Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Incident Response”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Cybersecurity Incident Response Guide for Wind

As wind energy systems become increasingly digitized and interconnected, they face a growing array of cyber threats that can disrupt operations, compromise safety, and trigger cascading impacts across the energy ecosystem. The Wind Incident Response Guide provides a structured, wind-specific framework for preparing for, detecting, responding to, and recovering from cyber incidents. Drawing on lessons from field demonstrations, cyber-physical testbeds, and stakeholder engagement across the wind sector, this guide integrates technical, operational, and regulatory considerations to support asset owners, operators, and responders. It outlines key roles and responsibilities, maps incident response phases to wind-specific scenarios, and highlights applicable laws, regulations, standards, and best practices. By tailoring general cybersecurity principles to the unique architectures and operational constraints of wind systems—including remote access, legacy components, and environmental interfaces—this guide aims to enhance resilience, reduce response time, and support coordinated action across public and private stakeholders. It is intended as a practical resource for utilities, developers, regulators, and emergency managers working to secure the future of wind energy.

17 - WIND ENERGY

AR4IR (Automated Reasoning for Incident Response) [SWR-24-103]

A basic formal methods tool with the ability to aid and/or automate a utilities’ incidence response and instills confidence that the proposed action satisfies the system’s physical constraints, the organization’s cyber policies, and will not cause violations of technical standards.

Etigowni, Sriharsha [National Renewable Energy Lab

Uncertainty Analysis of Inhalation Dose Coefficients for Nuclear Incident Response

This study addressed the need to characterize variability in inhalation dose coefficients due to uncertainties in respiratory tract deposition, systemic biokinetics, and physiological parameters. A Python-based implementation of the International Commission on Radiological Protection Publication 66 Human Respiratory Tract Model was developed called the Radiological Exposure Dose Calculator (REDCAL) to propagate parameter uncertainty.

61 RADIATION PROTECTION AND DOSIMETRY

NFPA Distributed Energy Resources Safety Training (DERST) For Emergency Responders

The National Fire Protection Association, with support from the Department of Energy, executed a multi-year initiative to develop, enhance, and disseminate Distributed Energy Resources Safety Training (DERST) tools for U.S. emergency responders. As Distributed Energy Resources (DER)—such as solar photovoltaics, battery energy storage systems (ESS), electric vehicles (EVs), and associated infrastructure—become increasingly prevalent, the NFPA identified a critical need for up-to-date standardized, accessible, and effective safety training tailored for the fire service and related public safety professionals. The project delivered a comprehensive suite of educational resources to improve responders’ abilities to safely manage DER-related incidents. This included: • Revised Modular Training Courses: Updated classroom-based DER safety courses, now modular and accessible nationwide through fire academies and the North American Fire Training Directors (NAFTD) network. • Live Burn Testing & Research: A full-scale controlled burn of a DER-equipped residential structure provided real-world data and insights, forming the basis for updated best practices. • A Gamified Simulation Tool – Firefighters Incident Response Simulation Tool (FIRST): A first-of-its-kind, multiplayer, scenario-based simulation using the Unreal Engine 5.0 to train responders in a realistic virtual, multi-DER incident environment. • Field Familiarization Software Tools & Prop Guide: Digital DER field familiarization evolutions software guide and a prop development manual to support field-based DER training exercises, enhancing responders' hands-on familiarity with DER infrastructure and collaboration on virtual incident responses. • National Dissemination Strategy: Strategic partnerships with NAFTD, Vector Solutions, and others enabled wide-scale distribution, with over 5,000 departments accessing resources and 1,100+ departments adopting the simulator in the first seven months. Also provided a web portal for easy access to all training and simulation programs developed under this grant for the U.S. responder community. Key findings from the project—particularly from the burn test—led to paradigm shifts in fire response tactics. For example, traditional approaches to garage fires may be hazardous if DERs are present, due to explosive off gassing and thermal runaway risks. The new training emphasizes scene assessment, stand-off approaches, thermal imaging verification, and careful post-incident cooling of DER components to prevent reignition. This initiative has had a significant national impact, raising awareness, enhancing preparedness, and supporting safer DER incident response practices. Significant engagement from the media, public safety organizations, and PBS coverage has further amplified the reach and adoption of NFPA’s DER safety training, tools, and simulations.

14 SOLAR ENERGY

Intern Deliverable Poster 2025

An Incident Response Plan (IRP) is a document that is created and maintained by an organization that provides guidance in the event of a cyber incident. The primary objectives of an IRP are to aid in the detection, response, and recovery from incidents, as well as to enhance preparation and preventative measures. An IRP should outline specific procedures at each stage of an incident, with the goal of minimizing asset damage, data leakage, and operational impact. By investing in a well-defined IRP, organizations can better manage and mitigate risks associated with cyber threats, ensuring business continuity and resilience. This poster summarizes incident response guidelines for wind energy, which faces unique cybersecurity and physical challenges.

