Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “timing vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Disproportionate impacts of COVID-19 in a large US city

COVID-19 has disproportionately impacted individuals depending on where they live and work, and based on their race, ethnicity, and socioeconomic status. Studies have documented catastrophic disparities at critical points throughout the pandemic, but have not yet systematically tracked their severity through time. Using anonymized hospitalization data from March 11, 2020 to June 1, 2021 and fine-grain infection hospitalization rates, we estimate the time-varying burden of COVID-19 by age group and ZIP code in Austin, Texas. During this 15-month period, we estimate an overall 23.7% (95% CrI: 22.5–24.8%) infection rate and 29.4% (95% CrI: 28.0–31.0%) case reporting rate. Individuals over 65 were less likely to be infected than younger age groups (11.2% [95% CrI: 10.3–12.0%] vs 25.1% [95% CrI: 23.7–26.4%]), but more likely to be hospitalized (1,965 per 100,000 vs 376 per 100,000) and have their infections reported (53% [95% CrI: 49–57%] vs 28% [95% CrI: 27–30%]). We used a mixed effect poisson regression model to estimate disparities in infection and reporting rates as a function of social vulnerability. We compared ZIP codes ranking in the 75th percentile of vulnerability to those in the 25th percentile, and found that the more vulnerable communities had 2.5 (95% CrI: 2.0–3.0) times the infection rate and only 70% (95% CrI: 60%-82%) the reporting rate compared to the less vulnerable communities. Inequality persisted but declined significantly over the 15-month study period. Our results suggest that further public health efforts are needed to mitigate local COVID-19 disparities and that the CDC’s social vulnerability index may serve as a reliable predictor of risk on a local scale when surveillance data are limited.

60 APPLIED LIFE SCIENCES↗

CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure

Society and modern life are dependent on critical infrastructure that is composed of expensive, special purpose devices that have long life cycles and may be in use for decades before being replaced. There are an abundance of organizations and individuals doing vulnerability analysis on a variety of systems, but what makes the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program unique and valuable is its strategic focus on high-priority critical infrastructure, close partnership with vendors, and ability to leverage bills of materials (BOMs) to identify and relate vulnerabilities to affected systems. Creating a bill of materials is a formal way of understanding and documenting the components of a system, including everything from integrated circuits to operating systems to third-party libraries. This is beneficial for connecting known vulnerabilities to affected devices, since vulnerabilities in a specific component are often not mapped to all systems that use that vulnerable component. Additionally, CyTRICS finds novel vulnerabilities through its vulnerability testing process and works closely with vendor partners to provide vulnerability reports so that affected systems can be patched in a timely manner. This presentation will describe the interrelated technical processes CyTRICS uses to create bills of materials and conduct vulnerability analysis.

99 GENERAL AND MISCELLANEOUS↗

Method and Apparatus for Reducing the Vulnerability of Latches to Single Event Upsets

A delay circuit includes a first network having an input and an output node, a second network having an input and an output, the input of the second network being coupled to the output node of the first network. The first network and the second network are configured such that: a glitch at the input to the first network having a length of approximately one-half of a standard glitch time or less does not cause the voltage at the output of the second network to cross a threshold, a glitch at the input to the first network having a length of between approximately one-half and two standard glitch times causes the voltage at the output of the second network to cross the threshold for less than the length of the glitch, and a glitch at the input to the first network having a length of greater than approximately two standard glitch times causes the voltage at the output of the second network to cross the threshold for approximately the time of the glitch. The method reduces the vulnerability of a latch to single event upsets. The latch includes a gate having an input and an output and a feedback path from the output to the input of the gate. The method includes inserting a delay into the feedback path and providing a delay in the gate.

Robert L Shuler, Jr.↗

Method and Apparatus for Reducing the Vulnerability of Latches to Single Event Upsets

A delay circuit includes a first network having an input and an output node, a second network having an input and an output, the input of the second network being coupled to the output node of the first network. The first network and the second network are configured such that: a glitch at the input to the first network having a length of approximately one-half of a standard glitch time or less does not cause tile voltage at the output of the second network to cross a threshold, a glitch at the input to the first network having a length of between approximately one-half and two standard glitch times causes the voltage at the output of the second network to cross the threshold for less than the length of the glitch, and a glitch at the input to the first network having a length of greater than approximately two standard glitch times causes the voltage at the output of the second network to cross the threshold for approximately the time of the glitch. A method reduces the vulnerability of a latch to single event upsets. The latch includes a gate having an input and an output and a feedback path from the output to the input of the gate. The method includes inserting a delay into the feedback path and providing a delay in the gate.

