Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Failure Mode and Effects Analysis (FMEA) for Photovoltaic Inverter

Photovoltaic (PV) inverters are critical yet vulnerable components in modern energy systems, often acting as reliability bottlenecks that increase the levelized cost of energy (LCOE). To address this, this paper presents a comprehensive Failure Mode and Effects Analysis (FMEA) tailored for PV inverters. Leveraging field data and literature, we identify failure-prone components, such as capacitors,, and relays, and prioritize their risks based on quantitative Risk Priority Numbers (RPNs). The analysis reveals that surge-induced MOV short circuits, capacitor degradation, and environmental cooling fan failures dominate the risk profile. These findings provide a targeted framework for reliability improvement, guiding future efforts in predictive diagnostics, design optimization, and accelerated life testing strategies.

14 SOLAR ENERGY↗

Towards Improving Container Security by Preventing Runtime Escapes

Container escapes enable the adversary to execute code on the host from inside an isolated container. Notably, these high severity escape vulnerabilities originate from three sources: (1) container profile misconfigurations, (2) Linux kernel bugs, and (3) container runtime vulnerabilities. While the first two cases have been studied in the literature, no works have investigated the impact of container runtime vulnerabilities. In this paper, to fill this gap, we study 59 CVEs for 11 different container runtimes. As a result of our study, we found that five of the 11 runtimes had nine publicly available PoC container escape exploits covering 13 CVEs. Our further analysis revealed all nine exploits are the result of a host component leaked into the container. Here, we apply a user namespace container defense to prevent the adversary from leveraging leaked host components and demonstrate that the defense stops seven of the nine container escape exploits.

42 ENGINEERING↗

Mapping heat vulnerability in cities: A tale of two california cities

Extreme heat is a major cause of weather-related deaths in the United States. To address this, a heat vulnerability index (HVI) is crucial for assessing heat risk and identifying vulnerable urban areas and populations, supporting city planning and emergency response. Current HVI studies often use Principal Component Analysis (PCA) on environmental, socioeconomic, and medical data to aggregate vulnerability indicators into a single index. However, these fixed aggregation weights struggle to adapt to different use cases, which may require varying focuses. Moreover, existing tools primarily consider outdoor heat exposure, providing an incomplete picture of actual exposure, as people spend most of their time indoors. Our research introduces an HVI web mapping tool that addresses these gaps in the literature by: (1) allowing flexible weights to adapt to different use cases, and (2) uniquely integrating both outdoor and indoor heat exposure by considering building characteristics for a more comprehensive risk assessment. We demonstrated this tool in two California cities with contrasting climates: Fresno (inland, arid, hot summers) and Oakland (temperate coastal). This HVI mapping tool provides essential decision support for policymakers and stakeholders in both short-term heat mitigation and long-term urban planning for building interventions and infrastructure development.

BES↗

Analyzing Risks of Virtual Private Network Connections

The use of Splunk for analyzing VPN logs is an effective approach for identifying vulnerabilities in network endpoints. Splunk, a powerful platform for searching, monitoring, and analyzing machine-generated data, enables organizations to aggregate VPN logs in real-time, providing insights into network activity, user behavior, and potential security risks. By indexing VPN traffic and authentication logs, security teams can track abnormal patterns such as multiple failed login attempts, unusual IP addresses, or unexpected changes in bandwidth usage, all of which could indicate potential vulnerabilities or breaches. With Splunk’s advanced search and reporting capabilities, users can create custom dashboards and alerts to detect suspicious activities. Automated searches can flag endpoints exhibiting unusual behavior, while correlation analysis can identify links between compromised devices and broader network vulnerabilities. In particular, Splunk's machine learning capabilities can be leveraged to predict and prevent threats by identifying trends that might otherwise be missed in traditional log analysis. This proactive approach to monitoring VPN logs allows for the early detection of security weaknesses, enabling rapid response and minimizing potential damage to network integrity. By enhancing endpoint visibility, Splunk plays a crucial role in securing remote connections and safeguarding sensitive information. Additionally, Splunk’s automation and alerting features allow teams to create custom workflows that notify them of vulnerable or misconfigured endpoints identified through Shodan. This synergy between Splunk’s log analysis and Shodan’s device intelligence enhances an organization’s ability to proactively identify and mitigate security risks, improving the overall resilience of their VPN infrastructure.

