Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Dynamic Risk Assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Evaluation of Physical Security Risk for Potential Implementation of FLEX using Dynamic Simulation Methods

The requirements for United States nuclear power plants to maintain a large onsite physical security force contribute to their large operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability Program Physical Security Pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. This pathway will analyze and minimize the conservatisms built into current security postures in order to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within this pathway has successfully developed a dynamic force-on-force (FOF) modeling framework using various computer simulation tools and integrated them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This document provides an overview of lessons learned in applying a dynamic computational framework that links results from a commercially available FOF simulation tool, a commercially available thermal-hydraulic tool, and EMRALD to an operating commercial nuclear power plant. This process of including plant procedures and multiple analysis results is being called Modeling and Analysis for Safety Security using Dynamic EMRALD Framework. Previous reports described how a user could integrate their plant-specific FOF models with the dynamic simulation tool EMRALD, model operator actions, integrate with probabilistic risk assessment tools, such as Computer Aided Fault Tree Analysis System or Systems Analysis Programs for Hands-on Integrated Reliability Evaluations, and with thermal-hydraulic tools, such as RELAP-5. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report documents the results of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. The purpose of this study was to verify that results achieved using generic models are similar to actual plant results and to refine our guidance of the use of the framework. Such an assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants. NOTE: The work performed in this report is based on a generic EMRALD model with actual plant data used for the analysis. However, only the generic model and general results of the analysis are in the report. No plant’s sensitive information is discussed in this report. The discussion shows examples of insights that can be obtained from the MASS-DEF methodology.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Plant-specific Model and Data Analysis using Dynamic Security Modeling and Simulation

The requirements for U.S. nuclear power plants to maintain a large on-site physical security force contribute to their high operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability (LWRS) program’s physical security pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. The conservatisms built into current security postures may be analyzed and minimized in order to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within LWRS program’s physical security pathway has successfully developed a dynamic force-on-force modeling framework using various computer simulation tools and integrating them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This document provides an update on the progress in applying a dynamic computational framework that links results from a commercially available force-on-force simulation tool, a commercially available thermal-hydraulic tool, and EMRALD to an operating commercial nuclear power plant. This report is only a summary of the progress and does not contain specific modeling results as those contain sensitive security information. This process of including plant procedures and multiple analysis results is being called Modeling and Analysis for Safety Security using Dynamic EMRALD Framework or MASS-DEF. Previous reports described how a user could integrate their plant-specific force-on-force models with the dynamic simulation tool EMRALD, model operator actions, integrate with probabilistic risk assessment tools, such as CAFTA (Computer Aided Fault Tree Analysis System) or SAPHIRE (Systems Analysis Programs for Hands-on Integrated Reliability Evaluations), and with thermal-hydraulic tools, such as RELAP-5. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report documents the results of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. This report does not contain any plant's sensitive information and/or Safeguards Information. The purpose of this study was to verify that results achieved using generic models are similar to actual plant results and to refine our guidance on the use of the framework. This assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Dynamic HRA for FLEX

In the presentation, previous efforts for FLEX dynamic HRA, PRIMERA-HRA method and its application to an ELAP scenario are introduced.

99 GENERAL AND MISCELLANEOUS↗

AUTOMATIC GENERATION OF EVENT TREES AND FAULT TREES: A MODEL-BASED APPROACH

In the past few decades, increasing complexity in modern engineering systems has been driven by the integration of a large number of components and by the fact that the system operations involve many disciplines (e.g., thermal-hydraulics, plant operations, cyber-security). Current safety/reliability modeling approaches to such systems are labor intensive, difficult to learn, and rely heavily on simplistic Boolean logic to depict failure propagation and accident progression. While these methods serve well for simple systems (i.e., linear causal systems with limited small inter- and intra-system interactions), their results are difficult to verify when modeling complex systems (typically performed through the extensive use of modeling assumptions). The development of new methods is addressed to meet these challenges through a model-based system engineering (MBSE) lens. Under MBSE philosophy, every aspect of the system (form or function) is represented by a model that completely characterizes its architecture or behavior. MBSE approach greatly improves the management of design, analysis and verification of complex systems. An integration of Dynamic Probabilistic Risk Assessment (DPRA) methods with MBSE models is proposed to perform safety/reliability analyses of engineering systems. In particular, MBSE representation of the system (performed using Systems Modeling Language [SysML]) is coupled with DPRA methods to automatically generate event trees and fault trees.

