Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “timing vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A time-varying vulnerability index for COVID-19 in New Mexico, USA using generalized propensity scores

The coronavirus disease (COVID-19) pandemic has highlighted systemic inequities in the United States and resulted in a larger burden of negative social outcomes for marginalized communities. New Mexico, a state in the southwestern US, has a unique population with a large racial minority population and a high rate of poverty that may make communities more vulnerable to negative social outcomes from COVID-19. To identify which communities may be at the highest relative risk, we created a county-level vulnerability index. After the first COVID-19 case was reported in New Mexico on March 11, 2020, we fit a generalized propensity score model that incorporates sociodemographic factors to predict county-level viral exposure and thus, the generic risk to negative social outcomes such as unemployment or mental health impacts. We used four static sociodemographic covariates important for the state of New Mexico—population, poverty, household size, and minority population—and weekly cumulative case counts to iteratively run our model each week and normalize the exposure score to create a time-varying vulnerability index. We found the relative vulnerability between counties varied in the first eight weeks from the initial COVID-19 case before stabilizing. This framework for creating a location-specific vulnerability index in response to an ongoing disaster may be used as a quick, deployable metric to inform health policy decisions such as allocating state resources to the county level.

59 BASIC BIOLOGICAL SCIENCES↗

Mitigating Extremist Maritime Threats to Radiological Material Transport Vessels

The 21st century has experienced a rise in the threat of global radicalism and extremist organizations, and there has been oft-reported interest from these groups in obtaining or exploiting radiological materials. The threat of extremists acquiring radiological materials while in transit or sabotaging a transport vessel carrying materials at sea is one that requires increased attention. Transport is already one of the most vulnerable times for any cargo but including the difficulties in securing a large ship on the open ocean makes oceanic transport of radiological materials a space of elevated vulnerability for sabotage, theft, or other attacks. The risks of violent extremist attacks on trade ships and trading routes are serious, as shipping routes sustain the global economy, but an attack on a radiological transport vessel could be a magnitude worse, impacting national and international security. While radicalists have largely remained on land in the past due to minimal maritime expertise or inability to project power out of their immediate vicinity, the world has witnessed past attacks on ships such as the USS Cole and the MV Limburg and it is likely only a matter of time before groups extend further into the sea and engage in more maritime campaigns against material transport vessels. This paper suggests methods for increasing safety and security on oceanic transport voyages through behavioral science principles and insider threat recognition training, as well as a better understanding of adversarial and extremist psychology. By providing transport personnel with the knowledge and support to identify and respond to unique maritime threats by extremists, these principles and training suggestions should advance and increase security on the high seas.

Kinney, Justin↗

Cybersecurity Anomaly Detection in SCADA-Assisted OT Networks Using Ensemble-Based State Prediction Model

The cybersecurity threats of power system gradually grow due to the increased sophisticated interactions between Information Technology (IT) and Operational Technology (OT) networks. False data injection attack (FDIA) that aims to compromise the Supervisory Control and Data Acquisition (SCADA) measurement and disturb the system operation is one of such cyber threats. Such attacks can potentially lead to significant operational issues at the control centers and substations, and hence, result in severe physical consequences. To avoid catastrophic failure across the power grid resulting from these attacks, it is essential to arm the OT network with real-time vulnerability assessment tools. To this end, this paper outlines various drawbacks of the Purdue architecture model to defend against cyberattacks in the OT network. Furthermore, a novel ensemble-based state prediction model is proposed to detect cybersecurity anomalies in SCADA assisted OT networks. The proposed model uses control center level generation and load forecasts, scheduled, and forced outages, power flow solutions, and the substation level historical data. The hypothesis of the proposed scheme relies on the fact that additional control center and substation data can hardly be accessed and compromised by attackers. One of the vital features of the proposed scheme is an hour-ahead prediction of the operational feasibility of the SCADA measurement range at the control center and substation in real time helps in detecting anomalies in measurements across both substation and the control center.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Using Artificial Soiling to Rank Anti-Soiling Coatings for Arid Climates

