Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “vulnerability analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Analysis of Historical Power Outages of the United States and the National Risk Index

Several works have been documented in the literature to study the societal effect of power outages and to analyze their correlation with the Social Vulnerability Index (SVI). However, the relationship between National Risk Index (NRI) and power outages is yet to be explored. This work analyzes the NRI indices such as Risk, Expected Annual Loss, Social Vulnerability, and Community Resilience with several resilience metrics such as event duration, impact duration, recovery duration, impact level, impact rate, recovery rate, recovery to impact ratio, and area under the outage curves to see the correlation of NRI indices with the resilience metrics. The results show that NRI indices such as Risk and Expected Annual Loss increase with the increase of event duration, impact duration, and recovery duration. All Other metrics are indifferent to the change in the Risk and EAL ratings. The results also show that there is no strong relationship between all the metrics and community resilience and social vulnerability. This work also performed the sensitivity analysis of the extreme event selection process. This sensitivity analysis reveals that the way of identifying extreme events has a significant impact on the evaluation of the events.

Bhusal, Narayan↗

Visualizing a Vulnerability: Its Connections to Hardware and Software

All Hazards Analysis (AHA) is a framework developed by Idaho National Laboratory that provides capabilities to collect, store, analyze, and visualize critical infrastructure information. A core function of AHA is its ability to simulate faults or outages in networks of infrastructure originating from a plethora of causes, ranging from natural disasters to cyberattacks. AHA utilizes Hardware and Software Bills of Material (HBOM and SBOM, respectively) along with Known Exploited Vulnerabilities (KEVs) to document the potential attack vectors for each piece of infrastructure. The objective of this contribution to AHA was to create a visualization tool that could capture the small details held in each individual artifact as well as preserve the large-scale connections that link them together to aid threat modeling.

58 GEOSCIENCES↗

Multi-Factor Impact Analysis of Agricultural Production in Bangladesh with Climate Change

Diverse vulnerabilities of Bangladesh's agricultural sector in 16 sub-regions are assessed using experiments designed to investigate climate impact factors in isolation and in combination. Climate information from a suite of global climate models (GCMs) is used to drive models assessing the agricultural impact of changes in temperature, precipitation, carbon dioxide concentrations, river floods, and sea level rise for the 2040-2069 period in comparison to a historical baseline. Using the multi-factor impacts analysis framework developed in Yu et al. (2010), this study provides new sub-regional vulnerability analyses and quantifies key uncertainties in climate and production. Rice (aman, boro, and aus seasons) and wheat production are simulated in each sub-region using the biophysical Crop Environment REsource Synthesis (CERES) models. These simulations are then combined with the MIKE BASIN hydrologic model for river floods in the Ganges-Brahmaputra-Meghna (GBM) Basins, and the MIKE21Two-Dimensional Estuary Model to determine coastal inundation under conditions of higher mean sea level. The impacts of each factor depend on GCM configurations, emissions pathways, sub-regions, and particular seasons and crops. Temperature increases generally reduce production across all scenarios. Precipitation changes can have either a positive or a negative impact, with a high degree of uncertainty across GCMs. Carbon dioxide impacts on crop production are positive and depend on the emissions pathway. Increasing river flood areas reduce production in affected sub-regions. Precipitation uncertainties from different GCMs and emissions scenarios are reduced when integrated across the large GBM Basins' hydrology. Agriculture in Southern Bangladesh is severely affected by sea level rise even when cyclonic surges are not fully considered, with impacts increasing under the higher emissions scenario.

Ruane, Alex C.↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Development of FRET clusters for CBRN Detection

Advanced sensor capabilities for the simultaneous on-site detection of specific chemical, biological, and radiological/nuclear (CBRN) threats is important to significantly limit the risk of exposure to personnel and allow the rapid collection of essential scientific data and critical evidence. Commercially available sensor capabilities are generally complex, and/or require highly specific and ultra-sensitive methods that are often power demanding or require offsite post-analysis for positive detection, leaving personnel vulnerable. The goal of this project is to develop a portable sensor capable of simultaneously detecting CBRN signatures using a multiplexed Förster Resonance Energy Transfer (FRET) based sensor. FRET sensors are tailorable, specific, and highly dependent on the donor-acceptor distance. In this project, nanoparticles were functionalized with aptamers that were designed for the detection of methylphosphonate, a sarin metabolite. FRET was measured between quantum dot donors and dye and metal nanoparticle acceptors using optical spectroscopy.