97 MATHEMATICS AND COMPUTING↗

Big Data Analytic for Cascading Failure Analysis

With the challenges of increased grid dynamics and more variability of power generation from renewable energy sources, rapidly increasing complexity in the grid model, and abundant data from measurements and simulations, the requirements for computational analysis have also increased dramatically. Power system operators and engineers need to analyze more scenarios, extract meaningful information from a larger set of data, and respond more quickly when faced with these new challenges for large-scale applications, such as contingency analysis. This paper proposes a novel big data analysis approach for power system cascading analysis, prevention, and remediation. The developed techniques will be capable of cascading analysis, better assessment of the system’s vulnerability level, as well as proposing potential remediation. Case studies using IEEE 118-bus system and a 500-bus system, with a comparison against a commercial tool, validate the advantages of the developed big data approach: accurate prediction, and more importantly, faster and effective correction actions.The developed techniques could be further used for other power system applications.

big data, cascading analysis, corrective action, m↗

HAPPA: A Modular Platform for HPC Application Resilience Analysis with LLMs Embedded

High-performance computing (HPC) systems are increasingly vulnerable to soft errors, which pose significant challenges in maintaining computational accuracy and reliability. Predicting the resilience of HPC applications to these errors is crucial for robust code protection and detailed resilience analysis. In this study, we present HAppA, a modular platform designed for HPC Application Resilience Analysis. Embedding Large Language Models (LLMs), HAppA addresses understanding the context information of long code sequences typical in HPC applications. HAppA implements a novel code representation module that chunks the code into fixed-size segments and aggregates the embeddings of these segments. Three aggregation methods have been explored: MeanPooling, MaxPooling, and LSTM-based techniques. We built a DAtaset for REsilience analysis using Fault Injection (FI), named DARE. Using our DARE dataset, HAppA is trained for regression prediction tasks. Our evaluation results demonstrate the predictive accuracy of HAppA compared to other models, particularly noting that the LSTM-based aggregation method -- HAppA-LSTM -- achieves a mean squared error (MSE) of 0.078 for SDC prediction, surpassing the existing state-of-the-art PARIS model, which recorded an MSE of 0.1172. Additionally, HAppA with the KeyBERT model extracts a list of keywords representing the source code. A comprehensive importance analysis of these keywords further elucidates the code patterns contributing to the error rate. These findings highlight the effectiveness of HAppA in analyzing the resilience of HPC applications and establish a new benchmark for predictive accuracy in resilience.

Jiang, Hailong [Kent State University]↗

Natural gas maximal load delivery for multi-contingency analysis

An increasing dependence on natural gas has amplified existing vulnerabilities to the power grid, including disruptions to gas transmission networks from natural and man-made disasters. To address the operational challenges arising from these disruptions, we, in this study, consider the problem of estimating the steady-state operating capacity of a damaged gas pipeline network while ensuring the maximal delivery of load. Specifically, we formulate the mixed-integer nonconvex maximal load delivery (MLD) problem, which proves difficult to solve on large-scale networks. To address this challenge, we present a relaxation of the MLD problem and use it to determine bounds on the transport capacity of a gas pipeline system. A rigorous computational evaluation over network models ranging in size from 11 to 4,197 junctions shows that the relaxation-based method is suitable for analyzing the impacts of multi-contingency network disruptions, often converging to the optimal solution of the relaxation in less than ten seconds.

03 NATURAL GAS↗

Eev (enrich Enforce Validate) With Cpefinder

This code is designed to take an existing STIX bundle with vulnerability data and enrich it with additional potential vulnerabilities to provide further insight during threat analysis. It also acts as a launch platform for other enrichments tools. The additional tools include, WAVgraph and STIXEnforcer.

Beckman, BryanR [Idaho National Laboratory (INL), ↗

Identification of Worst Impact Zones for Power Grids During Extreme Weather Events Using Q-Learning: Preprint

Both the frequency and intensity of extreme weather events have been trending higher in recent years, leading to significant infrastructure loss in the electric grid. The impact of these extreme weather events is desired to be analyzed and quantified in order to help transmission and distribution system operators to prepare and prevent significant losses. In this paper, we developed an approach that models the impact of extreme weather on the power grid and identifies the worst impact zone using Q-learning (a reinforcement learning approach). The identification results reveal grid vulnerability to weather events and provide insights for system operators to help achieve optimal resource allocation and crew dispatch in order to minimize the adverse impact of extreme weather. Simulation studies are conducted on the IEEE 123-node system to demonstrate the performance of the proposed approach.

