Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Vulnerability management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Vulnerability Management for Electric Vehicle Supply Equipment

Vulnerability management for EVSE is a challenging undertaking with all the necessary stakeholders and devices that are interconnected, this presentation reviews the challenges and opportunities for conducting CVD for EVSE.

97 MATHEMATICS AND COMPUTING

When ChatGPT Meets Vulnerability Management: The Good, the Bad, and the Ugly

Vulnerability management is a very challenging and time-consuming task. For many organizations, security operators need to learn about the properties of vulnerabilities to prioritize and mitigate them. Due to the lack of automated tools for vulnerability assessment, operators usually manually search for and read related information from sources online. Recent advances in large language models, like ChatGPT, open up an opportunity for time savings and may prompt operators to use these models as vulnerability information sources. In this work, we evaluate the ability of ChatGPT and several of its siblings to accurately answer user questions about vulnerability properties as well as to provide information for how to mitigate a vulnerability. We also explore their summarization capabilities when multiple vulnerability advisory documents are provided. We find that the models perform poorly on information retrieval tasks, but they perform quite well on summarization.

McClanahan, Kylie

Blueprint: Stakeholder-Specific Vulnerability Categorization Guidance

Vulnerability management is a process of discovering, analyzing, and handling new or reported security vulnerabilities in systems to prevent the systems from being exploited, to reduce risk, and to protect assets. For vulnerability analysis, handling, and response, the prioritization of organizational and analyst resources must precede. The Common Vulnerability Scoring System (CVSS) is a standard prioritization method that is used to rate the severity of security vulnerabilities in systems by assigning numerical severity scores, but it does not provide clear guidelines of how the numerical severity scores might inform decisions. The Stakeholder-Specific Vulnerability Categorization (SSVC) provides a method for prioritizing vulnerabilities based on the needs of the stakeholders involved in the vulnerability management process. Instead of the numerical scoring used in the CVSS, the SSVC focuses on contextual decision-making to determine how quickly and effectively an organization should respond to vulnerabilities. The main functionality of the SSVC accommodates the diversity of the stakeholders in the vulnerability management process, including finders, vendors, coordinators, deployers, and others. So, the SSVC should be designed to be used by any of these stakeholders, and it should be customizable to enable specific stakeholder decision models and risk appetites.

33 ADVANCED PROPULSION SYSTEMS

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization

I Can't Patch My OT Systems! A Look at CISA's KEVC Workarounds & Mitigations for OT

We examine the state of publicly available information about known exploitable vulnerabilities applicable to operational technology (OT) environments. Specifically, we analyze the Known Exploitable Vulnerabilities Catalog (KEVC) maintained by the US Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) to assess whether currently available data is sufficient for effective and reliable remediation in OT settings. Our team analyzed all KEVC entries through July 2025 to determine the extent to which OT environments can rely on existing remediation recommendations. We found that although most entries in the KEVC could affect OT environments, only 13% include vendor workarounds or mitigations as alternatives to patching. This paper also examines the feasibility of developing such alternatives based on vulnerability and exploit characteristics, and we present early evidence of success with this approach.

97 MATHEMATICS AND COMPUTING

Developing a Supply Chain Security Program

Amid growing concerns over foreign manufacturing for components and devices deployed in critical energy infrastructure, this research from the national labs will highlight best practices for developing and maintaining a supply chain security program. Tools for asset inventory, tips for developing and maintaining software- and hardware-bills-of-materials (SBOMs and HBOMs), recommended contractual language for vendor agreements, and identification of responsibilities will be shared. We discuss the one-time requirements to enable a successful supply chain security program and the best ways to operationalize this program for maximum impact, including development of robust practices for vulnerability tracking, patch management, and workarounds, with understanding of the reliability and uptime requirements for utilities. The recommendations shared are based on a cyber-informed engineering approach to identification of high-consequence impacts and the engineering controls related to supply chain management that can best mitigate these impacts. This approach allows for prioritization of resources. Additionally, we highlight relative up-front and ongoing costs associated with recommended controls. Viewers will leave with an understanding what a supply chain security program is, and what steps, prioritized for resource-constrained organizations, can build a robust program.

