Search NASA⌕ Search

SEARCH · Search NASA

Results for “Vulnerability”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Cybersecurity Challenges in Low-Inertia Power-Electronics-Dominated Grids

Here, the low inertia characteristics of the power electronics dominated grid (PEDG) introduces challenges while restoring voltage and frequency to their nominal values. These stability challenges create new cybersecurity vulnerabilities that are not thoroughly discussed in the literature. Cyber events such as false data injection (FDI), denial of service (DoS), man-in-the-middle attacks, stealthy attacks, and advanced persistent threats target PEDG to disrupt grid stability or gain financial benefits. The low inertia of PEDG (< 2s) compared to traditional grids (~10s) exacerbates these vulnerabilities. In response to stealthy attacks on state variables that supervisory layers cannot detect until significant harm occurs, the low inertia characteristics of PEDG offer substantial stealthy attack surfaces. To counteract such threats, PEDG must be equipped with ultra-fast real-time anomaly detection system and trajectory prediction mechanism to achieve effective cyberattack resiliency.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Preemptive optimization of a clinical antibody for broad neutralization of SARS-CoV-2 variants and robustness against viral escape

Most previously authorized clinical antibodies against severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2) have lost neutralizing activity to recent variants due to rapid viral evolution. To mitigate such escape, we preemptively enhance AZD3152, an antibody authorized for prophylaxis in immunocompromised individuals. Using deep mutational scanning (DMS) on the SARS-CoV-2 antigen, we identify AZD3152 vulnerabilities at antigen positions F456 and D420. Through two iterations of computational antibody design that integrates structure-based modeling, machine-learning, and experimental validation, we co-optimize AZD3152 against 24 contemporary and previous SARS-CoV-2 variants, as well as 20 potential future escape variants. Our top candidate, 3152-1142, restores full potency (100-fold improvement) against the more recently emerged XBB.1.5+F456L variant that escaped AZD3152, maintains potency against previous variants of concern, and shows no additional vulnerability as assessed by DMS. This preemptive mitigation demonstrates a generalizable approach for optimizing existing antibodies against potential future viral escape.

59 BASIC BIOLOGICAL SCIENCES↗

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN↗

Eev (enrich Enforce Validate) With Cpefinder

This code is designed to take an existing STIX bundle with vulnerability data and enrich it with additional potential vulnerabilities to provide further insight during threat analysis. It also acts as a launch platform for other enrichments tools. The additional tools include, WAVgraph and STIXEnforcer.

Beckman, BryanR [Idaho National Laboratory (INL), ↗

Using Machine Learning to Understand Electric and Hybrid Vehicles Ownership in Burdened and Nonburdened Communities

Transitioning to electric and hybrid vehicles (EHVs) for all communities is a pivotal step toward sustainable transportation and environmental conservation. This paper aims to understand the adoption of EHVs, focusing on burdened communities (BCs) in the United States. The EHV ownership-based analysis combines two datasets—behavioral data from the Puget Sound Regional Travel Survey integrated with BCs (Justice40) data covering transportation insecurity, environmental burden, social vulnerability, health vulnerability, and climate and disaster risk burden. After creating this unique database, descriptive analysis and modeling are used to analyze the data and predict EHV ownership in the future. Specifically, we use a new method that combines particle swarm optimization (PSO) with a stacking model named PSO-Stacking, which incorporates heterogeneous base learners of machine learning and deep learning. PSO applies a customized objective function to select the optimal hyperparameters for heterogeneous learners within the stacking model, effectively addressing challenges such as multicollinearity, data imbalance, nonlinearity, and overfitting. The proposed solution covers more accurate results than standard benchmark models for EHV ownership in BCs and non-BCs. In addition, the results of the PSO-Stacking method are explained using the local interpretable model-agnostic explanations technique. Results show a negative correlation between the BCs indicators, that is, higher transportation insecurity associated with lower EHV ownership. Furthermore, BCs have higher future climate risk scores, diesel particulate matter levels, and PM2.5 in the air than non-BCs because of higher conventional vehicle ownership. These communities are at higher risk and can benefit from electrification, EV infrastructure, and EV policies to address environmental challenges.

