Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

User Role Identification in Software Vulnerability Discussions over Social Networks

Understanding and early awareness of software vulnerabilities is vital for preventing and mitigating potential impacts from cybersecurity events. One step toward early characterization of software vulnerabilities may involve analyzing discussion and spread of information in online social networks. Prior work has used information from such discussions over multiple online forums to develop dynamic networks among users followed by analysis of structure, spread, and information evolution. In this work, we advance the state-of-the-art by focusing on data-driven learning of types, roles, and transition of roles exhibited by users over time. In social networks, users take on particular roles based on their actions and structure of the network. Identifying “meaningful” roles can help separate potential users of interest from the larger community, and identify patterns in a network. We will identify and compare roles found in online forums (e.g., Twitter) using techniques such as feature-based Non-negative Matrix Factorization coupled with topological and influence-based measures of centrality. Since users’ activities change over time, we also analyze role evolution in dynamic networks.

Jones, Rebecca D.↗

Distribution System Resilience Assessment Considering PV Vulnerabilities for Hurricane Events

Distribution networks are increasingly vulnerable to damage and outages from extreme weather events. The integration of solar photovoltaics (PVs) further complicates resilience analysis due to its weather-dependent nature. However, limited research has examined the impacts of weather on PVs under severe events like hurricanes. This paper proposes a probabilistic framework to assess distribution system resilience considering PV vulnerabilities during hurricanes. The framework incorporates (i) a spatiotemporal fragility model to evaluate failure probabilities for distribution lines and PVs, and (ii) resilience indices at both system and component levels. The approach offers valuable insights into the resilience of modern distribution grids under extreme weather conditions. Numerical results on the unbalanced IEEE 123-bus test system validate the effectiveness of the framework.

Vahedi, Soroush [University of Connecticut, Storrs↗

Vulnerability Studies Under EMP: Impedance and PCI Testing of the Grid Control Devices

Control devices such as inverters and generator controllers are critical for the stable operation of the power grid, especially for power stability control and power dispatch. However, the Electromagnetic Pulse (EMP) is a potential threat to electronic devices in modern power grids, therefore decreasing the power grid resilience and bringing unrecoverable damages to the devices. To reveal the impact mechanism of the EMP, impedance and Pulse Current Injection (PCI) testing is established to study the vulnerability of the grid control devices. The impedance of the grid control devices is accurately measured using impedance analyzers with different frequency ranges. Then the voltage and current responses are tested based on the PCI testing. The vulnerability experiments based on two grid control devices are carried out. And the comparison results reveal that most ports would be damaged under EC8, and some ports can survive under EC5 according to the calculated PCI response and cumulative energy. The results can provide a reference for the future design of control devices and the strategic resilience of power grids.

Qiu, Wei↗

Vulnerability Research Development Program Guide v.1

SAND2021-15515 O The Vulnerability Research Development Program (VRDP) Guide is a training program developed to help general purpose computer science staff become independently capable vulnerability researchers. VRDP Guide is both a course description and curriculum for the program. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Salim, Nasser↗

Unraveling Vulnerabilities in Endocrine Therapy-Resistant HER2+/ER+ Breast Cancer

Abstract Breast tumors overexpressing human epidermal growth factor receptor (HER2) confer intrinsic resistance to endocrine therapy (ET), and patients with HER2/estrogen receptor–positive (HER2+/ER+) breast cancer (BCa) are less responsive to ET than HER2–/ER+. However, real-world evidence reveals that a large subset of patients with HER2+/ER+ receive ET as monotherapy, positioning this treatment pattern as a clinical challenge. In the present study, we developed and characterized 2 in vitro models of ET-resistant (ETR) HER2+/ER+ BCa to identify possible therapeutic vulnerabilities. To mimic ETR to aromatase inhibitors (AIs), we developed 2 long-term estrogen deprivation (LTED) cell lines from BT-474 (BT474) and MDA-MB-361 (MM361). Growth assays, PAM50 subtyping, and genomic and transcriptomic analyses, followed by validation and functional studies, were used to identify targetable differences between ET-responsive parental and ETR-LTED HER2+/ER+ cells. Compared to their parental cells, MM361 LTEDs grew faster, lost ER, and increased HER2 expression, whereas BT474 LTEDs grew slower and maintained ER and HER2 expression. Both LTED variants had reduced responsiveness to fulvestrant. Whole-genome sequencing of aggressive MM361 LTEDs identified mutations in genes encoding transcription factors and chromatin modifiers. Single-cell RNA sequencing demonstrated a shift towards non-luminal phenotypes, and revealed metabolic remodeling of MM361 LTEDs, with upregulated lipid metabolism and ferroptosis-associated antioxidant genes, including GPX4. Combining a GPX4 inhibitor with anti-HER2 agents induced significant cell death in both MM361 and BT474 LTEDs. The BT474 and MM361 AI-resistant models capture distinct phenotypes of HER2+/ER+ BCa and identify altered lipid metabolism and ferroptosis remodeling as vulnerabilities of this type of ETR BCa.

