Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

An Analysis of Post Attack Impacts and Effects of Learning Parameters on Vulnerability Assessment of Power Grid

Due to the increasing number of heterogeneous devices connected to electric power grid, the attack surface increases the threat actors. Game theory and machine learning are being used to study the power system failures caused by external manipulation. Most of existing works in the literature focus on one-shot process of attacks and fail to show the dynamic evolution of the defense strategy. In this paper, we focus on an adversarial multistage sequential game between the adversaries of the smart electric power transmission and distribution system. We study the impact of exploration rate and convergence of the attack strategies (sequences of action that creates large scale blackout based on the system capacity) based on the reinforcement learning approach. We also illustrate how the learned attack actions disrupt the normal operation of the grid by creating transmission line outages, bus voltage violations, and generation loss. This simulation studies are conducted on IEEE 9 and 39 bus systems. The results show the improvement of the defense strategy through the learning process. The results also prove the feasibility of the learned attack actions by replicating the disturbances created in simulated power system.

attack impacts↗

PathTrace and MPVEASI: A Path Analysis Comparative Validation Study

Developed in 2018, PathTrace is a software package built with the intention of making path analysis simple and intuitive. PathTrace is a top-down pathway analysis software where a user is able to explore vulnerable pathways into a facility. The intention of utilizing a software tool like PathTrace is to characterize an existing physical protection system (PPS) and to upgrade the system to achieve a high level of response interruption, or probability of interruption (P I ) of the adversary. There are four steps for conducting path analysis using PathTrace. The first step is to identify an image to use to build the model and scale the model within PathTrace using a section of known distance (wall or fence perimeter, for example). The scaling process will produce a grid of cells through which the user is able to build a model. The second step is to fill out the grid of cells with four categories of materials: Barriers, Detection Areas, Jumps, and Targets. These materials apply associated delay and detection values to the cells in which they are applied. The third step is to represent the adversary and response forces. The adversaries are represented by their capabilities in interacting with the materials identified in step two, and the response is represented by how quickly they will be able to respond to an adversary attack. Finally, the user is able to take all of the information from the previous three steps and perform a Most Vulnerable Path (MVP) analysis. In this stage, the user is able to visualize vulnerable adversary pathways and reason about how to upgrade these pathways to provide a high level of P I .

97 MATHEMATICS AND COMPUTING↗

A Novel Framework for Parametric Analysis of Coastal Transition Zone Modeling

Abstract Vulnerability of coastal regions to extreme events motivates an operational coupled inland‐coastal modeling strategy focusing on the coastal transition zone (CTZ), an area between the coast and upland river. To tackle this challenge, we propose a top‐down framework for investigating the contribution of different processes to the hydrodynamics of CTZs with various geometrical shapes, different physical properties, and under several forcing conditions. We further propose a novel method, called tidal vanishing point (TVP), for delineating the extent of CTZs through the upland. We demonstrate the applicability of our framework over the United States East and Gulf coasts. We categorize CTZs in the region into three classes, namely, without estuary (direct river–coast connection), triangular‐, and trapezoidal‐shaped estuary. The results show that although semidiurnal tidal constituents are dominant in most cases, diurnal tidal constituents become more prevalent in the river segment as the discharge increases. Also, decreasing the bed roughness value promotes more significant changes in the results than increasing it by the same value. Additionally, the estuary promotes tidal energy attenuation and consequently decreases the reach of tidal signals through the upland. The proposed framework is generic and extensible to any coastal region.

Chegini, Taher↗

Large-Scale Hydrogen Storage Cyber Risk Assessment

Hydrogen storage systems may become more widely deployed throughout the country, and so it is possible that individual and interconnected systems will be exposed to cyber-attacks. These events can cause physical and financial harm to employees, people in the vicinity of the facility, and the company that owns the facility. The two main ways bad actors may access information or control from a hydrogen storage facility are through information technology and operations technology devices, the former of which refers to data and information from networked devices and the latter of which refers to onsite controls for the physical system. Both types of entryways into the system should be considered when companies conduct cyber risk assessments and when regulators develop or revise relevant codes and standards. This report analyzes cybersecurity risks associated with a generic hydrogen storage system by outlining the system's purpose and the importance of its cybersecurity. The hydrogen storage system architecture and communication protocols are provided to understand potential cyber vulnerabilities. Later, an event tree analysis is performed on hydrogen operation to identify system weaknesses by outlining potential attack scenarios. This report also identifies critical cyber assets related to different hydrogen operations followed by an examination of potential threats, and the impact of cyber assets on those operational assets.

