Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “timing vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A time-varying vulnerability index for COVID-19 in New Mexico, USA using generalized propensity scores

The coronavirus disease (COVID-19) pandemic has highlighted systemic inequities in the United States and resulted in a larger burden of negative social outcomes for marginalized communities. New Mexico, a state in the southwestern US, has a unique population with a large racial minority population and a high rate of poverty that may make communities more vulnerable to negative social outcomes from COVID-19. To identify which communities may be at the highest relative risk, we created a county-level vulnerability index. After the first COVID-19 case was reported in New Mexico on March 11, 2020, we fit a generalized propensity score model that incorporates sociodemographic factors to predict county-level viral exposure and thus, the generic risk to negative social outcomes such as unemployment or mental health impacts. We used four static sociodemographic covariates important for the state of New Mexico—population, poverty, household size, and minority population—and weekly cumulative case counts to iteratively run our model each week and normalize the exposure score to create a time-varying vulnerability index. We found the relative vulnerability between counties varied in the first eight weeks from the initial COVID-19 case before stabilizing. This framework for creating a location-specific vulnerability index in response to an ongoing disaster may be used as a quick, deployable metric to inform health policy decisions such as allocating state resources to the county level.

59 BASIC BIOLOGICAL SCIENCES↗

NASA's Advanced solid rocket motor

The Advanced Solid Rocket Motor (ASRM) will not only bring increased safety, reliability and performance for the Space Shuttle Booster, it will enhance overall Shuttle safety by effectively eliminating 174 failure points in the Space Shuttle Main Engine throttling system and by reducing the exposure time to aborts due to main engine loss or shutdown. In some missions, the vulnerability time to Return-to-Launch Site aborts is halved. The ASRM uses case joints which will close or remain static under the effects of motor ignition and pressurization. The case itself is constructed of the weldable steel alloy HP 9-4-0.30, having very high strength and with superior fracture toughness and stress corrosion resistance. The internal insulation is strip-wound and is free of asbestos. The nozzle employs light weight ablative parts and is some 5,000 pounds lighter than the Shuttle motor used to date. The payload performance of the ASRM-powered Shuttle is 12,000 pounds higher than that provided by the present motor. This is of particular benefit for payloads delivered to higher inclinations and/or altitudes. The ASRM facility uses state-of-the-art manufacturing techniques, including continuous propellant mixing and direct casting.

Mitchell, Royce E.↗

Numerical Study of Solidification Crack Susceptibility in Novel Refractory Alloy Systems

Calculation of Phase Diagrams (CALPHAD) -based solidification computa­tions, such as Scheil or equilibrium computations, have been utilized to propose crack solidification susceptibility indices (CSSIs) of cracking. These CSSIs have been proposed in order to predict the cracking susceptibility of an alloy in the solidification range, as a function of its solidification frac­tion and as dependent upon its wt.% elemental composition through the CALPHAD computation & via comparative methods between one composition & the next. Recently Kou at al. have proposed a novel CSSI where the gradient of the e.x. Scheil solidification curve is obtained in the critical solidification cracking region of greater than 0.95 fraction of solid. Therefore, a direct Temperature dependent metric is now available for the prediction, and presumably the control, of solidification cracking. In this TM, the researchers apply this Kou gradient method to refractory alloys for the first time & discuss justification for the approach via Spearman rank correlation with Varestraint cracking test data as well as by comparisons with Thermocalc based vulnerability time CSSI calculations. A Python Pycalphad module example of the approach is provided & can be utilized as an open-source resource that utilizes also open-source available thermodynamical databases, making the CSSI quantitative aspect of ICME more available and freely available to practitioners.