61 RADIATION PROTECTION AND DOSIMETRY↗

Best Practices for Timing Attack Mitigation

GPS signals play essential roles in the electric subsector by providing precision timing used to synchronize and record measurements from a range of equipment. However, previous research has demonstrated that GPS signals can be spoofed or jammed relatively easily in order to interfere with timing-reliant equipment. This document outlines utility best practices for mitigating against timing attacks in the electric subsector based on an assessment of the difficulty and impact of realistic timing attacks and testing of the effectiveness of technologies capable of mitigating them. This analysis builds on research establishing the vulnerability of GPS-reliant timing equipment to jamming and spoofing by elaborating the difficulty, consequences, and mitigations for timing attacks that adversaries might realistically attempt. While timing attacks are relatively low-cost, low-sophistication, and capable of systemic consequences in the electric subsector, they can be effectively mitigated through well-targeted and diverse mitigations.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Templates for Risk Informed Assurance with Curvature Embeddings (TRACE)

We investigate recovery of geometric structure from networks embedded in manifolds with spatially varying curvature, extending the constant-curvature framework of Lubold et al. (2023). Our work supports cascade risk assessment in critical infrastructure through the Templates for Risk-informed Assurance with Curvature Embeddings (TRACE) framework. Simulations on a bi-modal Gaussian surface show that constant-curvature methods yield weighted averages shaped by clique patterns, while hierarchical clustering identifies distinct regimes. Localized estimation, however, reveals boundary contamination in transitional regions. To address heterogeneity, we develop distance metrics for graphs with edge and node features, proving their metric validity, and validate them via deterministic graph generation from canonical tilings. We further propose a diffusion-based anomaly detection approach that treats networks as glued manifolds, using curvature discontinuities to detect structural anomalies. Employing the carré-du-champ operator and scalar curvature, we achieve robust anomaly discrimination, demonstrated on the Singapore Water Treatment (SWaT) dataset with joint network-traffic and sensor features. Integration with TRACE reveals how curvature shapes cascade dynamics: positive curvature impedes, while negative curvature accelerates propagation. This geometric perspective provides interpretable risk metrics and visualization tools for critical infrastructure managers. While full validation remains ongoing, our contributions establish a rigorous foundation for geometric analysis of network resilience and cascade vulnerability.

97 MATHEMATICS AND COMPUTING↗

Radiation Environments for Lunar Programs

Developing reliable space systems for lunar exploration and infrastructure for extended duration operations on the lunar surface requires analysis and mitigation of potential system vulnerabilities to radiation effects on materials and systems. This paper reviews the characteristics of space radiation environments relevant to lunar programs including the trans-Earth and trans-lunar injection trajectories through the Earth's radiation belts, solar wind surface dose environments, energetic solar particle events, and galactic cosmic rays and discusses the radiation design environments being developed for lunar program requirements to assure that systems operate successfully in the space environment.

Minow, Joseph I.↗

FIC Vulnerability Profile

The FIC team is engaged with Pacific Northwest National Laboratory’s (PNNL’s) Shamrock Cyber Team to provide cybersecurity analyses of the FIC software. Shamrock offers both Threat-Based Analysis services and Secure Software Development services. These services are ultimately used to understand and mitigate threats against software and to reduce vulnerabilities in software, thus improving overall cybersecurity and informing decision makers. Shamrock’s Secure Software Development services, specifically Static Analysis Security Testing (SAST) and Open-Source Analysis (OSA), produced this Vulnerability Profile.

