Search NASA⌕ Search

SEARCH · Search NASA

Results for “vulnerability”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 343 records · Page 19

Securing the Modern Grid: Federal Investments, Digitization, and Supply Chain Strategy

Across the United States (U.S.) grid expansion and modernization is underway, paving the way for accelerated load growth and intelligent resource management. Digitization of the grid is supported by several state and federal programs, providing support for utilities installing advanced metering infrastructure (AMI), AI-powered analytics systems, battery energy storage systems (BESS), and distributed energy resource management systems (DERMS) to transform the grid from a one-way power delivery system into an intelligent, responsive network that will enable faster load growth and power expansion of data centers for advanced artificial intelligence (AI) applications. The digital transformation of America's grid presents opportunity for increased efficiency and resiliency but also introduces new digital risks that require careful management. Digital equipment often contains several vulnerabilities such as unencrypted communication protocols, and persistent remote access capabilities that could be exploited to manipulate device settings, coordinate service disruptions, or inject false data into grid operations. These digital risks become particularly important as the grid must rapidly scale to support AI-driven data centers, which the administration has identified as essential for maintaining U.S. technological leadership and economic competitiveness. These vulnerabilities are compounded by supply chain realities: Chinese manufacturers currently produce 70-90% of essential grid components including inverters, batteries, and control systems, with the U.S. lacking domestic manufacturing capacity for critical assets like extra-high voltage transformers. Recent federal legislation has established Foreign Entity of Concern (FEOC) restrictions to address these risks, requiring projects to achieve escalating thresholds of non-FEOC content to receive tax credits while utilities work to expand sourcing channels for their supply chains and strengthen security measures. These restrictions arrive precisely when utilities face unprecedented electricity demand growth driven by the rapid growth in data centers, creating a considerable challenge: rapidly expanding infrastructure while navigating complex compliance requirements while lacking viable alternatives for many critical components. Idaho National Laboratory (INL) and its partners have developed practical approaches to help utilities navigate these intersecting challenges as they leverage federal investment to strengthen and grow the grid. These solutions include Cyber-Informed Engineering (CIE) principles that build resilience directly into systems, the Cirrus tool for secure cloud migration, and enhanced procurement guidance that embeds security requirements throughout equipment lifecycles. Federal initiatives, such as the Technical Assistance for Digital Assurance (TADA) project, provide direct support to utilities implementing these approaches while facilitating knowledge sharing across the industry. While these tools and frameworks cannot eliminate all risks inherent in foreign supply chain dependencies, they offer pragmatic pathways for strengthening security posture without sacrificing the deployment momentum essential to meeting surging electricity demand. Ultimately, securing America's digital energy infrastructure demands dedicated coordination across multiple fronts: building domestic supply chains, implementing robust digital assurance practices, and maintaining the aggressive modernization timeline necessary for reliability, resilience, and energy independence.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Utilizing Time Reversal Ultrasonics to Detect the Removal of Nuclear Materials from Geological Repositories (FY26 Mid-Year)

Detecting unauthorized nuclear material removal from storage environments, such as geological repositories, is a critical safeguards task essential to ensuring the integrity and non-diversion of nuclear materials. However, this process is fraught with significant technical challenges. Storage configurations often involve tightly packed nuclear material containers or obstructed environments, making detection of removal events exceedingly difficult. Optical surveillance cameras, which are commonly used for monitoring, suffer from substantial limitations, including restricted coverage, reliance on line-of-sight measurements, and vulnerability to environmental conditions in certain storage scenarios. As the global inventory of monitored nuclear materials increases and storage configurations become more complex— such as deep geological repositories, inaccessible storage vaults, and tightly packed containers—there is an urgent need for innovative detection technologies that can reliably identify unauthorized diversion events in these challenging environments. The challenge of detecting nuclear material removal in complex storage environments is both significant and urgent. Preventing unauthorized access, diversion, or tampering with nuclear materials is a cornerstone of global nuclear safeguards and nonproliferation efforts. Current detection methods are increasingly inadequate as storage configurations become more intricate and inaccessible. The limitations of existing technologies—such as their inability to detect changes behind obstructions, reliance on costly and labor-intensive processes, and vulnerability to environmental conditions—pose risks to the effectiveness of safeguards systems. Addressing this challenge is critical to maintaining international trust in nuclear safeguards frameworks and ensuring compliance with nonproliferation agreements. Our project builds on the proven concept of TRU technology that can address this unmet need. TRU has demonstrated exceptional spatial sensitivity and change detection capabilities in complex non-line-ofsight environments, making it uniquely suited for detecting unauthorized nuclear material removal in challenging storage configurations. Unlike optical methods, TRU is not limited by line-of-sight constraints or environmental conditions, enabling reliable detection of subtle alterations even behind obstructions. By leveraging TRU’s ability to identify removal or tampering events, we aim to develop a robust detection system that enhances safeguards in geological repositories, storage vaults, and other complex environments.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Data Center Cybersecurity, Supply Chain Risk Management, and Emerging Regulation Cohort Summary: Takeaways and Action Plans