Robert L Shuler Jr.↗

Development of a vadose zone advanced monitoring system: Tools to assess groundwater vulnerability

Performing repeat pore-fluid sampling over long time-scales can provide valuable information on unsaturated zone contaminants and their potential flux to ground water. This information can be used to manage groundwater remedies and identify contaminants that need to be sequestered in the vadose zone to minimize flux to ground water. Pore-water samples are commonly used to obtain contaminant concentrations within the vadose zone, but existing methods are limited as they only provide a single sample at one location and time. The vadose zone advanced monitoring system (VZAMS) has been designed to integrate multiple technologies into a single down-borehole system that allows for sampling of pore fluids (liquid and gas) to provide information about contamination and hydraulic conditions at multiple depths (~0.3-m intervals) within a cased borehole. Testing has been completed at the laboratory scale to verify the sampling elements of VZAMS, including geochemical testing for representative contaminants known to exist at the Hanford Site, located in southeastern Washington State. Physical tests focused on the ability of the sampler to draw fluid under unsaturated conditions. Initial geochemical testing showed that the stainless steel material used with the porous cuff may affect the sampled concentrations of redox-sensitive contaminants under very dry conditions. Additional laboratory testing demonstrated that the VZAMS components are able to collect representative samples for substances of interest under expected field conditions. In this paper, the design and functionality of a novel instrument are demonstrated in support of subsequent testing in the field.

54 ENVIRONMENTAL SCIENCES↗

Impacts of benchmarking choices on inferred model skill of the Arctic–Boreal terrestrial carbon cycle

Abstract Land surface models require continuous validation against observations to improve and reduce simulation uncertainty. However, inferred model performance can be heavily influenced by subjective choices made in the selection and application of observational data products. A key area often misrepresented by models is the Arctic–Boreal region, which is a potential tipping point region in Earth’s climate system due to large permafrost carbon stocks that are vulnerable to release with climate warming. We use the International Land Model Benchmarking (ILAMB) framework to evaluate how the model skill of TRENDY-v9 models varies based on the choice of observational-based benchmark and how benchmarks are applied in model evaluation. This analysis uses global datasets integrated into ILAMB and new, regionally-specific observational products from the Arctic–Boreal Vulnerability Experiment. Our results cover the overall time period of 1979–2019 and show that model scores can vary substantially depending on the data product applied, with higher model scores indicating better model performance against observations. The lowest model scores occur when benchmarked against regional, compared to global, datasets. We also evaluate observed and modeled functional relationships between ecosystem respiration and air temperature and between gross primary production and precipitation. Here, we find that the magnitude and shape of the responses are strongly impacted by the choice of observational dataset and the approach used to construct the functional relationship benchmark. These results suggest that model evaluation studies could conclude a false sense of model skill if only using a single benchmark data product or if not applying regional data products when performing a regional model analysis. Collectively, our findings highlight the influence of benchmarking choices on model evaluation and point to the need for benchmarking guidelines when assessing model skill.