97 - MATHEMATICS AND COMPUTING↗

Rancor-HUNTER: Using a Simulator Engine for Realistic Human Performance Modeling of Nuclear Power Operations

The Human Unimodel for Nuclear Technology to Enhance Reliability (HUNTER) is a software system to simulate human performance in support of human reliability analysis (HRA) in nuclear power plants. This paper summarizes recent work to integrate HUNTER with a plant simulator, namely the Rancor Microworld Simulator. Rancor is an offshoot of earlier work at Idaho National Laboratory (INL) to support plant modernization. The graphical software tools used to mimic digital human-system interface upgrades at INL’s Human Systems Simulation Laboratory were linked to the Rancor Microworld Simulator, an INL-developed simplified plant model. HUNTER becomes a “virtual operator” coupled to the Rancor simulator, thereby allowing a tight coupling between a digital human twin and a digital twin of the plant. Rancor-HUNTER may be run through Monte Carlo iterations across a dynamic range of performance shaping factors, thereby producing distributions of human performance in terms of procedure paths, errors instantiations, and task durations. This paper overviews the various unique features of Rancor-HUNTER and presents an example run of Rancor-HUNTER for a startup scenario.

99 - GENERAL AND MISCELLANEOUS↗

Event-modeled Risk Assessment Using Linked Diagrams

Event Modeling Risk Assessment using Linked Diagrams (EMRALD) is a software tool developed at INL for researching the capabilities of dynamic PRA (Probabilistic Risk Assessment). In order to promote the effective use of dynamic PRA by the general community, EMRALD focuses on the following key aspects: Simplifying the modeling process by providing a structure that corresponds to traditional PRA modeling methods Providing a user interface (UI) that makes it easy for the user to model and visualize complex interactions Allowing the user to couple with other analysis applications such as physics based simulations. This includes one-way communication for most applications and two-way loose coupling for customizable applications Providing the sequence and timing of events that lead to the specified outcomes when calculating results Traditional aspects of components with basic events, fault trees, and event trees are all captured in a dynamic framework of state diagrams, which are displayed.

Prescott, SteveR↗

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING↗

PSA 2025 DPRA for Cyber Optimization

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Evaluating defense options should include quantitative evaluation of overall effectiveness to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation and have difficulty with time dependent scenarios. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related integrity is a requirement set by the U.S. Nuclear Regulatory Commission. But companies are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want reliability analysis while optimizing cost, which requires more than safety modeling methods. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with timing and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues such as state-base explosion found in Markov-based tools. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies.

97 - MATHEMATICS AND COMPUTING↗

System risk quantification and decision making support using functional modeling and dynamic Bayesian network

Risk-informed decision-making requires a probabilistic assessment of the likelihood of success of control action, given the system status. This paper presents a systematic state transition modeling approach integrating dynamic probabilistic risk assessment with a decision-making process using a dynamic Bayesian network (DBN) coupled with functional modeling. A functional model designed with multilevel flow modeling (MFM) technique was used to build a system state structure inferred by energy, mass, and information flow so that one can verify the developed model with respect to system functionality. The MFM model represents the causal relationship among the nodes, which captures the structure of process parameters and control units. Each node may have multiple possible states, and the DBN structured by the MFM model represents the time-domain transitions among the defined states. Furthermore, the MFM-DBN integrated state transition modeling is a white-box approach that allows one to draw the system's risk profile by updating the system states and supports the decisions probabilistically with physical inference. An example of a simple heating system has been used to illustrate this process, including decision-making support based on quantitative risk profile. For demonstrating its applicability to a complex system operational decision making, a case study of station blackout accident scenario leading to the seal loss of coolant accident in a nuclear power plant is presented. The proposed approach effectively provided the risk profile along time for each option so that the operators can make the best decision, which minimizes the plant risk.

