Mjolnir: A Vulnerability Testbed for Power Systems AI
Explore the source record for details and available documents.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.
As the use of microservices continues to grow and become a foundational approach to architecting software solutions, ensuring the security of microservices is paramount. Docker images have emerged as the predominant solution to containerize microservices–and thus, Docker images are becoming a large attack surface. Thus, reducing vulnerabilities in Docker images will reduce microservice cyberattacks. A common way to find vulnerabilities in Docker images employs static analysis tools like Trivy and Grype. However, these tools frequently generate disparate vulnerability reports when analyzing the same Docker image, thus causing uncertainty in tool selection. We collected 927 Docker images, analyzed them with Trivy and Grype, and compared the vulnerabilities reported in each image. Among the 865 images found to have vulnerabilities, Trivy and Grype disagreed on both the number of vulnerabilities and the vulnerability IDs found therein. Since both tools interface with external vulnerability databases, some discrepancies can be attributed to how the tools interface with these external resources. The external vulnerability databases partially overlap and frequently contradict one another, thereby creating challenges for static analysis tool developers and end users alike. This New Ideas and Emerging Results (NIER) study contains new and critical information that practitioners need for selecting and using static analysis tools–given that increases in the use of Docker technologies means increases in the size of the attack surfaces.
Abstract. Fire is a fundamental part of the Earth system, with impacts on vegetation structure, biomass, and community composition, the latter mediated in part via key fire-tolerance traits, such as bark thickness. Due to anthropogenic climate change and land use pressure, fire regimes are changing across the world, and fire risk has already increased across much of the tropics. Projecting the impacts of these changes at global scales requires that we capture the selective force of fire on vegetation distribution through vegetation functional traits and size structure. We have adapted the fire behavior and effects module, SPITFIRE (SPread and InTensity of FIRE), for use with the Functionally Assembled Terrestrial Ecosystem Simulator (FATES), a size-structured vegetation demographic model. We test how climate, fire regime, and fire-tolerance plant traits interact to determine the biogeography of tropical forests and grasslands. We assign different fire-tolerance strategies based on crown, leaf, and bark characteristics, which are key observed fire-tolerance traits across woody plants. For these simulations, three types of vegetation compete for resources: a fire-vulnerable tree with thin bark, a vulnerable deep crown, and fire-intolerant foliage; a fire-tolerant tree with thick bark, a thin crown, and fire-tolerant foliage; and a fire-promoting C4 grass. We explore the model sensitivity to a critical parameter governing fuel moisture and show that drier fuels promote increased burning, an expansion of area for grass and fire-tolerant trees, and a reduction of area for fire-vulnerable trees. This conversion to lower biomass or grass areas with increased fuel drying results in increased fire-burned area and its effects, which could feed back to local climate variables. Simulated size-based fire mortality for trees less than 20 cm in diameter and those with fire-vulnerable traits is higher than that for larger and/or fire-tolerant trees, in agreement with observations. Fire-disturbed forests demonstrate reasonable productivity and capture observed patterns of aboveground biomass in areas dominated by natural vegetation for the recent historical period but have a large bias in less disturbed areas. Though the model predicts a greater extent of burned fraction than observed in areas with grass dominance, the resulting biogeography of fire-tolerant, thick-bark trees and fire-vulnerable, thin-bark trees corresponds to observations across the tropics. In areas with more than 2500 mm of precipitation, simulated fire frequency and burned area are low, with fire intensities below 150 kW m−1, consistent with observed understory fire behavior across the Amazon. Areas drier than this demonstrate fire intensities consistent with those measured in savannas and grasslands, with high values up to 4000 kW m−1. The results support a positive grass–fire feedback across the region and suggest that forests which have existed without frequent burning may be vulnerable at higher fire intensities, which is of greater concern under intensifying climate and land use pressures. The ability of FATES to capture the connection between fire disturbance and plant fire-tolerance strategies in determining biogeography provides a useful tool for assessing the vulnerability and resilience of these critical carbon storage areas under changing conditions across the tropics.
This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.
The cyber risk landscape for BESS and IBR can be broken up by threats, vulnerabilities, and consequences for these systems. This presentation walks through the cyber risk landscape for BESS through the lens of consequence-informed awareness and mitigation for each risk factor. Threats with varying capabilities have been demonstrated in real-world events. Though threat actors can rarely be directly influenced by organizations, exposure of systems to adversaries can be limited (a known issue with IBR systems) to reduce likelihood of adversaries accessing systems with disruptive consequences. Common trends in disclosed IBR vulnerabilities include weak password generation or managements for various devices or services and web portal vulnerabilities that provide unauthorized access to data or capabilities or elevated user privileges. Understanding these common vulnerabilities and considering the consequences if these types of vulnerabilities were to occur can help mitigate risk. Consequences range from loss-of-view events that have no reliability impact to asset damage or grid stability impacts. Five case studies are briefly shared to highlight trends in real-world events affecting IBR.