08 HYDROGEN↗

Large-Scale Hydrogen Storage Cyber Risk Assessment

Hydrogen storage systems are becoming more widely deployed throughout the country, and as their presence continues to grow, it is possible that individual and interconnected systems will be exposed to cyber-attacks. These events can cause physical and financial harm to employees, people in the vicinity, and to the company that owns the facility. The two main mechanisms malicious actors may access information or control from a hydrogen storage facility are through information technology and operations technology devices, the former of which refers to data and information from networked devices and the latter of which refers to onsite controls for the physical system. Both types of entryways into the system should be considered when facility managers conduct cyber risk assessments and when regulators develop or revise relevant codes and standards. This report analyzes cybersecurity risks applicable to a wide variety of hydrogen storage systems by outlining the system's purpose and the importance of its cybersecurity. The hydrogen storage system architecture and communication protocols are provided to understand potential cyber vulnerabilities. Later, an event tree analysis is performed on hydrogen operation to identify system weaknesses by outlining potential attack scenarios. This report also identifies critical cyber assets related to different hydrogen operations followed by an examination of potential threats, and the impact of cyber assets on those operational assets.

08 HYDROGEN↗

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN↗

Automated Vulnerability Detection (AVUD) for Compiled Smart Grid Software

This project developed and implemented a system for conducting cybersecurity vulnerability detection of smart grid components and systems by performing static analysis of compiled software (“firmware”). The resulting system for automated vulnerability detection (AVUD) was implemented as part of Oak Ridge National Laboratory’s existing test bed for smart meters, the Sustainable Campus Initiative. The work consisted of two phases: the first phase implemented the necessary software and computational models to perform the analysis, and the second phase demonstrated the system on example firmware in partnership with smart meter manufacturer Sensus USA, Inc. The resulting system won an R&D 100 award and has been successfully commercialized, winning a National Laboratory Consortium Commercialization Award.

97 MATHEMATICS AND COMPUTING↗

Analysis of Historical Power Outages of the United States and the National Risk Index

Several works have been documented in the literature to study the societal effect of power outages and to analyze their correlation with the Social Vulnerability Index (SVI). However, the relationship between National Risk Index (NRI) and power outages is yet to be explored. This work analyzes the NRI indices such as Risk, Expected Annual Loss, Social Vulnerability, and Community Resilience with several resilience metrics such as event duration, impact duration, recovery duration, impact level, impact rate, recovery rate, recovery to impact ratio, and area under the outage curves to see the correlation of NRI indices with the resilience metrics. The results show that NRI indices such as Risk and Expected Annual Loss increase with the increase of event duration, impact duration, and recovery duration. All Other metrics are indifferent to the change in the Risk and EAL ratings. The results also show that there is no strong relationship between all the metrics and community resilience and social vulnerability. This work also performed the sensitivity analysis of the extreme event selection process. This sensitivity analysis reveals that the way of identifying extreme events has a significant impact on the evaluation of the events.

Bhusal, Narayan↗

Visualizing a Vulnerability: Its Connections to Hardware and Software

All Hazards Analysis (AHA) is a framework developed by Idaho National Laboratory that provides capabilities to collect, store, analyze, and visualize critical infrastructure information. A core function of AHA is its ability to simulate faults or outages in networks of infrastructure originating from a plethora of causes, ranging from natural disasters to cyberattacks. AHA utilizes Hardware and Software Bills of Material (HBOM and SBOM, respectively) along with Known Exploited Vulnerabilities (KEVs) to document the potential attack vectors for each piece of infrastructure. The objective of this contribution to AHA was to create a visualization tool that could capture the small details held in each individual artifact as well as preserve the large-scale connections that link them together to aid threat modeling.