42 ENGINEERING↗

Integrating static PRA information with risk informed safety margin characterization (RISMC) simulation methods

The overall objective of the project was to develop a computationally feasible and user-friendly mechanized process to integrate traditional probabilistic risk assessment (PRA) and dynamic PRA (DPRA) results. Starting with the systematic identification of items in an existing PRA that need dynamic augmentation, the project used a generic 4-loop pressurized reactor (PWR) and 3-loop PWR as example plants. Station blackout (SBO) and large break loss of coolant accident SBLOCA) were selected as the example initiating events. Using the traditional event-tree (ET)/fault-tree (FT) methodology augmented by dynamic evet tree approach, the potential consequences of the initiating events were simulated with RELAP-3D and MELCOR/RASCAL codes to cover Level 1 through Level 3 of PRA. RAVEN and ADAPT software were used to generate Level 1 simulations with RELAP-3D and Level 2/3 simulations with MELCOR (Level 2)/RASCAL (Level 3), respectively. Example branching conditions (BCs) for SBO included AC power recovery time, valve repair failure time, reactor coolant pump leak time/break size and emergency power supply duration to a total of 9. Example BCs for LOCA included off-site power recovery time, diesel generator power recovery time, auxiliary feed water system operation time, safety relief valve failure to open upon demand, reactor coolant pump seal break time and size to a total of 21. Each RELAP-3D simulation (9,587 scenarios) was labelled OK or Core Damage based on the maximum allowed peak clad temperature (2,100oF). Each MELCOR simulation (4610 scenarios) was labeled as Bin over 10rem or Bin 0-10rem based on the dose at the site boundary. The scenarios were clustered based on the criteria above using the mean shift methodology. Classical PRA (CPRA) and DPRA results were compared to identify the ET sequences that need DPRA augmentation. Several approaches were proposed for the incorporation of these sequences into CPRA using clustering with the mean shift methodology, restructuring the CPRA ETs by adding new BCs/sequences, and using the concept of a limit surface. Procedures for decision making regarding the possible consequences of an initiating event (e.g. core damage or not, site evacuation or not) were developed using a convolutional neural network (CNN), a recurrent neural network (RNN) and a transformer neural network (TNN). The project has led to two PhD degrees, three archival journal papers and five refereed conference proceedings.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

New Approach Methodology for Assessing Inhalation Risks of a Contact Respiratory Cytotoxicant: Computational Fluid Dynamics-Based Aerosol Dosimetry Modeling for Cross-Species and In Vitro Comparisons

Regulatory agencies are considering alternative approaches to assessing inhalation toxicity that utilizes in vitro studies with human cells and in silico modeling in lieu of additional animal studies. In support of this goal, computational fluid-particle dynamics models were developed to estimate site-specific deposition of inhaled aerosols containing the fungicide, chlorothalonil, in the rat and human for comparisons to prior rat inhalation studies and new human in vitro studies. Under bioassay conditions, the deposition was predicted to be greatest at the front of the rat nose followed by the anterior transitional epithelium and larynx corresponding to regions most sensitive to local contact irritation and cytotoxicity. For humans, simulations of aerosol deposition covering potential occupational or residential exposures (1–50 µm diameter) were conducted using nasal and oral breathing. Aerosols in the 1–5 µm range readily penetrated the deep region of the human lung following both oral and nasal breathing. Under actual use conditions (aerosol formulations >10 µm), the majority of deposited doses were in the upper conducting airways. Beyond the nose or mouth, the greatest deposition in the pharynx, larynx, trachea, and bronchi was predicted for aerosols in the 10–20 µm size range. Only small amounts of aerosols >20 µm penetrated past the pharyngeal region. Using the ICRP clearance model, local retained tissue dose metrics including maximal concentrations and areas under the curve were calculated for each airway region following repeated occupational exposures. These results are directly comparable with benchmark doses from in vitro toxicity studies in human cells leading to estimated human equivalent concentrations that reduce the reliance on animals for risk assessments.

