Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Assessing the vulnerability of solar inverters to EMPs: Port testing, PCI modeling, and protection strategies

Renewable energy sources are becoming an ever-larger contributor to the power grid. These renewable energy sources depend upon the power electronic devices, specifically inverters, being essential for connecting Photovoltaic (PV) generation to the grid. However, the Electromagnetic Pulses (EMPs) caused by the high-altitude nuclear explosions can generate fast broad-band pulses with nanosecond rise time, potentially causing damage or destruction to electronic components. To assess the vulnerability of PV inverters to high-altitude EMPs, the port testing and Pulsed Current Injection (PCI) modeling schemes are proposed based on the port impedance analysis. Wide-band frequency measurements are achieved by fusing impedance results from three vector network analyzers. Then, a PCI model is used to simulate the induced response to EMP, with two typical immunity levels of EC5 and EC8 tested. Here, the experiment successfully excites the induced voltage and current under EMP, where the voltage and current can reach 1500V/40A and 8000V/150Aunder EC5 andEC8, respectively. The port vulnerability analysis results demonstrate that only some ports can survive under EC5. To defend against the impact of EMP, three protection strategies are discussed.

42 ENGINEERING↗

Vulnerable window of yield strength for swelling-driven fracture of phase-transforming battery materials

Abstract Despite numerous experimental and theoretical investigations of the mechanical behavior of high-capacity Si and Ge Li-ion battery anodes, our basic understanding of swelling-driven fracture in these materials remains limited. Existing theoretical studies have provided insights into elasto-plastic deformations caused by large volume change phase transformations, but have not modeled fracture explicitly beyond Griffith’s criterion. Here, we use a multi-physics phase-field approach to model self-consistently anisotropic phase transformation, elasto-plastic deformation, and crack initiation and propagation during lithiation of Si nanopillars. Our computational results reveal that fracture occurs within a “vulnerable window” inside the two-dimensional parameter space of yield strength and fracture energy and highlight the importance of taking into account the surface localization of plastic deformation to accurately predict the magnitude of tensile stresses at the onset of fracture. They further demonstrate how the increased robustness of hollow nanopillars can be understood as a direct effect of anode geometry on the size of this vulnerable window. Those insights provide an improved theoretical basis for designing next-generation mechanically stable phase-transforming battery materials undergoing large volume changes.

25 ENERGY STORAGE↗

How different power plant types contribute to electric grid reliability, resilience, and vulnerability: a comparative analytical framework

Abstract This work explores the dependability tradeoffs provided by the most common types of central power plants in the United States. Historically, the electricity sector has lacked consensus on how reliability , resilience , and vulnerability differ and how those metrics change depending on the power plant fleet composition. We propose distinct definitions for these metrics and an analytical framework to evaluate power plant fleet dependability. Using data analysis and literature review, we identify fifteen dependability attributes across which we rank eleven power plant types relative to natural gas combined-cycle (NGCC) plants. We use NGCC as the benchmark because it is common to many locations and is of relatively recent vintage. The framework shows that each power plant type has unique dependability benefits and drawbacks. We provide examples of how researchers may use the framework to evaluate grid dependability qualitatively under different scenarios. We find that assuming all attributes that contribute to grid dependability are equally important and additive, electric grid dependability is best supported when power plant fleets include a mixture of power generation technologies. Then, we discuss scenario characteristics that could alter the prioritization and relationships of attributes. We also find that if current capacity installation trends continue to favor low- and zero-carbon power plants, US power grids may benefit from increased resilience and reduced vulnerability at the cost of decreased reliability. We conclude by recommending methods for adapting the framework and quantifying relationships between attributes in individual scenarios.

Ramirez-Meyers, K. (ORCID:0000000291216952)↗

Vulnerability Detection Methodology for a Digital Signal Processor Micro-Controller at Edge Level Distributed Energy Resource Controller

Integration of renewable energy and energy storage based Distributed Energy Resource (DER) assets to the grid has seen an upsurge over the past few decades. Traditionally, energy would be generated at a thermal or nuclear power plant and then transmitted over long distance through the transmission grid and then supply to the customers at the distribution grid. Modern renewable energy based DER assets have brought energy production at the edge of distribution grid, which has made the grid vulnerable to cyber intrusion as the power flow controllers for such DER assets are now distributed across the grid from distribution level to transmission level. This paper discusses the vulnerability posed by such power flow controllers of DER assets and demonstrates a detection methodology for unauthorized access and manipulation of system configuration for Digital Signal Processor based Microcontrollers. Experimental results proving efficacy of the methodology have been shown in paper.