ICME integrated computational materials engineerin↗

Mitigating Extremist Maritime Threats to Radiological Material Transport Vessels

The 21st century has experienced a rise in the threat of global radicalism and extremist organizations, and there has been oft-reported interest from these groups in obtaining or exploiting radiological materials. The threat of extremists acquiring radiological materials while in transit or sabotaging a transport vessel carrying materials at sea is one that requires increased attention. Transport is already one of the most vulnerable times for any cargo but including the difficulties in securing a large ship on the open ocean makes oceanic transport of radiological materials a space of elevated vulnerability for sabotage, theft, or other attacks. The risks of violent extremist attacks on trade ships and trading routes are serious, as shipping routes sustain the global economy, but an attack on a radiological transport vessel could be a magnitude worse, impacting national and international security. While radicalists have largely remained on land in the past due to minimal maritime expertise or inability to project power out of their immediate vicinity, the world has witnessed past attacks on ships such as the USS Cole and the MV Limburg and it is likely only a matter of time before groups extend further into the sea and engage in more maritime campaigns against material transport vessels. This paper suggests methods for increasing safety and security on oceanic transport voyages through behavioral science principles and insider threat recognition training, as well as a better understanding of adversarial and extremist psychology. By providing transport personnel with the knowledge and support to identify and respond to unique maritime threats by extremists, these principles and training suggestions should advance and increase security on the high seas.

Kinney, Justin↗

Cybersecurity Anomaly Detection in SCADA-Assisted OT Networks Using Ensemble-Based State Prediction Model

The cybersecurity threats of power system gradually grow due to the increased sophisticated interactions between Information Technology (IT) and Operational Technology (OT) networks. False data injection attack (FDIA) that aims to compromise the Supervisory Control and Data Acquisition (SCADA) measurement and disturb the system operation is one of such cyber threats. Such attacks can potentially lead to significant operational issues at the control centers and substations, and hence, result in severe physical consequences. To avoid catastrophic failure across the power grid resulting from these attacks, it is essential to arm the OT network with real-time vulnerability assessment tools. To this end, this paper outlines various drawbacks of the Purdue architecture model to defend against cyberattacks in the OT network. Furthermore, a novel ensemble-based state prediction model is proposed to detect cybersecurity anomalies in SCADA assisted OT networks. The proposed model uses control center level generation and load forecasts, scheduled, and forced outages, power flow solutions, and the substation level historical data. The hypothesis of the proposed scheme relies on the fact that additional control center and substation data can hardly be accessed and compromised by attackers. One of the vital features of the proposed scheme is an hour-ahead prediction of the operational feasibility of the SCADA measurement range at the control center and substation in real time helps in detecting anomalies in measurements across both substation and the control center.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Using Artificial Soiling to Rank Anti-Soiling Coatings for Arid Climates

A simple method to evaluate (e.g., screen and rank) the performance of coatings that are fully or partially anti-soiling (AS) is lacking within the PV industry. Artificial soiling may be used as a rapid and economical assessment approach, offering an efficient alternative to time-intensive, site-specific field testing. In this study, we present an artificial soiling method to replicate the anti-soiling performance rankings of two groups of coated glass samples supplied by two manufacturers (group C with CA, CP, and CS coatings; group A with AC coating). These are compared to field aging in two climates: semi-arid Lemoore, California over 4 months, and the hot desert in Mesa, Arizona over 7 months. Both field and indoor performance ranking utilize the transmittance ratio, defined as the optical transmittance between a coated sample and an uncoated reference in each group, as an evaluation metric to assess the effectiveness of the artificial soiling approach in replicating field soiling. It is critical to mimic the dominant field meteorological conditions associated with soiling-prone days and vulnerable times of day during the soiling season. Our results reveal that the use of artificial soiling for field performance ranking among coatings strongly depends on the soil type (composition and particle distribution), dust surface density, and prevalent environmental factors (wetting saturation by humidity, dew condensation extent, and prior weathering history of the coating). The similar rank order relative to the field suggests that the artificial soiling approach presented may be used for down-selecting anti-soiling coatings prior to prolonged field validation.