This report summarizes the outcomes of the Data Center Cohort under the Department of Energy’s Technical Assistance for Digital Assurance (TADA) initiative, aimed at enhancing grid resilience through cybersecurity, supply chain risk management (SCRM), and Cyber-Informed Engineering (CIE). The cohort engaged 17 organizations across utilities, data center operators, vendors, and technology providers in three sessions combining presentations, discussions, and exercises. Key topics included AI-driven load behavior, cybersecurity vulnerabilities in UPS/BESS and cooling systems, governance gaps at utility–data center boundaries, and supply chain integrity. Five cross-cutting themes emerged: interconnection architecture vulnerabilities, fragmented governance, AI-driven stability risks, lack of regulatory frameworks, and long-term supply chain concerns. Actionable recommendations were developed, including implementing DMZ segmentation, formalizing vendor access agreements, designing AI workload limits, and advancing standards through NERC and state-level programs. These strategies aim to strengthen resilience, clarify responsibilities, and ensure secure integration of data centers into the grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Evaluation of Hardware and Software Bill of Materials (HBOMs/SBOMs) Extraction Methods

Hardware and software bills of materials (HBOMs and SBOMs) provide important visibility into the components, dependencies, and supply chain relationships within programmable digital devices. This visibility is critical for advanced nuclear reactor applications, where use of common or shared hardware components, software libraries, suppliers, or manufacturing processes may create common cause failure (CCF) vulnerabilities despite apparent diversity. This paper evaluates current approaches for obtaining and analyzing HBOMs and SBOMs in support of CCF, diversity and defense-in-depth (D3) assessments, and begins to explore potential methods for artificial intelligence/machine learning-based analysis. The availability of BOM information from advanced reactor manufacturers and vendors, representative hardware and software categories found in advanced reactor systems continues to limit research [13]. This paper compares commonly used BOM formats, including CycloneDX, SPDX, and SWID. It also surveys publicly available tools for generating BOMs from source code, compiled binaries, and hardware-related information, noting limitations in language coverage, system age, and format interoperability. Finally, this paper evaluates methods for correlating BOM data with vulnerability and exploitability information, including VEX, CVE, and CWE resources. The findings indicate that publicly available nuclear-vendor BOMs are limited, making third-party extraction and research into novel analysis techniques necessary.

Cybersecurity↗

Machine Learning for Anomaly Detection in Neural Network Security and SRF Cavities

This dissertation explores the development and deployment of machine learning approaches to address critical challenges in anomaly detection across two distinct domains: neural network security in federated learning settings and cavity behavior analysis in particle accelerator operations at Jefferson Lab in Newport News, Virginia. Anomaly detection identifies deviations from expected patterns, safeguarding systems in cybersecurity, industry, and research against malicious activities and failures. This dissertation demonstrates how our machine learning approaches enhance detection accuracy and efficiency in both neural network security and industrial applications. First, we investigate vulnerabilities in deep neural networks deployed in federated learning. Although federated learning preserves user privacy by training models locally, it remains vulnerable to backdoor attacks, in which malicious participants embed hidden triggers that induce targeted misbehavior. We propose a self-supervised contrastive learning framework to detect and mitigate such backdoor attacks. In our experiments, this method achieves higher detection accuracy and lower false positive rates than existing defenses, while operating without access to local model updates or original training data and thus preserving the privacy guarantees of the federated setting. Second, we address the operational reliability of superconducting radio-frequency (SRF) cavities at the Continuous Electron Beam Accelerator Facility (CEBAF). Our research leverages an unsupervised learning approach, combined with Principal Component Analysis (PCA) and k-means clustering, to identify anomalous behaviors in SRF cavities. Our method detects subtle anomalous behavior by analyzing SRF signal data. This knowledge allows for the early detection and resolution of potential faults, significantly improving the efficiency and reliability of operations. Third, we extend these insights to time-series anomaly detection more broadly. We design a contrastive-learning based model tailored to increasingly dynamic environments and academic research. This model improves detection accuracy in settings that require real-time monitoring and predictive maintenance. Our research underscores the broader applicability and impact of advanced machine learning techniques in anomaly detection. By extracting meaningful patterns from complex data, machine learning can significantly enhance security in distributed neural networks and improve the efficiency of particle accelerator operations. This dissertation serves as a stepping stone for future investigations into the vast possibilities of anomaly detection, inspiring further exploration and development of machine learning techniques in this field.

