Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “consequence prioritization”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

CCE Phase 1: Consequence Prioritization

Idaho National Laboratory (INL) developed the Consequence-driven Cyber-informed Engineering (CCE) methodology to provide public and private organizations with steps to work collaboratively and establish a working relationship to protect critical infrastructure and other national assets. This process is a considerable undertaking, iterative in nature, and—as time and resources allow—should become a part of a company’s culture. By focusing on the impact of potentially negative Events, CCE provides a better understanding of how and why adversaries can affect critical functions and services using cyber-enabled sabotage. This document describes Phase 1 of the CCE process.

99 GENERAL AND MISCELLANEOUS↗

CCE Phase 2: System-of-System Analysis

During Phase 1, Consequence Prioritization, the CCE Team identified High Consequence Events (HCEs) that can be accomplished through cyber means to impact critical functions, services, and processes. During Phase 2, System-of-Systems Analysis (SoS Analysis), the CCE Team will conduct a systematic review and analysis of information related to the equipment, systems, processes, operations, maintenance, testing, and procurement practices based on the HCEs identified in Phase 1.

99 GENERAL AND MISCELLANEOUS↗

The Science of Scientific Software Development and Use

Increasingly powerful and affordable computing has revolutionized scientific and scholarly discovery across a broad range of fields. Computing relies on software, which has been rapidly growing in scope, diversity, and complexity. At the same time, the methods, processes, and tools used to produce and utilize this essential software are often ad hoc, and the study and improvement of them is often done without the benefit of direct funding or prioritization. Consequently, concerns are growing about the productivity of the developers and users of scientific software, its sustainability, and the trustworthiness of the results that it produces. The US Department of Energy Office of Science (DOE-SC) is at the forefront of modern software-enabled scientific discovery across numerous areas of computational, experimental, and observational science, including major investments in national user facilities that support these activities. In December 2021, the DOE-SC Office of Advanced Scientific Computing Research (ASCR) convened a workshop on basic research needs for the Science of Scientific Software Development and Use (SSSDU). Through keynote presentations, lightning talks, and breakout groups, participants discussed the current practice of software development, maintenance, evolution, and use, and considered how the scientific method could be used to examine these practices and develop more evidence-based approaches to enhance the impact of software and computing on all areas of science. Workshop participants identified three priority research directions (PRDs) and three important crosscutting themes that center on the following overarching insight: software has become an essential part of modern science that impacts new discovery, policy, and technological development. To have full confidence in science delivered via software, we must improve the processes and tools that help us create and use it, and this enhancement requires a deep understanding of the diverse array of teams and individuals doing the work. The full workshop report will be available at https://doi.org/10.2172/1846009.

97 MATHEMATICS AND COMPUTING↗

Basic Research Needs in The Science of Scientific Software Development and Use: Investment in Software is Investment in Science

Increasingly powerful and affordable computing has revolutionized scientific and scholarly discovery across a broad range of fields. Computing relies on software, which has been rapidly growing in scope, diversity, and complexity. At the same time, the methods, processes, and tools used to produce and utilize this essential software are often ad hoc, and the study and improvement of them are often done without the benefit of direct funding or prioritization. Consequently, concerns are growing about the productivity of the developers and users of scientific software, its sustainability, and the trustworthiness of the results that it produces. Increased investment, especially in the characterization and improvement of how scientific software is developed and used, is important for sustaining and improving the impact of software as the scope and complexity of scientific efforts expand. Without this investment, we face the risk of diminishing returns on our software investments because the demands for increased functionality, usability, reliability, and more will not be sufficiently met. The US Department of Energy Office of Science (DOE/SC) is at the forefront of modern software-enabled scientific discovery across numerous areas of computational, experimental, and observational science, including major investments in national user facilities that support these activities. For many years, DOE/SC software investments have provided tremendous value to the scientific community. We want to continue and further improve the value of DOE/SC software efforts by using a scientific approach to understanding and improving how scientific software is developed and used. In December 2021, the DOE/SC Office of Advanced Scientific Computing Research (ASCR) convened a workshop on basic research needs for the Science of Scientific-Software Development and Use (SSSDU). Through keynote presentations, lightning talks, and breakout groups, which built on insights from 124 pre-workshop position papers, participants discussed the current practice of software development, maintenance, evolution, and use, and considered how the scientific method could be used to examine these practices and develop more evidence-based approaches to enhance the impact of software and computing on all areas of science. Workshop participants identified three priority research directions (PRDs) and three important crosscutting themes that center on the following overarching insight: Software has become an essential part of modern science, impacting discoveries, policy, and technological development. To maintain and improve confidence in science delivered via software, we must improve the processes and tools that help us create and use software, and this enhancement requires a deep understanding of the diverse array of teams and individuals doing the work.

