Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “vulnerability assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

DPSIR-ESA Vulnerability Assessment (DEVA) Framework: Synthesis, Foundational Overview, and Expert Case Studies

Land resources are central to understanding the relationship between humans and their environment. We broadly define a land resource to include all the ecological resources of climate, water, soil, landforms, flora, and fauna, and all the socioeconomic systems that interact with agriculture, forestry, and other land uses within some system boundary. Understanding the vulnerability of land resources to changes in land management or climate forcing is critical to developing sustainable land management strategies. Vulnerability assessments are complex given the multiple uses of the assessments, the multi-disciplinary nature of the problem, limited understanding, the dynamic structure of vulnerability, scale issues, and problems with identifying effective vulnerability indicators. Here, we propose a novel conceptual framework for vulnerability assessments of land resources that combines the driver– pressure–state–impact–response (DPSIR) framework adopted by the European Environment Agency to describe interactions between society and the environment, and the exposure-sensitivity-adaptive capacity (ESA) framework used by the Intergovernmental Panel on Climate Change to assess impacts of climate change. The DPSIR-ESA Vulnerability Assessment (DEVA) framework operationalizes the process of assessing the vulnerability of a target system to external stressors. The DEVA framework includes the following elements: 1) Definition of the target system (Land resource), 2) Description of internal characteristics of the target system (State), 3) Description of target system vulnerability indicators (Adaptive capacity, Sensitivity), 4) Description of stressor characteristics (Drivers, Pressures), 5) Description of stressor vulnerability indicators (Exposure), 6) Description of target system response to stressors (Impacts), and 7) Description of modifications to target systems or stressors (Responses). In stating that they have “applied the DEVA framework”, analysts acknowledge that they have (a) considered the full breadth of each DEVA element, (b) have made conscious decisions to limit the scope and complexity of certain elements, and (c) can communicate both the rationale for these decisions and the impact of these decisions on the vulnerability assessment results and recommendations. The DEVA framework was refined during invited presentations and follow-up discussions from a series of Special Sessions with leading experts at two successive ASABE Annual International Meetings. Six case studies drawn from the sessions elaborate upon the DEVA framework and provide concrete examples of the key concepts. The DEVA approach gives engineers, planners, and analysts a new, flexible framework to apply a broad array of useful tools toward assessment of land resource system vulnerability.

Anandhi, Aauvadi↗

Assessment of Physical Security Modeling and Simulation in the Vulnerability Assessment Process

This report provides a comprehensive assessment of physical security modeling and simulation tools available for use in the vulnerability assessment (VA) process for nuclear facilities. It outlines the historical evolution of VA methodologies, emphasizing the transition from traditional layer-based approaches to a more holistic framework that integrates detection probabilities directly into combat simulations. The document details the critical components of the VA process, including the characterization of targets, threats, and protective measures, as well as the development of adversary scenarios that reflect both insider and outsider threats. It highlights the importance of performance assurance programs, emphasizing the need for continuous evaluation and testing of security systems to ensure their effectiveness against evolving threats. Additionally, the report discusses the significance of utilizing accredited modeling and simulation tools in accredited areas to accurately represent adversary actions and the corresponding responses of protective forces. By establishing a systematic approach to VA, this document aims to enhance the overall security posture of nuclear facilities, ensuring compliance with regulatory standards while effectively mitigating risks associated with potential adversarial actions.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Climate Vulnerability Assessment and Resilience Planning for Idaho National Laboratory

Idaho National Laboratory’s (INL’s) mission is to discover, demonstrate, and secure innovative nuclear energy solutions, other clean energy options, and critical infrastructure. This INL’s Climate Vulnerability Assessment and Resilience Plan (VARP) was developed to enable and sustain that mission while ensuring the viability of operations considering expected climate change impacts. The VARP was developed according to the narrative requirements from the “Vulnerability Assessment and Resilience Planning Guidance, Version 1.2” document issued in February 2022. A prescribed process was used to identify mission-critical systems and components, determine historical and expected climate impacts, and develop resilient solutions. Experts from across INL, including operations staff, researchers, and climate scientists supplied input to the process. Analyses of climate modeling sources revealed that under scenarios of higher and lower greenhouse gas emissions (Representative Concentration Pathway (RCP) 4.5 and RCP 8.5), INL anticipates an increase in climate hazards, including drought, heat waves, wildfire, and precipitation. Increased frequency and duration of climatic hazards forecasts high impacts on certain mission-critical asset and infrastructure types. Utilizing the VARP Risk Assessment Tool, projected high climate hazard impacts across multiple asset and infrastructure types at the INL include energy generation and distribution systems, Site buildings, specialized or mission-critical equipment, and transportation and fleet infrastructure. Some of these mission-critical asset and infrastructure types maintain high adaptive capacity to climatic changes; however, others may need additional adaptive capacity to withstand increased frequency and duration of climate hazards. INL identified close to 300 resilient solutions that were consolidated into 11 solution categories to be tracked in the Department of Energy Sustainability Dashboard. The identified solutions are a starting point for future project development and analysis. These data are intended to inform decision makers on climate issues and potential solutions across INL and associated communities. The VARP is not intended to be a budget tool or project decision document on its own, but rather one of many tools used by decision makers to establish resilient priorities. This initial document provides the framework and foundation to resilient solutions. In the coming years, each solution needs to be fully developed, costed, and prioritized based on mission-critical risk and funding priorities.