14 SOLAR ENERGY↗

The Impact of Radio Frequency Interference (RFI) on VLBI2010

A significant motivation for the development of a next generation system for geodetic VLBI was to address growing problems related to RFI. In this regard, the broadband 2-14 GHz frequency range proposed for VLBI2010 has advantages and disadvantages. It has the advantage of flexible allocation of band frequencies and hence the ability to avoid areas of the spectrum where RFI is worst. However, the receiver is at the same time vulnerable to saturation from RFI anywhere in the full 2-14 GHz range. The impacts of RFI on the VLBI2010 analog signal path, the sampler, and the digital signal processing are discussed. In addition, a number of specific RFI examples in the 2-14 GHz range are presented.

Petrachenko, William↗

Hardware Aware Mitigation of Timing Side-Channel Vulnerabilities in Critical Infrastructure Software

Program runtime/timing attacks exploit variations in a program’s execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime sidechannel attacks attempt to balance the execution time of the sensitive code for different control flow paths to eliminate the timing leakage. However, during the mitigation process, most techniques do not consider the underlying hardware/device on which the target program is supposed to run on. This can lead to over-fixing (unnecessary extra operations), under-fixing (not solving the imbalance properly), and even failures. We propose DISARM, a joint hardware-software methodology (unlike any existing solution) for mitigating runtime side-channel vulnerabilities that utilizes timing values from real embedded devices to generate targeted software fixes. We implement DISARM to support C/C++/Java source codes and validate it across 22 standard benchmarks. DISARM outperforms state-of-the-art solutions such as PENDULUM and DifFuzzAR in terms of execution time overhead (up to −46%), code size overhead (up to −10%), and correctness (no failures) on five different embedded/edge devices.

Suha, Tasneem [University of Maine]↗

Security Enhancements for Distributed Energy Resource Systems Interconnected with Distribution Networks: Final Technical Report

The revised IEEE 1547 Standard defines new complex communication-adjustable voltage and frequency regulation and ride-through characteristics, while maintaining the general antiislanding requirement for unintentional islanding situations. Unintentional islanding is prohibited while intentional islanding is specifically allowed, thus effectively enabling microgrid operation mode. Further, IEEE 1547-2018 Standard introduces new requirements in terms of interoperability so that the DER plant/circuit segments may be seamlessly integrated with the utility networks but at the same time become vulnerable to a cyber-attack. Traditional cybersecurity measures including encryption, authentication and role-based access control may not be fully implementable to all communication protocols specified in the IEEE 1547 Standard. Therefore, in this project we have identified, researched, implemented and tested several cyberphysical approaches that rely mostly on the behavior of the DER circuit and may help with validating the incoming command and control action potentially coming through an insecure communications channel. Additionally, we have built semantic models and communications profiles for DER facilities and have implemented lightweight IEC 61850 based publisher-subscriber GOOSE messaging mechanism, with security extensions in terms of authentication and encryption. The project proposed information models for integration into UCA OpenFMB 2.0 profiles focusing on grid code compliance.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Shield to Pin Coupling of Lightning-Like Transients on Payload Umbilical Cables on a Launch Pad