97 MATHEMATICS AND COMPUTING↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction, A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

01 COAL, LIGNITE, AND PEAT↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Consequence-driven cyber-informed engineering and related systems and methods

Embodiments of the disclosure relate to a computer-implemented consequence-driven cyber-informed engineering tool for performing and reporting consequence-based prioritization, system-of-systems breakdown, consequence-based targeting, and mitigations and protections. Embodiments of a CCE tool may perform one or more steps of defining a target industrial control system (ICS), wherein the target ICS includes operational goals, critical functions, and critical services; determining one or more scored high consequence events (HCE) associated with the defined target ICS; prioritizing the scored HCEs according to an HCE severity index; and updating a dashboard with one or more representations of the prioritized HCEs, wherein the updated dashboard is associated with the CCE tool and presented at a display.

Assante, Michael↗

Consequence-Driven Cybersecurity for High-Power Electric Vehicle Charging Infrastructure

Cybersecurity of high-power charging infrastructure for electric vehicles (EVs) is critical to the safety, reliability, and consumer confidence in this publicly accessible technology. Cybersecurity vulnerabilities in high-power EV charging infrastructure may also present risks to broader transportation and energy-infrastructure systems. Here, this paper details a methodology used to analyze and prioritize high-consequence events that could result from cybersecurity sabotage to high-power charging infrastructure. The highest prioritized events are evaluated under laboratory conditions for the severity of impact and the complexity of cybersecurity manipulation. Mitigation solutions and strategies are presented to secure the vulnerabilities that potentially lead to high-consequence events. These mitigations can be immediately implemented by industry or executed during the design stage.

25 ENERGY STORAGE↗

Quantitative Risk Assessment for Fuel Cell Electric Bus Hydrogen Storage and Refueling Facility

It is necessary to understand the safety implications and risk mitigation options for fuel cell electric bus fleet deployment, especially for related facilities responsible for operations such as production, storage, compression, and dispensing of hydrogen for use by the buses. In this report, we present a quantitative risk assessment for a potential fuel cell electric bus fleet that was motivated by efforts to improve resilience at the Portland International Airport but can be applicable to a range of hydrogen case studies and use cases. We estimated risk for a facility that produces, stores, compresses, and dispenses hydrogen for the fleet of buses, with a focus on individual risk to people in terms of annual frequency of fatality. We considered the frequency of hydrogen leaks that could result in harmful physical outcomes like jet fires or explosions, and the consequences of those outcomes for people. We created customized fault trees to calculate the frequencies of different sizes of leaks and event sequence diagrams to calculate ignition probabilities for the various leak sizes. We also leveraged the HyRAM+ toolkit to use these inputs to calculate overall risk for the facility, which we separated into one section responsible for producing, storing, and compressing hydrogen, and one section responsible for dispensing the hydrogen to the buses. We found that the dispensing area seemed to have a higher risk than the production/storage/compression area of the facility, largely because of the inclusion of a component with a high leak frequency (the heat exchanger used to cool the hydrogen before entering the vehicle, to prevent overheating and expansion of hydrogen in the onboard tank). For the example production and refueling facility we evaluated and the data we used for the analysis, the leak frequency had a larger impact on the risk differences between the two sections on the facility, compared to the physical outcome consequence, which was slightly different due to the varying fuel conditions, but not substantially different. Actions can be taken to prevent these hazards (e.g., lowering leak frequencies in system components) or to mitigate the consequences if they do occur (e.g., installing barriers to protect people if ignition events occur). The choice of which actions to take depends not only on safety considerations but also on space, time, staffing, feasibility, and financial constraints. Therefore, the quantitative risk assessment approach can help understand relative risk contributions from different components, leak sizes, consequences, and human actions, to prioritize risk reduction strategies and balance these parameters. The outcomes of this report may be useful for a variety of stakeholders working in the hydrogen, transportation, vehicle, and aviation sector, including those responsible for aspects like facility design, operations, and regulations. There is not a single value of risk that determines whether a hypothetical system is “safe” or not. The insights about risk mitigations may be leveraged, and the quantitative risk assessment approach can be applied to other case studies to understand risk priorities and contributions specific to different FCEB and hydrogen facility uses.

08 HYDROGEN↗

Communications Reliability for Vehicle Grid Integration

Electric Vehicles (EVs) adoption rate has been steadily increasing in the US leading to a growing number of charging stations including faster DC (Direct Current) chargers and slower Level 1 and Level 2 AC (Alternating Current) chargers. This increase in demand for electricity is further exacerbated by recent developments in Artificial Intelligence (AI) technology, advanced manufacturing, and digitization. These factors will require electric utilities to upgrade their infrastructure to keep up with the increasing electrical demand (especially during peak hours). An easy way to counteract the need for these upgrades is to shift a major chunk of active charge sessions (durations where there is energy transfer from charger to EV's propulsion battery) to off-peak hours thereby flattening the load curve and making the infrastructure more resilient. This concept is known as Smart Charge Management (SCM). EV owners also benefit from SCM since it lowers their charging costs and consequently their transportation costs by prioritizing charging during off-peak hours. SCM takes advantage of EV's capability to act as a controllable load or DER (Distributed Energy Resource). This report summarizes the reliability analysis performed on the communication required for two of these SCM use-cases. This analysis only focuses on SCM strategies for unidirectional charging (energy transfer from EVSE to EV or V1G) and not bidirectional charging.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Informed Engineering Briefing for ABET

Cyber-Informed Engineering (CIE) is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system, energy or otherwise, to mitigate or even eliminate avenues for cyber-enabled attacks.?CIE concepts use design decisions and engineering controls to prioritize defense against the worst possible consequences of cyberattacks facing critical infrastructure systems and asset owners. These slides offer a deep dive into Cyber-Informed Engineering for engineering educators.