Aslam, Zeeshan [ORNL]↗

Strengthening Resilience: Florida Resident Voices on Resource Needs During Power Outages

Extreme weather events related to climate change, and an aging electricity infrastructure are disrupting reliable electricity services to a greater degree. Further, previous research has found that more socially vulnerable populations are more likely to live in areas with a higher probability of power outages. Here, this study examines the issues that people face during power outages and the resources that help individuals maintain resilience during power outages caused by extreme weather events in socially vulnerable communities. Using qualitative data from focus groups with 56 individuals in Central and North Florida, the research highlights lived experiences during outages and difficulties using and accessing resources during these conditions. Based on a qualitative review of the focus group discussions, this paper explores the solutions and support systems residents believe would improve their ability to cope. The findings offer insights to guide policy and strategic planning, with the goal of strengthening personal preparedness and response by focusing on the resources people consider most helpful for enduring frequent and severe outages.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Associations between regional blood-brain barrier permeability, aging, and Alzheimer’s disease biomarkers in cognitively normal older adults

Background Increased blood-brain barrier permeability (BBBp) has been hypothesized as a feature of aging that may lead to the development of Alzheimer’s disease (AD). We sought to identify the brain regions most vulnerable to greater BBBp during aging and examine their regional relationship with neuroimaging biomarkers of AD. Methods We studied 31 cognitively normal older adults (OA) and 10 young adults (YA) from the Berkeley Aging Cohort Study (BACS). Both OA and YA received dynamic contrast-enhanced MRI (DCE-MRI) to quantify K trans values, as a measure of BBBp, in 37 brain regions across the cortex. The OA also received Pittsburgh compound B (PiB)-PET to create distribution volume ratios (DVR) images and flortaucipir (FTP)- PET to create partial volume corrected standardized uptake volume ratios (SUVR) images. Repeated measures ANOVA assessed the brain regions where OA showed greater BBBp than YA. In OA, K trans values were compared based on sex, Aβ positivity status, and APOE4carrier status within a composite region across the areas susceptible to aging. We used linear models and sparse canonical correlation analysis (SCCA) to examine the relationship between K trans and AD biomarkers. Results OA showed greater BBBp than YA predominately in the temporal lobe, with some involvement of parietal, occipital and frontal lobes. Within an averaged ROI of affected regions, there was no difference in K trans values based on sex or Aβ positivity, but OA who were APOE4carriers had significantly higher K trans values. There was no direct relationship between averaged K trans and global Aβ pathology, but there was a trend for an Ab status by tau interaction on K trans in this region. SCCA showed increased K trans was associated with increased PiB DVR, mainly in temporal and parietal brain regions. There was not a significant relationship between K trans and FTP SUVR. Discussion Our findings indicate that the BBB shows regional vulnerability during normal aging that overlaps considerably with the pattern of AD pathology. Greater BBBp in brain regions affected in aging is related to APOE genotype and may also be related to the pathological accumulation of Aβ.

Science & Technology - Other Topics↗

Animal movement estimation and network-based epidemic modeling: Illustration for the swine industry in Iowa (US)

Animal movement plays a critical role in disease transmission between farms. However, in the United States, the lack of available animal shipment data, sometimes coupled with a lack of detailed information about farm demographics and characteristics, presents great challenges for epidemic modeling and prediction. In this study, we proposed a new method based on the maximum entropy to generate “synthetic” animal movement networks, considering available statistics about the premises operation type, operation size, and the distance between premises. We illustrated our method for the swine movement networks in Iowa and performed network analyses to gain insights into the swine industry. We then applied the generated networks to a network-based epidemic model to identify potential system vulnerabilities in terms of disease transmission. The model was parameterized for African Swine Fever (ASF) as the US swine industry is quite concerned about this disease. Results show that premises with a central role in the network are more vulnerable to disease outbreaks and play an important role in disease spread. Simulations with outbreaks starting from random farms reveal no significant large outbreaks, indicating the system’s relative robustness against arbitrary disease introductions. However, outbreaks originating from high out-degree farms can lead to large epidemic sizes. This underscores the importance for stakeholders and policymakers to continue improving animal movement records and traceability programs in the US and the value of making that data available to epidemiologists and modelers to better understand risk and inform strategies aimed to cost-effectively prevent and control disease transmission. Our approach could be easily adapted to estimate movement networks in other animal production systems and to inform disease spread models for various infectious diseases.

