Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “security assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Revisiting Current Paradigms: Subject Matter Expert Views on High Consequence Facility Security Assessments

Security assessments support decision-makers' ability to evaluate current capabilities of high consequence facilities (HCF) to respond to possible attacks. However, increasing complexity of today's operational environment requires a critical review of traditional approaches to ensure that implemented assessments are providing relevant and timely insights into security of HCFs. Using interviews and focus groups with diverse subject matter experts (SMEs), this study evaluated the current state of security assessments and identified opportunities to achieve a more "ideal" state. The SME-based data underscored the value of a systems approach for understanding the impacts of changing operational designs and contexts (as well as cultural influences) on security to address methodological shortcomings of traditional assessment processes. These findings can be used to inform the development of new approaches to HCF security assessments that are able to more accurately reflect changing operational environments and effectively mitigate concerns arising from new adversary capabilities.

36 MATERIALS SCIENCE↗

Certification and prediction of post-disturbance states in dynamic security assessment

Dynamic security assessment usually involves the simulation of system dynamics under large disturbances. The instant large disturbance occurs, the post-disturbance state of the system could deviate significantly from the pre-disturbance one. It is desirable and necessary to develop an efficient method to certify the existence of state and predict the approximate post-disturbance state because: (1) faster warning can be made in online assessment; and (2) the dynamic simulator can be given better initial values to calculate precise solutions, which prevents convergence failure brought on by poor initial values. We propose a novel approach for efficiently certifying and predicting the post-disturbance states in dynamic security assessment. Based on the fixed-point power flow mapping approach applied to salient pole generator models, the criterion for determining the existence and uniqueness of the post-disturbance solution is derived, and the bounds of post-disturbance solution can be rigorously characterized.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Dynamic security assessment of systems powered only by grid-forming power plants with uncertain dispatch using polynomial vectors

A modern challenge in power engineering is to perform the dynamic security assessment (DSA) of grids that are 100% powered by inverter-based resources (IBRs). Addressing this challenge is difficult because: (i) the dispatch of IBRs can be uncertain as a result of the variability of renewable resources and (ii) they have hard current control limits that cannot be neglected, contrasting synchronous machines. To address this problem, this paper sets forth a framework to conduct DSA of bulk power systems that are 100% powered by grid-forming IBRs. Furthermore, the framework considers that IBR operational conditions are unknown but bounded by a zonotope which is also expressed as a polynomial vector for uncertainty propagation via Dormand–Prince integration. The framework is applied to modified versions of the WSCC 9-bus and IEEE 39-bus grids.

14 SOLAR ENERGY↗

Security assessment and impact analysis of cyberattacks in integrated T&D power systems

In this paper, we examine the impact of cyberattacks in an integrated transmission and distribution (T&D) power grid model with distributed energy resource (DER) integration. We adopt the OCTAVE Allegro methodology to identify critical system assets, enumerate potential threats, analyze and prioritize risks for threat scenarios. Based on the analysis, attack strategies and exploitation scenarios are identified which could lead to system compromise. Specifically, we investigate the impact of data integrity attacks in inverted-based solar PV controllers, control signal blocking attacks in protective switches and breakers, and coordinated monitoring and switching time-delay attacks. Index Terms—Cyberattacks, security assessment, impact analysis, case studies, integrated power systems.

14 SOLAR ENERGY↗

Security Assessment of an LBP16-Protocol-Based Computer Numerical Control Machine

Subtractive manufacturing systems, specifically, computer numerical control machines, have revolutionized the manufacturing industry. Computer numerical control machining is the preferred method for producing finished parts due to its efficiency, speed and suitability for high-volume production. Securing computer numerical control machines is a priority. Compromises or disruptions of these machines can result in significant downtime, loss of productivity and financial loss. This study examines the vulnerabilities and risks associated with computer numerical control machines, in particular, systems utilizing the LBP16 protocol for controller-machine communications. The study reveals that an adversary can execute cyber-physical attacks such as sabotage and denial of service. The potential security threats emphasize the importance of implementing robust security measures to mitigate the cyber risks to computer numerical control machines.