17 - WIND ENERGY

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Validating Protection System Behavior with Machine Learning in a Master State Overseer

As power system protection devices continue the widespread transition from analog to digital, they become increasingly intricate. The internal functions and communication between critical grid components must now be significantly more complex to keep up with the demands of the modern smart grid. This brings increased difficulty in maintenance and monitoring, making it harder to identify potential misoperation, power anomalies, and cyber threats. Such issues are often only pinpointed after an exhaustive and costly post-mortem analysis, when a major outage or damage has already occurred. A solution is needed for validating protection systems as they operate, independently evaluating grid state and confirming whether the protection system is behaving accordingly. As opposed to incident response, this acts as a constant verification mechanism that raises a flag when subtler issues are noticed, catching them earlier and preventing larger incidents. This work presents the implementation of such a system, expanding on the prototype developed by the authors in a previous paper. This is accomplished with a machine learning (ML) system capable of validating the performance of protection systems by classifying anomalous events and characterizing protection system responses based solely on available current and voltage measurements. Additionally, this system is contextualized within a larger, modular Master State awareness Overseer (MSO) framework, responsible for monitoring, analyzing, and managing an electric grid.

24 - POWER TRANSMISSION AND DISTRIBUTION

A Software/Hardware Framework for Efficient and Safe Emergency Response in Post-Crash Scenarios of Battery Electric Vehicles

The adoption rate of battery electric vehicles (EVs) is rapidly increasing. Electric vehicles differ significantly from conventional internal combustion engine vehicles and vary widely across different manufacturers. Emergency responders (ERs) and recovery personnel may have less experience with EVs and lack timely access to critical information such as the extent of the stranded energy present, high-voltage safety hazards, and post-crash handling procedures in a user-friendly manner. This paper presents a software/hardware interactive tool named Electric Vehicle Information for Incident Response Solutions (EVIRS) to aid in the quick access to emergency response and recovery information. The current prototype of EVIRS identifies EVs using the VIN or Make, Model, and Year, and offers several useful features for ERs and recovery personnel. These features include integration and easy access to emergency response procedures tailored to an identified EV, vehicle structural schematics, the quick identification of battery pack specifications, and more. For EVs that are not severely damaged, EVIRS can perform calculations to estimate stranded energy in the EV’s battery and discharge time for various power loads using either EV dashboard information or operational data accessed through the CAN interface. Knowledge of this information may be helpful in the post-crash handling, management, and storage of an EV. The functionality and accuracy of EVIRS were demonstrated through laboratory tests using a 2021 Ford Mach-E and associated data acquisition system. The results indicated that when the remaining driving range was used as an input, EVIRS was able to estimate the pack voltage with an error of less than 3 V. Conversely, when pack voltage was used as an input, the estimated state of charge (SOC) error was less than 5% within the range of 30–90% SOC. Additionally, other features, such as retrieving emergency response guides for identified EVs and accessing lessons learned from archived incidents, have been successfully demonstrated through EVIRS for quick access. EVIRS can be a valuable tool for emergency responders and recovery personnel, both in action and during offline training, by providing crucial information related to assessing EV/battery safety risks, appropriate handling, de-energizing, transport, and storage in an integrated and user-friendly manner.

25 ENERGY STORAGE

Oakland University Cybersecurity Center (Final Scientific/Technical Report)

This report summarizes the outcomes of Award DE-CR0000023, “Oakland University Cybersecurity Center,” a 31-month project funded by the U.S. Department of Energy Office of Cybersecurity, Energy Security, and Emergency Response (CESER). The project addressed cybersecurity risks facing small and medium-sized manufacturers (SMMs) transitioning to Industry 4.0. The project integrated customer discovery, applied research, and cybersecurity training development. A total of 51 cybersecurity assessments identified significant gaps in baseline practices, incident response, and workforce capability. Research efforts produced a scalable mitigation framework tailored to SMM environments, and workforce analysis identified persistent talent gaps. Eight cybersecurity training modules were developed and deployed via Oakland University’s Professional and Continuing Education (PACE) platform. All objectives were completed, with 98.93% federal budget utilization and cost share exceeding requirements. The project establishes a scalable model for strengthening cybersecurity resilience and workforce capacity across U.S. manufacturing supply chains.

24 POWER TRANSMISSION AND DISTRIBUTION

Dose Exceedance Distance Sensitivity Based on Parametric Uncertainty

Sandia National Laboratories (SNL) collaborated with the US Nuclear Regulatory Commission's (NRC) Office of Nuclear Security and Incident Response (NSIR) and Office of Nuclear Regulatory Research (RES) to investigate the reasonable variability in the estimation of dose exceedance distances. SNL performed calculations using the MACCS code to elucidate the sensitivity of dose exceedance distances to variations in user input parameters.