54 ENVIRONMENTAL SCIENCES↗

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization↗

2022 Climate Change Vulnerability Assessment and Resilience Plan Summary

Los Alamos National Laboratory (LANL, or the Laboratory) produced a Vulnerability Assessment and Resilience Plan (VARP) following Department of Energy (DOE) Guidance to assess and manage climate change related risks to the Laboratory’s assets and operations. This is a condensed summary of the Laboratory’s 2022 VARP – the full version of the document is not publicly available at this time. The VARP was led by the Pollution Prevention (P2) Program in the Environmental Protection and Compliance Division (EPC-DO) and covers the entirety of the 36-square-mile LANL site in Los Alamos, New Mexico. A Steering Committee, composed of representatives from the three main Laboratory Directorates and the Los Alamos Field Office, identified real property Critical Assets based on their Mission Dependency Index (MDI) scores. LANL used MDI scores of 70 and above, which are considered Mission-Critical, to generate a list of 141 Critical Asset facilities.

54 ENVIRONMENTAL SCIENCES↗

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Geothermal Sector Cybersecurity Vulnerability Assessment

A review of geothermal sector-specific cybersecurity vulnerabilities and risks (consequences) was conducted at the request of the Geothermal Technologies Office (GTO). The vulnerabilities and risks reviewed in this study have relevance to achieving the 2019 GeoVision Report (DOE GTO 2019) technological advancements and expected sector growth. The study offers areas for consideration but does not quantify the likelihood (frequency) of the consequences. This cybersecurity analysis project represents a proactive effort to identify areas to enhance cybersecurity in geothermal development and operations. It was not initiated to address any immediate threat or specific known risk. Of the eight identified vulnerabilities analyzed, the review identified reservoir data system monitoring as one that is unique to geothermal systems and may warrant further investigation to better understand risk and mitigation. A detailed analysis of the other vulnerabilities may highlight additional uniqueness relative to other industries. Further research actions are recommended to better quantify risk and enhance cybersecurity preparedness of the sector. As the geothermal industry grows, the cybersecurity strategies to be deployed will be of increasing importance to ensure resilient, reliable, and secure clean energy for years to come.

cyber-physical security↗

Grid Utility Asset Vulnerability Assessment (GUAVA) Software Tool

Increasing demand and changes in generation portfolios is pushing power grid to operate towards the limit. However, due to lack of analytical tools for understanding various scales of impact on grid, it is becoming more vulnerable to wide scale power outages and blackouts. A vulnerable grid operating at its limit can be easily disrupted by asset failures caused by devastating hurricanes which has been known to damage transmission and distribution lines along its track. In this direction, researchers have focused on determining these assets by conducting Monte Carlo simulations of hurricanes with uncertainties and collected a large set of simulation data. To determine the infrastructure updates necessary for mitigating wide scale impact of hurricanes on the grid, we propose a software tool named “Grid Utility Asset Vulnerability Analysis” (GUAVA) framework. GUAVA presents a novel data-driven probabilistic analytical approach to (1) post-process hurricane failure scenarios, (2) identify/rank assets that are most vulnerable and critical to failing and are associated with highest impact/risk, and (3) to inform system upgrade decisions & prioritization. Based on the observed results and employed data-driven methodology, it is expected GUAVA can be adapted to provide power system planners with a recommendation engine for making informed decisions to improve resilience of grid.

Mahapatra, Kaveri↗

Aggregation in bottom-up vulnerability assessments and equity implications: The case of Jordanian households’ water supply

Bottom-up methods for water resources modeling rely on acceptability thresholds to find, through a response surface, which deeply uncertain futures lead to system failure. They commonly treat water users as aggregate actors, which may preclude analysis of the equity impacts of interventions. This paper explores how aggregation choices for large groups of water users lead to different policy recommendations in response surface assessments. Herein, two aggregation methods with varying parameters are considered: percentile satisfaction targets and generalized mean. A 2-dimensional stress-test assessment across groundwater availability and population is applied to household water supply in Jordan. The study compares six different policies covering supply enhancement and rebalancing, using a country-wide multi-agent model that characterizes households across socioeconomic strata. For different aggregation levels, policies are ordered by their associated robustness index. Results show that aggregation choices may modify response surfaces as much as policy changes and strongly determine policy preference. Modifying allocation rules can substantially reduce the disparity in household vulnerability. Preferences defined by aggregation intervals provide a finer understanding of trade-offs among water users and may improve deliberation over equity under deep uncertainty.

54 ENVIRONMENTAL SCIENCES↗

Vulnerability Assessments for Power-Electronics-Based Smart Grids

Here, in this paper, a novel method is proposed to evaluate the cyber security of the power-electronics-based smart grids (PESG). The proposed method considers the performance and stability of both the individual inverter and the grid. To our knowledge, this is a first attempt to evaluate the performance and stability of PESG due to cyber attacks. We first develop impedance-based modeling and cyber-attack modeling for PESG. Then we propose innovative two security criteria to evaluate the security of PESG, including stability-based and metrics-based. For metrics-based criteria, we propose to use both total harmonic distortion (THD) and space phasor model (SPM) to evaluate the inverter performance. The simulation results with a two-inverter-based power grid verify the validity and accuracy of the proposed security evaluation method. Results have shown that the performance and stability of PESG are significantly affected by cyber attacks, and thus there is indeed a need to further study cyber security issues of PESG.

24 POWER TRANSMISSION AND DISTRIBUTION↗