Poe, Jeralyn (ORCID:0000000318495278)↗

Cy-Phy ADS: Cyber Physical Anomaly Detection Framework for EV Charging Systems

Today’s large-scale Electric Vehicle (EV) infrastructures are heavily dependent on information communication technologies to maintain their operation and to support communication within sub-system components as well as the outside world. These technologies are vulnerable to various cyber and physical threats. Timely identification and mitigation of these threats are critical for improving human safety, avoiding economic losses, and preventing catastrophic system failures. By addressing this, our work presents a ResNet Autoencoder (AE) based Cyber-Physical Anomaly Detection System (Cy-Phy ADS) for detecting anomalies in EV Controller Area Network (CAN) protocol communication. It consists of four main components: Cyber-Physical Feature Extractor, ResNet AE-based Anomaly Detection Framework, Cyber-Physical Health Metric (CPHM), and Visualization Dashboard. The presented framework was trained and tested using CAN data collected from the EV charging system testbed at the Idaho National Laboratory. The presented Cy-Phy ADS compared against six widely used unsupervised anomaly detection algorithms: One Class Support Vector Machine (OCSVM), Variational Autoencoder (VAE), LSTM Autoencoder (LSTM AE), Isolation Forest (IForest), Principle Component Analysis (PCA) and Local Outlier Factor (LOF). Here the presented approach showed the highest accuracy among the compared methods. Further, the proposed approach showed comparable performance in terms of precision, F1, and False positive rate. It also showed the lowest training and inference time compared to the neural network-based baseline algorithms compared against with. Additionally, the Cy-Phy ADS has advantages such as unsupervised training, the ability to provide a holistic metric for system health characterization, and non-linear feature extraction.

99 GENERAL AND MISCELLANEOUS↗

Temperature-induced degradation of GaN HEMT: An in situ heating study

High-power electronics, such as GaN high electron mobility transistors (HEMTs), are expected to perform reliably in high-temperature conditions. This study aims to gain an understanding of the microscopic origin of both material and device vulnerabilities to high temperatures by real-time monitoring of the onset of structural degradation under varying temperature conditions. This is achieved by operating GaN HEMT devices in situ inside a transmission electron microscope (TEM). Electron-transparent specimens are prepared from a bulk device and heated up to 800 °C. High-resolution TEM (HRTEM), scanning TEM (STEM), energy-dispersive x-ray spectroscopy (EDS), and geometric phase analysis (GPA) are performed to evaluate crystal quality, material diffusion, and strain propagation in the sample before and after heating. Gate contact area reduction is visible from 470 °C accompanied by Ni/Au intermixing near the gate/AlGaN interface. Elevated temperatures induce significant out-of-plane lattice expansion at the SiNx/GaN/AlGaN interface, as revealed by geometry-phase GPA strain maps, while in-plane strains remain relatively consistent. Exposure to temperatures exceeding 500 °C leads to almost two orders of magnitude increase in leakage current in bulk devices in this study, which complements the results from our TEM experiment. The findings of this study offer real-time visual insights into identifying the initial location of degradation and highlight the impact of temperature on the bulk device’s structure, electrical properties, and material degradation.

36 MATERIALS SCIENCE↗

Freddie Software Security Patching

Software applications become more complicated over time as they depend on many third-party, open-source libraries. The Freddie Platform Services team actively improves software security by addressing software bugs and vulnerabilities that negatively impact software applications, especially those providing real-time operations and services for the federal partners and industries. In order to detect bugs and patch vulnerabilities in software development and maintenance cycles, an automated and systematic approach is needed. This document describes what bugs and vulnerabilities are, and how they can be detected by using static code analyzers and software composition analysis tools. Once vulnerabilities are detected, the patching approaches, such as upgrading direct and transitive dependencies and loading custom classes first, are presented together with their strengths and weaknesses. In addition, patching walkthrough, example code, lessons learned throughout the vulnerability patching process and the recommended practices are discussed.

Chok Fung Lai↗

Time-Based CAN IDS Paper Results Code

Modern vehicles are complex cyber-physical systems made of hundreds of electronic control units (ECUs) that communicate over controller area networks (CANs). This inherited complexity has expanded the CAN attack surface which is vulnerable to message injection attacks. These injections change the overall timing characteristics of messages on the bus, and thus, to detect these malicious messages, time-based intrusion detection systems (IDSs) have been proposed. However, time-based IDSs are usually trained and tested on low-fidelity datasets with unrealistic, labeled attacks. This makes difficult the task of evaluating, comparing, and validating IDSs. Here we detail and benchmark four time-based IDSs against the newly published ROAD dataset, the first open CAN IDS dataset with real (non-simulated) stealthy attacks with physically verified effects. We found that methods that perform hypothesis testing by explicitly estimating message timing distributions have lower performance than methods that seek anomalies in a distribution related statistic. In particular, these “distribution-agnostic” based methods outperform “distribution-based” methods by at least 55% in area under the precision-recall curve (AUC-PR). Our results expand the body of knowledge of CAN time-based IDSs by providing details of these methods and reporting their results when tested on datasets with real advanced attacks. Finally, we develop an after-market plug-in detector using lightweight hardware, which can be used to deploy the best performing IDS method on nearly any vehicle.

