstrated with a cyber-energy emulation that accelerates the analysis of cyberattacks and system behavior.

ADVANCED PROPULSION SYSTEMS,POWER TRANSMISSION AND↗

Cyber–physical vulnerability and resiliency analysis for DER integration: A review, challenges and research needs

High penetration of renewable and sustainable Distributed Energy Resources (DER) into the traditional distribution system requires a well-coordinated control strategy for the improvement of system-wide reliability and resiliency. Implementation of such a holistic control architecture requires a flexible, near real-time, and bi-directional communication framework for facilitating the participation of various agents in a multi-vendor heterogeneous smart grid. While the sustainability of energy generation is ensured, this exposes the smart grid to extrinsic cyber threats, and appropriate defense mechanism(s) must be deployed to guarantee continued reliability and resiliency of the power grid. Further, the comprehensive literature review presented in this paper discusses the latest trends in the DER control schemes with fast communication requirements and their accompanying cyber–physical vulnerabilities. These control schemes are compared and contrasted for various traits. A three-level DER system architecture has been depicted, facilitating the deployment of these control schemes. The current developments of standard communication protocols, key security mechanisms, and best practices along major standards and guidelines are explored. The impacts of different attack types with miscellaneous DER functions based on various control schemes and associated mitigation solutions are also provided. Finally, challenges and future research directions for limiting cyber-power susceptibility to enhance resiliency are summarized. The work presented here will help us enabling a cyber-resilient and sustainable smart electric grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Forensic Analysis of SOHO Router Binaries

Small Office/Home Office (SOHO) routers are used by millions of consumers across the United States, and are commensurately vulnerable. Forensic analysis of SOHO router firmware helps to understand and mitigate those vulnerabilities. This poster focused particularly on analysis of BusyBox executables, a software suite that provides several Unix utilities in a single file. Three main tools were used to analyze the binaries. BinWalk was used to extract the files, but also to build entropy graphs, extract Linux kernel images, and identify CPU architectures; WiiBin processed the binaries to find endianness, architecture, the percent compressed/encrypted, and compiler data; and @DisCo, a machine learning tool used to determine function similarity in disassembled binaries, analyzed similarities and determined versions of extracted BusyBox files from each router. These tools found that venders from all five routers utilized the same version of the BusyBox software across different firmware updates, demonstrating the importance of constant firmware scrutiny to protect against security vulnerabilities.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Geospatial Capabilities to Couple Hazard and Social Vulnerability Data in Water Distribution Criticality Analysis

A resilience analysis of a water distribution system is greatly enhanced by the integration of up-to-date geospatial data describing the water system, hazards, and surrounding community. The Water Network Tool for Resilience (WNTR), an open-source Python package designed to simulate and analyze the resilience of water distribution systems, was recently updated to incorporate geographic information system (GIS) data into the resilience analysis. This paper describes the GIS capabilities and includes a case study using the drinking water distribution system model for a large city in Pennsylvania. The case study focuses on potential pipe damage from landslides and on pipes that are particularly difficult to repair. The analysis couples data on hazards, social vulnerability, and the location of emergency services to identify and prioritize high-impact critical infrastructure for mitigation. Results demonstrate that pipes can be prioritized for mitigation based on water shortage and vulnerable populations that are affected. In conclusion, the methods can be adopted for general use and are available as part of the WNTR software.

GIS, landslide↗

FIND: A Synthetic weather generator to control drought Frequency, Intensity, and Duration

Water systems worldwide are experiencing climate change-induced shifts in drought properties like frequency, intensity, and duration, affecting water security and reliability. To develop and test effective drought preparedness plans, researchers often use synthetic weather generators to create hydrological scenarios that explore drought variability beyond historical records. Existing weather generators typically allow users to adjust streamflow statistics like percentiles or temporal correlation but do not directly control drought properties of frequency, intensity, and duration. To fill this gap, we propose FIND (Frequency, INtensity, and Duration) synthetic weather generator. FIND incorporates a standardized drought index to directly and in dependently control drought frequency, intensity, and duration in generated streamflow time series while preserving observed hydrological variability. Use cases for FIND include i) water systems analysis applications that seek to train and test drought strategies under historical and plausible future drought conditions, and ii) bottom-up vulnerability studies relating system vulnerability outcomes to specific changes in drought properties of frequency, intensity, and duration. Here, we demonstrate FIND’s versatility through three experiments: replicating historically observed drought properties, generating streamflow scenarios for multiple sites preserving correlation between their drought conditions, and generating a set of scenarios with direct and independent changes in drought properties. FIND source code is openly available for applications beyond the scope of this paper.