60 APPLIED LIFE SCIENCES↗

Stem hydraulic conductivity and vulnerability to cavitation for 26 tree species in Panama

Stem hydraulic conductivity and vulnerability to cavitation were measured for 26 tree species located in Panama. The data were generated to better understand the ecology of the focal tree species. Complementary NGEE-Tropics datasets for these species include sap flow, leaf-level gas exchange, and leaf water potential. Stem samples were collected from distal branches of canopy trees, brought to the Smithsonian Tropical Research Institute laboratory in Gamboa, Panama, and allowed to dry to various water potentials before measurements. For each species, a Weibull function was fit to the 90% quantile of the relationship between stem area specific hydraulic conductivity (Ks) and stem water potential. From these functions, maximum Ks and vulnerability parameters were derived. The data files in the package include raw data, derived parameters, and the R script used for analysis.

54 ENVIRONMENTAL SCIENCES↗

Vulnerabilities in Artificial Intelligence and Machine Learning Applications and Data

Artificial intelligence (AI) applications driven by machine learning (ML) are transformational technologies within the international nuclear security regime. Advancements realized by AI—faster and improved data insights, more efficient and automated processes, reductions in human error—enable nuclear security applications such as behavior analysis for insider threat mitigation, source tracking of stolen nuclear material, and facial recognition software for physical protection. In addition to the advantages, however, there are also inherent vulnerabilities and threats associated with its use and risk mitigations must be built into any AI/ML-enabled systems. This work provides a background on AI and ML and different data types used in the field, including open-source intelligence information (OSINT) that is discoverable by AI tools and application data that are used by AI tools for decision-making and automation. Current and potential AI applications and vulnerabilities related to their use within the nuclear security regime are also discussed.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Prioritizing ICS Beachhead Systems for Cyber Vulnerability Testing

Cyber Testing for Resilient Industrial Control Systems™ (CyTRICS™) is the Department of Energy’s (DOE’s) program for cybersecurity vulnerability testing, digital subcomponent enumeration, and forensic assessment. CyTRICS leverages best-in-class test facilities and analytic capabilities at six DOE National Laboratories and strategic partnerships with key stakeholders including technology developers, manufacturers, asset owners and operators, and interagency partners. During the program’s development, CyTRICS established a unique methodology for prioritizing digital components within operational technology (OT) and industrial control systems (ICS) in the Energy Sector Industrial Base (ESIB) for cyber vulnerability testing. The CyTRICS Prioritization Process leverages multiple characteristics of systems, components, and their contextual deployment to calculate a quantification of individual digital components for CyTRICS testing. The initial version of the CyTRICS Prioritization Process was premised largely upon the impact which could result to an industrial control system if the digital component under testing was compromised, either through malicious means, faulty engineering, or other modes. The worldwide compromise of the SolarWinds Orion platform, first reported in December 2020, through malicious interference with the digital patching cycle was a watershed event in cyber supply chain security. The SolarWinds compromised demonstrated the strategic importance of certain types of ubiquitous software, and the ability to generate widespread cybersecurity effects. To address this challenge and as a part of the Department of Energy’s response to the SolarWinds compromise, DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) directed the National Laboratories to evolve the CyTRICS Prioritization Process methodology to encompass additional factors related to the strategic importance of digital components. CESER directed CyTRICS researchers to identify, characterize, and append strategic factors to the CyTRICS Prioritization Process to provide additional weight to these characteristics. National Laboratory expert researchers identified functionality, distribution, and platform characteristics for digital components in ICS and OT that they assessed would be likely targeted in strategic initial-access cyber attack. CyTRICS has termed these factors “ICS Beachhead Systems,” leveraging a definition first advanced by Schneider Electric, which is intended as a blanket term to encompass digital components, products, and systems in OT. This paper describes the ICS Beachhead Systems identified and the rationale for inclusion. As a next step in the research and refinement process, the National Laboratories will validate this initial set of characteristics against digital components evaluated by the CyTRICS program and current implementation of the CyTRICS Prioritization Process. After validation, CyTRICS researchers will then develop a scoring methodology to generate a quantitative score to assess the degree to which a digital component is characterized as an ICS Beachhead System. Finally, the National Laboratories will append this scoring to the existing CyTRICS Prioritization Process algorithm.