Bhowmik, Pankaj↗

User Role Identification in Software Vulnerability Discussions over Social Networks

Understanding and early awareness of software vulnerabilities is vital for preventing and mitigating potential impacts from cybersecurity events. One step toward early characterization of software vulnerabilities may involve analyzing discussion and spread of information in online social networks. Prior work has used information from such discussions over multiple online forums to develop dynamic networks among users followed by analysis of structure, spread, and information evolution. In this work, we advance the state-of-the-art by focusing on data-driven learning of types, roles, and transition of roles exhibited by users over time. In social networks, users take on particular roles based on their actions and structure of the network. Identifying “meaningful” roles can help separate potential users of interest from the larger community, and identify patterns in a network. We will identify and compare roles found in online forums (e.g., Twitter) using techniques such as feature-based Non-negative Matrix Factorization coupled with topological and influence-based measures of centrality. Since users’ activities change over time, we also analyze role evolution in dynamic networks.

Jones, Rebecca D.↗

Distribution System Resilience Assessment Considering PV Vulnerabilities for Hurricane Events

Distribution networks are increasingly vulnerable to damage and outages from extreme weather events. The integration of solar photovoltaics (PVs) further complicates resilience analysis due to its weather-dependent nature. However, limited research has examined the impacts of weather on PVs under severe events like hurricanes. This paper proposes a probabilistic framework to assess distribution system resilience considering PV vulnerabilities during hurricanes. The framework incorporates (i) a spatiotemporal fragility model to evaluate failure probabilities for distribution lines and PVs, and (ii) resilience indices at both system and component levels. The approach offers valuable insights into the resilience of modern distribution grids under extreme weather conditions. Numerical results on the unbalanced IEEE 123-bus test system validate the effectiveness of the framework.

Vahedi, Soroush [University of Connecticut, Storrs↗

Vulnerability Studies Under EMP: Impedance and PCI Testing of the Grid Control Devices

Control devices such as inverters and generator controllers are critical for the stable operation of the power grid, especially for power stability control and power dispatch. However, the Electromagnetic Pulse (EMP) is a potential threat to electronic devices in modern power grids, therefore decreasing the power grid resilience and bringing unrecoverable damages to the devices. To reveal the impact mechanism of the EMP, impedance and Pulse Current Injection (PCI) testing is established to study the vulnerability of the grid control devices. The impedance of the grid control devices is accurately measured using impedance analyzers with different frequency ranges. Then the voltage and current responses are tested based on the PCI testing. The vulnerability experiments based on two grid control devices are carried out. And the comparison results reveal that most ports would be damaged under EC8, and some ports can survive under EC5 according to the calculated PCI response and cumulative energy. The results can provide a reference for the future design of control devices and the strategic resilience of power grids.

Qiu, Wei↗

Convergent evolution of tree hydraulic traits in Amazonian habitats: implications for community assemblage and vulnerability to drought

Amazonian droughts are increasing in frequency and severity. However, little is known about how this may influence species-specific vulnerability to drought across different ecosystem types. We measured 16 functional traits for 16 congeneric species from six families and eight genera restricted to floodplain, swamp, white-sand or plateau forests of Central Amazonia. We investigated whether habitat distributions can be explained by species hydraulic strategies, and if habitat specialists differ in their vulnerability to embolism that would make water transport difficult during drought periods. We found strong functional differences among species. Nonflooded species had higher wood specific gravity and lower stomatal density, whereas flooded species had wider vessels, and higher leaf and xylem hydraulic conductivity. The P 50 values (water potential at 50% loss of hydraulic conductivity) of nonflooded species were significantly more negative than flooded species. However, we found no differences in hydraulic safety margin among species, suggesting that all trees may be equally likely to experience hydraulic failure during severe droughts. Water availability imposes a strong selection leading to differentiation of plant hydraulic strategies among species and may underlie patterns of adaptive radiation in many tropical tree genera. Our results have important implications for modeling species distribution and resilience under future climate scenarios.

59 BASIC BIOLOGICAL SCIENCES↗

Vulnerability Research Development Program Guide v.1

SAND2021-15515 O The Vulnerability Research Development Program (VRDP) Guide is a training program developed to help general purpose computer science staff become independently capable vulnerability researchers. VRDP Guide is both a course description and curriculum for the program. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Salim, Nasser↗

Unraveling Vulnerabilities in Endocrine Therapy-Resistant HER2+/ER+ Breast Cancer