24 POWER TRANSMISSION AND DISTRIBUTION↗

System Health and Status Reporting is Used to Improve Infrastructure Systems at the Hanford Site - 20449

Reliable physical infrastructure systems are vital to completing the clean-up mission and the start-up and commissioning of new nuclear waste processing facilities at the Hanford Site. Key infrastructure systems at Hanford include water, sewer, and electrical utilities, roads, telecommunications/network systems, and fire systems. All of the infrastructure systems are non-nuclear, General Service systems that are being maintained under formal engineering configuration control and none are specifically credited in any documented safety analysis (DSA). Starting in calendar year 2017, the Hanford Site's infrastructure and services contractor started producing system health and status reports for a total of 15 critical infrastructure systems as means to get a better understanding of each system's health and how it could be improved to ensure better and more reliable service delivery. As the reporting, tracking, and use of the metrics has matured, the number of systems for which reports are being developed has been expanded to a total of 23. Each of the critical infrastructure systems are assigned primary and alternate design authorities that complete qualifications on each assigned system. The design authorities actively manage and maintain configuration control on each of their systems and track metrics associated with availability, maintenance (corrective and preventive), and configuration of the technical baseline. The metrics are based on the principles established in Chapter V of DOE O 420.1C, Facility Safety, [1] and have been tailored as appropriate to each of the key infrastructure systems. An overall assessment of system health is performed and documented on a routine basis (e.g., quarterly). Included in this documentation is a quantitative score for each of the metrics (i.e., availability, maintenance, configuration management) along with results of system walk-downs, description of any permanent design modifications, identification of new or emerging issues and vulnerabilities affecting the system, and an assessment by the design authority of actions necessary to improve the system health score. The overall status scores are calculated using a formula and based on a pre-determined grading scale, a color is assigned for simple presentation. The information gained from developing the reports is being used to (1) assist with making timely and better informed decisions through the use of solid technical bases that are increasing the overall reliability and capabilities of the Site's infrastructure systems as new expense and capital projects in the Reliability Projects Investment Portfolio (RPIP) are prioritized and executed; (2) feed the risk management program, and (3) integrate the technical content of Master Plans that describe the Site's needs for the system and the system's capabilities to meet those future needs. (authors)

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Digital Tools for the Preventive Conservation of Built Heritage: The Church of Santa Ana in Seville

Historic Building Information Modelling (HBIM) plays a pivotal role in heritage conservation endeavours, offering a robust framework for digitally documenting existing structures and supporting conservation practices. However, HBIM’s efficacy hinges upon the implementation of case-specific approaches to address the requirements and resources of each individual asset and context. This paper defines a flexible and generalisable workflow that encompasses various aspects (i.e., documentation, surveying, vulnerability assessment) to support risk-informed decision making in heritage management tailored to the peculiar conservation needs of the structure. This methodology includes an initial investigation covering historical data collection, metric and condition surveys and non-destructive testing. The second stage includes Finite Element Method (FEM) modelling and structural analysis. All data generated and processed are managed in a multi-purpose HBIM model. The methodology is tested on a relevant case study, namely, the church of Santa Ana in Seville, chosen for its historical significance, intricacy and susceptibility to seismic action. The defined level of detail of the HBIM model is sufficient to inform the structural analysis, being balanced by a more accurate representation of the alterations, through linked orthophotos and a comprehensive list of alphanumerical parameters. This ensures an adequate level of information, optimising the trade-off between model complexity, investigation time requirements, computational burden and reliability in the decision-making process. Field testing and FEM analysis provide valuable insight into the main sources of vulnerability in the building, including the connection between the tower and nave and the slenderness of the columns.