A simple method to evaluate (e.g., screen and rank) the performance of coatings that are fully or partially anti-soiling (AS) is lacking within the PV industry. Artificial soiling may be used as a rapid and economical assessment approach, offering an efficient alternative to time-intensive, site-specific field testing. In this study, we present an artificial soiling method to replicate the anti-soiling performance rankings of two groups of coated glass samples supplied by two manufacturers (group C with CA, CP, and CS coatings; group A with AC coating). These are compared to field aging in two climates: semi-arid Lemoore, California over 4 months, and the hot desert in Mesa, Arizona over 7 months. Both field and indoor performance ranking utilize the transmittance ratio, defined as the optical transmittance between a coated sample and an uncoated reference in each group, as an evaluation metric to assess the effectiveness of the artificial soiling approach in replicating field soiling. It is critical to mimic the dominant field meteorological conditions associated with soiling-prone days and vulnerable times of day during the soiling season. Our results reveal that the use of artificial soiling for field performance ranking among coatings strongly depends on the soil type (composition and particle distribution), dust surface density, and prevalent environmental factors (wetting saturation by humidity, dew condensation extent, and prior weathering history of the coating). The similar rank order relative to the field suggests that the artificial soiling approach presented may be used for down-selecting anti-soiling coatings prior to prolonged field validation.

14 SOLAR ENERGY↗

Hardware Aware Mitigation of Timing Side-Channel Vulnerabilities in Critical Infrastructure Software

Program runtime/timing attacks exploit variations in a program’s execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime sidechannel attacks attempt to balance the execution time of the sensitive code for different control flow paths to eliminate the timing leakage. However, during the mitigation process, most techniques do not consider the underlying hardware/device on which the target program is supposed to run on. This can lead to over-fixing (unnecessary extra operations), under-fixing (not solving the imbalance properly), and even failures. We propose DISARM, a joint hardware-software methodology (unlike any existing solution) for mitigating runtime side-channel vulnerabilities that utilizes timing values from real embedded devices to generate targeted software fixes. We implement DISARM to support C/C++/Java source codes and validate it across 22 standard benchmarks. DISARM outperforms state-of-the-art solutions such as PENDULUM and DifFuzzAR in terms of execution time overhead (up to −46%), code size overhead (up to −10%), and correctness (no failures) on five different embedded/edge devices.

Suha, Tasneem [University of Maine]↗

Security Enhancements for Distributed Energy Resource Systems Interconnected with Distribution Networks: Final Technical Report

The revised IEEE 1547 Standard defines new complex communication-adjustable voltage and frequency regulation and ride-through characteristics, while maintaining the general antiislanding requirement for unintentional islanding situations. Unintentional islanding is prohibited while intentional islanding is specifically allowed, thus effectively enabling microgrid operation mode. Further, IEEE 1547-2018 Standard introduces new requirements in terms of interoperability so that the DER plant/circuit segments may be seamlessly integrated with the utility networks but at the same time become vulnerable to a cyber-attack. Traditional cybersecurity measures including encryption, authentication and role-based access control may not be fully implementable to all communication protocols specified in the IEEE 1547 Standard. Therefore, in this project we have identified, researched, implemented and tested several cyberphysical approaches that rely mostly on the behavior of the DER circuit and may help with validating the incoming command and control action potentially coming through an insecure communications channel. Additionally, we have built semantic models and communications profiles for DER facilities and have implemented lightweight IEC 61850 based publisher-subscriber GOOSE messaging mechanism, with security extensions in terms of authentication and encryption. The project proposed information models for integration into UCA OpenFMB 2.0 profiles focusing on grid code compliance.

24 POWER TRANSMISSION AND DISTRIBUTION↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Peak radial growth of diffuse-porous species occurs during periods of lower water availability than for ring-porous and coniferous trees

Climate models project warmer summer temperatures will increase the frequency and heat severity of droughts in temperate forests of Eastern North America. Hotter droughts are increasingly documented to affect tree growth and forest dynamics, with critical impacts on tree mortality, carbon sequestration and timber provision. The growing acknowledgement of the dominant role of drought timing on tree vulnerability to water deficit raises the issue of our limited understanding of radial growth phenology for most temperate tree species. Here, we use well-replicated dendrometer band data sampled frequently during the growing season to assess the growth phenology of 610 trees from 15 temperate species over 6 years. Patterns of diameter growth follow a typical logistic shape, with growth rates reaching a maximum in June, and then decreasing until process termination. On average, we find that diffuse-porous species take 16–18 days less than other wood-structure types to put on 50% of their annual diameter growth. However, their peak growth rate occurs almost a full month later than ring-porous and conifer species (ca. 24 ± 4 days; mean ± 95% credible interval). Unlike other species, the growth phenology of diffuse-porous species in our dataset is highly correlated with their spring foliar phenology. We also find that the later window of growth in diffuse-porous species, coinciding with peak evapotranspiration and lower water availability, exposes them to a higher water deficit of 88 ± 19 mm (mean ± SE) during their peak growth than ring-porous and coniferous species (15 ± 35 mm and 30 ± 30 mm, respectively). Given the high climatic sensitivity of wood formation, our findings highlight the importance of wood porosity as one predictor of species climatic sensitivity to the projected intensification of the drought regime in the coming decades.