97 MATHEMATICS AND COMPUTING↗

A Method for Measuring Coupled Individual and Social Vulnerability to Environmental Hazards

Although models of social vulnerability to environmental hazards are commonly developed to support policy interventions in emergencies and disasters, their utility is hindered by a lack of contextual information on individuals exposed to and affected by hazards. We develop a novel approach to model social vulnerability that couples individuals and their varying forms of protective capacity with the social fabric of the communities in which they reside. The backbone of our model is the Public-Use Microdata Sample (PUMS), a product of the U.S. Census Bureau that preserves a representative sample of completed responses to the American Community Survey (ACS). The PUMS enables us to understand the full range of individual protective capacities against a hazard in an exposed area, which we term individual vulnerability profiles (IVPs). In this case, we examine IVPs in the Coney Island-Brighton Beach section of New York City, which suffered severe impacts during Hurricane Sandy in 2012. To manage the large number of unique IVPs in Coney Island-Brighton Beach, we perform a segmentation analysis to generalize them into thematic cohort vulnerability profiles (CVPs) representing a typology of vulnerable people in Coney Island-Brighton Beach during Sandy. From synthetic populations of CVPs, we then estimate how individuals in varying housing types were coexposed to Sandy at the census tract level by classifying these areas into community social vulnerability profiles (SVPs). Our results provide a topology of social vulnerability that simultaneously links individual, community, and population-wide concerns, enabling a more holistic understanding of resources and interventions beneficial to human security during events like Sandy than is attainable with area-level metrics.

54 ENVIRONMENTAL SCIENCES↗

Bifurcation Analysis of DC Electric Power Systems for Deep Space Exploration Spacecraft

Electric power system reliability is a crucial factor in the application of both manned and unmanned spacecraft that could alter the success of space exploration missions. Understanding the behavior of these electric systems is essential to determine the safe operating conditions, and subsequently, prevent undesired conditions which may cause system-wide blackouts, leaving the spacecraft in a vulnerable position. This study will use bifurcation analysis to determine the behavior of DC spacecraft electric power systems and identify the major causes of voltage instability.

Bifurcation Analysis↗

Failure Mode and Effects Analysis (FMEA) for Photovoltaic Inverter

Photovoltaic (PV) inverters are critical yet vulnerable components in modern energy systems, often acting as reliability bottlenecks that increase the levelized cost of energy (LCOE). To address this, this paper presents a comprehensive Failure Mode and Effects Analysis (FMEA) tailored for PV inverters. Leveraging field data and literature, we identify failure-prone components, such as capacitors,, and relays, and prioritize their risks based on quantitative Risk Priority Numbers (RPNs). The analysis reveals that surge-induced MOV short circuits, capacitor degradation, and environmental cooling fan failures dominate the risk profile. These findings provide a targeted framework for reliability improvement, guiding future efforts in predictive diagnostics, design optimization, and accelerated life testing strategies.

14 SOLAR ENERGY↗

Electrical alternans during rest and exercise as predictors of vulnerability to ventricular arrhythmias

This investigation was performed to evaluate the feasibility of detecting repolarization alternans with the heart rate elevated with a bicycle exercise protocol. Sensitive spectral signal-processing techniques are able to detect beat-to-beat alternation of the amplitude of the T wave, which is not visible on standard electrocardiogram. Previous animal and human investigations using atrial or ventricular pacing have demonstrated that T-wave alternans is a marker of vulnerability to ventricular arrhythmias. Using a spectral analysis technique incorporating noise reduction signal-processing software, we evaluated electrical alternans at rest and with the heart rate elevated during a bicycle exercise protocol. In this study we defined optimal criteria for electrical alternans to separate patients from those without inducible arrhythmias. Alternans and signal-averaged electrocardiographic results were compared with the results of vulnerability to ventricular arrhythmias as defined by induction of sustained ventricular tachycardia or fibrillation at electrophysiologic evaluation. In 27 patients alternans recorded at rest and with exercise had a sensitivity of 89%, specificity of 75%, and overall clinical accuracy of 80% (p <0.003). In this patient population the signal-averaged electrocardiogram was not a significant predictor of arrhythmia vulnerability. This is the first study to report that repolarization alternans can be detected with heart rate elevated with a bicycle exercise protocol. Alternans measured using this technique is an accurate predictor of arrhythmia inducibility.