63 RADIATION, THERMAL, AND OTHER ENVIRON. POLLUTAN↗

Tactical Analysis for Calculating Contextual Risk at Boundaries: Summary of Laboratory Directed Research & Development Effort

The Tactical Analysis for Calculating Contextual Risk at Boundaries (TACCRAB) tool is an innovative digital twin (DT) platform and automated risk algorithm designed to transform operational decision-making in structured screening environments, with an initial focus on Southern Border Land Ports of Entry (POEs). The invention provides integration points for advanced artificial intelligence, predictive modeling, and real-time data analysis to produce a comprehensive risk management tool that enables proactive, data-informed security strategies. The core inventive features of TACCRAB center on its unique risk algorithm, which dynamically calculates contextual risk by synthesizing historical data, near real-time streaming data from the checkpoints themselves, and AI-generated predictions. Unlike traditional risk assessment methods, TACCRAB utilizes a DT to provide comprehensive operational insights, allowing stakeholders to visualize, simulate, and optimize checkpoint configurations with unprecedented speed and contextual awareness. TACCRAB's key innovation lies in its ability to combine multiple complex inputs - including technology detection probabilities, resource availability, screening pathway characteristics, and threat actor behavioral patterns - into a unified risk calculation and update these inputs based on changing operational and environmental conditions. By leveraging a DT that continuously updates and learns from linked data, TACCRAB can suggest adaptive mitigation strategies that minimize risk while maintaining operational efficiency. Particularly novel is the platform's approach to decision support, which goes beyond static risk assessment. The DT provides dynamic metrics such as wait times, resource allocation effectiveness, and potential emerging threat scenarios, enabling users to view sophisticated, relevant what-if simulations and optimize checkpoint operations in near real-time. The system's architecture allows for generalized application across different screening environments, such as secure facilities, ports of entry, and soft targets, making it a versatile tool for security and operational management. The invention distinguishes itself through its comprehensive integration of predictive modeling, AI-driven pattern discovery, and user-friendly interface design. By combining these elements, TACCRAB transforms complex risk data into actionable insights, supporting decision-makers at various organizational levels - from booth agents making split-second screening decisions to checkpoint managers optimizing the day's resource allocation to strategic planners managing long-term investments.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Nuclear safety Enhanced: A Deep dive into current and future RAVEN applications

As the horizon of nuclear energy expands with the advent of small modular reactors, IV generation reactors, and fusion reactors, there is a growing perspective that the licensing process could benefit from a more comprehensive approach. Moving beyond traditional deterministic and PRA analysis might pave the way for a novel safety analysis paradigm propelled by the increasing computational power at our disposal. This paper explores different methodologies that can improve the outcomes of nuclear safety analysis. These range from uncertainty quantification techniques, aimed at enhancing the precision of safety margins, to deploying dynamic event trees by driving system code simulations, capturing the potential evolutions of severe accidents. These methodologies introduce innovative dimensions to safety analysis, considering the consequences of postulated events and the dynamics of accident sequences. However, they also bring forth challenges, especially in managing the complexity and sheer volume of potential scenarios. The paper touches upon some strategies to counter these challenges, emphasizing the importance of adaptability and continuous evolution in the face of emerging nuclear safety concerns. Additionally, the paper sheds light on the need for advanced tools to apply these methodologies. Among these tools is RAVEN, an open-source software designed for parametric and probabilistic analyses. Its core components, including distribution, sampler, and reduced order model, enable various applications, from risk assessment and mitigation to dynamic learning and plant control logic simulations.

97 - MATHEMATICS AND COMPUTING↗

Exotanium DOE SBIR Phase I Results Summary

Exotanium demonstrated this technology with the Idaho National Laboratory’s MASTODON application, a Multiphysics environment designed to run typical high-performance computing (HPC) simulations for structural dynamics, seismic analysis, and risk assessment. The MASTODON application was packaged into a container using Docker, Deployed on Amazon ECS, and managed through a custom Scale-Out Compute on AWS (SOCA) implementation.