14 SOLAR ENERGY

Enhancing Power Resilience for Remote Communities: A Comprehensive Renewable Energy Solution for Itbayat Island

The island of Itbayat, Philippines, faces significant challenges in maintaining a reliable and resilient power supply due to its current reliance on a vulnerable power distribution system managed by a local electric cooperative. The existing infrastructure, which includes diesel generators and a radial network configuration with some above-ground lines, is highly susceptible to frequent typhoons and adverse weather conditions. These factors, combined with inadequate staffing and high operational costs, result in frequent power outages that disrupt daily life and hinder economic development. This white paper proposes a comprehensive solution to enhance the resilience and reliability of Itbayat's power system by integrating renewable energy sources, specifically solar photovoltaic (PV) systems, battery storage, and a microgrid controller. The proposed solution aims to reduce dependency on diesel fuel, optimize energy use, and provide a sustainable and robust power supply for the island. Key components of the solution include: 1. Solar PV Installation: Deploying solar PV panels to harness abundant solar energy, reducing reliance on diesel fuel. 2. Battery Storage Systems: Installing battery storage to store excess solar energy and ensure a continuous power supply during low solar generation periods. 3. Microgrid Controller: Implementing a microgrid controller to manage and optimize the integration of solar PV, battery storage, and existing diesel generators. The proposed solution addresses several critical issues, including system vulnerability, generator dependency, and operational inefficiencies. By adopting this innovative approach, Itbayat Island can achieve a more resilient, efficient, and sustainable energy infrastructure, ensuring a stable power supply for its residents and enhancing overall energy security.

14 SOLAR ENERGY

Threat Landscape for BESS and IBR

The cyber risk landscape for BESS and IBR can be broken up by threats, vulnerabilities, and consequences for these systems. This presentation walks through the cyber risk landscape for BESS through the lens of consequence-informed awareness and mitigation for each risk factor. Threats with varying capabilities have been demonstrated in real-world events. Though threat actors can rarely be directly influenced by organizations, exposure of systems to adversaries can be limited (a known issue with IBR systems) to reduce likelihood of adversaries accessing systems with disruptive consequences. Common trends in disclosed IBR vulnerabilities include weak password generation or managements for various devices or services and web portal vulnerabilities that provide unauthorized access to data or capabilities or elevated user privileges. Understanding these common vulnerabilities and considering the consequences if these types of vulnerabilities were to occur can help mitigate risk. Consequences range from loss-of-view events that have no reliability impact to asset damage or grid stability impacts. Five case studies are briefly shared to highlight trends in real-world events affecting IBR.

14 - SOLAR ENERGY

Yesterday’s extremes, today’s new normal: flood risk in the Kathmandu Valley, Nepal

Unplanned urban growth has left many cities increasingly vulnerable to extreme rainfall events, particularly in regions with inadequate drainage infrastructures and development encroaching on natural floodplains. Here, in this perspective paper, we examine the September 2024 floods that struck Central Nepal, triggered by a persistent low-pressure system and enhanced by converging moisture flows from the Arabian Sea and the Bay of Bengal which led to widespread catastrophic damage. In the Kathmandu Valley, floodwaters expanded to more than 2.5 times the bankfull water extent, causing significant damage to housing, transportation network, and critical infrastructure, displacing thousands of residents, and severely disrupting urban services. This event highlights the urgent need for improved flood management strategies that integrate both structural and non-structural measures into the infrastructure development. While early warning systems provided critical lead time, challenges remain in reducing forecasting uncertainties and improving communication across government agencies and with local communities. A forward-looking approach is essential, including probabilistic flood forecasting systems, sustainable floodplain management, risk-sensitive land use planning, climate- and disaster- resilient infrastructure development, and the integration of nature-based solutions like urban green and blue spaces to mitigate flood impacts. By involving local communities in planning and preparedness efforts, particularly through citizen science initiatives, and engagement with underserved and disadvantaged communities, Nepal can better adapt to the growing risks posed by extreme rainfall and urban flooding and enhance long-term disaster resilience in rapidly urbanizing areas like Kathmandu Valley.