58 GEOSCIENCES↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Development of FRET clusters for CBRN Detection

Advanced sensor capabilities for the simultaneous on-site detection of specific chemical, biological, and radiological/nuclear (CBRN) threats is important to significantly limit the risk of exposure to personnel and allow the rapid collection of essential scientific data and critical evidence. Commercially available sensor capabilities are generally complex, and/or require highly specific and ultra-sensitive methods that are often power demanding or require offsite post-analysis for positive detection, leaving personnel vulnerable. The goal of this project is to develop a portable sensor capable of simultaneously detecting CBRN signatures using a multiplexed Förster Resonance Energy Transfer (FRET) based sensor. FRET sensors are tailorable, specific, and highly dependent on the donor-acceptor distance. In this project, nanoparticles were functionalized with aptamers that were designed for the detection of methylphosphonate, a sarin metabolite. FRET was measured between quantum dot donors and dye and metal nanoparticle acceptors using optical spectroscopy.

61 RADIATION PROTECTION AND DOSIMETRY↗

Best Practices for Timing Attack Mitigation

GPS signals play essential roles in the electric subsector by providing precision timing used to synchronize and record measurements from a range of equipment. However, previous research has demonstrated that GPS signals can be spoofed or jammed relatively easily in order to interfere with timing-reliant equipment. This document outlines utility best practices for mitigating against timing attacks in the electric subsector based on an assessment of the difficulty and impact of realistic timing attacks and testing of the effectiveness of technologies capable of mitigating them. This analysis builds on research establishing the vulnerability of GPS-reliant timing equipment to jamming and spoofing by elaborating the difficulty, consequences, and mitigations for timing attacks that adversaries might realistically attempt. While timing attacks are relatively low-cost, low-sophistication, and capable of systemic consequences in the electric subsector, they can be effectively mitigated through well-targeted and diverse mitigations.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Templates for Risk Informed Assurance with Curvature Embeddings (TRACE)

We investigate recovery of geometric structure from networks embedded in manifolds with spatially varying curvature, extending the constant-curvature framework of Lubold et al. (2023). Our work supports cascade risk assessment in critical infrastructure through the Templates for Risk-informed Assurance with Curvature Embeddings (TRACE) framework. Simulations on a bi-modal Gaussian surface show that constant-curvature methods yield weighted averages shaped by clique patterns, while hierarchical clustering identifies distinct regimes. Localized estimation, however, reveals boundary contamination in transitional regions. To address heterogeneity, we develop distance metrics for graphs with edge and node features, proving their metric validity, and validate them via deterministic graph generation from canonical tilings. We further propose a diffusion-based anomaly detection approach that treats networks as glued manifolds, using curvature discontinuities to detect structural anomalies. Employing the carré-du-champ operator and scalar curvature, we achieve robust anomaly discrimination, demonstrated on the Singapore Water Treatment (SWaT) dataset with joint network-traffic and sensor features. Integration with TRACE reveals how curvature shapes cascade dynamics: positive curvature impedes, while negative curvature accelerates propagation. This geometric perspective provides interpretable risk metrics and visualization tools for critical infrastructure managers. While full validation remains ongoing, our contributions establish a rigorous foundation for geometric analysis of network resilience and cascade vulnerability.

97 MATHEMATICS AND COMPUTING↗

FIC Vulnerability Profile

The FIC team is engaged with Pacific Northwest National Laboratory’s (PNNL’s) Shamrock Cyber Team to provide cybersecurity analyses of the FIC software. Shamrock offers both Threat-Based Analysis services and Secure Software Development services. These services are ultimately used to understand and mitigate threats against software and to reduce vulnerabilities in software, thus improving overall cybersecurity and informing decision makers. Shamrock’s Secure Software Development services, specifically Static Analysis Security Testing (SAST) and Open-Source Analysis (OSA), produced this Vulnerability Profile.