60 APPLIED LIFE SCIENCES↗

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Assessment and Coordination of EVSE Cybersecurity Standards

Cybersecurity certification programs for Electric Vehicle Supply Equipment (EVSE) are fragmented due to no single certification covering all aspects of the device and additionally the existence of multiple programs and under different levels of regulation. These devices are also confronted by the intricate assembly of product software, firmware, and hardware. Devices contain both logical and physical interfaces. These multifaceted devices have vulnerabilities at many levels and interconnect with other potentially vulnerable systems including the electric vehicle, the cloud where data and payment information are stored, and the electric grid and electric grid equipment including utilities. Of the EVSE certification programs that are found, none are directly for the cybersecurity of EVSE. Many standards are for safety, specifically battery safety, some are cybersecurity standards for other types of equipment and can be modeled for EVSE. In specific, ISA/IEC 62443 is found to be significantly in line with EVSE security needs and will be used in future testing to certify EVSE and help guide the project to demonstrate where gaps exist, where strengths lie in the standard and how this can be used to lead the certification efforts in harmonizing EVSE cybersecurity standards. In addition, there are multiple efforts that are currently seeking to build EVSE standards or revise existing standards to address gaps. This effort is seeking to establish a cybersecurity program for EVSE that will inform customers and help increase the level of security across products and state EVSE procurements to achieve consistency across different jurisdictions.

33 ADVANCED PROPULSION SYSTEMS↗

Integration of equitable resilience metrics into climate-informed electric utility planning processes: phase one

Working together, Sandia National Laboratories, Southern California Edison (SCE) - an Investor-Owned Utility (IOU) - and the California Public Utilities Commission (CPUC) are studying how electric utilities can use equity and resilience metrics to help inform the prioritization and sequencing of resilience-driven infrastructure investments. To this end, this project evaluated “Social Burden,” an equitable resilience metric which measures the potential impact of disruptions in access to non-electric critical services on people and estimates community resilience to these disruptions. The Social Burden was expanded to incorporate SCE’s existing equity metric and applied to evaluate the potential impacts from a range of climate-informed hypothetical outage scenarios developed under SCE’s 2022 Climate Adaptation Vulnerability Assessment. One baseline (“blue-sky”) state and eight different outage scenarios were evaluated to measure the potential impacts of the outages on non-electric infrastructure, critical services, and people. Key findings include: 1) the Social Burden framework is flexible enough to adapt to and build upon existing utility equity and/or resilience metrics, 2) Social Burden results highlight the high degree of non-electric service redundancy within the SCE service area with most (6/8) hypothetical outage scenarios predicted to increase people’s Social Burden by less than 10%; however, 3) access to critical services and people’s ability to obtain them is unequal and spatially clustered, meaning that there are some hypothetical outage scenarios (2/8) that will exert a higher toll on communities directly experiencing the outage as well as some nearby communities with pre-existing vulnerabilities. The report concludes with recommendations for potential use cases of the expanded Social Burden metric and identifies priority follow-on work. Potential use cases may include incorporating equity into IOU’s prioritization of climate resilience investments. Additionally, Social Burden analysis may provide additional data and insights to augment grid planning, potentially by identifying additional needs and/or prioritizing previously identified needs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Assessing Historical Extreme Weather Event Impacts