Kathmandu Valley

Roadmap for the future of extreme wildfire events

Background Extreme wildfire events (EWEs) represent a growing threat globally, posing substantial risks to ecosystems, human communities, and infrastructure. Despite increased recognition of their ecological, social, and economic significance, current definitions of EWEs vary widely, reflecting disciplinary biases and regional contexts. This article emerges from an interdisciplinary workshop convened to reassess and refine the definition of EWEs, examine their impacts across ecological and social dimensions, and identify critical knowledge gaps impeding our understanding of these infrequent but important events. Results Our synthesis highlights significant limitations with existing definitions, particularly their reliance on subjective thresholds and their emphasis on extreme fire behavior alone. EWEs encompass a spectrum of complex, multi-dimensional phenomena that extend beyond immediate biophysical characteristics to include cumulative social, economic, and ecological impacts. These impacts often manifest over extended timeframes and include hazardous environmental contamination, severe geomorphic disturbances, ecosystem transformations, and unintended consequences of post-fire management actions. Current wildfire modeling frameworks inadequately capture these compounding factors, particularly the interactions among social systems, ecological conditions, and extreme fire behavior. To overcome these issues, we advocate for an interdisciplinary and context-sensitive approach to defining and studying EWEs. This revised definition emphasizes wildfires exhibiting anomalies in fire behavior, ecological outcomes, or social impacts relative to historically observed baselines, accommodating variability across different geographic regions and ecological settings. Conclusions Adopting an interdisciplinary framework that integrates biophysical and social sciences will enhance the predictive capability of wildfire models and improve resilience planning and response strategies. Filling identified knowledge gaps—such as limited high-quality empirical fire behavior data and insufficient integration of social dynamics into modeling—will better prepare communities and ecosystems to cope with and adapt to EWEs. This inclusive approach underscores the necessity for collaboration across disciplines and sectors, essential to managing extreme wildfires in an era of increasing climatic and ecological uncertainty.

54 ENVIRONMENTAL SCIENCES

Unsupervised Detection of SOC Spoofing in OCPP 2.0.1 EV Charging Communication Protocol Using One-Class SVM

The electric vehicles (EVs) market keeps growing globally; thus, it is critical to secure the EV charging communication protocols in order to guarantee reliable and fair charging operations among the customers. The Open Charge Point Protocol (OCPP) 2.0.1 supports the communication between the Electric Vehicle Supply Equipment (EVSE) and Charging Station Management Systems (CSMSs); therefore, it becomes vulnerable to several types of attacks, which aim to jeopardize smart charging, billing, and energy management. Specifically, OCPP 2.0.1 allows the self-reporting of the State of Charge (SOC) values, which makes it vulnerable to spoofing-based cyberattacks, which target manipulating the scheduling priorities, distorting the load forecasts, and extending the charging sessions in an unfair manner. In this paper, we try to address this type of attack by providing a comprehensive analysis of the SOC spoofing attacks and introducing a novel unsupervised detection framework based on the One-Class Support Vector Machine (OCSVM) algorithm. Specifically, two types of attack scenarios are analyzed (i.e., priority manipulation and session extension) by deriving engineered features that capture the nonlinear relationships under normal charging behavior. Detailed simulation-based results are derived by utilizing the DESL-EPFL Level 3 EV charging dataset. Our results demonstrate high F1-score and recall in identifying spoofed SOC values and that the proposed OCSVM model demonstrates superior performance compared to alternative clustering and deep-learning based detectors.

EV charging

Coordinated Thermal Safety Attack and Defense on EV Battery Management Systems

Battery temperature sensor and battery current sensor data which are key sensing inputs to the Battery Management Controllers in electric vehicles, are vulnerable to possible cyber/ physical manipulation due to known vulnerabilities inherited from CAN bus technology that is used for in-vehicle communications between electronic control units that transfer sensing and control data. In this paper, we first create a simulation that enables us to evaluate impact of cyber physical attacks on electric vehicle battery management system in a controlled environment that violates thermal safety. Specifically, we emulate a Level 3 - DC fast charging system with SAE J1772/CCS, integrated with standard charging controls and thermal safety controls on EVs, and various sensing data flows. Second, we propose a coordinated current and battery temperature attack that has crippling economic, and safety impacts. Third, we quantify the usability, economic and safety impacts of such attacks as a function of the extent of data manipulation. Finally, we propose a physics model driven detection technique to detect presence of such attacks.

