Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “High Consequence Event”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction, A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

01 COAL, LIGNITE, AND PEAT↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Consequence-Driven Cybersecurity for High-Power Electric Vehicle Charging Infrastructure

Cybersecurity of high-power charging infrastructure for electric vehicles (EVs) is critical to the safety, reliability, and consumer confidence in this publicly accessible technology. Cybersecurity vulnerabilities in high-power EV charging infrastructure may also present risks to broader transportation and energy-infrastructure systems. Here, this paper details a methodology used to analyze and prioritize high-consequence events that could result from cybersecurity sabotage to high-power charging infrastructure. The highest prioritized events are evaluated under laboratory conditions for the severity of impact and the complexity of cybersecurity manipulation. Mitigation solutions and strategies are presented to secure the vulnerabilities that potentially lead to high-consequence events. These mitigations can be immediately implemented by industry or executed during the design stage.

25 ENERGY STORAGE↗

Cyber-Informed Engineering: Standards Development Organization Quick Start Guide

Cyber-Informed Engineering (CIE) is an emerging methodology focused on identifying and reducing high-consequence events that may affect physical critical infrastructure systems as a result of their dependence on digital technology. CIE, developed by National Laboratories and promoted by the Department of Energy (DOE), incorporates consequence-focused planning into the design and engineering process from the earliest stages of a project. This guide provides a concise overview of CIE and offers practical insight into how Standards Development Organizations (SDOs) can interpret CIE principles and apply those concepts in updates to various standards. It is important to remember that CIE extends beyond a compliance checklist, emphasizing a broader, interpretive approach. Instead, it encourages an interpretive mindset - a "turning of 'what if' to 'even if'" approach that anticipates and engineers out high-consequence events. The authors encourage SDOs to establish and promote CIE principles as enhancements for more resilient-by-design outcomes across critical infrastructure energy sectors. The 12 core principles of CIE outline specific behaviors and actions that SDOs and engineers may adopt to enhance system resilience. This guide applies these principles in a manner intended to be relevant across various technologies and threat landscapes. We welcome institutions and vendors to identify new or different framework alignments and mappings as we collectively work towards a safer and more reliable digital landscape.

97 MATHEMATICS AND COMPUTING↗

Consequence analyses of sabotage-induced radiological releases in high-temperature helium-cooled prismatic microreactors

Here, this study analyzes the radiological dose consequences of sabotage-induced accidents at three high-temperature helium-cooled prismatic microreactors (HTPMs) with thermal power ratings of 1, 10, and 50 MWt. Each HTPM employs uranium oxycarbide tristructural isotropic fuel enriched to 19.75 wt% high-assay low-enriched uranium. Simulations were conducted to estimate reactor core inventory at the point of fuel discharge––when the effective multiplication factor reduced to less than 1––representing peak radionuclide inventory. Postulated sabotage scenarios leading to reactor shutdown were analyzed at two intervals: immediately post-shutdown (0 h) and 3 days after shutdown using the SCALE code for radionuclide inventories and the RASCAL tool for dose consequences. Results show that although HTPMs benefit from inherent safety features and robust fuel design, radiological consequences scale with reactor power because of increased source term inventories. Smaller microreactors exhibited proportionally lower dose consequences. To support the economic and regulatory feasibility of microreactor deployment, this study emphasizes the value of a risk-informed, performance-based approach, as supported by regulations like 10 CFR Parts 100 and 53 in the United States. Microreactor developers should perform site-specific assessments of potential sabotage or low-probability, high-consequence events, especially when considering minimal on-site or full off-site emergency response.

Consequence↗

Cyber-Informed Engineering Validation Methods and Guidance

Validation is an important step in any systems engineering process to ensure the correct system was made to fulfill stakeholders’ needs, goals, and expectations. In the context of Cyber-Informed Engineering (CIE), validation ensures cyber impact is reduced through implemented design choices and CIE requirements. This document details a process in validating CIE-based design choices relative to their effectiveness at mitigating high consequence events. The document includes a case study to illustrate the CIE validation process. The case study explores the implementation of CIE validation within the engineering lifecycle of a chemical mixing plant.

