Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

A time-varying vulnerability index for COVID-19 in New Mexico, USA using generalized propensity scores

The coronavirus disease (COVID-19) pandemic has highlighted systemic inequities in the United States and resulted in a larger burden of negative social outcomes for marginalized communities. New Mexico, a state in the southwestern US, has a unique population with a large racial minority population and a high rate of poverty that may make communities more vulnerable to negative social outcomes from COVID-19. To identify which communities may be at the highest relative risk, we created a county-level vulnerability index. After the first COVID-19 case was reported in New Mexico on March 11, 2020, we fit a generalized propensity score model that incorporates sociodemographic factors to predict county-level viral exposure and thus, the generic risk to negative social outcomes such as unemployment or mental health impacts. We used four static sociodemographic covariates important for the state of New Mexico—population, poverty, household size, and minority population—and weekly cumulative case counts to iteratively run our model each week and normalize the exposure score to create a time-varying vulnerability index. We found the relative vulnerability between counties varied in the first eight weeks from the initial COVID-19 case before stabilizing. This framework for creating a location-specific vulnerability index in response to an ongoing disaster may be used as a quick, deployable metric to inform health policy decisions such as allocating state resources to the county level.

59 BASIC BIOLOGICAL SCIENCES↗

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY↗

ML Clustering to Identify Natural Gas Pipeline Infrastructure Vulnerabilities

The network of more than 2.5 million miles of natural gas pipelines the U.S. are exposed to a range of vulnerabilities, ranging from extreme weather, to human behavior, and increasingly, to cyber threats. Advanced, data-driven analytics, including the use of machine learning and artificial intelligence, afford an opportunity to identify potential vulnerabilities, better understand risks, and help mitigate vulnerabilities in the network. At NETL, machine learning is being used to explore pipeline vulnerabilities and identify significant clusters of failure events, including failures due to weather, human behavior, and materials. These findings are being used to support the development of new technologies, including sensors, but can also be used to evaluate and inform mitigation strategies to reduce risks and vulnerabilities throughout the network.

Bauer, Jennifer↗

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization↗

Hydraulically‐vulnerable trees survive on deep‐water access during droughts in a tropical forest

Summary Deep‐water access is arguably the most effective, but under‐studied, mechanism that plants employ to survive during drought. Vulnerability to embolism and hydraulic safety margins can predict mortality risk at given levels of dehydration, but deep‐water access may delay plant dehydration. Here, we tested the role of deep‐water access in enabling survival within a diverse tropical forest community in Panama using a novel data‐model approach. We inversely estimated the effective rooting depth (ERD, as the average depth of water extraction), for 29 canopy species by linking diameter growth dynamics (1990–2015) to vapor pressure deficit, water potentials in the whole‐soil column, and leaf hydraulic vulnerability curves. We validated ERD estimates against existing isotopic data of potential water‐access depths. Across species, deeper ERD was associated with higher maximum stem hydraulic conductivity, greater vulnerability to xylem embolism, narrower safety margins, and lower mortality rates during extreme droughts over 35 years (1981–2015) among evergreen species. Species exposure to water stress declined with deeper ERD indicating that trees compensate for water stress‐related mortality risk through deep‐water access. The role of deep‐water access in mitigating mortality of hydraulically‐vulnerable trees has important implications for our predictive understanding of forest dynamics under current and future climates.