Abstract Breast tumors overexpressing human epidermal growth factor receptor (HER2) confer intrinsic resistance to endocrine therapy (ET), and patients with HER2/estrogen receptor–positive (HER2+/ER+) breast cancer (BCa) are less responsive to ET than HER2–/ER+. However, real-world evidence reveals that a large subset of patients with HER2+/ER+ receive ET as monotherapy, positioning this treatment pattern as a clinical challenge. In the present study, we developed and characterized 2 in vitro models of ET-resistant (ETR) HER2+/ER+ BCa to identify possible therapeutic vulnerabilities. To mimic ETR to aromatase inhibitors (AIs), we developed 2 long-term estrogen deprivation (LTED) cell lines from BT-474 (BT474) and MDA-MB-361 (MM361). Growth assays, PAM50 subtyping, and genomic and transcriptomic analyses, followed by validation and functional studies, were used to identify targetable differences between ET-responsive parental and ETR-LTED HER2+/ER+ cells. Compared to their parental cells, MM361 LTEDs grew faster, lost ER, and increased HER2 expression, whereas BT474 LTEDs grew slower and maintained ER and HER2 expression. Both LTED variants had reduced responsiveness to fulvestrant. Whole-genome sequencing of aggressive MM361 LTEDs identified mutations in genes encoding transcription factors and chromatin modifiers. Single-cell RNA sequencing demonstrated a shift towards non-luminal phenotypes, and revealed metabolic remodeling of MM361 LTEDs, with upregulated lipid metabolism and ferroptosis-associated antioxidant genes, including GPX4. Combining a GPX4 inhibitor with anti-HER2 agents induced significant cell death in both MM361 and BT474 LTEDs. The BT474 and MM361 AI-resistant models capture distinct phenotypes of HER2+/ER+ BCa and identify altered lipid metabolism and ferroptosis remodeling as vulnerabilities of this type of ETR BCa.

60 APPLIED LIFE SCIENCES↗

Stem hydraulic conductivity and vulnerability to cavitation for 26 tree species in Panama

Stem hydraulic conductivity and vulnerability to cavitation were measured for 26 tree species located in Panama. The data were generated to better understand the ecology of the focal tree species. Complementary NGEE-Tropics datasets for these species include sap flow, leaf-level gas exchange, and leaf water potential. Stem samples were collected from distal branches of canopy trees, brought to the Smithsonian Tropical Research Institute laboratory in Gamboa, Panama, and allowed to dry to various water potentials before measurements. For each species, a Weibull function was fit to the 90% quantile of the relationship between stem area specific hydraulic conductivity (Ks) and stem water potential. From these functions, maximum Ks and vulnerability parameters were derived. The data files in the package include raw data, derived parameters, and the R script used for analysis.

54 ENVIRONMENTAL SCIENCES↗

Vulnerabilities in Artificial Intelligence and Machine Learning Applications and Data

Artificial intelligence (AI) applications driven by machine learning (ML) are transformational technologies within the international nuclear security regime. Advancements realized by AI—faster and improved data insights, more efficient and automated processes, reductions in human error—enable nuclear security applications such as behavior analysis for insider threat mitigation, source tracking of stolen nuclear material, and facial recognition software for physical protection. In addition to the advantages, however, there are also inherent vulnerabilities and threats associated with its use and risk mitigations must be built into any AI/ML-enabled systems. This work provides a background on AI and ML and different data types used in the field, including open-source intelligence information (OSINT) that is discoverable by AI tools and application data that are used by AI tools for decision-making and automation. Current and potential AI applications and vulnerabilities related to their use within the nuclear security regime are also discussed.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Prioritizing ICS Beachhead Systems for Cyber Vulnerability Testing

Cyber Testing for Resilient Industrial Control Systems™ (CyTRICS™) is the Department of Energy’s (DOE’s) program for cybersecurity vulnerability testing, digital subcomponent enumeration, and forensic assessment. CyTRICS leverages best-in-class test facilities and analytic capabilities at six DOE National Laboratories and strategic partnerships with key stakeholders including technology developers, manufacturers, asset owners and operators, and interagency partners. During the program’s development, CyTRICS established a unique methodology for prioritizing digital components within operational technology (OT) and industrial control systems (ICS) in the Energy Sector Industrial Base (ESIB) for cyber vulnerability testing. The CyTRICS Prioritization Process leverages multiple characteristics of systems, components, and their contextual deployment to calculate a quantification of individual digital components for CyTRICS testing. The initial version of the CyTRICS Prioritization Process was premised largely upon the impact which could result to an industrial control system if the digital component under testing was compromised, either through malicious means, faulty engineering, or other modes. The worldwide compromise of the SolarWinds Orion platform, first reported in December 2020, through malicious interference with the digital patching cycle was a watershed event in cyber supply chain security. The SolarWinds compromised demonstrated the strategic importance of certain types of ubiquitous software, and the ability to generate widespread cybersecurity effects. To address this challenge and as a part of the Department of Energy’s response to the SolarWinds compromise, DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) directed the National Laboratories to evolve the CyTRICS Prioritization Process methodology to encompass additional factors related to the strategic importance of digital components. CESER directed CyTRICS researchers to identify, characterize, and append strategic factors to the CyTRICS Prioritization Process to provide additional weight to these characteristics. National Laboratory expert researchers identified functionality, distribution, and platform characteristics for digital components in ICS and OT that they assessed would be likely targeted in strategic initial-access cyber attack. CyTRICS has termed these factors “ICS Beachhead Systems,” leveraging a definition first advanced by Schneider Electric, which is intended as a blanket term to encompass digital components, products, and systems in OT. This paper describes the ICS Beachhead Systems identified and the rationale for inclusion. As a next step in the research and refinement process, the National Laboratories will validate this initial set of characteristics against digital components evaluated by the CyTRICS program and current implementation of the CyTRICS Prioritization Process. After validation, CyTRICS researchers will then develop a scoring methodology to generate a quantitative score to assess the degree to which a digital component is characterized as an ICS Beachhead System. Finally, the National Laboratories will append this scoring to the existing CyTRICS Prioritization Process algorithm.