When a vulnerability is reported by the National Vulnerability Database (NVD), affected products are listed in the structured Common Platform Enumeration (CPE) format. Unfortunately, if the vulnerability is in a software library (e.g., Log4j), it will not include CPEs for each product containing that library. In these cases, security operators need to manually read the vendor's or third-party security advisories to see if their product is affected. However, these advisories do not report affected products in a structured format, which prevents automated processing, This paper makes the first effort towards automatically constructing structured CPEs for the vulnerable products in a non-NVD security advisory from the unstructured data in the advisory. Since this is a very challenging problem, this paper specifically focuses on the initial but key step of matching the un-structured vendor names in security advisories to the structured vendor representations in the standard CPE format. We explore the feasibility of using string similarity to solve the problem. The basic idea is to compare a vendor name from the non-NVD advisory with each vendor in the official CPE dictionary. The CPE vendor with the highest similarity score to the advisory's vendor will be considered as the match. We first conduct an experimental, comparative study of multiple mainstream string similarity metrics for this matching problem. To improve the performance, we then design a new string similarity metric that is adapted from an existing metric by weighing different tokens in the advisory's vendor name differently.
Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.
The use of Splunk for analyzing VPN logs is an effective approach for identifying vulnerabilities in network endpoints. Splunk, a powerful platform for searching, monitoring, and analyzing machine-generated data, enables organizations to aggregate VPN logs in real-time, providing insights into network activity, user behavior, and potential security risks. By indexing VPN traffic and authentication logs, security teams can track abnormal patterns such as multiple failed login attempts, unusual IP addresses, or unexpected changes in bandwidth usage, all of which could indicate potential vulnerabilities or breaches. With Splunk’s advanced search and reporting capabilities, users can create custom dashboards and alerts to detect suspicious activities. Automated searches can flag endpoints exhibiting unusual behavior, while correlation analysis can identify links between compromised devices and broader network vulnerabilities. In particular, Splunk's machine learning capabilities can be leveraged to predict and prevent threats by identifying trends that might otherwise be missed in traditional log analysis. This proactive approach to monitoring VPN logs allows for the early detection of security weaknesses, enabling rapid response and minimizing potential damage to network integrity. By enhancing endpoint visibility, Splunk plays a crucial role in securing remote connections and safeguarding sensitive information. Additionally, Splunk’s automation and alerting features allow teams to create custom workflows that notify them of vulnerable or misconfigured endpoints identified through Shodan. This synergy between Splunk’s log analysis and Shodan’s device intelligence enhances an organization’s ability to proactively identify and mitigate security risks, improving the overall resilience of their VPN infrastructure.
We examine the state of publicly available information about known exploitable vulnerabilities applicable to operational technology (OT) environments. Specifically, we analyze the Known Exploitable Vulnerabilities Catalog (KEVC) maintained by the US Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) to assess whether currently available data is sufficient for effective and reliable remediation in OT settings. Our team analyzed all KEVC entries through July 2025 to determine the extent to which OT environments can rely on existing remediation recommendations. We found that although most entries in the KEVC could affect OT environments, only 13% include vendor workarounds or mitigations as alternatives to patching. This paper also examines the feasibility of developing such alternatives based on vulnerability and exploit characteristics, and we present early evidence of success with this approach.
Abstract Fuzzing is an automated process for discovering inputs in a program that may trigger unexpected behavior. Today, fuzzing has become a standard practice for the discovery of bugs and security vulnerabilities. However, the main issue with such practices is that the exploration of the input space of programs can often be prohibitively expensive. Therefore, several alternative fuzzing strategies have been introduced during the last few years. Some fuzzing techniques rely on human expertise to provide a plausible set of initial input examples, namely, seeds. However, the process of handcrafting seeds for fuzzing purposes often becomes strenuous for humans as it requires a deeper understanding of the Program-Under-Test (PUT). Also, the use of known inputs to programs often does not trigger vulnerable program behavior or may not reach potentially vulnerable code locations. To address those issues, we propose a seed generation framework that enables Human-In-The-Loop (HITL) directed fuzzing where the human assumes a more active role in the creation of seeds that can penetrate and assess desired locations of the PUT. Our proposed framework uses Symbolic Execution (SE) to generate seeds that exercise paths to target program locations. Moreover, our framework enables the visualization of the explored execution paths in the binary of the PUT for the generated seeds. We evaluated our approach on a set of 12 carefully designed C programs with diverse characteristics that mimic real-world programs. The experimental results show the effectiveness of the proposed approach in improving the performance of standard fuzzing tools such as the American Fuzzy Lop ("Image missing" <#comment/> ). Specifically, our solution can generate seeds that substantially enhance the performance of the fuzzer, achieving speedups ranging from $$1.46\times $$ 1.46 × to $$68.53\times $$ 68.53 × for branch conditions, $$1.39\times $$ 1.39 × to $$254.62\times $$ 254.62 × for branch depths, $$14,879.59\times $$ 14 , 879.59 × to $$30,295.88\times $$ 30 , 295.88 × for branch widths over traditional seeds. Additionally, the speedup increases with the number of target function ranging from $$12,260\times $$ 12 , 260 × to $$22,856.07\times $$ 22 , 856.07 × over traditional seeds while only requiring less than 15 seconds on average for the seed generation step.