54 ENVIRONMENTAL SCIENCES↗

Geothermal Sector Cybersecurity Vulnerability Assessment

A review of geothermal sector-specific cybersecurity vulnerabilities and risks (consequences) was conducted at the request of the Geothermal Technologies Office (GTO). The vulnerabilities and risks reviewed in this study have relevance to achieving the 2019 GeoVision Report (DOE GTO 2019) technological advancements and expected sector growth. The study offers areas for consideration but does not quantify the likelihood (frequency) of the consequences. This cybersecurity analysis project represents a proactive effort to identify areas to enhance cybersecurity in geothermal development and operations. It was not initiated to address any immediate threat or specific known risk. Of the eight identified vulnerabilities analyzed, the review identified reservoir data system monitoring as one that is unique to geothermal systems and may warrant further investigation to better understand risk and mitigation. A detailed analysis of the other vulnerabilities may highlight additional uniqueness relative to other industries. Further research actions are recommended to better quantify risk and enhance cybersecurity preparedness of the sector. As the geothermal industry grows, the cybersecurity strategies to be deployed will be of increasing importance to ensure resilient, reliable, and secure clean energy for years to come.

cyber-physical security↗

VWC-BERT: Scaling Vulnerability–Weakness–Exploit Mapping on Modern AI Accelerators

Defending cybersystems needs accurate mapping of software and hardware vulnerabilities to generalized descriptions of weaknesses, and weaknesses to exploits. These mappings enable cyber defenders to build plans for effective defense and assessment of potential risks to a cybersystem. With close to 170k vulnerabilities, manual mapping is not a feasible option. However, automated mapping is challenging due to limited training data, computational intractability, and limitations in computational natural language processing. Tools based on breakthroughs in Transformer-based language models have been demonstrated to classify vulnerabilities with high accuracy. We make three key contributions in this paper: (1) We present a new framework, \VWCBERT, that augments the Transformer-based hierarchical multi-class classification framework of Das et al. (\textsc{V2W-BERT}) with the ability to map weaknesses to exploits. (2) We implement \VWCBERT~ on modern AI accelerator platforms using two data parallel techniques for the pre-training phase and demonstrate nearly linear speedups across NVIDIA and Graphcore accelerator platforms. We observe nearly linear speedups for up to 16 V100 and 8 A100 GPUs, and about 3.4$\times$ speedup for A100 relative to V100 GPUs. We also observe excellent speedups on Graphcore, with $5.7\times$ speedup on 128 IPUs relative to 16 IPUs. Enabled by scaling, we also demonstrate higher accuracy using a larger language model, RoBERTa-Large. We show up to 87\% accuracy for strict and up to 98\% accuracy for relaxed classification. (3) We develop a novel parallel link manager for the link prediction phase and demonstrate up to 21$\times$ speedup with 16 V100 GPUs relative to one V100 GPU, and thus reducing the runtime from 2.5 hours to 10 minutes. We believe that generalizability and scalability of \VWCBERT~ will benefit both the theoretical development and practical deployment of novel cyberdefense solutions and vulnerability classification.

Das, Siddhartha Shankar↗

Efficient Clustering of Software Vulnerabilities using Self Organizing Map (SOM)

The common vulnerabilities and exposures (CVE) database was created with a mission to ``identify, define, and catalog publicly disclosed cybersecurity vulnerabilities''. This rich body of information can be used to enable rapid and efficient response to secure and defend cyber operations and protect critical cyber infrastructure. The main goal of this paper is to develop a visual analytics tool to enable deep analysis of CVEs using unsupervised clustering techniques. We enhance our analysis by first mapping CVEs to hierarchical-classes in Common Weakness Enumeration (CWE) using information in the National Vulnerability Database (NVD). Both the mapping and the numerical representation of CVEs are enabled by V2W-BERT, which uses natural language processing of the extensive information in NVD to generate a large tabular database of 137,226 CVE entries from 1999 to 2020, where each CVE is represented by a vector of 768 numerical features. The vectorized data is processed by Self-Organizing Maps (SOM), which is an unsupervised machine learning technique for dimensionality reduction, visual representation and clustering. Using a Torus map of 6417 units, we achieve ~10-fold data compression of ~140k CVEs using SOM. The trained map is further clustered using standard K-means clustering into 138 clusters of CVEs. We conducted a brief investigation of the rich mapping of CVEs to best-matching-units to K-means clusters, as well as CVEs to CWEs. For example, this novel mapping provided insight into the role of CWE-59 and CWE-264 in several CVEs that is otherwise hard to explore in the original data. We conclude that our this novel approach will not only enable deep analysis of the complex relationships between CVEs and CWEs, but also a mechanism to quickly respond to and design mitigation actions for rapidly evolving vulnerabilities that have not been mapped to existing CWEs.