Forihat, Yahya [Virginia Commonwealth University, ↗

DOE CESER 6 GHz Interference Study

DOE CESER has sponsored Idaho National Laboratory (INL) to conduct an objective and independent study of potential 6 GHz interference from outdoor operation of unlicensed devices in the 6 GHz band on fixed service (FS) microwave communication links operated by electrical sector incumbents in that band. INL is collaborating with University of Notre Dame (UND), Electric Power Research Institute (EPRI), Lockard & White, Southern Company, and AT&T, to gather data with real-world 6 GHz interference experiments and identify (1) the potential for interference from unlicensed devices and (2) the interference necessary to cause harm to the incumbents. In addition to the functional assessment, a security assessment of the FCC mandated Automatic Frequency Coordination (AFC) System to regulate use of unlicensed 6 GHz standard power devices is also being conducted. A major objective is to create a science-based and defensible methodology used to produce the necessary data and to derive objective conclusions. This proven methodology can then be used to produce objective data and conclusions for other spectrum bands with similar incumbent uses including 4.4 – 4.9 GHz and 7.125 – 7.4 GHz, identified in the reconciliation bill that was adopted on July 4, 2025, as well as the National Spectrum Strategy discussions that are ongoing. This report contains 6 GHz field experiments and findings in the following real-world scenarios with commercial unlicensed standard power (SP) 6 GHz devices regulated by Automated Frequency Coordination (AFC): • University of Notre Dame (UND) Stadium with a capacity of 80,000 spectators, where Wi-Fi operating in 6 GHz has been deployed recently • Southern Company 6 GHz FS microwave link between Columbus and Fortson, Georgia Following are the following key findings from this study. 1. The AFC is under-protective of FS when line-of-sight exists along the path centerline. Data collected at Southern’s 6 GHz fixed link site shows significant erosion of as much as 21.4-24.4 dB of under-protection that can lead to potential service degradation under typical operating conditions. This first key finding is most likely the result of erroneous use of the RF propagation model. INL will collaborate with EPRI and the AFC Functional Requirements Working Group to submit a change request to the WinnForum TS-1014 standard towards correct use of the propagation model by the AFC. 2. There is additive interference effect of about 3 dB from nearly equal power interferers measured from simultaneous operation of two SP AP's operating co-channel with the FS receive from different locations along the path. This second key finding should be used to add the impact of additive interference of operation of multiple APs in the same geographical area, to the next generation of AFCs. INL will collaborate with FCC on the need for the AFC to consider additive interference. We also recommend that additional experiments are conducted on 6 GHz spectrum interference to further improve the AFC operation as the number of outdoor Wi-Fi devices continues to increase. These proposed steps and recommendations will make the co-existence of the incumbents and the 6 GHz outdoor Wi-Fi providers possible without any impact on the incumbents with a win-win outcome for all.

6 GHz↗

An Evaluation of The Dynamic Physical Security Risk Assessment Methodology for Fleet-Wide Applications

The requirements for U.S. nuclear power plants to maintain a large onsite physical security force contribute to their high operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability (LWRS) program’s physical security pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. The conservatisms built into current security postures may be analyzed and minimized to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within LWRS program’s physical security pathway has successfully developed a dynamic force-on-force modeling framework using various computer simulation tools and integrating them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This integrated process for physical security analysis is named Modeling and Analysis for Safety Security using Dynamic EMRALD Framework (MASS-DEF). This document provides an update on the progress in applying the MASS-DEF process to an operating commercial nuclear power plant as well as additional industry feedback regarding use of the tool for other physical security risk-informed topics. This report is only a summary of the progress and does not contain specific modeling results as those contain sensitive security information. Previous reports described how a user could integrate their plant-specific force-on-force models with the dynamic simulation tool EMRALD, model operator actions, and integrate with probabilistic risk assessment tools, such as CAFTA (Computer Aided Fault Tree Analysis System) or SAPHIRE (Systems Analysis Programs for Hands-on Integrated Reliability Evaluations), and with thermal-hydraulic tools, such as RELAP-5 or MAAP. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report is an update the progress of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. This report also provides an update to the procedural guidance for the MASS-DEF process and an overview of the generic models available for use by utilities. This report does not contain any plant’s sensitive information and/or safeguards information. This study’s purpose was to verify that the results achieved using generic models are similar to actual plant results and refine our guidance on the use of the framework. This assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Framework Using Applied Process Analysis Methods to Assess Water Security in the Vu Gia–Thu Bon River Basin, Vietnam