42 ENGINEERING↗

Consequence-driven cyber-informed engineering and related systems and methods

Embodiments of the disclosure relate to a computer-implemented consequence-driven cyber-informed engineering tool for performing and reporting consequence-based prioritization, system-of-systems breakdown, consequence-based targeting, and mitigations and protections. Embodiments of a CCE tool may perform one or more steps of defining a target industrial control system (ICS), wherein the target ICS includes operational goals, critical functions, and critical services; determining one or more scored high consequence events (HCE) associated with the defined target ICS; prioritizing the scored HCEs according to an HCE severity index; and updating a dashboard with one or more representations of the prioritized HCEs, wherein the updated dashboard is associated with the CCE tool and presented at a display.

Assante, Michael↗

CCE Case Study: Stinky Cheese Company

This document explores how to apply Consequence-driven Cyber-informed Engineering (CCE) to identify and mitigate catastrophic effects resulting from cyber-enabled sabotage in a case study. For this case study, we will examine a fictional organization named the Stinky Cheese Company.

99 GENERAL AND MISCELLANEOUS↗

A Review of Resilience and Long-Term Planning in Power and Water Systems in the United States

There is recognition among power and water utilities that the frequency and magnitude of high consequence and low probability events could increase as a result of climate change. The interconnected nature of energy-water systems raises the possibility of cascading failures, increasing complexity and risks. Resilience and long-term planning are important ways of weathering the effects of climate change. First, to understand more about resilience, we reviewed existing literature on resilience definitions, metrics, and modeling, focusing on integrated water-power systems. Second, to understand how resilience and planning are being applied in practice, we interviewed utilities and organized, curated, and synthesized the interview data to arrive at several key findings, which are presented here. We found that there is not a consistent definition for resilience, yet it is something that utilities regularly plan for, often with different names and varying methods/measures. However, there is a tangible shift in the industry towards defining and determining measurable resilience metrics. While the exact metrics are a work in progress, utilities are taking steps forward by (1) putting people and culture at the center of resilience, (2) recognizing their own interdependencies, and (3) pursuing better cross-sector collaboration.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Overland flow numerical model prediction, Lower Triangle Region in East River Watershed, Colorado, 3 days

This data package contains numerical simulation results of surface flow variables such as flow velocity and water depth in Lower Triangle Region in East River Watershed, Colorado. The surface flow is a consequence of a high intensity rainfall event with a total duration of 3 days, available at a resolution of 10 minutes. The results are computed on triangular multiresolution meshes with resolutions ranging from 10 meter to 80 meter. The data package also contains a simulation on a uniform triangular mesh with a resolution of 10 meter. The simulations consider surface flow only and neglect subsurface flow, infiltration, and evapotranspiration. The purpose of the data is to assess the quality of a mesh refinement strategy.

54 ENVIRONMENTAL SCIENCES↗

How Low Can You Go? Using Synthetic 3D Imagery to Drastically Reduce Real-World Training Data for Object Detection

Deep convolutional neural networks (DCNNs) currently provide state-of-the-art performance on image classification and object detection tasks, and there are many global security mission areas where such models could be extremely useful. Crucially, the success of these models is driven in large part by the widespread availability of high-quality open source data sets such as Image Net, Common Objects in Context (COCO), and KITTI, which contain millions of images with thousands of unique labels. However, global security relevant objects-of-interest can be difficult to obtain: relevant events are low frequency and high consequence; the content of relevant images is sensitive; and adversaries and proliferators seek to obscure their activities. For these cases where exemplar data is hard to come-by, even fine-tuning an existing model with available data can be effectively impossible. Recent work demonstrated that models can be trained using a combination of real-world and synthetic images generated from 3D representations; that such models can exceed the performance of models trained using real-world data alone; and that the generated images need not be perfectly realistic (Tremblay, et al., 2018). However, this approach still required hundreds to thousands of real-world images for training and fine tuning, which for sparse, global security-relevant datasets can be an unrealistic hurdle. In this research, we validate the performance and behavior of DCNN models as we drive the number of real-world images used for training object detection tasks down to a minimal set. We perform multiple experiments to identify the best approach to train DCNNs from an extremely small set of real-world images. In doing so, we: Develop state-of-the-art, parameterized 3D models based on real-world images and sample from their parameters to increase the variance in synthetic image training data; Use machine learning explainability techniques to highlight and correct through targeted training the biases that result from training using completely synthetic images; and Validate our results by comparing the performance of the models trained on synthetic data to one another, and to a control model created by fine-tuning an existing ImageNet-trained model with a limited number (hundreds) of real-world images.