Moriano, Pablo [Oak Ridge National Lab. (ORNL), Oa↗

Precise Timing Based on Pulsar Observation for Grid Synchronization

While Global Positioning System signals are widely used as the synchronized timing Sources for wide-area measurement systems for power grid monitoring and control, they are vulnerable to failures and malicious attacks. To address this Problem, an alternative kind of timing sources, the millisecond pulsars, were proposed to serve the power grid as they are more precise and physically indestructible. Millisecond pulsars are a kind of neutron stars that emit radio pulse signals that have extremely stable periods of milliseconds. However, the observed pulse Signals from pulsars cannot be directly used for timing because of their low signal-to-noise ratio and the dispersion effects of interstellar medium. In this paper, the precise timing method based on pulsar observation data is proposed to interpret the pulsar observation data and therefrom to generate precise timing signal for the power grid synchronization. In our proposed method,. incoherent de-dispersion is used on the observation data to mitigate the effect of interstellar medium. dispersion. Then spectrum analysis and segment folding are used to precisely estimate the local pulsar period. Finally the standard pulse per second signal is generated from. the estimated pulsar period and its precision. is analyzed. Experiments with the observation data of the pulsar based timing signal can be more accurate compared to GPS timing signals.

Luo, Xiqian↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Mini Report: LLMs for Vulnerability Repair in Code

Software vulnerability repair is a notoriously difficult task that is both time consuming and labor intensive. While research into this area has a long history, the recent successes of large language models (LLMs) across many tasks have also spurred efforts to leverage LLM capabilities for automated software vulnerability repair. Currently, there are limitations in the capabilities of LLMs to fix bugs and insufficiently addressed problems in the evaluations of these studies may cause performance to not transfer when they are used in practice. Additionally, most research in the area treats finding and fixing bugs as separate concerns - how to best combine all the subtasks involved in removing vulnerabilities from code remains an open question. In this report, we summarize our findings and opinions on the current state of the art in LLM-assisted code vulnerability repair, highlighting current unresolved problems in the field as well as potential applications and future research.

97 MATHEMATICS AND COMPUTING↗

Effect of GPS Manipulation to Traditional and Next Generation Relay Protection

This project’s objective is to test the effect of GPS timing variations on relay protection algorithms to determine vulnerabilities and the associated hazards to the electric grid. This will focus on differential protection which utilizes peer to peer communication between substations to determine if the current is not equivalent. This requires the use of GPS to sync the two substations and can be vulnerable to GPS manipulation. However, the effects of GPS manipulation are not a commonly known risk. Therefore, this LDRD will address the risks of GPS manipulation for such a widely implemented technology. For differential protection a GPS resilient architecture was implemented and tested for differential protective relays through a direct serial fiber connection between the two relays. This allows for one relay to be the master and provide synchronization outside of timestamp for differential protection.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Nanoporous Wood Chips Based Sizable, Robust, and Low-Cost Honeycomb Vacuum Insulation Panels (DOE BENEFIT Final Research Performance Progress Report (RPPR))

Conventional vacuum insulation panels (VIPs) suffer from severe limitations including high cost, vulnerability to perforation, and significant performance degradation over time due to vacuum loss. InventWood Inc. (IW) and partnering teams completely re-engineered the VIP structure by constructing arrays of isolated vacuum-cells to enable limited cutting at designated areas (in between vacuum cells) and reduced consequential vacuum loss due to puncture. The teams also replaced the expensive vacuum insulation core materials with a low-cost commercial wood pulp and recycled long fiber. The wood pulp derived VIP can deliver an overall panel insulation of R15 (<0.01W/m·K) with over 90% thermal resistance retention after cutting (R13.5 overall, R5 along the cut edges). In addition, the vacuum-cell-array design minimizes edge losses, resulting in more durable performance, longer service life (>50 years), and higher R-value per dollar towards a cost target of <$1/ft 2 ·in. It is anticipated that the Nanochip-VIP will attract strong market interest and become an affordable insulation solution for energy efficient buildings and retrofits, leading to significant reductions in energy usage.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Anticipating Hazard Impacts through Capacity Building and Co-development