Panchal, Khyati↗

Grid Utility Asset Vulnerability Assessment (GUAVA) Software Tool

Increasing demand and changes in generation portfolios is pushing power grid to operate towards the limit. However, due to lack of analytical tools for understanding various scales of impact on grid, it is becoming more vulnerable to wide scale power outages and blackouts. A vulnerable grid operating at its limit can be easily disrupted by asset failures caused by devastating hurricanes which has been known to damage transmission and distribution lines along its track. In this direction, researchers have focused on determining these assets by conducting Monte Carlo simulations of hurricanes with uncertainties and collected a large set of simulation data. To determine the infrastructure updates necessary for mitigating wide scale impact of hurricanes on the grid, we propose a software tool named “Grid Utility Asset Vulnerability Analysis” (GUAVA) framework. GUAVA presents a novel data-driven probabilistic analytical approach to (1) post-process hurricane failure scenarios, (2) identify/rank assets that are most vulnerable and critical to failing and are associated with highest impact/risk, and (3) to inform system upgrade decisions & prioritization. Based on the observed results and employed data-driven methodology, it is expected GUAVA can be adapted to provide power system planners with a recommendation engine for making informed decisions to improve resilience of grid.

Mahapatra, Kaveri↗

V-INT: Automated Vulnerability Intelligence and Risk Assessment

The project team, including the University of Arkansas (UA) as the lead, the University of Arkansas at Little Rock (UALR), Network Perception (NP), and Bastazo, has successfully researched, developed, and demonstrated the V-INT toolset, and also integrated it into the commercial products of NP (i.e., NP-View) and Bastazo (i.e., Spartan). The end product is a cybersecurity software tool for energy utilities that can automatically assess the risks of software vulnerabilities in an organization’s assets considering the organization’s firewall policies. It allows security operators to identify the small portion of vulnerabilities that poses true threats to their system (i.e., those that are not protected by firewall policies) and prioritize the mitigation of these vulnerabilities to minimize risks. It also allows security operators to identify the vulnerability-induced attack paths under their organization’s firewall policy, providing effective decision supports for mitigating potential attacks.

97 MATHEMATICS AND COMPUTING↗

Mini Report: LLMs for Vulnerability Repair in Code

Software vulnerability repair is a notoriously difficult task that is both time consuming and labor intensive. While research into this area has a long history, the recent successes of large language models (LLMs) across many tasks have also spurred efforts to leverage LLM capabilities for automated software vulnerability repair. Currently, there are limitations in the capabilities of LLMs to fix bugs and insufficiently addressed problems in the evaluations of these studies may cause performance to not transfer when they are used in practice. Additionally, most research in the area treats finding and fixing bugs as separate concerns - how to best combine all the subtasks involved in removing vulnerabilities from code remains an open question. In this report, we summarize our findings and opinions on the current state of the art in LLM-assisted code vulnerability repair, highlighting current unresolved problems in the field as well as potential applications and future research.

97 MATHEMATICS AND COMPUTING↗

Mapping heat vulnerability in cities: A tale of two california cities

Extreme heat is a major cause of weather-related deaths in the United States. To address this, a heat vulnerability index (HVI) is crucial for assessing heat risk and identifying vulnerable urban areas and populations, supporting city planning and emergency response. Current HVI studies often use Principal Component Analysis (PCA) on environmental, socioeconomic, and medical data to aggregate vulnerability indicators into a single index. However, these fixed aggregation weights struggle to adapt to different use cases, which may require varying focuses. Moreover, existing tools primarily consider outdoor heat exposure, providing an incomplete picture of actual exposure, as people spend most of their time indoors. Our research introduces an HVI web mapping tool that addresses these gaps in the literature by: (1) allowing flexible weights to adapt to different use cases, and (2) uniquely integrating both outdoor and indoor heat exposure by considering building characteristics for a more comprehensive risk assessment. We demonstrated this tool in two California cities with contrasting climates: Fresno (inland, arid, hot summers) and Oakland (temperate coastal). This HVI mapping tool provides essential decision support for policymakers and stakeholders in both short-term heat mitigation and long-term urban planning for building interventions and infrastructure development.