97 MATHEMATICS AND COMPUTING↗

Risk Management and Risk Aversion, from Benefit to Impediment

Risk management is a critical tool for improving the probability of project success by identifying, assessing, prioritizing, and attempting to control threats to project realization. For industries that require high operational reliability due to the potential consequences of off-normal events, such as the nuclear, aerospace, and chemical sectors, a major focus of risk management is the preservation of process safety. Due to the nature of the processes or systems under consideration, the associated process safety analyses (such as risk and safety assessments) and safety features can require significant resources. These costs are typically tolerated either due to the need to satisfy regulatory requirements or based on the assumption that they generally decrease the occurrence of unwanted events and therefore improve the probability of project success. However, as the level of acceptable or tolerable risk from unwanted events decreases, the required resources necessary for ensuring and demonstrating satisfaction of these criteria can grow and in turn can become one of the dominant impediments to project success. This paper outlines a high-level theoretical framework for the consideration of dominant project risks, which includes potential project failure from both the occurrence of high consequence off-normal events and the inability to achieve project completion due to the resource needs and innovation losses associated with extreme risk aversion. Utilizing such an integrated approach permits an attempt to optimize the probability of successful project realization while also providing valuable insight into the proper level of acceptable risk. The work is presented as a first step, in hopes of spurring additional discussion and analysis regarding appropriate levels of risk tolerance and the balance of project benefits.

Grabaskas, David↗

River Geomorphology Affects Biogeochemical Responses to Hydrologic Events in a Large River Ecosystem

Shifts in the frequency and intensity of high discharge events due to climate change may have important consequences for the hydrology and biogeochemistry of rivers. However, our understanding of event-scale biogeochemical dynamics in large rivers lags that of small streams. To fill this gap, we used high-frequency sensor data collected during four consecutive summers from a main channel and backwater site of the Upper Mississippi River. We identified high discharge events and calculated event concentration-discharge responses for both physical-chemical (nitrate, turbidity, and fluorescent dissolved organic matter) and biological (chlorophyll-a and cyanobacteria) constituents using metrics of hysteresis and slope. We found a range of responses across events, particularly for nitrate. Although fluorescent dissolved organic matter (FDOM) and turbidity exhibited more consistent responses across events, contrasting hysteresis metrics indicated that FDOM was flushed to the river from more distant sources than turbidity. Biological responses (chlorophyll a and cyanobacteria) differed more between sites than physical and chemical constituents. Lastly, we found that the event characteristics best explaining concentration responses differed between sites, with event magnitude more frequently related to responses in the main channel, and antecedent wetness conditions associated with response variation in the backwater. Furthermore, our results indicate that event responses in large rivers are distinct across the diverse habitats and biogeochemical components of a large floodplain river, which has implications for local and downstream ecosystems as the climate shifts.

54 ENVIRONMENTAL SCIENCES↗

Regulatory Considerations Regarding Potential High Temperature Fluid Releases in Advanced Reactor Designs

The current effort is supported by the U.S. Department of Energy (DOE), Advanced Reactor Demonstration Program (ARDP) Regulatory Development, Regulatory Framework Modernization area, which seeks to address potential regulatory challenges for advanced reactor vendors that are currently or will soon be initiating the licensing process. In pursuit of this goal, this effort seeks to aid the advanced reactor industry and regulatory bodies in understanding and addressing the potential occurrence of high-temperature fluid releases in advanced reactor designs as part of licensing and regulatory oversight of operation. Improving the awareness and understanding of the behavior and potential consequences associated with high-temperature fluid release events can ensure that they are appropriately considered and addressed.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Revealing the Statistics of Extreme Events Hidden in Short Weather Forecast Data