Resilience planning, particularly energy and water resilience planning, has been a key priority for the federal government for many years, leading federal agencies to develop processes for identifying and addressing critical resilience gaps at their facilities and sites. Furthermore, recent federal policy is driving agencies to prioritize climate change impacts as a more central component of their resilience planning efforts. To achieve this, federal sites must understand their vulnerability to climate change, which involves identifying climate hazards projected to impact the site (known as exposure), as well as understanding the sensitivity (the degree to which a site, including its people and the things they value, could be harmed by that exposure), and adaptive capacity of the site (the degree to which the site could lessen bathe potential for harm by taking action to reduce exposure and sensitivity). To assess and understand sensitivity and adaptive capacity, it is important to first obtain a baseline and understand how a site has been impacted by past events, in addition to considering the potential for unprecedented impacts based on climate projections. This information paper highlights current limitations for developing event history assessments and suggests a framework for more consistently capturing key data points. The purpose of this paper is to help inform how organizations could begin structuring a comprehensive process for recording the impacts of extreme weather events in order to facilitate climate vulnerability assessments, and thus, resilience planning.

54 ENVIRONMENTAL SCIENCES↗

The Essence of Cryptol: A Denotational Cryptol Interpreter in Coq for Foundational Assurances for Quantum Resistant Cryptosystems

Systems of the utmost consequence need a means to establish authenticity of software and data. Cryptosystems implement authentication, but can be vulnerable to cryptographic and implementation attacks. With the threat of quantum cryptographic attacks, “post-quantum” cryptosystems (PQCs) must be henceforth used in these systems. However, the new cryptography needs new ways to, rigorously and machine-checkably, prove systems free of vulnerabilities. We propose a retargetable capability to rapidly instantiate proven correct postquantum cryptosystems through novel proof-carrying synthesis and proof-automation technique, extending those proven successful on existing systems. This capability is crucial to meeting the cryptographic requirements for future high-consequence systems. Since specifications for high consequence cryptography are presently captured in a domain specific language known as Cryptol. While this can enable convenient fully automated reasoning about Cryptol specificaitons and implementations via the Software Analysis Workbench (SAW), Cryptol has expressivity gaps, so that cryptosystems with probabilistic programming features like Falcon cannot be fully expressed in the language. Moreover, SAW’s automation fails for programs and specificaitons with inductive and recursive structure, as in the Sphincs+ PQC. Finally, Cryptol and SAW together represent some 200,000 lines of unverified Haskell, so that the any guarantees about high consequence cryptography are presently contingent on a large, unverified, yet trusted computing base. The first step of the larger project of agile, assured crpytography is therefore to provide a formal, mechanized semantics for Cryptol, so that the specifications expressed by cryptographers in Cryptol can be reasoned about and compiled into performant implementations with a foundational, machine checkable certificate of correctness. This report describes our work on this first step, culminating in the design of a certified denotational interpreter, in Coq, for core Cryptol.

97 MATHEMATICS AND COMPUTING↗

Bridging the Gap on Data, Metrics, and Analyses for Grid Resilience to Weather Events: Information that utilities can provide regulators, state energy offices, and other stakeholders

A growing number of states require regulated utilities to file resilience plans to improve the electric grid’s ability to anticipate, withstand, adapt to and recover from increasingly severe weather events. This report aims to help state regulators identify and request data, metrics, and analyses from utilities and use it in decisions on utility resilience plans and investments. The report reviews state requirements and utility plans focused on overall grid resilience, climate change resilience and vulnerabilities, infrastructure modernization, storm protection, and wildfire mitigation. It details types of data, metrics, and analyses across five categories--and provides examples of each from the utility plans. The first category is vulnerability assessments, or evaluations of the susceptibility of systems, communities, or assets to potential harm from identified hazards. The second is data on hazards and the exposure of utility assets and customers to these hazards. The third is attribute metrics, or system characteristics that contribute to or describe the resilience of a system. The fourth is performance metrics, which are impacts of resilience investments on system performance--typically a reduction of negative impacts from hazard events. Finally, evaluation and prioritization are analyses that utilities conduct to estimate impacts from resilience measures (evaluation) and prioritize measures based on costs and estimated impacts (prioritization). The report concludes with examples of key trends and emerging best practices for states and utilities, and identifies areas for further research.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Unraveling the Noise: An Investigation Plan for Signal Interference in Hearing Aids