The Vu Gia–Thu Bon (VG–TB) river basin is facing numerous challenges to water security, particularly in light of the increasing impacts of climate change. These challenges, including salinity intrusion, shifts in rainfall patterns, and reduced water supply in downstream areas, are of great concern. This study comprehensively assessed the current state of water security in the basin using robust statistical analysis methods such as the Process Analysis Method (PAM), SMART principle, and Analytic Hierarchy Process (AHP). This resulted in the development of a comprehensive assessment framework for water security in the VG–TB river basin. This framework identified five key dimensions, with basin development activities (0.32), the ability to meet water needs (0.24), and natural disaster resilience (0.19) being the most crucial and water resource potential being the least crucial (0.11) according to the AHP methodology. The latter also highlighted 15 indicators, four of which are particularly influential, including waste resources (0.54), flood (0.53), water storage capacity (0.45), and basin governance (0.42). Furthermore, 28 variables with high weight factors were identified. This framework aligns with the UN-Water water security definition and addresses the global water sustainability criteria outlined in Sustainable Development Goal 6 (SDG6). It enables the computation of a comprehensive Water Security Index (WSI) for specific regions, providing a strong foundation for decision-making and policy formulation. It aims to enhance water security in the context of climate change and support sustainable basin development, thereby guiding future research and policy decisions in water resource management.

54 ENVIRONMENTAL SCIENCES↗

Assessment of Physical Security Modeling and Simulation in the Vulnerability Assessment Process

This report provides a comprehensive assessment of physical security modeling and simulation tools available for use in the vulnerability assessment (VA) process for nuclear facilities. It outlines the historical evolution of VA methodologies, emphasizing the transition from traditional layer-based approaches to a more holistic framework that integrates detection probabilities directly into combat simulations. The document details the critical components of the VA process, including the characterization of targets, threats, and protective measures, as well as the development of adversary scenarios that reflect both insider and outsider threats. It highlights the importance of performance assurance programs, emphasizing the need for continuous evaluation and testing of security systems to ensure their effectiveness against evolving threats. Additionally, the report discusses the significance of utilizing accredited modeling and simulation tools in accredited areas to accurately represent adversary actions and the corresponding responses of protective forces. By establishing a systematic approach to VA, this document aims to enhance the overall security posture of nuclear facilities, ensuring compliance with regulatory standards while effectively mitigating risks associated with potential adversarial actions.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Cyber Attack Sequences Generation for Electric Power Grid

Security assessment of cyber-physical energy systems (CPESs) such as the electric power grid is a critical operation to maintain availability, reliability, and quality of service in the presence of persistent threats from malicious cyber actors. Existing security assessment approaches such as penetration testing and red teaming rely on subject matter expert experience and forensic cyber analysis of historical events to perform realistic, threat-informed assessments of CPES defense. CPESs have a large attack surface because of the heterogeneity and complexity of underlying topology, devices, measurements, and vulnerabilities. The aforementioned approaches lead to partial coverage of the attack surface with a large set of unknown but possible exploits. There is a need to automate the CPES attack surface discovery and contextualize it for relevant, highly probable, real-world attack scenarios. We propose a methodology and framework to facilitate the discovery of the CPES attack surface. We present a multilayer attack graph with ranked attack sequences to describe CPES failure scenarios. We present a work-in-progress framework that lists key components to automate the attack modeling and sequence generation. We demonstrate the published National Electric Sector Cybersecurity Organization Resource CPES failure scenario to highlight the trustworthiness of generated attack sequences.

Dutta, Ashutosh↗

Contingency Analysis Based on Partitioned and Parallel Holomorphic Embedding

In the steady-state contingency analysis, the traditional Newton-Raphson method suffers from non-convergence issues when solving post-outage power flow problems, which hinders the integrity and accuracy of security assessment. In this paper, we propose a novel robust contingency analysis approach based on holomorphic embedding (HE). Here, the HE-based simulator provides theoretical convergence guarantee, which is desirable because it avoids the influence of numerical issues and provides a credible security assessment conclusion. In addition, based on the multi-area characteristics of real-world power systems, a partitioned HE (PHE) method is proposed with an interfacebased partitioning of HE formulation. The PHE method does not undermine the numerical robustness of HE and significantly reduces the computation burden in large-scale contingency analysis. The PHE method is further enhanced by parallel or distributed computation to become parallel PHE (P2HE). Tests on a 458-bus system, a synthetic 419-bus system and a large-scale 21447-bus system demonstrate the advantages of the proposed methods in robustness and efficiency.

42 ENGINEERING↗