Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

The Nuclear System-of-Systems Capabilities Analytic Process

This dissertation discusses the impetus for, development of, and initial demonstration of NuSCAPTM: the Nuclear System-of-Systems Capabilities Analytic Process TM . NuSCAP is an approach executed via a Python® application that enables capabilities-based vulnerability analyses of military systems of systems (SOS) exposed to prompt nuclear weapon effects. The NuSCAP application calls on industry-standard, fast-running nuclear weapon effects tools and the Monte Carlo N-Particle®1 (MCNP®) code to evaluate the impact of nuclear weapon environments on the military capabilities of a complex and networked SOS.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Designing Resilience for Advanced Energy Systems

Advancements in energy technologies are making the grid more powerful, more efficient, and cleaner. As these promising innovations flourish across our communities, it is essential that our nation's infrastructure also becomes more resilient. Natural disasters, cyberattacks, user error, and a changing climate all present risks that could have devastating consequences. Individual emergencies are unique, but holistic planning and proactive measures can harden the grid and help anticipate and respond to any number of threats. The National Renewable Energy Laboratory (NREL) is at the forefront of this transition, establishing a vision for resilient energy systems today, and in the future.

energy disruption↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

MARVEL 90% Final Design Report

This document provides documentation of the Microreactor Applications Research Validation and Evaluation Project’s (MARVEL) 90% Final Design, as required by U.S. Department of Energy (DOE) Standard-1189, “Integration of Safety into the Design Process." Per DOE-STD-1189-2016, the 90% Final Design documentation focuses on design completion, at a level capable of supporting procurement, construction, testing, and operation. At this phase, the design organization finalizes the hazards and accident analyses, Fire Hazard Analysis (FHA), security vulnerability assessments, and other supporting analyses for design completion. The objective of this report is to provide a high-level summary of the design thus far and provide references including, but not limited to, the following design deliverables: • Complete final drawings, specifications and commercial grade dedications that may be released for bid and/or construction. • Clearly defined testing plans for the safety and functionality of all subsystems. • Quality Assurance Program for Design, Testing and Procurement. • Software Quality Assurance Plan. • Code of Record (COR), applicable design requirements including codes and standards. • Final design that meets all the requirements stipulated in the COR. • Final design review, consisting of final validation of comment resolution from previous reviews, and a review of any additional developments since the last review. • Updated Safety Design Strategy. • Hazard Analysis. • Fire Hazard Analysis. • Accident analysis. • Security vulnerability assessment. • Current and detailed cost estimate. • Current construction schedule, and • Risk & Opportunities Assessment.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Proteo-Genomic Analysis Identifies Two Major Sites of Vulnerability on Ebolavirus Glycoprotein for Neutralizing Antibodies in Convalescent Human Plasma

Three clinically relevant ebolaviruses – Ebola (EBOV), Bundibugyo (BDBV), and Sudan (SUDV) viruses, are responsible for severe disease and occasional deadly outbreaks in Africa. The largest Ebola virus disease (EVD) epidemic to date in 2013-2016 in West Africa highlighted the urgent need for countermeasures, leading to the development and FDA approval of the Ebola virus vaccine rVSV-ZEBOV (Ervebo ® ) in 2020 and two monoclonal antibody (mAb)-based therapeutics (Inmazeb ® [atoltivimab, maftivimab, and odesivimab-ebgn] and Ebanga ® (ansuvimab-zykl) in 2020. The humoral response plays an indispensable role in ebolavirus immunity, based on studies of mAbs isolated from the antibody genes in peripheral blood circulating ebolavirus-specific human memory B cells. However, antibodies in the body are not secreted by circulating memory B cells in the blood but rather principally by plasma cells in the bone marrow. Little is known about the protective polyclonal antibody responses in convalescent plasma. Here we exploited both single-cell antibody gene sequencing and proteomic sequencing approaches to assess the composition of the ebolavirus glycoprotein (GP)-reactive antibody repertoire in the plasma of an EVD survivor. We first identified 1,512 GP-specific mAb variable gene sequences from single cells in the memory B cell compartment. Using mass spectrometric analysis of the corresponding GP-specific plasma IgG, we found that only a portion of the large B cell antibody repertoire was represented in the plasma. Molecular and functional analysis of proteomics-identified mAbs revealed recognition of epitopes in three major antigenic sites - the GP head domain, the glycan cap, and the base region, with a high prevalence of neutralizing and protective mAb specificities that targeted the base and glycan cap regions on the GP. Polyclonal plasma antibodies from the survivor reacted broadly to EBOV, BDBV, and SUDV GP, while reactivity of the potently neutralizing mAbs we identified was limited mostly to the homologous EBOV GP. Together these results reveal a restricted diversity of neutralizing humoral response in which mAbs targeting two antigenic sites on GP – glycan cap and base – play a principal role in plasma-antibody-mediated protective immunity against EVD.