In this paper we describe in-situ testing of a long payload umbilical, on a launch site, injected with “lightning- like” transients and describe resulting pin-to-pin voltages. Injections and voltage measurements near the ground support equipment room, as well as at a location near the payload junction box, are made. The umbilical cables tested include an outer over-braid and the inner conductor coupling is examined for open circuit, short-circuit and various loads representative of spacecraft input impedances. This testing is important because the Kennedy Space Center (KSC) where the lightning occurrence is the highest in the United States, is the primary launch site for Launch Services Program spacecraft customers. Lightning planning is essential but developing a lightning plan is often overlooked or not adequately analyzed leaving the spacecraft vulnerable to time delays or even damage when lightning occurs. At other popular launch sites like Vandenberg Air Force Base (VAFB) where lightning occurs less often, although at the same or greater intensity when it does occur, lightning planning is often completely ignored by the spacecraft. The two major questions to be addressed in the lightning plan are what retesting should be done to establish a “goodness” level and what is the trigger criteria for this testing? The spacecraft will typically use a standard spacecraft check-out procedure to address the necessary retesting, but determining the trigger criteria is often an issue. For instance, a spacecraft needs to understand what their immunity is to a certain lightning magnitude and location. Determining the amount of current that can be coupled onto a spacecraft umbilical can be calculated by using worst case assumptions or measured with current probes and current measurement devices. Spacecraft can also determine what pin-to-pin voltages they are sensitive to, however pin-to-pin voltage measurements are not typically taken during the strike due to the invasive nature of this measurement. In this paper, we present detailed data on the shield to pin voltage transfer functions to provide insight to the spacecraft developers for lightning retest criteria planning. The results from this unique testing opportunity provide essential details on specific coupling mechanisms affecting spacecraft hardware that interfaces with the ground support equipment. This missing link between cable shield currents and payload susceptibility voltages has been methodically tested and representative data presented.

Trout, Dawn↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

NASA's Research in Aircraft Vulnerability Mitigation

Since its inception in 1958, the National Aeronautics and Space Administration s (NASA) role in civil aeronautics has been to develop high-risk, high-payoff technologies to meet critical national aviation challenges. Following the events of Sept. 11, 2001, NASA recognized that it now shared the responsibility for improving homeland security. The NASA Strategic Plan was modified to include requirements to enable a more secure air transportation system by investing in technologies and collaborating with other agencies, industry, and academia. NASA is conducting research to develop and advance innovative and commercially viable technologies that will reduce the vulnerability of aircraft to threats or hostile actions, and identify and inform users of potential vulnerabilities in a timely manner. Presented in this paper are research plans and preliminary status for mitigating the effects of damage due to direct attacks on civil transport aircraft. The NASA approach to mitigation includes: preventing loss of an aircraft due to a hit from man-portable air defense systems; developing fuel system technologies that prevent or minimize in-flight vulnerability to small arms or other projectiles; providing protection from electromagnetic energy attacks by detecting directed energy threats to aircraft and on/off-board systems; and minimizing the damage due to high-energy attacks (explosions and fire) by developing advanced lightweight, damage-resistant composites and structural concepts. An approach to preventing aircraft from being used as weapons of mass destruction will also be discussed.

Allen, Cheryl L.↗

Big Cypress Water Resources: Using Earth Observations to Assess Water Quality in Big Cypress Reservation, FL

Upstream agricultural development and runoff are driving harmful algal blooms in the Big Cypress Reservation. The Seminole Tribe of Florida Environmental Resource Management Department monitors water quality in the Big Cypress Reservation, located on the north end of Big Cypress National Preserve. The Environmental Resource Management Department aims to incorporate Earth observations into its investigative approach, which consists of Geographic Information Systems and in situ water sampling. We assessed the feasibility of using Earth observations to measure harmful algal blooms over time and identify vulnerable areas. We analyzed data from multiple remote sensing platforms and sensors, including Landsat 8 Thermal Infrared Spectrometer(TIRS), Landsat 9 TIRS-2, Landsat 9 Operational Land Imager 2, Sentinel-2 MultiSpectral Instrument, and Sentinel-3 Ocean and Land Color Instrument. We determined that it was challenging to use Sentinel-3, Landsat 8, and Landsat 9 imagery for monitoring the canals within the Reservation, and that Sentinel-2 was the most capable platform for the study area. Using Sentinel-2, we created spectral indices for the detection of algal blooms. We used these indices to measure algal blooms at 8 stations across the Big Cypress Reservation. We then created time series and seasonal decompositions of in situ water sample data and indices to visualize relationships between datasets, along with correlation matrices. Our correlations were not conclusive. However, we found that the spectral indices have the potential to detect algal blooms. Lastly, we evaluated Maxar WorldView-3 imagery and found that using data from sensors with higher spatial resolutions would improve results.