42 ENGINEERING↗

Supporting U.S. National Security Through Cybersecurity Partnerships

At NLR, we're studying energy evolutions and threats to understand the challenges they pose and uncover ways to leverage grid advancements to achieve more secure, defensible, and reliable systems. Our integrated research approach bridges the gap between cyber threats and real-world consequences to deliver actionable solutions that reduce vulnerabilities and help strengthen U.S. national security.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Standards for Distributed Energy Resources: Gaps and Harmonization Strategy

This report examines cybersecurity standards for Distributed Energy Resources (DERs) in light of their rapid growth and increasing integration into energy systems. It identifies critical gaps in existing frameworks, including inadequate coverage of DER-specific challenges, complexities in implementing comprehensive standards, integration issues with legacy systems, adoption hurdles for newer standards, and a lack of harmonization across regulatory landscapes. The analysis highlights vulnerabilities such as data integrity risks, unauthorized device control, and denial-of-service attacks across various DER technologies like solar PV, wind turbines, energy storage systems, and hydrogen fuel cells. The report proposes a harmonization strategy to address these deficiencies by developing unified cybersecurity requirements, certification programs, and training resources while fostering collaboration among stakeholders such as government agencies, industry groups, DER operators, manufacturers, and research institutions. A phased roadmap is outlined to refine and implement these measures through pilot testing and widespread adoption. Ultimately, the report underscores the urgent need for coordinated efforts to enhance DER cybersecurity and ensure the reliable operation of future energy systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

The Nuclear System-of-Systems Capabilities Analytic Process

This dissertation discusses the impetus for, development of, and initial demonstration of NuSCAPTM: the Nuclear System-of-Systems Capabilities Analytic Process TM . NuSCAP is an approach executed via a Python® application that enables capabilities-based vulnerability analyses of military systems of systems (SOS) exposed to prompt nuclear weapon effects. The NuSCAP application calls on industry-standard, fast-running nuclear weapon effects tools and the Monte Carlo N-Particle®1 (MCNP®) code to evaluate the impact of nuclear weapon environments on the military capabilities of a complex and networked SOS.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Designing Resilience for Advanced Energy Systems

Advancements in energy technologies are making the grid more powerful, more efficient, and cleaner. As these promising innovations flourish across our communities, it is essential that our nation's infrastructure also becomes more resilient. Natural disasters, cyberattacks, user error, and a changing climate all present risks that could have devastating consequences. Individual emergencies are unique, but holistic planning and proactive measures can harden the grid and help anticipate and respond to any number of threats. The National Renewable Energy Laboratory (NREL) is at the forefront of this transition, establishing a vision for resilient energy systems today, and in the future.

energy disruption↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

MARVEL 90% Final Design Report

This document provides documentation of the Microreactor Applications Research Validation and Evaluation Project’s (MARVEL) 90% Final Design, as required by U.S. Department of Energy (DOE) Standard-1189, “Integration of Safety into the Design Process." Per DOE-STD-1189-2016, the 90% Final Design documentation focuses on design completion, at a level capable of supporting procurement, construction, testing, and operation. At this phase, the design organization finalizes the hazards and accident analyses, Fire Hazard Analysis (FHA), security vulnerability assessments, and other supporting analyses for design completion. The objective of this report is to provide a high-level summary of the design thus far and provide references including, but not limited to, the following design deliverables: • Complete final drawings, specifications and commercial grade dedications that may be released for bid and/or construction. • Clearly defined testing plans for the safety and functionality of all subsystems. • Quality Assurance Program for Design, Testing and Procurement. • Software Quality Assurance Plan. • Code of Record (COR), applicable design requirements including codes and standards. • Final design that meets all the requirements stipulated in the COR. • Final design review, consisting of final validation of comment resolution from previous reviews, and a review of any additional developments since the last review. • Updated Safety Design Strategy. • Hazard Analysis. • Fire Hazard Analysis. • Accident analysis. • Security vulnerability assessment. • Current and detailed cost estimate. • Current construction schedule, and • Risk & Opportunities Assessment.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Proteo-Genomic Analysis Identifies Two Major Sites of Vulnerability on Ebolavirus Glycoprotein for Neutralizing Antibodies in Convalescent Human Plasma