59 BASIC BIOLOGICAL SCIENCES↗

Kentucky Disasters: Multi-Hazard Approach to Mapping Flood Susceptibility and Vulnerability in Kentucky

Flooding is the most common and costly natural disaster in Kentucky, with major flood events in 2022 and 2023 highlighting the need for flood risk assessment. In partnership with the National Weather Service Jackson and Paducah Forecast Offices and the Kentucky Climate Center, we mapped flood risk in Kentucky using a multi-hazard approach that considered two dimensions of risk: flood susceptibility based on a weighted combination of seven physical factors and flood vulnerability based on 13 socioeconomic and infrastructure factors. We additionally analyzed NASA Soil Moisture Active Passive (SMAP) observations of surface soil moisture to explore the utility of SMAP observations for future analysis of flood risk. By analyzing flood susceptibility, we found that with equal rainfall, western Kentucky generally displays a higher propensity to flood than eastern Kentucky. In contrast, our flood vulnerability analysis indicated that more vulnerable areas were generally concentrated in the eastern part of the state. Through a combined perspective, our flood risk analysis identified much of the state as having moderate degrees of flood susceptibility and vulnerability. Our parallel analysis of antecedent soil moisture found that SMAP soil moisture levels were variable in the months leading up to each flood event but were drier than normal in the month prior to the 2023 event, as shown by negative soil moisture anomalies. These results were limited by challenges with weighting input parameters and a lack of validation but overall demonstrate the feasibility of using GIS and Earth observations for mapping flood risk and soil moisture.

analytic hierarchy process↗

Freddie Software Security Patching

Software applications become more complicated over time as they depend on many third-party, open-source libraries. The Freddie Platform Services team actively improves software security by addressing software bugs and vulnerabilities that negatively impact software applications, especially those providing real-time operations and services for the federal partners and industries. In order to detect bugs and patch vulnerabilities in software development and maintenance cycles, an automated and systematic approach is needed. This document describes what bugs and vulnerabilities are, and how they can be detected by using static code analyzers and software composition analysis tools. Once vulnerabilities are detected, the patching approaches, such as upgrading direct and transitive dependencies and loading custom classes first, are presented together with their strengths and weaknesses. In addition, patching walkthrough, example code, lessons learned throughout the vulnerability patching process and the recommended practices are discussed.

Chok Fung Lai↗

Comparing multi-source urban flood indicators: satellite, simulation, and citizen-reported data

Urban flooding arises from complex mechanisms, making it challenging to capture accurately with a single detection method. This study evaluates three complementary approaches to detect flooding across three Chicago neighborhoods: (i) Sentinel-1 synthetic aperture radar (SAR), offering weather-independent, high-resolution (10 m) imagery of surface inundation; (ii) the storm water management model (SWMM), simulating combined sewer overflow and drainage performance; and (iii) citizen-generated 311 service requests, capturing observed flooding impacts. By analyzing six storms ranging from severe to mild, we examine how each source uniquely contributes to identifying urban flood events. SAR imagery effectively identifies standing water but can miss brief flooding due to satellite revisit constraints. SWMM provides detailed insights into system-wide drainage behavior yet may underestimate localized street-level flooding. Meanwhile, 311 calls reflect real-world flooding impacts but are vulnerable to underreporting. Statistical overlap analysis highlights chronic flood hotspots repeatedly identified across multiple detection methods, indicating persistent infrastructure and topographic vulnerabilities. Temporal analysis further reveals that while SWMM flooding aligns closely with rainfall peaks, 311 calls typically precede or persist beyond these peaks. Our findings emphasize the value of using satellite observations, hydrological modeling, and resident-reported data in a complementary manner to better interpret patterns in flood timing, severity, and spatial distribution—providing insights that can inform targeted infrastructure improvements and contribute to urban flood resilience planning.

311↗

Historical Power Outages of the United States and the Social Vulnerability Index

Several works have been documented in the literature to study the societal effect of power outages and to analyze their correlation with the Social Vulnerability Index (SVI). Because the SVI is calculated based on the summed rank of multiple vulnerability factors for environmental hazards, it can include factors irrelevant to power outages caused by extreme events. This work performs a detailed correlation analysis for social vulnerability and power outages by considering different SVI themes (e.g., socioeconomic status, household composition, racial and ethnic minority status, and housing and transportation) and power outages with and without a threshold for extreme weather events. Although there is some relation between specific themes and aspects of power outages and the SVI in the results, there is no strong distinction between power outage durations and low vs. high SVI values. These results point to the need for further research that grounds the specific factors and methods used to develop SVI and related indices to energy services and power systems disruptions.