Bluetooth Low Energy (BLE) has revolutionized the performance of hearing aids with functionalities like seamless audio streaming and enhanced auditory functions. However, BLE operates within the highly congested 2.4 GHz frequency band, making it susceptible to signal interference that can degrade performance, reduce audio quality, and impact user experience. This paper documents interference patterns in BLE communication and introduces practical mitigation techniques aimed at improving the reliability of hearing aids. Attack vectors associated with Bluetooth enabled hearing aids include communication jamming, the interception of data between target devices, and GATT handle exploitation. Attackers could also use the vulnerabilities to block communications or intercept sensitive audio streams, posing significant security and privacy risks. These threats compromise two critical components of the CIA triad: (1) availability, by causing persistent connectivity issues, and (2) integrity, by enabling unauthorized data modifications. It is necessary to deal with these problems to ensure hearing aids work well and safely. This study investigates the impact of BLE signal interference on hearing aids, using tools such as HackRF [1], a Python tool to simulate interference scenarios, and Ubertooth [2] to sniff Bluetooth traffic between hearing aids and the device with the application. This paper investigates testing of BLE traffic in search of specific interference patterns that would impact the functionality of hearing aids, including jamming and flooding. This research focuses on developing robust mitigation techniques with the aim of securing BLE-enabled hearing aids against those vulnerabilities.

Baldwin, David [Savannah River National Laboratory↗

An assessment of the global cooling supply chain and implications for critical minerals

The global room air conditioner (AC) industry has undergone rapid growth, and the U.S. and India now face new supply chain risks due to China’s dominant role in manufacturing and driving demand. As India’s room AC market and related electricity consumption increases with continued economic development, it faces dual challenges of supply chain vulnerabilities and power grid blackouts from higher peak loads. To mitigate supply chain vulnerabilities for high-efficiency cooling equipment and critical mineral inputs to AC components, there is an increasing need to diversify the supply chain and address energy security and peak load risks to both the U.S. and India. This report assesses the potential for diversifying supply chains and scaling up manufacturing of highly efficient cooling equipment technologies and related critical mineral inputs in the U.S. and India. Successful cooperation on these technologies will enable the U.S., India, and their Quadrilateral Security Dialogue (Quad) partners to diversify AC supply chains while meeting India’s large and growing demand for efficient cooling. In the similarly concentrated supply chain for critical minerals, the U.S. and India can work with Japan and Australia to leverage each country’s strengths in diversifying mining, processing, and refining while pursuing alternatives to materials with high supply chain risks and supporting increased recycling and circular economy approaches.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

How Quantum Sensing Will Help Solve GPS Denial in Warfare

The U.S. military’s ability to posture, deter, and prevail in future conflicts may rest on the quantum sensing position, navigation, and timing (PNT) capabilities that are currently being developed. Heavy reliance on GPS signals for PNT has become a critical vulnerability for the U.S. military. Meanwhile, the conflict in Ukraine has demonstrated that GPS denial and electronic warfare (EW) is now a key component of modern combat and satellite-guided munitions are reportedly being rendered ineffective. The Department of Defense (DOD) is focusing on upgrading GPS to use stronger, military-specific signals, which will still be vulnerable to EW and anti-satellite capabilities. A more diverse and resilient alternate-PNT strategy is needed to ensure mission success.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Reverse Engineering of Medical Devices for Innovation and Advancement in Healthcare

• Medical technology is rapidly evolving and introducing new functionality and methodologies that suggest a higher risk for common vulnerability exposures (CVE) • Introduction of functionalities like Wi-Fi, Bluetooth, and internet connectivity require devices to be rigorously evaluated for vulnerabilities • Subsequently like many other fields cell-phone interconnectivity suggests a significantly higher level of risk to critical infrastructure and data security

Baldwin, David [Savannah River National Laboratory↗