59 BASIC BIOLOGICAL SCIENCES↗

Challenges in Firmware Re-Hosting, Emulation, and Analysis

System emulation and firmware re-hosting have become popular techniques to answer various security and performance related questions, such as determining whether a firmware contain security vulnerabilities or meet timing requirements when run on a specific hardware platform. While this motivation for emulation and binary analysis has previously been explored and reported, starting to either work or research in the field is difficult. To this end, we provide a comprehensive guide for the practitioner or system emulation researcher. Here, we layout common challenges faced during firmware re-hosting, explaining successive steps and surveying common tools used to overcome these challenges. We provide classification techniques on five different axes, including emulator methods, system type, fidelity, emulator purpose, and control. These classifications and comparison criteria enable the practitioner to determine the appropriate tool for emulation. We use our classifications to categorize popular works in the field and present 28 common challenges faced when creating, emulating, and analyzing a system from obtaining firmwares to post emulation analysis.

97 MATHEMATICS AND COMPUTING↗

Security Vulnerability and Mitigation in Photovoltaic Systems

Software and firmware vulnerabilities pose security threats to photovoltaic (PV) systems. When patches are not available or cannot be timely applied to fix vulnerabilities, it is important to mitigate vulnerabilities such that they cannot be exploited by attackers or their impacts will be limited when exploited. However, the vulnerability mitigation problem for PV systems has received little attention. This paper analyzes known security vulnerabilities in PV systems, proposes a multi-level mitigation framework and various mitigation strategies including neural network-based attack detection inside inverters, and develops a prototype system as a proof-of-concept for building vulnerability mitigation into PV system design.

14 SOLAR ENERGY↗

Evaluating cyber-risk in synchrophasor systems

Technology related to evaluating cyber-risk for synchrophasor systems is disclosed. In one example of the disclosed technology, a method includes generating an event tree model of a timing-attack on a synchrophasor system architecture. The event tree model can be based on locations and types of timing-attacks, an attack likelihood, vulnerabilities and detectability along a scenario path, and consequences of the timing-attack. A cyber-risk score of the synchrophasor system architecture can be determined using the event tree model. The synchrophasor system architecture can be adapted in response to the cyber-risk score.

Pal, Seemita↗

Tempus Project (Final Report)

This final technical report tracks the accomplishments of the Tempus Project to the statement of project objectives and resulting deliverables. The objective of the Tempus project was to develop and demonstrate the capabilities of a secure, modular, and customizable time synchronization platform that provides layers of protection from GPS spoofing attacks and other vulnerabilities. These vulnerabilities present a challenge to power system operators utilizing GPS-based time synchronization, as time synchronization increasingly plays a critical role in the efficient and reliable operation of power systems. The Tempus project addressed these concerns through the development of a secure, customizable time synchronization platform. The Tempus platform applies a layered approach to time security that protects from manipulation of timing systems used by power utilities. The Tempus platform consists of a component framework utilizing modularized time sources and customizable manipulation detection algorithms. With multiple time sources, and comparisons between sources and tracking sudden or subtle changes to the timing phase and time information, the Tempus system can detect and mitigate compromised timing sources.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Center for Alternative Synchronization and Timing (CAST) Technical Bulletin #007: Holdover Experiment #1

Stable and accurate timing forms the foundation of many modern essential services. While Global Navigation Satellite Systems (GNSS) provide a cheap way to achieve extremely accurate timing, these systems are vulnerable to interference and complete outages, forcing systems that rely on them into a state of holdover. Testing and characterizing holdover performance is therefore essential for ensuring that these modern services do not go down when GNSS-based timing is unavailable.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Center for Alternative Synchronization and Timing (CAST) Technical Bulletin #006: Holdover Experimental Summary