97 MATHEMATICS AND COMPUTING↗

Automated Vulnerability Detection (AVUD) for Compiled Smart Grid Software

This project developed and implemented a system for conducting cybersecurity vulnerability detection of smart grid components and systems by performing static analysis of compiled software (“firmware”). The resulting system for automated vulnerability detection (AVUD) was implemented as part of Oak Ridge National Laboratory’s existing test bed for smart meters, the Sustainable Campus Initiative. The work consisted of two phases: the first phase implemented the necessary software and computational models to perform the analysis, and the second phase demonstrated the system on example firmware in partnership with smart meter manufacturer Sensus USA, Inc. The resulting system won an R&D 100 award and has been successfully commercialized, winning a National Laboratory Consortium Commercialization Award.

97 MATHEMATICS AND COMPUTING↗

FIC Vulnerability Profile

The FIC team is engaged with Pacific Northwest National Laboratory’s (PNNL’s) Shamrock Cyber Team to provide cybersecurity analyses of the FIC software. Shamrock offers both Threat-Based Analysis services and Secure Software Development services. These services are ultimately used to understand and mitigate threats against software and to reduce vulnerabilities in software, thus improving overall cybersecurity and informing decision makers. Shamrock’s Secure Software Development services, specifically Static Analysis Security Testing (SAST) and Open-Source Analysis (OSA), produced this Vulnerability Profile.

97 MATHEMATICS AND COMPUTING↗

Territorial Government Revenue Vulnerability Index (TGRVI): Measuring Financial Impacts to Territorial Governments during the COVID-19 Pandemic

The Territorial Government Revenue Vulnerability Index (TGRVI) measures the vulnerability of U.S. territorial government revenues by estimating monthly changes relative to a January 2020 baseline. Revenues accounted for in the index include: taxes on products and sales, transportation and housing revenues, individual income taxes, severance taxes and royalties, and property taxes.

99 GENERAL AND MISCELLANEOUS↗

Charliecloud is not affected by CVE-2024-21626 or related vulnerabilities

As you may be aware, four vulnerabilities in popular open-source container implementations were announced on January 21. Nicknamed “Leaky Vessels” by the Snyk Security Labs team that discovered them [1], these vulnerabilities in runC (CVE-2024-21626) and Moby BuildKit (CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653) allow malicious container images or builds to execute arbitrary code on the container host with the privileges of the container runtime, i.e., a “container breakout”. Often, including typical configurations of Docker and/or Kubernetes, that means full root access.

97 MATHEMATICS AND COMPUTING↗

A Multi-Model, Multi-Scale Research Program in Stressors, Responses, and Coupled Systems Dynamics at the Energy-Water-Land Nexus and for Concentrated, Interdependent Infrastructures: Toward Next Generation Capabilities in Integrated Impacts, Adaptation, and Vulnerability (I-IAV) Modeling and a Community of Practice

The goal of this research program was to build a next generation integrated suite of science-driven modeling and analytic capabilities, and a more expanded and connected community of practice, for analyses of the stressors, impacts, adaptations and vulnerabilities of global and regional change. The emphasis was on understanding energy-water-land interactions and feedbacks and interdependent infrastructures at appropriate regional and temporal scales. Although the scope spans many complex facets of data, modeling, and analysis, as well as scales appropriate for integrated impacts and adaptation research, the focus of this effort was the development of multi-model, multi-scale capabilities spanning the domains of Multi-Sector Dynamics (MSD) models; Impact, Adaptation, and Vulnerability (IAV) models; and Earth System Models (ESMs).

54 ENVIRONMENTAL SCIENCES↗

Review of Electric Vehicle Charger Cybersecurity Vulnerabilities, Potential Impacts, and Defenses

Worldwide growth in electric vehicle use is prompting new installations of private and public electric vehicle supply equipment (EVSE). EVSE devices support the electrification of the transportation industry but also represent a linchpin for power systems and transportation infrastructures. Cybersecurity researchers have recently identified several vulnerabilities that exist in EVSE devices, communications to electric vehicles (EVs), and upstream services, such as EVSE vendor cloud services, third party systems, and grid operators. The potential impact of attacks on these systems stretches from localized, relatively minor effects to long-term national disruptions. Fortunately, there is a strong and expanding collection of information technology (IT) and operational technology (OT) cybersecurity best practices that may be applied to the EVSE environment to secure this equipment. In this paper, we survey publicly disclosed EVSE vulnerabilities, the impact of EV charger cyberattacks, and proposed security protections for EV charging technologies.