Bhusal, Narayan↗

Vulnerabilities, Influences and Interaction Paths: Failure Data for Integrated System Risk Analysis

We describe graph-based analysis methods for identifying and analyzing cross-subsystem interaction risks from subsystem connectivity information. By discovering external and remote influences that would be otherwise unexpected, these methods can support better communication among subsystem designers at points of potential conflict and to support design of more dependable and diagnosable systems. These methods identify hazard causes that can impact vulnerable functions or entities if propagated across interaction paths from the hazard source to the vulnerable target. The analysis can also assess combined impacts of And-Or trees of disabling influences. The analysis can use ratings of hazards and vulnerabilities to calculate cumulative measures of the severity and importance. Identification of cross-subsystem hazard-vulnerability pairs and propagation paths across subsystems will increase coverage of hazard and risk analysis and can indicate risk control and protection strategies.

Malin, Jane T.↗

Security Vulnerability Profiles of NASA Mission Software: Empirical Analysis of Security Related Bug Reports

NASA develops, runs, and maintains software systems for which security is of vital importance. Therefore, it is becoming an imperative to develop secure systems and extend the current software assurance capabilities to cover information assurance and cybersecurity concerns of NASA missions. The results presented in this report are based on the information provided in the issue tracking systems of one ground mission and one flight mission. The extracted data were used to create three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified the software bugs that are security related and classified them in specific security classes. This information was then used to create the security vulnerability profiles (i.e., to determine how, why, where, and when the security vulnerabilities were introduced) and explore the existence of common trends. The main findings of our work include:- Code related security issues dominated both the Ground and Flight mission IVV security issues, with 95 and 92, respectively. Therefore, enforcing secure coding practices and verification and validation focused on coding errors would be cost effective ways to improve mission's security. (Flight mission Developers issues dataset did not contain data in the Issue Category.)- In both the Ground and Flight mission IVV issues datasets, the majority of security issues (i.e., 91 and 85, respectively) were introduced in the Implementation phase. In most cases, the phase in which the issues were found was the same as the phase in which they were introduced. The most security related issues of the Flight mission Developers issues dataset were found during Code Implementation, Build Integration, and Build Verification; the data on the phase in which these issues were introduced were not available for this dataset.- The location of security related issues, as the location of software issues in general, followed the Pareto principle. Specifically, for all three datasets, from 86 to 88 the security related issues were located in two to four subsystems.- The severity levels of most security issues were moderate, in all three datasets.- Out of 21 primary security classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, these classes contributed from around 80 to 90 of all security issues in each dataset. This again proves the Pareto principle of uneven distribution of security issues, in this case across CWE classes, and supports the fact that addressing these dominant security classes provides the most cost efficient way to improve missions' security. The findings presented in this report uncovered the security vulnerability profiles and identified the common trends and dominant classes of security issues, which in turn can be used to select the most efficient secure design and coding best practices compiled by the part of the SARP project team associated with the NASA's Johnson Space Center. In addition, these findings provide valuable input to the NASA IVV initiative aimed at identification of the two 25 CWEs of ground and flight missions.

vulnerability↗

Blueprint: Coordinated Vulnerability Disclosure (CVD) Adoption for Information Sharing and Analysis Center (ISAC)-Like Groups

The electric vehicle supply equipment (EVSE) industry is an incredibly diverse set of participants (EVSE manufacturers, charge network operators (CNOs), original equipment manufacturers (OEMs), etc.), and with the potential for an Information Sharing and Analysis Centers (ISAC) or ISAC-like group, it requires a series of guidance for doing a multiparty coordinated vulnerability disclosure (CVD) such that a group like this could be successful. This blueprint provides a template and guidance to stakeholders in the EVSE industry for conducting a multiparty CVD. It also formalizes what multiparty CVD could look like in an ISAC-like group with multiple entities as well as vulnerability coordinators by specifically calling out who in the ISAC-like group may be involved, and which industry members it may apply to. This blueprint leverages tools such as Vultron, VINCE, etc. along with open resources such as the Software Engineering Institutes guide for coordinated vulnerability disclosure, for the stakeholder in the EVSE industry to start up a CVD program of their own.