61 RADIATION PROTECTION AND DOSIMETRY

Photosynthetic Biohybrid System for Enhanced Abiotic N 2 -to-NH 3 Conversion under Ambient Conditions

Photosynthetic biohybrid systems (PBSs) offer an eco-friendly approach to transforming solar energy into value-added products by integrating biological entities with inorganic semiconductors. However, the chemical conversion capacity of most PBSs has inherent limitations, as whole-cell bacteria and isolated enzymes require fine-tuning of environmental conditions. Here, in this study, we report a new PBS developed by introducing free-standing ceria nanoparticles into the purple membrane (PM) of Halobacterium salinarum archaea, which can unidirectionally transfer charge carriers in response to incident photons, even after separation from living archaea at various conditions. Our microscopy, spectroscopy, and synchrotron X-ray scattering analyses confirm that the electrostatic assembly between ceria and PM creates seamless interfacial contact, thereby enhancing the photocatalytic capacity of ceria. Although the conversion of dinitrogen (N 2 ) to ammonia (NH 3 ) is thermodynamically challenging due to the triple bond in N 2 and a series of charge-transfer reactions, our PM–ceria (PMC) hybrid nanoparticle efficiently produces NH 3 by reducing N 2 using solar energy even under atmospheric pressure and room temperature while simultaneously converting glycerol into value-added derivatives. Additionally, our PMC nanoparticle involves neither toxic/precious metals nor bioengineering processes to achieve enhanced photocatalytic N 2 -to-NH 3 conversion. This study sheds light on the new aspect of PBSs by employing PM to potentially resolve the global energy and environmental challenges posed by the conventional Haber–Bosch process.

Jang, Jinhyeong [Argonne National Laboratory (ANL)

Reconstruction of beam parameters and betatron radiation spectra measured with a Compton spectrometer

The photon flux resulting from high-energy electron beam interactions with high-field systems, such as those found in the upcoming FACET-II experiments at the SLAC National Accelerator Laboratory, yields deep insight into the electron beam’s underlying dynamics during the interaction. However, extracting this information is an intricate process. To demonstrate how to approach this challenge using modern methods, this paper utilizes simulated data that models plasma wakefield acceleration-derived betatron radiation in experiments to determine reliable methods of reconstructing key beam and beam-plasma interaction properties. For betatron radiation measurements, translating the observed 200⁢ keV to 30⁢ MeV photon double-differential energy-angle spectra obtained from an advanced Compton spectrometer requires testing multiple methods to optimize the pipeline from its response to incident electron beam information. The paper compares maximum likelihood estimation and machine learning to refine the translation of photon spectra into precise electron beam metrics, such as spot size, energy, and emittance, enhancing the understanding of beam behavior within these dense, high-field environments. We also introduce machine learning and the expected maximization algorithm to reconstruct the primary photon spectrum, employing a multilayer neural network for regression analysis of the energy and angle spectra. With appropriate modifications, the advanced methods reproduce relevant incident beam parameters with high accuracy, even for beam sizes in the <10 μ⁢m range. This capacity is critical to understanding intense beam propagation and its optimization in plasma.

Beam code development & simulation techniques

National Cancer Institute (NCI) Exposomic Linkage Protocol

The purpose of this work is to create point-level linkages of residential history data, which is provided by the Surveillance, Epidemiology, and End Results (SEER) program, to air pollution exposure data so that we can develop longitudinal measures of exposure and investigate their effects on cancer incidence, treatment response, and survival. The Louisiana, New Jersey, Kentucky, and Iowa registries were previously linked to LexisNexis residential history data through the National Cancer Institute (NCI). We will enhance the utility of the existing residential location data by geocoding addresses based on data from between 1995 and 2024 and spatially linking the locations to air pollution, indoor radon, and the US Environmental Protection Agency’s (EPA) Risk-Screening Environmental Indicators (RSEI) exposure data (Figure 1).

63 RADIATION, THERMAL, AND OTHER ENVIRON. POLLUTAN

Cybersecurity Enhancement in Digital Substations: Hidden Markov Model-Based Smart Cyber Switching and Threat Response

The rising incidence of cyber-attacks on critical infrastructure and power grids poses significant threats to the stability and reliability of electrical substations, with potentially devastating consequences such as extended blackouts. This paper introduces an advanced cybersecurity framework aimed at safeguarding IEC 61850-based substations through the integration of software-defined networking (SDN) and digital twin (DT) technologies. The proposed DT-based framework employs smart cyber switching (SCS) for proactive threat mitigation and concurrent intelligent electronic device (CIED) for swift system restoration, thereby maintaining continuous operational integrity and robust cybersecurity defenses. Central to this framework is the adaptive port controller (APC), which enables dynamic port management to adapt to evolving threats, and an intrusion detection system (IDS) designed to detect and neutralize malicious attacks on IEC 61850-based sampled value (SV) and generic object-oriented substation event (GOOSE) messages within the substation’s communication network. Further, novel predictive intrusion detection and response (PIDR) algorithm is implemented on a digital substation (DS) to predict the best route to be taken by the attacker. The efficacy of these comprehensive cybersecurity frameworks is validated through rigorous simulations and a hardware-in-the-loop (HIL) testbed, showcasing the system’s ability to sustain substation operations amidst cyber-attacks.

Digital substation