Ferguson, Hal [Old Dominion University]↗

IoT Firmware Emulation and Its Security Application in Fuzzing: A Critical Revisit

As IoT devices with microcontroller (MCU)-based firmware become more common in our lives, memory corruption vulnerabilities in their firmware are increasingly targeted by adversaries. Fuzzing is a powerful method for detecting these vulnerabilities, but it poses unique challenges when applied to IoT devices. Direct fuzzing on these devices is inefficient, and recent efforts have shifted towards creating emulation environments for dynamic firmware testing. However, unlike traditional software, firmware interactions with peripherals that are significantly more diverse presents new challenges for achieving scalable full-system emulation and effective fuzzing. This paper reviews 27 state-of-the-art works in MCU-based firmware emulation and its applications in fuzzing. Instead of classifying existing techniques based on their capabilities and features, we first identify the fundamental challenges faced by firmware emulation and fuzzing. We then revisit recent studies, organizing them according to the specific challenges they address, and discussing how each specific challenge is addressed. We compare the emulation fidelity and bug detection capabilities of various techniques to clearly demonstrate their strengths and weaknesses, aiding users in selecting or combining tools to meet their needs. Finally, we highlight the remaining technical gaps and point out important future research directions in firmware emulation and fuzzing.

Zhou, Wei (ORCID:0000000178340839)↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Unsupervised Detection of SOC Spoofing in OCPP 2.0.1 EV Charging Communication Protocol Using One-Class SVM

The electric vehicles (EVs) market keeps growing globally; thus, it is critical to secure the EV charging communication protocols in order to guarantee reliable and fair charging operations among the customers. The Open Charge Point Protocol (OCPP) 2.0.1 supports the communication between the Electric Vehicle Supply Equipment (EVSE) and Charging Station Management Systems (CSMSs); therefore, it becomes vulnerable to several types of attacks, which aim to jeopardize smart charging, billing, and energy management. Specifically, OCPP 2.0.1 allows the self-reporting of the State of Charge (SOC) values, which makes it vulnerable to spoofing-based cyberattacks, which target manipulating the scheduling priorities, distorting the load forecasts, and extending the charging sessions in an unfair manner. In this paper, we try to address this type of attack by providing a comprehensive analysis of the SOC spoofing attacks and introducing a novel unsupervised detection framework based on the One-Class Support Vector Machine (OCSVM) algorithm. Specifically, two types of attack scenarios are analyzed (i.e., priority manipulation and session extension) by deriving engineered features that capture the nonlinear relationships under normal charging behavior. Detailed simulation-based results are derived by utilizing the DESL-EPFL Level 3 EV charging dataset. Our results demonstrate high F1-score and recall in identifying spoofed SOC values and that the proposed OCSVM model demonstrates superior performance compared to alternative clustering and deep-learning based detectors.

EV charging↗

Digital Tools for the Preventive Conservation of Built Heritage: The Church of Santa Ana in Seville

Historic Building Information Modelling (HBIM) plays a pivotal role in heritage conservation endeavours, offering a robust framework for digitally documenting existing structures and supporting conservation practices. However, HBIM’s efficacy hinges upon the implementation of case-specific approaches to address the requirements and resources of each individual asset and context. This paper defines a flexible and generalisable workflow that encompasses various aspects (i.e., documentation, surveying, vulnerability assessment) to support risk-informed decision making in heritage management tailored to the peculiar conservation needs of the structure. This methodology includes an initial investigation covering historical data collection, metric and condition surveys and non-destructive testing. The second stage includes Finite Element Method (FEM) modelling and structural analysis. All data generated and processed are managed in a multi-purpose HBIM model. The methodology is tested on a relevant case study, namely, the church of Santa Ana in Seville, chosen for its historical significance, intricacy and susceptibility to seismic action. The defined level of detail of the HBIM model is sufficient to inform the structural analysis, being balanced by a more accurate representation of the alterations, through linked orthophotos and a comprehensive list of alphanumerical parameters. This ensures an adequate level of information, optimising the trade-off between model complexity, investigation time requirements, computational burden and reliability in the decision-making process. Field testing and FEM analysis provide valuable insight into the main sources of vulnerability in the building, including the connection between the tower and nave and the slenderness of the columns.