42 - ENGINEERING↗

Consequence Based Framework for Deployment of Cloud Solutions in the Digital Energy Transition

This study proposes a framework for evaluating cloud computing deployment in the electric sector, focusing on the digital transition of energy systems. It assesses the implications of cloud technology adoption, particularly in terms of security, operational resilience, and efficiency. The paper introduces a method for consequence-driven risk analysis, enabling utilities to prioritize and mitigate potential threats effectively. It also discusses the shared responsibility model in cloud computing, highlighting the need for collaborative security efforts. The research aims to provide utilities with a strategic assessment tool for cloud adoption, emphasizing the importance of security culture in enhancing cloud computing's role in critical infrastructure.

99 GENERAL AND MISCELLANEOUS↗

A Resilient Integrated Resource Planning Framework for Transmission Systems: Analysis and Optimization

This article presents a resilient Integrated Resource Planning (IRP) framework designed for transmission systems, with a specific focus on analyzing and optimizing responses to High-Impact Low-Probability (HILP) events. The framework aims to improve the resilience of transmission networks in the face of extreme events by prioritizing the assessment of events with significant consequences. Unlike traditional reliability-based planning methods that average the impact of various outage durations, this work adopts a metric based on the proximity of outage lines to generators to select HILP events. The system’s baseline resilience is evaluated by calculating load curtailment in different parts of the network resulting from HILP outage events. The transmission network is represented as an undirected graph. Graph-theoretic techniques are used to identify islands with or without generators, potentially forming segmented grids or microgrids. This article introduces Expected Load Curtailment (ELC) as a metric to quantify the system’s resilience. The framework allows for the re-evaluation of system resilience by integrating additional generating resources to achieve desired resilience levels. Optimization is performed in the re-evaluation stage to determine the optimal placement of distributed energy resources (DERs) for enhancing resilience, i.e., minimizing ELC. Case studies on the IEEE 24-bus system illustrate the effectiveness of the proposed framework. In the broader context, this resilient IRP framework aligns with energy sustainability goals by promoting robust and resilient transmission networks, as the optimal placement of DERs for resilience enhancement not only strengthens the system’s ability to withstand and recover from disruptions but also contributes to efficient resource utilization, advancing the overarching goal of energy sustainability.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Tool for the Risk-Informed Management of Critical Mission Resilience

We describe a methodology and tool for the risk-informed management and planning of mission resilience. By mapping concepts of resilience onto the elements of a streamlined risk model we are able to tap the substantial portfolio of established risk concepts to provide rapid insights in the evaluation and high-level screening of prospective resilience enhancement measures. This provides a risk-informed, levelized basis for the comparison of disparate resilience solutions and the means of establishing preferences. The methodology begins with identification of critical missions met by a site, and establishment of the supporting physical assets. Scenarios that would result in failure of these assets are systematically identified. Each scenario comprises three elements: realization of a hazard or threat resulting in loss of resources (the current focus being on power, natural gas, and water) to the asset, failure of measures in place to protect the asset against those losses, and realization of the consequent impacts. These scenarios are quantified in terms of their probabilities of occurrence and the magnitude of the resultant consequences (mission outage time), allowing risk-prioritization to focus resilience enhancement considerations. What-If? analyses are conducted through adjusting elements of the risk calculation to reflect the deployment of prospective resilience measures, by which means the efficacies of each of those measures can be compared using common risk metrics across diverse resilience strategies. This paper will also describe the insights from example applications.

resilience, risk, risk assesment, energy, water↗

FIC Consequence Profile - Hypothetical Cybercrime Syndicate Adversary Dossier

The FIC team has engaged PNNL’s Shamrock Cyber team to produce this Consequence Profile. This Consequence Profile is an Adversary Dossier, which provides the foundation for a thorough understanding of unacceptable mission outcomes, and the threats and vulnerabilities that make these outcomes plausible. The dossier helps stakeholders and development teams understand each other’s viewpoints. It also provides a means for reducing overall risk by prioritizing threats and vulnerabilities based on unacceptable outcomes. The Consequence Profile can be used as is, or as content to inform other reports tailored to a specific audience. It is intended to enable decision makers at all levels to improve the security posture of the system.

Beaman, Jacob E.↗