25 ENERGY STORAGE

Securing the Modern Grid: Federal Investments, Digitization, and Supply Chain Strategy

Across the United States (U.S.) grid expansion and modernization is underway, paving the way for accelerated load growth and intelligent resource management. Digitization of the grid is supported by several state and federal programs, providing support for utilities installing advanced metering infrastructure (AMI), AI-powered analytics systems, battery energy storage systems (BESS), and distributed energy resource management systems (DERMS) to transform the grid from a one-way power delivery system into an intelligent, responsive network that will enable faster load growth and power expansion of data centers for advanced artificial intelligence (AI) applications. The digital transformation of America's grid presents opportunity for increased efficiency and resiliency but also introduces new digital risks that require careful management. Digital equipment often contains several vulnerabilities such as unencrypted communication protocols, and persistent remote access capabilities that could be exploited to manipulate device settings, coordinate service disruptions, or inject false data into grid operations. These digital risks become particularly important as the grid must rapidly scale to support AI-driven data centers, which the administration has identified as essential for maintaining U.S. technological leadership and economic competitiveness. These vulnerabilities are compounded by supply chain realities: Chinese manufacturers currently produce 70-90% of essential grid components including inverters, batteries, and control systems, with the U.S. lacking domestic manufacturing capacity for critical assets like extra-high voltage transformers. Recent federal legislation has established Foreign Entity of Concern (FEOC) restrictions to address these risks, requiring projects to achieve escalating thresholds of non-FEOC content to receive tax credits while utilities work to expand sourcing channels for their supply chains and strengthen security measures. These restrictions arrive precisely when utilities face unprecedented electricity demand growth driven by the rapid growth in data centers, creating a considerable challenge: rapidly expanding infrastructure while navigating complex compliance requirements while lacking viable alternatives for many critical components. Idaho National Laboratory (INL) and its partners have developed practical approaches to help utilities navigate these intersecting challenges as they leverage federal investment to strengthen and grow the grid. These solutions include Cyber-Informed Engineering (CIE) principles that build resilience directly into systems, the Cirrus tool for secure cloud migration, and enhanced procurement guidance that embeds security requirements throughout equipment lifecycles. Federal initiatives, such as the Technical Assistance for Digital Assurance (TADA) project, provide direct support to utilities implementing these approaches while facilitating knowledge sharing across the industry. While these tools and frameworks cannot eliminate all risks inherent in foreign supply chain dependencies, they offer pragmatic pathways for strengthening security posture without sacrificing the deployment momentum essential to meeting surging electricity demand. Ultimately, securing America's digital energy infrastructure demands dedicated coordination across multiple fronts: building domestic supply chains, implementing robust digital assurance practices, and maintaining the aggressive modernization timeline necessary for reliability, resilience, and energy independence.

24 POWER TRANSMISSION AND DISTRIBUTION

TASTI-GRID: Improving Electric Grid Resilience across the State of Tennessee

Residential, industrial, and large load data center facility expansion have exacerbated management backlogs. Additionally, as newer technologies emerge in larger utility providers, a chasm between urban and rural resilience grows – creating segmentation across the state. With new development, industries, and large load additions to the electric grid across the Volunteer state, utilities must contend with these new connections, management backlogs, and technology gaps – while addressing an increase in major outages with more frequent extreme weather events, such as Hurricane Helene in 2024. This issues, in turn, have given way to greater vulnerabilities in adjacent infrastructure – including transportation and emergency management services, among others.

24 POWER TRANSMISSION AND DISTRIBUTION

Towards automated and real-time multi-object detection of anguilliform fishes from sonar data using YOLOv8 deep learning algorithm

Eels (Anguilla spp.), including American eels (Anguilla rostrata), European eels (Anguilla anguilla), and Japanese eels (Anguilla japonica), are species of critical management and regulatory concern due to their vulnerability to various stressors during downstream migrations. Accurate and efficient detection of migrating eels can improve our understanding of fish behaviors and fish-hydraulic structure interactions, thereby facilitating the design, operation, and optimization of more effective downstream passage facilities from both biological and economic perspectives. However, a real-time, automated framework for detecting migrating eels in real-world applications is currently lacking. Leveraging imaging sonar as a reliable technology for fish passage monitoring, field data are acquired using imaging sonar and then converted to single sonar frames/images for subsequent analysis. In this study, a framework based on the You Only Look Once Version 8 (YOLOv8)-based convolutional neural network is proposed for multi-object detection of eels and non-eel fish using the sonar images after image subtraction and additional wavelet denoising. The results from both training and testing phases demonstrate that the framework's ability can successfully detect both eels and non-eel fish in preprocessed sonar images, achieving F1-scores and mAP@0.50 exceeding 0.84. Additionally, the incorporation of wavelet denoising during preprocessing slightly improve detection performance. Furthermore, the transferability of this framework from eel to lamprey detection is demonstrated to be feasible given the similar morphological characteristics of these two species. Overall, the proposed framework achieves accurate and efficient detection of migrating eels, providing reliable and real-time information that can help conserve vulnerable eel and eel-like populations.

Deep learning