Improving forecast accuracy, extending lead time, understanding hazard susceptibility, and integrating exposure and vulnerability data to generate impact-based forecasts are critical in mitigating disaster impacts. These efforts enable anticipatory action through enhancing the efficacy of early warning systems to assess potential multi-dimensional hazard impacts. In response to this need, SERVIR has co-developed a series of hazard services providing vital information from national to regional scales. This poster showcases examples of geospatial services co-developed with partners through a capacity building approach, supporting the establishment of hazard early warning / early action systems. These services integrate multidimensional vulnerability and exposure data to comprehensively assess impacts. Furthermore, these services demonstrate how co-development and capacity building can advance the development of impact-based forecasts and multi-hazards services. By prioritizing collaboration, human insights, local knowledge, capacity building, and employing applied science approaches in geospatial service development, this work has helped create inclusive and customized solutions. These solutions are tailored to meet the needs of local communities and are readily adaptable into decision-making processes.

weather↗

Validating a Dynamic PWR Safety and Security Model?

Nuclear power plants (NPPs) are assessed for safety and security using separate models that cannot capture how an attacker's decisions and a plant's response unfold together in real time, leaving regulators and operators without a complete picture of true plant vulnerability. Traditional probabilistic risk assessment (PRA) methods treat adversarial events as fixed initiators with predetermined outcomes, and are structurally incapable of representing the time-dependent interplay between physical security events, safety system response, and operator mitigative actions. At Idaho National Laboratory (INL), I contributed to the development and validation of Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF). Where static PRA relies on event-tree logic that cannot evolve mid-scenario, MASS-DEF couples a time-dependent dynamic PRA tool EMRALD (Event Modeling Risk Assessment using Linked Diagrams) with attack simulation software, allowing attacker behavior, plant system states, and operator actions to interact across time. My work focused on validating a general Pressurized Water Reactor (PWR) model. I traced model logic against PWR plant to identified errors in logic and confirm accuracy. I then built and tested attack scenarios against a general PWR model to verify that the model produced expected outcomes across all logical pathways. I also contributed a section to a related technical paper applying the same EMRALD platform to radiation dose modeling. Results show that MASS-DEF can quantitatively demonstrate that many plants exceed their regulatory security thresholds. This demonstrated margin provides a technically defensible basis for reducing the number of guards without compromising regulatory compliance. Physical security costs represent roughly 10% of annual operating budgets, making such reductions directly meaningful to INL's mission of sustaining existing commercial NPPs. This internship strengthened my understanding of nuclear systems, probabilistic modeling, and technical writing, and has solidified my pursuit of a career at a national laboratory.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

EMP Testing of NAE Magnetic Motor Starters

Sandia National Laboratories (SNL) performed a high-altitude nuclear electromagnetic pulse (HEMP) critical generation station component vulnerability test campaign with a focus on high-frequency, conducted early-time (E1) HEMP for the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This report provides vulnerability test results to investigate component response and/or damage thresholds to reasonable HEMP threat levels that will help to inform site vulnerability assessments, mitigation planning, and modeling calibrations. This work details testing of North American Electric (NAE) magnetic motor starters to determine the effects of conducted HEMP environments. Motor starters are the control elements that provide power to motors throughout a generating plant; a starter going offline would cause loss of power to critical pumps and compressors, which could lead to component damage or unplanned plant outages. Additionally, failed starters would be unable to support plant startup. Six industrial motor starters were tested: two 2 horsepower (HP) starters with breaker disconnects and typical protection equipment, two 20 HP starters with breaker disconnects, and two 20 HP starters with fused disconnects. Each starter was placed in a circuit with a generator and inductive motor matching the starter rating. The conducted EMP insult was injected on the power cables passing through the motor starter, with separate tests for the generator and motor sides of the starter.

24 POWER TRANSMISSION AND DISTRIBUTION↗