97 MATHEMATICS AND COMPUTING↗

A Method for Measuring Coupled Individual and Social Vulnerability to Environmental Hazards

Although models of social vulnerability to environmental hazards are commonly developed to support policy interventions in emergencies and disasters, their utility is hindered by a lack of contextual information on individuals exposed to and affected by hazards. We develop a novel approach to model social vulnerability that couples individuals and their varying forms of protective capacity with the social fabric of the communities in which they reside. The backbone of our model is the Public-Use Microdata Sample (PUMS), a product of the U.S. Census Bureau that preserves a representative sample of completed responses to the American Community Survey (ACS). The PUMS enables us to understand the full range of individual protective capacities against a hazard in an exposed area, which we term individual vulnerability profiles (IVPs). In this case, we examine IVPs in the Coney Island-Brighton Beach section of New York City, which suffered severe impacts during Hurricane Sandy in 2012. To manage the large number of unique IVPs in Coney Island-Brighton Beach, we perform a segmentation analysis to generalize them into thematic cohort vulnerability profiles (CVPs) representing a typology of vulnerable people in Coney Island-Brighton Beach during Sandy. From synthetic populations of CVPs, we then estimate how individuals in varying housing types were coexposed to Sandy at the census tract level by classifying these areas into community social vulnerability profiles (SVPs). Our results provide a topology of social vulnerability that simultaneously links individual, community, and population-wide concerns, enabling a more holistic understanding of resources and interventions beneficial to human security during events like Sandy than is attainable with area-level metrics.

54 ENVIRONMENTAL SCIENCES↗

Failure Mode and Effects Analysis (FMEA) for Photovoltaic Inverter

Photovoltaic (PV) inverters are critical yet vulnerable components in modern energy systems, often acting as reliability bottlenecks that increase the levelized cost of energy (LCOE). To address this, this paper presents a comprehensive Failure Mode and Effects Analysis (FMEA) tailored for PV inverters. Leveraging field data and literature, we identify failure-prone components, such as capacitors,, and relays, and prioritize their risks based on quantitative Risk Priority Numbers (RPNs). The analysis reveals that surge-induced MOV short circuits, capacitor degradation, and environmental cooling fan failures dominate the risk profile. These findings provide a targeted framework for reliability improvement, guiding future efforts in predictive diagnostics, design optimization, and accelerated life testing strategies.

14 SOLAR ENERGY↗

Towards Improving Container Security by Preventing Runtime Escapes

Container escapes enable the adversary to execute code on the host from inside an isolated container. Notably, these high severity escape vulnerabilities originate from three sources: (1) container profile misconfigurations, (2) Linux kernel bugs, and (3) container runtime vulnerabilities. While the first two cases have been studied in the literature, no works have investigated the impact of container runtime vulnerabilities. In this paper, to fill this gap, we study 59 CVEs for 11 different container runtimes. As a result of our study, we found that five of the 11 runtimes had nine publicly available PoC container escape exploits covering 13 CVEs. Our further analysis revealed all nine exploits are the result of a host component leaked into the container. Here, we apply a user namespace container defense to prevent the adversary from leveraging leaked host components and demonstrate that the defense stops seven of the nine container escape exploits.

42 ENGINEERING↗

Mapping heat vulnerability in cities: A tale of two california cities

Extreme heat is a major cause of weather-related deaths in the United States. To address this, a heat vulnerability index (HVI) is crucial for assessing heat risk and identifying vulnerable urban areas and populations, supporting city planning and emergency response. Current HVI studies often use Principal Component Analysis (PCA) on environmental, socioeconomic, and medical data to aggregate vulnerability indicators into a single index. However, these fixed aggregation weights struggle to adapt to different use cases, which may require varying focuses. Moreover, existing tools primarily consider outdoor heat exposure, providing an incomplete picture of actual exposure, as people spend most of their time indoors. Our research introduces an HVI web mapping tool that addresses these gaps in the literature by: (1) allowing flexible weights to adapt to different use cases, and (2) uniquely integrating both outdoor and indoor heat exposure by considering building characteristics for a more comprehensive risk assessment. We demonstrated this tool in two California cities with contrasting climates: Fresno (inland, arid, hot summers) and Oakland (temperate coastal). This HVI mapping tool provides essential decision support for policymakers and stakeholders in both short-term heat mitigation and long-term urban planning for building interventions and infrastructure development.

BES↗