Three clinically relevant ebolaviruses – Ebola (EBOV), Bundibugyo (BDBV), and Sudan (SUDV) viruses, are responsible for severe disease and occasional deadly outbreaks in Africa. The largest Ebola virus disease (EVD) epidemic to date in 2013-2016 in West Africa highlighted the urgent need for countermeasures, leading to the development and FDA approval of the Ebola virus vaccine rVSV-ZEBOV (Ervebo ® ) in 2020 and two monoclonal antibody (mAb)-based therapeutics (Inmazeb ® [atoltivimab, maftivimab, and odesivimab-ebgn] and Ebanga ® (ansuvimab-zykl) in 2020. The humoral response plays an indispensable role in ebolavirus immunity, based on studies of mAbs isolated from the antibody genes in peripheral blood circulating ebolavirus-specific human memory B cells. However, antibodies in the body are not secreted by circulating memory B cells in the blood but rather principally by plasma cells in the bone marrow. Little is known about the protective polyclonal antibody responses in convalescent plasma. Here we exploited both single-cell antibody gene sequencing and proteomic sequencing approaches to assess the composition of the ebolavirus glycoprotein (GP)-reactive antibody repertoire in the plasma of an EVD survivor. We first identified 1,512 GP-specific mAb variable gene sequences from single cells in the memory B cell compartment. Using mass spectrometric analysis of the corresponding GP-specific plasma IgG, we found that only a portion of the large B cell antibody repertoire was represented in the plasma. Molecular and functional analysis of proteomics-identified mAbs revealed recognition of epitopes in three major antigenic sites - the GP head domain, the glycan cap, and the base region, with a high prevalence of neutralizing and protective mAb specificities that targeted the base and glycan cap regions on the GP. Polyclonal plasma antibodies from the survivor reacted broadly to EBOV, BDBV, and SUDV GP, while reactivity of the potently neutralizing mAbs we identified was limited mostly to the homologous EBOV GP. Together these results reveal a restricted diversity of neutralizing humoral response in which mAbs targeting two antigenic sites on GP – glycan cap and base – play a principal role in plasma-antibody-mediated protective immunity against EVD.

59 BASIC BIOLOGICAL SCIENCES↗

Comparing multi-source urban flood indicators: satellite, simulation, and citizen-reported data

Urban flooding arises from complex mechanisms, making it challenging to capture accurately with a single detection method. This study evaluates three complementary approaches to detect flooding across three Chicago neighborhoods: (i) Sentinel-1 synthetic aperture radar (SAR), offering weather-independent, high-resolution (10 m) imagery of surface inundation; (ii) the storm water management model (SWMM), simulating combined sewer overflow and drainage performance; and (iii) citizen-generated 311 service requests, capturing observed flooding impacts. By analyzing six storms ranging from severe to mild, we examine how each source uniquely contributes to identifying urban flood events. SAR imagery effectively identifies standing water but can miss brief flooding due to satellite revisit constraints. SWMM provides detailed insights into system-wide drainage behavior yet may underestimate localized street-level flooding. Meanwhile, 311 calls reflect real-world flooding impacts but are vulnerable to underreporting. Statistical overlap analysis highlights chronic flood hotspots repeatedly identified across multiple detection methods, indicating persistent infrastructure and topographic vulnerabilities. Temporal analysis further reveals that while SWMM flooding aligns closely with rainfall peaks, 311 calls typically precede or persist beyond these peaks. Our findings emphasize the value of using satellite observations, hydrological modeling, and resident-reported data in a complementary manner to better interpret patterns in flood timing, severity, and spatial distribution—providing insights that can inform targeted infrastructure improvements and contribute to urban flood resilience planning.

311↗

Historical Power Outages of the United States and the Social Vulnerability Index

Several works have been documented in the literature to study the societal effect of power outages and to analyze their correlation with the Social Vulnerability Index (SVI). Because the SVI is calculated based on the summed rank of multiple vulnerability factors for environmental hazards, it can include factors irrelevant to power outages caused by extreme events. This work performs a detailed correlation analysis for social vulnerability and power outages by considering different SVI themes (e.g., socioeconomic status, household composition, racial and ethnic minority status, and housing and transportation) and power outages with and without a threshold for extreme weather events. Although there is some relation between specific themes and aspects of power outages and the SVI in the results, there is no strong distinction between power outage durations and low vs. high SVI values. These results point to the need for further research that grounds the specific factors and methods used to develop SVI and related indices to energy services and power systems disruptions.

Bhusal, Narayan↗