97 MATHEMATICS AND COMPUTING↗

Success Path Method: Introduction to the Success Path Method Software Tool©

As part of its commitment to advancing safety and reliability assessment methodologies, Argonne National Laboratory pioneered the use of an evaluation method called the Success Path Method (SPM) to improve risk management for offshore oil and gas operations. The development of the SPM at Argonne has been driven by the need to improve existing risk assessment methodologies by focusing on the steps necessary for success rather than failure modes alone. This is particularly important for industrial environments like offshore facilities that perform multiple functions under a continuously evolving set of operational conditions – such as water depth and temperature, currents, and weather conditions. In these dynamic environments, the traditional Probabilistic Risk Assessment (PRA) approach is far too complex as it focuses on what can go wrong – which comprises an infinite failure space that must be fully explored and understood. By shifting the focus to a finite space of success paths, the SPM enables operators and decision makers to prioritize a manageable number of steps that must go right to ensure success. Building on its five decades of experience in safety assessments for the nuclear industry, Argonne made major adaptations to existing risk assessment methods utilizing features similar to fault trees that are traditionally used in PRA to map all pathways in which the system can malfunction. In contrast, SPM identifies the components and processes that must function correctly to achieve specific outcomes – such as preventing the uncontrolled release of hydrocarbons during drilling operations. The SPM framework integrates equipment, procedures, software, processes, and human actions to ensure that physical barriers meet critical safety functions in dynamic operational conditions. This approach helps identify failure modes and improve operational risk management by narrowing the focus to key success elements, which in turn reduces uncertainty and helps users understand, manage, and respond to failures.

97 MATHEMATICS AND COMPUTING↗

Validating a Dynamic PWR Safety and Security Model?

Nuclear power plants (NPPs) are assessed for safety and security using separate models that cannot capture how an attacker's decisions and a plant's response unfold together in real time, leaving regulators and operators without a complete picture of true plant vulnerability. Traditional probabilistic risk assessment (PRA) methods treat adversarial events as fixed initiators with predetermined outcomes, and are structurally incapable of representing the time-dependent interplay between physical security events, safety system response, and operator mitigative actions. At Idaho National Laboratory (INL), I contributed to the development and validation of Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF). Where static PRA relies on event-tree logic that cannot evolve mid-scenario, MASS-DEF couples a time-dependent dynamic PRA tool EMRALD (Event Modeling Risk Assessment using Linked Diagrams) with attack simulation software, allowing attacker behavior, plant system states, and operator actions to interact across time. My work focused on validating a general Pressurized Water Reactor (PWR) model. I traced model logic against PWR plant to identified errors in logic and confirm accuracy. I then built and tested attack scenarios against a general PWR model to verify that the model produced expected outcomes across all logical pathways. I also contributed a section to a related technical paper applying the same EMRALD platform to radiation dose modeling. Results show that MASS-DEF can quantitatively demonstrate that many plants exceed their regulatory security thresholds. This demonstrated margin provides a technically defensible basis for reducing the number of guards without compromising regulatory compliance. Physical security costs represent roughly 10% of annual operating budgets, making such reductions directly meaningful to INL's mission of sustaining existing commercial NPPs. This internship strengthened my understanding of nuclear systems, probabilistic modeling, and technical writing, and has solidified my pursuit of a career at a national laboratory.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Linking classical PRA models to a dynamic PRA

Here, this paper presents a series of methods designed to incorporate classical Probabilistic Risk Assessment (PRA) models such as Event Trees (ETs) and Fault Trees (FTs) into dynamic PRA. In contrast to classical PRA, dynamic PRA couples stochastic methods with system simulators to determine the risks associated with complex systems such as nuclear power plants. Compared with classical PRA methods, they can evaluate with higher resolution the safety impact of timing and sequencing of events on the progression of the accident. As part of a dynamic PRA analysis, it is not uncommon that parts of the system to be analyzed might not require a computationally expensive simulation model. These parts could be in fact modeled by employing classical PRA models (e.g., a FT). Here, we present a set of methods and tools that can be used to link the most common classical PRA models (ETs, FTs, reliability block diagrams and Markov models) to simulation codes such as RELAP5-3D: creating a “hybrid PRA.” In order to show the potential of such an hybrid PRA we employ this method to verify ET modeling assumptions (e.g., success criteria) using a large break loss of coolant accident initiating event as a test case. In this respect, we link a set of FTs from the original PRA to the RELAP5-3D code and perform a hybrid PRA. The FTs are employed to model the control logic of several safety systems and to propagate component failures throughout the system. Provided the generated dynamic PRA data, we show how conservative assumptions in the original PRA can be identified and how such original PRA can be modified by updating success criteria captured by the set of RELAP5-3D simulation runs.