Stable and accurate timing forms the foundation of many modern essential services. While Global Navigation Satellite Systems (GNSS) provide a cheap way to achieve extremely accurate timing, these systems are vulnerable to interference and complete outages, forcing systems that rely on them into a state of holdover. Testing and characterizing holdover performance is therefore essential for ensuring that these modern services do not go down when GNSS-based timing is unavailable.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Effect of thermal aging on corrosion behavior of duplex stainless steels

Abstract Despite their exceptional mechanical and corrosion properties, duplex stainless steels (DSS) have not found widespread use in high-temperature applications due to concerns over thermal aging and embrittlement at elevated operational temperatures (> 300 °C). The present study investigated the effect of thermal aging time on the electrochemical properties of lean and standard grade DSS that are exposed to a range of pressurized water reactors containing LiOH and H 3 BO 3 . The results indicated that the electrolyte chemistry plays a significant role in the corrosion behavior of the DSS alloys. Corrosion resistance decreased with thermal aging time for all DSS alloys; however, standard grade DSS (2205 and 2209-w) alloys showed better corrosion resistance than lean grades (2003, 2101, 2101-w). The presence of dissolved oxygen in the electrolytes resulted in a significant increase in corrosion rate for the DSS alloys, but it did not affect the general trend of corrosion rates with aging time. All DSS alloys became vulnerable to pitting corrosion due to chloride addition, but the pitting resistance decreased with increasing thermal aging time. Increased boron B content resulted in degradation of corrosion resistance of the DSS alloys, while minor changes in pH did not show a significant change in corrosion resistance. Mechanical and metallurgical characterization coupled with electrochemical characterization of the DSS alloys gave a comprehensive insight into the effects of thermal aging on the electrochemical response of the DSS. Graphical abstract

Murkute, Pratik (ORCID:0000000278636346)↗

Nomogram for Predicting Postoperative Portal Venous Systemic Thrombosis in Patients with Cirrhosis Undergoing Splenectomy and Esophagogastric Devascularization

Objectives. The aim of the study is to develop a nomogram for predicting postoperative portal venous systemic thrombosis (PVST) in patients with cirrhosis undergoing splenectomy and esophagogastric devascularization. Methods. In total, 195 eligible patients were included. Demographic characteristics were collected, and the results of perioperative routine laboratory investigations and ultrasound examinations were also recorded. Blood cell morphological traits, including the red cell volume distribution width (RDW), mean platelet volume, and platelet distribution width, were identified. Univariate and multivariate logistic regressions were implemented for risk factor filtration, and an integrated nomogram was generated and then validated using the bootstrap method. Results. A color Doppler abdominal ultrasound examination on a postoperative day (POD) 7 (38.97%) revealed that 76 patients had PVST. The results of the multivariate logistic regression suggested that a higher RDW on POD3 (RDW3) (odds ratio (OR): 1.188, 95% confidence interval (CI): 1.073–1.326), wider portal vein diameter (OR: 1.387, 95% CI: 1.203–1.642), history of variceal hemorrhage (OR: 3.407, 95% CI: 1.670–7.220), and longer spleen length (OR: 1.015, 95% CI: 1.001–1.029) were independent risk parameters for postoperative PVST. Moreover, the nomogram integrating these four parameters exhibited considerable capability in PVST forecasting. The nomogram’s receiver operating characteristic curve reached 0.83 and achieved a sensitivity and specificity of 0.711 and 0.848, respectively, at its cutoff. The nomogram’s calibration curve demonstrated that it was well calibrated. Conclusion. The nomogram exhibited excellent performance in PVST prediction and might assist surgeons in identifying vulnerable patients and administering timely prophylaxis.

Chen, Miao↗

Best Practices for Timing Attack Mitigation

GPS signals play essential roles in the electric subsector by providing precision timing used to synchronize and record measurements from a range of equipment. However, previous research has demonstrated that GPS signals can be spoofed or jammed relatively easily in order to interfere with timing-reliant equipment. This document outlines utility best practices for mitigating against timing attacks in the electric subsector based on an assessment of the difficulty and impact of realistic timing attacks and testing of the effectiveness of technologies capable of mitigating them. This analysis builds on research establishing the vulnerability of GPS-reliant timing equipment to jamming and spoofing by elaborating the difficulty, consequences, and mitigations for timing attacks that adversaries might realistically attempt. While timing attacks are relatively low-cost, low-sophistication, and capable of systemic consequences in the electric subsector, they can be effectively mitigated through well-targeted and diverse mitigations.

24 POWER TRANSMISSION AND DISTRIBUTION↗