97 MATHEMATICS AND COMPUTING↗

Automated Vulnerability Detection (AVUD) for Compiled Smart Grid Software

This project developed and implemented a system for conducting cybersecurity vulnerability detection of smart grid components and systems by performing static analysis of compiled software (“firmware”). The resulting system for automated vulnerability detection (AVUD) was implemented as part of Oak Ridge National Laboratory’s existing test bed for smart meters, the Sustainable Campus Initiative. The work consisted of two phases: the first phase implemented the necessary software and computational models to perform the analysis, and the second phase demonstrated the system on example firmware in partnership with smart meter manufacturer Sensus USA, Inc. The resulting system won an R&D 100 award and has been successfully commercialized, winning a National Laboratory Consortium Commercialization Award.

97 MATHEMATICS AND COMPUTING↗

FIC Vulnerability Profile

The FIC team is engaged with Pacific Northwest National Laboratory’s (PNNL’s) Shamrock Cyber Team to provide cybersecurity analyses of the FIC software. Shamrock offers both Threat-Based Analysis services and Secure Software Development services. These services are ultimately used to understand and mitigate threats against software and to reduce vulnerabilities in software, thus improving overall cybersecurity and informing decision makers. Shamrock’s Secure Software Development services, specifically Static Analysis Security Testing (SAST) and Open-Source Analysis (OSA), produced this Vulnerability Profile.

97 MATHEMATICS AND COMPUTING↗

Territorial Government Revenue Vulnerability Index (TGRVI): Measuring Financial Impacts to Territorial Governments during the COVID-19 Pandemic

The Territorial Government Revenue Vulnerability Index (TGRVI) measures the vulnerability of U.S. territorial government revenues by estimating monthly changes relative to a January 2020 baseline. Revenues accounted for in the index include: taxes on products and sales, transportation and housing revenues, individual income taxes, severance taxes and royalties, and property taxes.

99 GENERAL AND MISCELLANEOUS↗

Charliecloud is not affected by CVE-2024-21626 or related vulnerabilities

As you may be aware, four vulnerabilities in popular open-source container implementations were announced on January 21. Nicknamed “Leaky Vessels” by the Snyk Security Labs team that discovered them [1], these vulnerabilities in runC (CVE-2024-21626) and Moby BuildKit (CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653) allow malicious container images or builds to execute arbitrary code on the container host with the privileges of the container runtime, i.e., a “container breakout”. Often, including typical configurations of Docker and/or Kubernetes, that means full root access.

97 MATHEMATICS AND COMPUTING↗

A Multi-Model, Multi-Scale Research Program in Stressors, Responses, and Coupled Systems Dynamics at the Energy-Water-Land Nexus and for Concentrated, Interdependent Infrastructures: Toward Next Generation Capabilities in Integrated Impacts, Adaptation, and Vulnerability (I-IAV) Modeling and a Community of Practice

The goal of this research program was to build a next generation integrated suite of science-driven modeling and analytic capabilities, and a more expanded and connected community of practice, for analyses of the stressors, impacts, adaptations and vulnerabilities of global and regional change. The emphasis was on understanding energy-water-land interactions and feedbacks and interdependent infrastructures at appropriate regional and temporal scales. Although the scope spans many complex facets of data, modeling, and analysis, as well as scales appropriate for integrated impacts and adaptation research, the focus of this effort was the development of multi-model, multi-scale capabilities spanning the domains of Multi-Sector Dynamics (MSD) models; Impact, Adaptation, and Vulnerability (IAV) models; and Earth System Models (ESMs).

54 ENVIRONMENTAL SCIENCES↗