Chaves, Estefanía↗

Cyber-Informed Engineering (CIE) Workbook: End-of-Train (EoT) / Head-of-Train (HoT) Communications

This workbook presents a vulnerability (CVE-2025-1727 ) found in train applications and guides a digital risk assessment and mitigation analysis and application of Cyber-Informed Engineering principles to mitigate the potential consequences and ultimately the hazard through the engineering discipline because of exploiting this vulnerability. Workshop participants are encouraged to use the workbook to capture insights and lessons learned. The workbook guides the participant to: • Understand the HE communication vulnerability • Map digital threats to physical consequences • Use bowtie analysis to illustrate both “security” and “engineering” barriers • Apply CIE principles to ensure that even if communications are compromised, the physical engineered system still behaves safely. • Produce an actionable set of engineered and infosec controls for implementation

42 - ENGINEERING↗

Geothermal Sector Cybersecurity Vulnerability Assessment

A review of geothermal sector-specific cybersecurity vulnerabilities and risks (consequences) was conducted at the request of the Geothermal Technologies Office (GTO). The vulnerabilities and risks reviewed in this study have relevance to achieving the 2019 GeoVision Report (DOE GTO 2019) technological advancements and expected sector growth. The study offers areas for consideration but does not quantify the likelihood (frequency) of the consequences. This cybersecurity analysis project represents a proactive effort to identify areas to enhance cybersecurity in geothermal development and operations. It was not initiated to address any immediate threat or specific known risk. Of the eight identified vulnerabilities analyzed, the review identified reservoir data system monitoring as one that is unique to geothermal systems and may warrant further investigation to better understand risk and mitigation. A detailed analysis of the other vulnerabilities may highlight additional uniqueness relative to other industries. Further research actions are recommended to better quantify risk and enhance cybersecurity preparedness of the sector. As the geothermal industry grows, the cybersecurity strategies to be deployed will be of increasing importance to ensure resilient, reliable, and secure clean energy for years to come.

cyber-physical security↗

Using Machine Learning to Understand Electric and Hybrid Vehicles Ownership in Burdened and Nonburdened Communities

Transitioning to electric and hybrid vehicles (EHVs) for all communities is a pivotal step toward sustainable transportation and environmental conservation. This paper aims to understand the adoption of EHVs, focusing on burdened communities (BCs) in the United States. The EHV ownership-based analysis combines two datasets—behavioral data from the Puget Sound Regional Travel Survey integrated with BCs (Justice40) data covering transportation insecurity, environmental burden, social vulnerability, health vulnerability, and climate and disaster risk burden. After creating this unique database, descriptive analysis and modeling are used to analyze the data and predict EHV ownership in the future. Specifically, we use a new method that combines particle swarm optimization (PSO) with a stacking model named PSO-Stacking, which incorporates heterogeneous base learners of machine learning and deep learning. PSO applies a customized objective function to select the optimal hyperparameters for heterogeneous learners within the stacking model, effectively addressing challenges such as multicollinearity, data imbalance, nonlinearity, and overfitting. The proposed solution covers more accurate results than standard benchmark models for EHV ownership in BCs and non-BCs. In addition, the results of the PSO-Stacking method are explained using the local interpretable model-agnostic explanations technique. Results show a negative correlation between the BCs indicators, that is, higher transportation insecurity associated with lower EHV ownership. Furthermore, BCs have higher future climate risk scores, diesel particulate matter levels, and PM2.5 in the air than non-BCs because of higher conventional vehicle ownership. These communities are at higher risk and can benefit from electrification, EV infrastructure, and EV policies to address environmental challenges.

Aslam, Zeeshan [ORNL]↗

Vulcan-Forge: Architecture and Design of a Multi-Modal Forensic Analysis Plugin for CALDERA

Forge and VULCAN together describe an open-architecture cybersecurity analysis ecosystem that unifies forensic artifact processing, detection engineering, and vulnerability intelligence within integrated platforms. Forge operates as a plugin for MITRE CALDERA, ingesting diverse evidence formats—including EVTX, PCAP/PCAPNG, CSV, JSON, YAML, XML, binaries, and archives—to construct a unified artifact graph enriched with severity scoring, TLP classification, and audit trails. It provides subsystems for artifact parsing, streaming structured-data visualization, NetworkMiner-based packet inspection, PE/.NET binary analysis, and LLM-assisted triage and rule generation, with outputs validated against CCCS-YARA and pySigma schemas. VULCAN complements this by serving as a cybersecurity analyst platform that integrates a Neo4j knowledge graph, Qdrant vector retrieval, SSVC-based triage, and a local LLM to deliver CVE intelligence and forensic analysis through a multi-source ingest pipeline drawing from NVD, CISA KEV, EPSS, MITRE ATT&CK, and CAPEC. Together, they bridge structured threat intelligence with automated forensic analysis and detection workflows.