Extreme weather events have significant consequences, dominating the impact of climate on society. While high-resolution weather models can forecast many types of extreme events on synoptic timescales, long-term climatological risk assessment is an altogether different problem. A once-in-a-century event takes, on average, 100 years of simulation time to appear just once, far beyond the typical integration length of a weather forecast model. Therefore, this task is left to cheaper, but less accurate, low-resolution or statistical models. But there is untapped potential in weather model output: despite being short in duration, weather forecast ensembles are produced multiple times a week. Integrations are launched with independent perturbations, causing them to spread apart over time and broadly sample phase space. Collectively, these integrations add up to thousands of years of data. We establish methods to extract climatological information from these short weather simulations. Using ensemble hindcasts by the European Center for Medium-range Weather Forecasting archived in the subseasonal-to-seasonal (S2S) database, we characterize sudden stratospheric warming (SSW) events with multi-centennial return times. Consistent results are found between alternative methods, including basic counting strategies and Markov state modeling. By carefully combining trajectories together, we obtain estimates of SSW frequencies and their seasonal distributions that are consistent with reanalysis-derived estimates for moderately rare events, but with much tighter uncertainty bounds, and which can be extended to events of unprecedented severity that have not yet been observed historically. These methods hold potential for assessing extreme events throughout the climate system, beyond this example of stratospheric extremes.

58 GEOSCIENCES↗

Valuing Resilience Benefits of Microgrids for an Interconnected Island Distribution System

Extreme climate-driven events such as hurricanes, floods, and wildfires are becoming more intense in areas exposed to these threats, requiring approaches to improve the resilience of the electrical infrastructure serving these communities. Long-duration outages caused by such high impact events propagate to economic, health, and social consequences for communities. As essential service providers, electric utilities are mandated to provide safe, economical and reliable electricity to their customers. The public is becoming less tolerant to these more frequent disruptions, especially in view of technological advances that are intended to improve power quality, reliability and resilience. One promising solution is state-of-the-art microgrids and the advanced controls employed therein. This paper presents and demonstrates an approach to technoeconomic analysis that can be used to value the avoided economic consequences of grid resilience investments, as applied to the islands of Vieques and Culebra in Puerto Rico. This valuation methodology can support policies to incorporate resilience value into any investment decision-making process, especially those which serve the public interest.

24 POWER TRANSMISSION AND DISTRIBUTION↗

SURVEILLANCE DETECTION FOR TRANSPORTATION OPERATIONS PERSONNEL TO PREVENT HIJACKING, THEFT, SABOTAGE, AND MALICIOUS SECURITY EVENTS DURING TRANSPORTING NUCLEAR MATERIAL

The secure transportation of high-consequence materials, including nuclear and radiological assets, is a critical global priority in the face of escalating terrorism, security threats, and violent protests targeting these operations. Effective surveillance detection—the ability to identify, assess, and respond to potential threats across a continuum of scenarios—is paramount in addressing these challenges. This paper outlines a phased, multi-tiered training program designed to strengthen the surveillance detection capabilities of organizations responsible for nuclear material transport. The proposed training program adopts a progressive approach, gradually increasing in technical complexity to provide participants with comprehensive knowledge and tools for implementing robust security strategies. It targets a wide spectrum of stakeholders, including competent authorities, regulators, inspectors, shippers, carriers, law enforcement, and emergency response personnel, equipping them to plan, evaluate, and safeguard nuclear material transportation effectively. Each phase of the program emphasizes distinct elements of the surveillance detection continuum and transport security, focusing on critical topics such as threat identification, adversary task timelines, protective methodologies, and attack mitigation strategies. The training framework is anchored in technical exchanges and scenario-driven courses that reflect real-world complexities and challenges. By addressing the surveillance detection continuum comprehensively—from early threat assessment to active countermeasures—the program reinforces global efforts to secure nuclear assets. It aligns with international security objectives and fosters a strong security culture within participating organizations, ensuring personnel are prepared to counter potential threats and maintain the safe, secure movement of these materials. Ultimately, this initiative aims to enhance preparedness, security, and response capabilities, supporting the global mission to safeguard high-consequence materials against evolving threats.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