BES↗

The role of height–driven constraints and compensations on tree vulnerability to drought

Frequent observations of higher mortality in larger trees than in smaller ones during droughts have sparked an increasing interest in size–dependent drought–induced mortality. However, the underlying physiological mechanisms are not well understood, with height–associated hydraulic constraints often being implied as the potential mechanism driving increased drought vulnerability. Here we performed a quantitative synthesis on how key traits that drive plant water and carbon economy change with tree height within species and assessed the implications that the different constraints and compensations may have on the interacting mechanisms (hydraulic failure, carbon starvation and/or biotic–agent attacks) affecting tree vulnerability to drought. While xylem tension increases with tree height, taller trees present a range of structural and functional adjustments, including more efficient water use and transport and greater water uptake and storage capacity, that mitigate the path–length–associated drop in water potential. These adaptations allow taller trees to withstand episodic water stress. Conclusive evidence for height–dependent increased vulnerability to hydraulic failure and carbon starvation, and their coupling to defence mechanisms and pest and pathogen dynamics, is still lacking. Further research is needed, particularly at the intraspecific level, to ascertain the specific conditions and thresholds above which height hinders tree survival under drought.

54 ENVIRONMENTAL SCIENCES↗

Identifying spatiotemporal patterns in opioid vulnerability: investigating the links between disability, prescription opioids and opioid-related mortality

Background: The opioid crisis remains one of the most daunting and complex public health problems in the United States. This study investigates the national epidemic by analyzing vulnerability profiles of three key factors: opioid-related mortality rates, opioid prescription dispensing rates, and disability rank ordered rates. Methods: This study utilizes county level data, spanning the years 2014 through 2020, on the rates of opioid-related mortality, opioid prescription dispensing, and disability. To successfully estimate and predict trends in these opioid-related factors, we augment the Kalman Filter with a novel spatial component. To define opioid vulnerability profiles, we create heat maps of our filter’s predicted rates across the nation’s counties and identify the hotspots. In this context, hotspots are defined on a year-by-year basis as counties with rates in the top 5% nationally. Results: Our spatial Kalman filter demonstrates strong predictive performance. From 2014 to 2018, these predictions highlight consistent spatiotemporal patterns across all three factors, with Appalachia distinguished as the nation’s most vulnerable region. Starting in 2019 however, the dispensing rate profiles undergo a dramatic and chaotic shift. Conclusions: The initial primary drivers of opioid abuse in the Appalachian region were likely prescription opioids; however, it now appears that abuse is sustained by illegal drugs. Additionally, we find that the disabled subpopulation may be more at risk of opioid-related mortality than the general population. Public health initiatives must extend beyond controlling prescription practices to address the transition to and impact of illicit drug use.

60 APPLIED LIFE SCIENCES↗

Vulnerabilities in Satellite Communications Underscore Threat to Critical Infrastructure

INL analysts assess critical infrastructure sectors leveraging satellite communications (SATCOM) are likely inadvertently increasing the attack surface caused by inherent vulnerabilities in equipment and communications pathways. A lack of ownership regarding security in SATCOM ecosystems creates pervasive information security risk, and the obfuscation of patching responsibility means the mitigation of publicly and privately disclosed vulnerabilities is difficult to track. With these factors in consideration, INL analysts assess the number of attacks against SATCOM is likely to increase in the next decade as threat actors exploit these vulnerabilities.