97 - MATHEMATICS AND COMPUTING↗

Cyber risk assessment and investment optimization using game theory and ML-based anomaly detection and mitigation for wide-area control in smart grids

The electric power grid is increasingly becoming susceptible to cyber attacks that exploit vulnerabilities in the smart grid control, information, and physical layers. Successful cyber attacks can have catastrophic impacts on the social and economic well-being of any nation all over the globe. It has, thus, become imperative to secure the smart grid against such adversarial actions to ensure stable, secure, and reliable operation of the grid. The existing research and industry practices prove to be inadequate in terms of providing pragmatic and effective defense methodologies and measures for long-term cybersecurity planning and real-time cybersecurity for grid operation. For example, existing works lack models that incorporate uncertain behavior of cyber-attackers and pragmatic defense measures for cyber risk assessment and cybersecurity investment optimization which often provide unreliable and strictly qualitative solutions to these problems. At the same time, with the growing number of cyber incidents in the grid, there still exists a need to develop attack-resilient algorithms for wide-area monitoring, protection, and control (WAMPAC) applications like the wide-area voltage control systems (WAVCS) for Flexible AC Transmissions Systems (FACTS) that lack in scalable and feasible solutions from the cybersecurity perspective. This dissertation proposes novel models and methodologies for: (1) Cybersecurity planning, and (2) Cybersecurity for system operation. The cybersecurity planning is achieved through cyber risk assessment and cybersecurity resource investment optimization for long-term cybersecurity of the grid using game theory and attack-defense trees. Cybersecurity for system operation consists of development of cyber anomaly detection and mitigation algorithms for flexible AC transmission system (FACTS) controller-based wide-area voltage control systems (WAVCS) using machine learning (ML), and software defined networking-based moving target defense network routing for achieving real-time cyber-physical security for grid operations. This is followed by hardware-in-the-loop (HIL) implementation and evaluation of these attack prevention, detection, and mitigation algorithms and methodologies showcasing their feasibility in a close to real-world environment. For cybersecurity planning, a novel approach involving a combination of game theory and attack defense trees (ADT) for optimal cybersecurity resource allocation in the smart grid is proposed. This methodology involves modeling of the cyber-physical smart grid substations as ADTs, defining attacker costs, defense costs, and attack probabilities for attack access points. Using game theoretical formulation, optimal defense strategies for the defender of the system to invest cybersecurity resources in the grid are obtained. Additionally, a game-theoretic framework is developed for quantitative cyber-physical risk assessment of the grid under a dynamically changing cyber threat space and uncertain behavior of cyber attackers which is further used to optimize investments in the smart grid's cybersecurity resources. The attacker, defender, and the smart grid system are modeled while incorporating attacker-stochasticity and federal guidelines for smart grid cybersecurity. This allows quantification of threat, vulnerabilities, and attack impact of the grid for quantitative risk assessment. The defender's budget to invest in the security resources in the grid is optimized based on the strategies leading to minimum system risk. The evaluation of the proposed solutions highlight the feasibility for practical implementation of these methodologies and algorithms in the smart grid, while taking the federal requirements and guidelines for smart grid security into consideration. For achieving cybersecurity for system operation, attack prevention, detection, and mitigation algorithms and methodologies are developed specifically for FACTS-based WAVCS. Anomaly detection and mitigation in the WAVCS are achieved using algorithms based on machine learning which involves offline training and testing of ML models with CPS datasets incorporating physics-based features that allow accurate distinction between system faults and cyber attacks. For attack prevention, a methodology based on software defined network (SDN)-based moving target defense (MTD) network routing is proposed that enables prevention of Denial of Service (DoS) type attacks on the smart grid communication system. Subsequently, these methodologies and algorithms are implemented and evaluated on an HIL testbed that allows for real-time attack prevention, detection, and mitigation of emulated cyber attacks on the WAVCS in a close to real-world environment. The results show highly accurate and efficient performance of the implemented algorithms and methodologies with the smart grid system operating within the NERC's system operation limits even in the presence of DoS and data integrity cyber attacks. This work opens up future research opportunities in other directions such as (1) Expanding cybersecurity planning methodologies to real-time cyber contingency analysis with different game formulations; and (2) Applying the cybersecurity for system operation algorithms to broader categories of wide-area control applications.

24 POWER TRANSMISSION AND DISTRIBUTION↗