97 MATHEMATICS AND COMPUTING↗

Utility-Scale Operational Consequences for Solar Grid Services

This report delves into the critical aspects of grid services provided by solar inverter-based resources (IBRs), with an emphasis on the evolving landscape of microgrids, virtual power plants (VPPs), aggregators, and distributed energy resource management systems (DERMS). As the energy sector undergoes a transformative shift towards more decentralized and resilient grid architectures, understanding the multifaceted risks associated with these technologies becomes paramount. The report categorizes these risks into organizational, technical, and procedural domains, providing a thorough risk assessment framework that stakeholders can utilize to anticipate and mitigate potential issues. In addressing the increasing complexity of grid interconnections, the report highlights the importance of Cyber-Informed Engineering (CIE). By embedding engineering controls and cybersecurity measures into the early stages of system design, this approach aims to fortify grid infrastructure against emerging cyber threats. The analysis includes an exploration of best practices and strategies for integrating CIE principles to enhance grid security and resilience. To provide practical insights, the report conducts a detailed consequence analysis of various grid services and cyber mitigations that can be applied through the interconnection process. This analysis evaluates the potential impacts of different failure modes and vulnerabilities, offering a clear understanding of the consequences that could arise from disruptions within the energy grid. The findings are further enriched by a series of case studies that illustrate real-world scenarios and lessons learned from past incidents. Through this comprehensive examination of grid services and their criticality, the report aims to prepare industry professionals with the knowledge and tools necessary to navigate the complexities of modern energy systems. By providing a comprehensive approach that includes risk assessment, cybersecurity, and consequence analysis, solar stakeholders can more effectively guarantee the reliability, efficiency, and security of the energy grid.

14 SOLAR ENERGY↗

Probabilistic Failure Criterion of SiC/SiC Composites Under Multiaxial Loading

Owing to its excellent mechanical properties and stability under high temperature and neutron irradiation conditions, SiC/SiC composites have emerged as a promising material for light water reactors (LWRs) in the development of accident-tolerant fuel (ATF) systems. Structural integrity and retention of hermeticity are two crucial requirements for SiC/SiC claddings during normal operations, and both of them are closely related to the proportional limit stress (PLS) of the material. Understanding the behavior of SiC/SiC composites under multiaxial stress states and developing a probabilistic approach for evaluating the structural vulnerability are of paramount importance for reliability-based analysis and design of SiC/SiC composite claddings. So far, there has been very limited effort towards experimental and analytical investigations of probabilistic failure of SiC/SiC claddings. This critical knowledge gap motivates this research. A probabilistic failure criterion for SiC/SiC composites under multi-axial loading is developed, and this criterion is incorporated into reliability analysis of the structural integrity of SiC/SiC fuel cladding. The research consists of two parts: 1) experimental investigation of multiaxial failure behavior of SiC/SiC composites, and 2) theoretical modeling of time-dependent probabilistic failure of SiC/SiC cladding. In the experimental investigation, the PLS is determined through the examination of stress-strain response, the acoustic emission measurement, as well as the X-ray computed tomography. The theoretical framework is derived by combin- ing the finite weakest-link statistical model and the subcritical damage growth model. This theoretical model captures the time-dependent failure mechanism of the material, which has a major consequence for predicting the lifetime distribution of the cladding. Meanwhile, the model also predicts that the failure statistics of the cladding depends strongly on the cladding length. The results of the multiaxial experiments reveal the level of statistical variation of the PLS of SiC/SiC materials under different stress states. The theoretical model provides a robust analytical tool for extrapolation of small-scale laboratory test results to the behavior of full-scale claddings. These findings establish a scientific foundation for the development of reliability-based design of SiC/SiC fuel claddings, which will play an essential role in improving the structural safety and integrity of LWRs.

42 ENGINEERING↗