99 GENERAL AND MISCELLANEOUS↗

Social Vulnerability and Beacon Hill Resilience Hub Network [Slides]

Improving community resilience to climate change impacts is a core goal of the Beacon Hill stakeholder task force. Developing a network of resilience hubs in the community is a strategy the task force is pursuing to build this resilience. This technical assistance aims to assist the task force in their resilience hub network planning by: identifying hazards that the resilience hubs may address; providing background information on social vulnerability and climate impacts; identifying populations in Beacon Hill who are at risk to disproportionate climate impacts due to social isolation and physical vulnerability characteristics (e.g., lack of transportation or internet); and identifying the potential role of resilience hubs that align with best practices for reducing social vulnerability to climate impacts.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Blueprint: Coordinated Vulnerability Disclosure (CVD) Adoption for Information Sharing and Analysis Center (ISAC)-Like Groups

The electric vehicle supply equipment (EVSE) industry is an incredibly diverse set of participants (EVSE manufacturers, charge network operators (CNOs), original equipment manufacturers (OEMs), etc.), and with the potential for an Information Sharing and Analysis Centers (ISAC) or ISAC-like group, it requires a series of guidance for doing a multiparty coordinated vulnerability disclosure (CVD) such that a group like this could be successful. This blueprint provides a template and guidance to stakeholders in the EVSE industry for conducting a multiparty CVD. It also formalizes what multiparty CVD could look like in an ISAC-like group with multiple entities as well as vulnerability coordinators by specifically calling out who in the ISAC-like group may be involved, and which industry members it may apply to. This blueprint leverages tools such as Vultron, VINCE, etc. along with open resources such as the Software Engineering Institutes guide for coordinated vulnerability disclosure, for the stakeholder in the EVSE industry to start up a CVD program of their own.

97 MATHEMATICS AND COMPUTING↗

Climate Vulnerability Assessment and Resilience Planning for Idaho National Laboratory

Idaho National Laboratory’s (INL’s) mission is to discover, demonstrate, and secure innovative nuclear energy solutions, other clean energy options, and critical infrastructure. This INL’s Climate Vulnerability Assessment and Resilience Plan (VARP) was developed to enable and sustain that mission while ensuring the viability of operations considering expected climate change impacts. The VARP was developed according to the narrative requirements from the “Vulnerability Assessment and Resilience Planning Guidance, Version 1.2” document issued in February 2022. A prescribed process was used to identify mission-critical systems and components, determine historical and expected climate impacts, and develop resilient solutions. Experts from across INL, including operations staff, researchers, and climate scientists supplied input to the process. Analyses of climate modeling sources revealed that under scenarios of higher and lower greenhouse gas emissions (Representative Concentration Pathway (RCP) 4.5 and RCP 8.5), INL anticipates an increase in climate hazards, including drought, heat waves, wildfire, and precipitation. Increased frequency and duration of climatic hazards forecasts high impacts on certain mission-critical asset and infrastructure types. Utilizing the VARP Risk Assessment Tool, projected high climate hazard impacts across multiple asset and infrastructure types at the INL include energy generation and distribution systems, Site buildings, specialized or mission-critical equipment, and transportation and fleet infrastructure. Some of these mission-critical asset and infrastructure types maintain high adaptive capacity to climatic changes; however, others may need additional adaptive capacity to withstand increased frequency and duration of climate hazards. INL identified close to 300 resilient solutions that were consolidated into 11 solution categories to be tracked in the Department of Energy Sustainability Dashboard. The identified solutions are a starting point for future project development and analysis. These data are intended to inform decision makers on climate issues and potential solutions across INL and associated communities. The VARP is not intended to be a budget tool or project decision document on its own, but rather one of many tools used by decision makers to establish resilient priorities. This initial document provides the framework and foundation to resilient solutions. In the coming years, each solution needs to be fully developed, costed, and prioritized based on mission-critical risk and funding priorities.

54 ENVIRONMENTAL SCIENCES↗