Chaves, Estefanía↗

Biological response of eelgrass epifauna, Taylor's Sea hare ( Phyllaplysia taylori ) and eelgrass isopod ( Idotea resecata ), to elevated ocean alkalinity

Abstract. Marine carbon dioxide removal (mCDR) approaches are under development to mitigate the effects of climate change by sequestering carbon in stable reservoirs, with the potential co-benefit of local reductions in coastal acidification impacts. One such method is ocean alkalinity enhancement (OAE). A specific OAE method is the generation of aqueous alkalinity via electrochemistry to enhance the alkalinity of the receiving water by the extraction of acid from seawater, thereby avoiding the issues of solid dissolution kinetics and the release of impurities into the ocean from alkaline minerals. While electrochemical acid extraction is a promising method for increasing the carbon dioxide sequestration potential of the ocean, the biological effects of increasing seawater alkalinity and pH within an OAE project site are relatively unknown. This study aims to address this knowledge gap by testing the effects of increased pH and alkalinity, delivered in the form of aqueous NaOH, on two eelgrass epifauna in the US Pacific Northwest, Taylor's sea hare (Phyllaplysia taylori) and eelgrass isopod (Idotea resecata), chosen for their ecological importance as salmon prey and for their role in eelgrass ecosystems. Four-day experiments were conducted in closed bottles to allow measurements of the evolution of carbonate species throughout the experiment, with water refreshed twice daily to maintain elevated pH, across pHNBS (NBS standard scale) treatments ranging from 7.8 to 9.3. Sea hares experienced mortality in all pH treatments, ranging from 37 % mortality at pHNBS 7.8 to 100 % mortality at pHNBS 9.3. Isopods experienced lower mortality rates in all treatment groups, ranging from 13 % at pHNBS 7.8 to 21 % at pHNBS 9.3, which did not significantly increase with higher pH treatments. These experiments represent an extreme of constant exposure to elevated pH and alkalinity, which should be considered in the context of both the natural variation and the dilution of alkalinity experienced by marine communities across an OAE project site. Different invertebrate species will likely have different responses to increased pH and alkalinity, depending on their physiological vulnerabilities. Investigation of the potential vulnerabilities of local marine species will help inform the decision-making process regarding mCDR planning and permitting.

marine carbon dioxide removal↗

Screening Tool for Equitable Adoption and Deployment of Solar (STEADy Solar)

The Screening Tool for Equitable Adoption and DeploYment of Solar (STEADy Solar) is a database and mapping tool designed to promoting clean energy investments for low-income communities across the United States. The tool indicates locations that may be eligible for the Investment Tax Credit bonus adders defined in the 2022 Inflation Reduction Act (IRA) and combines this information with demographics, social vulnerability, solar technical potential, solar economics (modeled net present value), and building counts by use-type. It can be used by states, municipalities, community-based organizations, developers, and researchers to identify sites where solar projects may be economical and where federal incentives may be available to support equitable adoption of solar. Specific values include: Areas eligible for the Energy Communities Tax Credit Bonus Program (including brownfield site counts) Areas eligible for the Low Income Communities Bonus Credit Program (including Tribal Lands, and covered affordable housing project counts) Areas categorized as disadvantaged by Justice40 Commercial and Residential Solar economics characterized by the Net Present Value and Simple Payback Period Total Population, Race, and Ethnicity Median Household Income, Poverty rate, Household Tenure Social Vulnerability Count of buildings, developable rooftop solar capacity (in kWdc) and estimated annual generation potential (in kWh) on four building types: Government General Services, Government Emergency Response, Grade Schools, and Colleges/Universities. The linked report describes the STEADy dataset metadata and presents high level insights from the data. The downloadable and formatted excel dataset makes it easy for users to gain insights for their locations. Supporting .csv and shapefiles provide users with the full data to run their own analyses on equitable solar siting.