Remote sensing↗

Peak radial growth of diffuse-porous species occurs during periods of lower water availability than for ring-porous and coniferous trees

Climate models project warmer summer temperatures will increase the frequency and heat severity of droughts in temperate forests of Eastern North America. Hotter droughts are increasingly documented to affect tree growth and forest dynamics, with critical impacts on tree mortality, carbon sequestration and timber provision. The growing acknowledgement of the dominant role of drought timing on tree vulnerability to water deficit raises the issue of our limited understanding of radial growth phenology for most temperate tree species. Here, we use well-replicated dendrometer band data sampled frequently during the growing season to assess the growth phenology of 610 trees from 15 temperate species over 6 years. Patterns of diameter growth follow a typical logistic shape, with growth rates reaching a maximum in June, and then decreasing until process termination. On average, we find that diffuse-porous species take 16–18 days less than other wood-structure types to put on 50% of their annual diameter growth. However, their peak growth rate occurs almost a full month later than ring-porous and conifer species (ca. 24 ± 4 days; mean ± 95% credible interval). Unlike other species, the growth phenology of diffuse-porous species in our dataset is highly correlated with their spring foliar phenology. We also find that the later window of growth in diffuse-porous species, coinciding with peak evapotranspiration and lower water availability, exposes them to a higher water deficit of 88 ± 19 mm (mean ± SE) during their peak growth than ring-porous and coniferous species (15 ± 35 mm and 30 ± 30 mm, respectively). Given the high climatic sensitivity of wood formation, our findings highlight the importance of wood porosity as one predictor of species climatic sensitivity to the projected intensification of the drought regime in the coming decades.

59 BASIC BIOLOGICAL SCIENCES↗

Security Vulnerability and Mitigation in Photovoltaic Systems

Software and firmware vulnerabilities pose security threats to photovoltaic (PV) systems. When patches are not available or cannot be timely applied to fix vulnerabilities, it is important to mitigate vulnerabilities such that they cannot be exploited by attackers or their impacts will be limited when exploited. However, the vulnerability mitigation problem for PV systems has received little attention. This paper analyzes known security vulnerabilities in PV systems, proposes a multi-level mitigation framework and various mitigation strategies including neural network-based attack detection inside inverters, and develops a prototype system as a proof-of-concept for building vulnerability mitigation into PV system design.

14 SOLAR ENERGY↗

Evaluating cyber-risk in synchrophasor systems

Technology related to evaluating cyber-risk for synchrophasor systems is disclosed. In one example of the disclosed technology, a method includes generating an event tree model of a timing-attack on a synchrophasor system architecture. The event tree model can be based on locations and types of timing-attacks, an attack likelihood, vulnerabilities and detectability along a scenario path, and consequences of the timing-attack. A cyber-risk score of the synchrophasor system architecture can be determined using the event tree model. The synchrophasor system architecture can be adapted in response to the cyber-risk score.

Pal, Seemita↗

Tempus Project (Final Report)

This final technical report tracks the accomplishments of the Tempus Project to the statement of project objectives and resulting deliverables. The objective of the Tempus project was to develop and demonstrate the capabilities of a secure, modular, and customizable time synchronization platform that provides layers of protection from GPS spoofing attacks and other vulnerabilities. These vulnerabilities present a challenge to power system operators utilizing GPS-based time synchronization, as time synchronization increasingly plays a critical role in the efficient and reliable operation of power systems. The Tempus project addressed these concerns through the development of a secure, customizable time synchronization platform. The Tempus platform applies a layered approach to time security that protects from manipulation of timing systems used by power utilities. The Tempus platform consists of a component framework utilizing modularized time sources and customizable manipulation detection algorithms. With multiple time sources, and comparisons between sources and tracking sudden or subtle changes to the timing phase and time information, the Tempus system can detect and mitigate compromised timing sources.

24 POWER TRANSMISSION AND DISTRIBUTION↗