Clinical Trial↗

Towards Improving Container Security by Preventing Runtime Escapes

Container escapes enable the adversary to execute code on the host from inside an isolated container. Notably, these high severity escape vulnerabilities originate from three sources: (1) container profile misconfigurations, (2) Linux kernel bugs, and (3) container runtime vulnerabilities. While the first two cases have been studied in the literature, no works have investigated the impact of container runtime vulnerabilities. In this paper, to fill this gap, we study 59 CVEs for 11 different container runtimes. As a result of our study, we found that five of the 11 runtimes had nine publicly available PoC container escape exploits covering 13 CVEs. Our further analysis revealed all nine exploits are the result of a host component leaked into the container. Here, we apply a user namespace container defense to prevent the adversary from leveraging leaked host components and demonstrate that the defense stops seven of the nine container escape exploits.

42 ENGINEERING↗

Mapping heat vulnerability in cities: A tale of two california cities

Extreme heat is a major cause of weather-related deaths in the United States. To address this, a heat vulnerability index (HVI) is crucial for assessing heat risk and identifying vulnerable urban areas and populations, supporting city planning and emergency response. Current HVI studies often use Principal Component Analysis (PCA) on environmental, socioeconomic, and medical data to aggregate vulnerability indicators into a single index. However, these fixed aggregation weights struggle to adapt to different use cases, which may require varying focuses. Moreover, existing tools primarily consider outdoor heat exposure, providing an incomplete picture of actual exposure, as people spend most of their time indoors. Our research introduces an HVI web mapping tool that addresses these gaps in the literature by: (1) allowing flexible weights to adapt to different use cases, and (2) uniquely integrating both outdoor and indoor heat exposure by considering building characteristics for a more comprehensive risk assessment. We demonstrated this tool in two California cities with contrasting climates: Fresno (inland, arid, hot summers) and Oakland (temperate coastal). This HVI mapping tool provides essential decision support for policymakers and stakeholders in both short-term heat mitigation and long-term urban planning for building interventions and infrastructure development.

BES↗

Analyzing Risks of Virtual Private Network Connections

The use of Splunk for analyzing VPN logs is an effective approach for identifying vulnerabilities in network endpoints. Splunk, a powerful platform for searching, monitoring, and analyzing machine-generated data, enables organizations to aggregate VPN logs in real-time, providing insights into network activity, user behavior, and potential security risks. By indexing VPN traffic and authentication logs, security teams can track abnormal patterns such as multiple failed login attempts, unusual IP addresses, or unexpected changes in bandwidth usage, all of which could indicate potential vulnerabilities or breaches. With Splunk’s advanced search and reporting capabilities, users can create custom dashboards and alerts to detect suspicious activities. Automated searches can flag endpoints exhibiting unusual behavior, while correlation analysis can identify links between compromised devices and broader network vulnerabilities. In particular, Splunk's machine learning capabilities can be leveraged to predict and prevent threats by identifying trends that might otherwise be missed in traditional log analysis. This proactive approach to monitoring VPN logs allows for the early detection of security weaknesses, enabling rapid response and minimizing potential damage to network integrity. By enhancing endpoint visibility, Splunk plays a crucial role in securing remote connections and safeguarding sensitive information. Additionally, Splunk’s automation and alerting features allow teams to create custom workflows that notify them of vulnerable or misconfigured endpoints identified through Shodan. This synergy between Splunk’s log analysis and Shodan’s device intelligence enhances an organization’s ability to proactively identify and mitigate security risks, improving the overall resilience of their VPN infrastructure.

97 MATHEMATICS AND COMPUTING↗

Big Data Analytic for Cascading Failure Analysis

With the challenges of increased grid dynamics and more variability of power generation from renewable energy sources, rapidly increasing complexity in the grid model, and abundant data from measurements and simulations, the requirements for computational analysis have also increased dramatically. Power system operators and engineers need to analyze more scenarios, extract meaningful information from a larger set of data, and respond more quickly when faced with these new challenges for large-scale applications, such as contingency analysis. This paper proposes a novel big data analysis approach for power system cascading analysis, prevention, and remediation. The developed techniques will be capable of cascading analysis, better assessment of the system’s vulnerability level, as well as proposing potential remediation. Case studies using IEEE 118-bus system and a 500-bus system, with a comparison against a commercial tool, validate the advantages of the developed big data approach: accurate prediction, and more importantly, faster and effective correction actions.The developed techniques could be further used for other power system applications.

big data, cascading analysis, corrective action, m↗