14 SOLAR ENERGY↗

Evaluation of high pressure water blast with rotating spray bar for removing paint and rubber deposits from airport runways, and review of runway slipperiness problems created by rubber contamination

A high pressure water blast with rotating spray bar treatment for removing paint and rubber deposits from airport runways is studied. The results of the evaluation suggest that the treatment is very effective in removing above surface paint and rubber deposits to the point that pavement skid resistance is restored to trafficked but uncontaminated runway surface skid resistance levels. Aircraft operating problems created by runway slipperiness are reviewed along with an assessment of the contributions that pavement surface treatments, surface weathering, traffic polishing, and rubber deposits make in creating or alleviating runway slipperiness. The results suggest that conventional surface treatments for both portland cement and asphaltic concrete runways are extremely vulnerable to rubber deposit accretions which can produce runway slipperiness conditions for aircraft operations as or more slippery than many snow and ice-covered runway conditions. Pavement grooving surface treatments are shown to be the least vulnerable to rubber deposits accretion and traffic polishing of the surface treatments examined.

Horne, W. B.↗

Landsat Application of Remote Sensing to Shoreline-form Analysis

The author has identified the following significant results. Areas of the coast were selected which have historically shown vulnerability to storm damage. On Assateague Island, there are six such areas: the western tip of Fishing Point; the southern National Park Service parking lot; Smith Hammocks; Fox Hill Level; Little Fox Hill Level; and the northern five kilometers of the island. Comparative analysis of these areas with other data and with large and small scale aerial photographs shows them to be associated with large overwash fans and shoreline cusping. Initial analysis of Landsat imagery and high altitude photography indicates that the areas of high vulnerability are also associated with the angular orientation of the shoreline.

Dolan, R.↗

Simulated lightning test shuttle .03 scale model

Lightning Attach Point tests were conducted for the space shuttle launch configuration (Orbiter, External Tank and Solid Rocket Boosters). A series of 250 long spark tests (15 to 20 foot sparks) determined that the orbiter may be struck on the nose, windshield brow, tail and wingtips during launch but not on the main engine nozzles which have been shown to be vulnerable to lightning damage. The orbiter main engine and SRB exhaust plumes were simulated electrically with physical models coated with graded resistance paints. The tests showed that the exhaust plumes from the SRB provide additional protection for the main engine nozzles. However, the tests showed that the Orbiter Thermal Protection System (TPS), which has also been shown to be vulnerable to lightning damage, may be struck during launch. Therefore further work is indicated in the areas of swept stroke studies on the model and on TPS panels. Further attach point testing is also indicated on the free-flying orbiter. Photographs of the test setup are shown.

Clifford, D. W.↗

High performance dash-on-warning air mobile missile system

Because fixed missile bases have become increasingly vulnerable to strategic nuclear attack, an air-mobile missile system is proposed, whereby ICBMs can be launched from the hold of large subsonic aircraft following a missile-assisted supersonic dash of the aircraft to a safe distance from their base (about 50 n mi). Three major categories of vehicle design are presented: staged, which employs vertical take-off and a single solid rocket booster similar to that used on the Space Shuttle; unstaged, which employs vertical take-off and four internally-carried reusable liquid rocket engines; and alternative concepts, some using horizontal take-off with duct-burning afterburners. Attention is given to the economics of maintaining 200 ICBMs airborne during an alert (about $600 million for each fleet alert, exclusive of acquisition costs). The chief advantages of the system lie in its reduced vulnerability to suprise attack, because it can be launched on warning, and in the possibility for recall of the aircraft if the warning proves to be a false alarm.

Hague, D. S.↗

Effects of carbon/graphite fiber contamination on high voltage electrical insulation

The contamination mechanics and resulting failure modes of high voltage electrical insulation due to carbon/graphite fibers were examined. The high voltage insulation vulnerability to carbon/graphite fiber induced failure was evaluated using a contamination system which consisted of a fiber chopper, dispersal chamber, a contamination chamber, and air ducts and suction blower. Tests were conducted to evaluate the effects of fiber length, weathering, and wetness on the insulator's resistance to carbon/graphite fibers. The ability of nuclear, fossil, and hydro power generating stations to maintain normal power generation when the surrounding environment is contaminated by an accidental carbon fiber release was investigated. The vulnerability assessment included only the power plant generating equipment and its associated controls, instrumentation, and auxiliary and support systems.

Garrity, T.↗

Navy LOVA propellant development

The progress realized on evaluation of inert binder, nitramine formulations is considered with respect to their development for use as low vulnerability ammunition (LOVA) propellants. Burning rate, plasticizers, crosslink agents, physical property and vulnerability studies are discussed and some preliminary conclusions presented.

Vreatt, W. H.↗