Abstract Embodied carbon refers to the greenhouse gas emission associated with the lifecycle of buildings. Embodied carbon policies are critical for addressing the environmental impact of construction materials and advancing climate goals. Despite their importance, the adoption of embodied carbon policies has been limited globally, influenced by economic, environmental, institutional, and trade factors. This study employs structural equation modeling to analyze 37 countries, testing ten hypotheses across four categorical factors. The base model reveals the significant influence of environmental vulnerability and institutional frameworks on policy adoption, while robustness models confirm the critical role of trade dependencies and economic competitiveness in shaping national embodied carbon strategies. Findings underscore that countries with high climate vulnerability and strong institutional support are more likely to adopt embodied carbon policies. Conversely, trade-reliant nations face challenges balancing competitiveness and sustainability. Policy implications suggest the need for international collaboration to align trade policies with carbon reduction goals, targeted support for vulnerable nations, and the integration of embodied carbon considerations into existing climate frameworks. These results offer a roadmap for policymakers to design more effective and equitable embodied carbon policies, fostering global progress toward sustainable construction and decarbonization.
Soil organic carbon (SOC) comprises particulate (POC) and mineral-associated organic carbon (MAOC), which differ in formation, stabilization, and loss mechanisms. While the current global distribution of POC and MAOC is characterized, their vulnerability under future climate scenarios remains unclear. Using 3284 topsoil (0-30 cm) observations from six continents, we identify high-latitude soils as global hotspots of SOC vulnerability under shared socioeconomic pathway scenarios (SSP126, SSP245, and SSP585). Under a high-emission scenario (SSP585), high-latitude soils are projected to lose substantial POC by 2100, accounting for about 81 ± 10% of total SOC losses. These declines are driven by the high proportion of SOC stored as POC (f POC ) and its high temperature sensitivity. We show that f POC is a robust indicator of SOC vulnerability to climate change. Globally, the projected POC decline corresponds to a cumulative carbon dioxide (CO 2 ) release of 81.34 Pg CO 2 -equivalent by 2100, highlighting the importance of preserving POC to mitigate climate feedbacks.
Indoor cooling is essential to reduce heat stress and increase passive survivability during heatwaves. Although air conditioning (AC) is recommended for maintaining indoor thermal comfort, low- and medium-income households in the U.S. often do not own an AC and/or limit AC usage to reduce energy consumption and associated costs, thereby risking their health and safety. With the frequency and intensity of heatwaves increasing, cooling centers are considered an appropriate alternative to indoor cooling and a possible mitigation strategy to prevent adverse health impacts of heat exposure. However, these centers are limited in numbers and not always accessible. This requires (i) developing a geospatial framework using physical and social factors for optimal siting of cooling centers to meet future needs and (ii) ranking of existing and potential cooling centers (schools, libraries, religious institutions) based on their accessibility among vulnerable populations and proximity to healthcare facilities. We developed and deployed a geospatial framework based on the Multi-criteria Decision Analysis approach in five U.S. cities (Los Angeles (LA), Phoenix, Austin, Atlanta, Miami) to evaluate the effectiveness of the framework in ranking cooling centers based on accessibility and population coverage. The results revealed that (i) access to cooling centers varies across cities and 32.2–50.7% of centers are within walking distance of the most vulnerable populations, (ii) vulnerable populations exposed to Urban Heat Island (UHI) effects are more likely to experience energy burden, and (iii) about 21.2–49.4% of population with high energy burden have access to these centers. Considering that more cooling centers are needed to assist energy burdened households alleviate heat exposure impacts, the framework developed herein could be adapted to incorporate other factors (e.g. health impacts, policies) to assess site suitability of existing shelters, identify potential sites for new cooling centers, and geo-target communities where energy efficient emerging technologies could be deployed to reduce heat stress.