97 MATHEMATICS AND COMPUTING↗

Highly silanized cellulose biocomposites for sustainable insulation materials

Microfibrillated lignocellulose networks, derived from agricultural byproducts, represent an environmentally friendly biogenic material production due to their abundant availability to circular bioeconomy and inherent carbon sink in life cycle analysis. Yet, its vulnerability to moisture and flammability, coupled with challenges in creating highly reinforced insulation materials, poses challenges for the carbon-zero green building sector. Here we address these challenges with a new concept of in-situ grafting polymerization of nanoporous silica in pre-formed lignocellulosic fiber networks. The seamlessly integrating nanoporous silica with cellulose through hydrogen bonding networks enabled us to prepare highly reinforced biogenic composites for green building insulations. A high reinforcement biocomposite with hierarchal arrangements of nanoporous silica within the cellulose network exhibits remarkable attributes. It boasts a thermal conductivity of 24.2 mW·m –1 ·K –1 , a flexural modulus of 942 MPa, and soundproofing with a 20.8 % noise reduction, as well as the fire resistance characterized by an extended time to ignition and a reduced peak heat release rate of 144 kW·m –2 at 35 kW·m –2 of incident radiant heat flux. Furthermore, it demonstrates a reduced water absorption capacity, dropping from 5.12 g·g –1 to 0.75 g·g –1 . Altogether, this study opens the new pathways towards sustainable carbon-zero building materials in the context of circular bioeconomy.

36 MATERIALS SCIENCE↗

Gene-by-environment interactions influence the fitness cost of gene copy-number variation in yeast

Abstract Variation in gene copy number can alter gene expression and influence downstream phenotypes; thus copy-number variation provides a route for rapid evolution if the benefits outweigh the cost. We recently showed that genetic background significantly influences how yeast cells respond to gene overexpression, revealing that the fitness costs of copy-number variation can vary substantially with genetic background in a common-garden environment. But the interplay between copy-number variation tolerance and environment remains unexplored on a genomic scale. Here, we measured the tolerance to gene overexpression in four genetically distinct Saccharomyces cerevisiae strains grown under sodium chloride stress. Overexpressed genes that are commonly deleterious during sodium chloride stress recapitulated those commonly deleterious under standard conditions. However, sodium chloride stress uncovered novel differences in strain responses to gene overexpression. West African strain NCYC3290 and North American oak isolate YPS128 are more sensitive to sodium chloride stress than vineyard BC187 and laboratory strain BY4743. Consistently, NCYC3290 and YPS128 showed the greatest sensitivities to overexpression of specific genes. Although most genes were deleterious, hundreds were beneficial when overexpressed—remarkably, most of these effects were strain specific. Few beneficial genes were shared between the sodium chloride-sensitive isolates, implicating mechanistic differences behind their sodium chloride sensitivity. Transcriptomic analysis suggested underlying vulnerabilities and tolerances across strains, and pointed to natural copy-number variation of a sodium export pump that likely contributes to strain-specific responses to overexpression of other genes. Our results reveal extensive strain-by-environment interactions in the response to gene copy-number variation, raising important implications for the accessibility of copy-number variation-dependent evolutionary routes under times of stress.

60 APPLIED LIFE SCIENCES↗

Fail-Safe Logic Design Strategies Within Modern FPGA Architectures

Fail-safe computing refers to computing systems that revert to a non-operational safe state when a fault occurs. In this paper, we investigate a circuit level technique as mitigation for single event upsets (SEUs) and fault injection attacks on field programmable gate arrays (FPGAs), and analyze the effectiveness of the technique as a fail-safe monitor for an encryption algorithm. The propagation of fault effects through FPGA primitives including lookup tables (LUTs) and programmable interconnect points (PIPs) is assessed within an FPGA architecture created using an open source tool, and validated using fault injection experiments on an FPGA. The analysis reveals additional vulnerabilities exist within reconfigurable architectures over those in equivalent fail-safe application specific integrated circuit (ASIC), thus requiring a more elaborate network of redundant circuits and checking logic. The configuration memory bits (CMBs), which configure routing and designate logic functions within the LUTs of the FPGA, add complexity to fail-safe design strategies by introducing additional fault conditions and fault propagation paths. A resource-efficient fail-safe circuit design technique called DEsign for Fail-safe in reCONfigurable systems (DEFCON) is proposed. The benefits and limitations associated with DEFCON are described in the context of fault injection experiments carried out as simulations and in FPGA hardware.

Bhakta, Priya A. [Univ. of New Mexico, Albuquerque↗

Residential Building Stock Characterization in Palm Beach County, Florida

This building stock characterizations is intended to help Palm Beach County (PBC) Office of Resilience (OOR) and municipalities composing the Municipal Resilience Partnership prioritize building energy efficiency investments to reduce energy costs and increase resilience for the county's most vulnerable residents. The analysis utilizes NREL’s ResStock model to characterize PBC’s residential building stock, including building type, renter/owner status, size (square footage), age of buildings (vintage), HVAC system types, and, for multi-family buildings, number of units. Building energy efficiency, weatherization, and electrification upgrade packages were assessed for approximate cost, customer bill-savings, and emissions reductions potential and findings will help guide OOR financial assistance program design.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