33 ADVANCED PROPULSION SYSTEMS↗

Insights into the vulnerability of Antarctic glaciers from the ISMIP6 ice sheet model ensemble and associated uncertainty

Abstract. The Antarctic Ice Sheet represents the largest source of uncertainty in future sea level rise projections, with a contribution to sea level by 2100 ranging from −5 to 43 cm of sea level equivalent under high carbon emission scenarios estimated by the recent Ice Sheet Model Intercomparison for CMIP6 (ISMIP6). ISMIP6 highlighted the different behaviors of the East and West Antarctic ice sheets, as well as the possible role of increased surface mass balance in offsetting the dynamic ice loss in response to changing oceanic conditions in ice shelf cavities. However, the detailed contribution of individual glaciers, as well as the partitioning of uncertainty associated with this ensemble, have not yet been investigated. Here, we analyze the ISMIP6 results for high carbon emission scenarios, focusing on key glaciers around the Antarctic Ice Sheet, and we quantify their projected dynamic mass loss, defined here as mass loss through increased ice discharge into the ocean in response to changing oceanic conditions. We highlight glaciers contributing the most to sea level rise, as well as their vulnerability to changes in oceanic conditions. We then investigate the different sources of uncertainty and their relative role in projections, for the entire continent and for key individual glaciers. We show that, in addition to Thwaites and Pine Island glaciers in West Antarctica, Totten and Moscow University glaciers in East Antarctica present comparable future dynamic mass loss and high sensitivity to ice shelf basal melt. The overall uncertainty in additional dynamic mass loss in response to changing oceanic conditions, compared to a scenario with constant oceanic conditions, is dominated by the choice of ice sheet model, accounting for 52 % of the total uncertainty of the Antarctic dynamic mass loss in 2100. Its relative role for the most dynamic glaciers varies between 14 % for MacAyeal and Whillans ice streams and 56 % for Pine Island Glacier at the end of the century. The uncertainty associated with the choice of climate model increases over time and reaches 13 % of the uncertainty by 2100 for the Antarctic Ice Sheet but varies between 4 % for Thwaites Glacier and 53 % for Whillans Ice Stream. The uncertainty associated with the ice–climate interaction, which captures different treatments of oceanic forcings such as the choice of melt parameterization, its calibration, and simulated ice shelf geometries, accounts for 22 % of the uncertainty at the ice sheet scale but reaches 36 % and 39 % for Institute Ice Stream and Thwaites Glacier, respectively, by 2100. Overall, this study helps inform future research by highlighting the sectors of the ice sheet most vulnerable to oceanic warming over the 21st century and by quantifying the main sources of uncertainty.

54 ENVIRONMENTAL SCIENCES↗

Pyrotechnic hazards classification and evaluation program. Electrostatic vulnerability of the E8 and XM15/XM165 clusters, phase 1

A survey of the electrostatic vulnerability of explosive manufacturing plants and recommendations for reducing the vulnerability are discussed. During the course of the investigations, the XM15/XM165 and the E8 launcher were shown to be susceptible to electrostatic ignition. The pyrotechnic hazard of prime concern associated with electrostatics is that of the spark which can be generated. The heat, shock, and ionization produced by the spark can cause ignition of pyrotechnics. However, as a result of the initial ignition tests (XM15 fuse train), changes have been incorporated to make the fusing system relatively safe from premature electrostatic activation.

Source record↗

Preliminary tests of vulnerability of typical aircraft electronics to lightning-induced voltages

Tests made on two pieces of typical aircraft electronics equipment to ascertain their vulnerability to simulated lightning-induced transient voltages representative of those which might occur in flight when the aircraft is struck by lightning were conducted. The test results demonstrated that such equipment can be interfered with or damaged by transient voltages as low as 21 volts peak. Greater voltages can cause failure of semiconductor components within the equipment. The results emphasize a need for establishment of coordinated system susceptibility and component vulnerability criteria to achieve lightning protection of aerospace electrical and electronic systems.

Plumer, J. A.↗

Vulnerability of dynamic systems

Directed graphs are associated with dynamic systems in order to determine in any given system if each state can be reached by at least one input (input reachability), or can each state reach at least one output (output reachability). Then, the structural perturbations of a dynamic system are identified as lines or points removals from the corresponding digraph, and a system is considered vulnerable at those lines or points of the digraph whose removal destroys its input or output reachability. A suitable framework is formulated for resolving the problems of reachability and vulnerability which applies to both linear and nonlinear systems alike.

Siljak, D. D.↗