The increasing occurrence of extreme weather events is challenging power grid operation. For extreme weather events, the system operator is responsible for estimating the power outages and scheduling the restoration resources. This paper proposes an outage evaluation framework to identify the possible unserved load profiles, vulnerable areas, and mobile energy adequacy. The outputs of an outage prediction model tool are used to generate numerous faulted line scenarios. Next, each scenario's nodal unserved load profile is obtained by solving a three-phase restoration model that considers repair crews and mobile energy resources (MERs). Then, a novel scenario clustering strategy is developed to cluster the unserved load profiles into multiple representative profiles which the system operator can focus on. Finally, case studies on a distribution system evaluate the damage caused by an extreme weather event and verify the effectiveness of the proposed scenario clustering strategy.
Several works have been documented in the literature to study the societal effect of power outages and to analyze their correlation with the Social Vulnerability Index (SVI). However, the relationship between National Risk Index (NRI) and power outages is yet to be explored. This work analyzes the NRI indices such as Risk, Expected Annual Loss, Social Vulnerability, and Community Resilience with several resilience metrics such as event duration, impact duration, recovery duration, impact level, impact rate, recovery rate, recovery to impact ratio, and area under the outage curves to see the correlation of NRI indices with the resilience metrics. The results show that NRI indices such as Risk and Expected Annual Loss increase with the increase of event duration, impact duration, and recovery duration. All Other metrics are indifferent to the change in the Risk and EAL ratings. The results also show that there is no strong relationship between all the metrics and community resilience and social vulnerability. This work also performed the sensitivity analysis of the extreme event selection process. This sensitivity analysis reveals that the way of identifying extreme events has a significant impact on the evaluation of the events.
Network Time Protocol (NTP), as it traditionally generated and widely consumed, is a legacy system with known security vulnerabilities. The vulnerabilities can be mitigated by modern implementations of NTP that use internal and external redundancy for better accuracy and fault tolerance. Precision Time Protocol (PTP) is an alternative that uses master clocks inside secure networks to eliminate the known vulnerabilities of NTP.
Despite the rapid growth of solar energy, we still lack a dynamic, high-fidelity database that tracks the spatiotemporal variations of solar PVs and their associated infrastructures across different places at a spatially resolved scale. The absence of such data presents a barrier to various applications such as solar PV growth projection, solar energy integration, solar incentive design, and climate risk assessment. In this project, we aim to bridge this gap by developing AI-based algorithms to extract granular information about solar PV installations and their associated infrastructures (i.e., distribution grids) from widely available unstructured data like remote sensing images and street views. As a result, we have built the Solar Energy Atlas, a fine-grained, large-scale geospatial overlay of distributed solar PVs and distribution grids. On top of it, we have advanced the understanding of solar adoption and distribution grid vulnerability to climate-induced extremes. Our major contributions can be summarized as follow: (1) By developing new AI algorithms, we have built the most comprehensive solar PV spatiotemporal database covering the entire US. This is the first time we obtained the exact GPS locations, size, subtype, and installation year information for rooftop solar PVs across the US. This database can be used for solar PV growth projection, solar energy integration, solar energy policy analysis and design, and spatially-resolved climate risk assessment. (2) Leveraging this database, we have uncovered the socioeconomic driving factors that are correlated with earlier onset of solar adoption and higher saturated adoption levels. We have identified the heterogeneity in the effects of different types of financial incentives on solar adoption and provided implications for tailoring incentive design based on local income levels to promote equitable solar adoption. (3) We have developed a distribution grid GIS mapping algorithm which can obtain granular geospatial and topology information about distribution grids using multi-modal open data, reducing the dependency on hard-to-obtain smart meter data of conventional approaches. It shows effectiveness in both the U.S. and Sub-Saharan Africa. Using this algorithm, we have uncovered the non-uniform vulnerability of distribution grids to wildfires in California in the aspects of undergrounding protection and Distributed Energy Resources (DER) preparedness. This has provided important implications for improving the affordability and equity of grid adaptation approaches. (3) We have made our produced database publicly available and provided user-friendly interface to enable various stakeholders and the general public to interact with the data. We have also integrated the produced data into the Data Commons platform to enable the public to access the data and correlate it with other location-specific characteristics simply using natural language as queries. The impact of our project is three-fold: (1) New algorithms for mapping solar PVs and distribution grids across space and time, which are open source to facilitate researchers and industry; (2) New databases of solar PVs and distribution grids that have been made publicly available for engineering, social, and policy applications; (3) New understandings and actionable insights on the potential approaches to promoting solar adoption and reducing energy infrastructure vulnerabilities. In this report, we start by discussing the project background and motivation (section 5), followed by the overview of project objectives (section 6). Results and discussion for each task are presented in section 7. Significant accomplishments are summarized in section 8. This report will be concluded by discussing the paths forwards (section 9), products (section 10), and team roles (section 11).