Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Predicting Fire Season Severity in South America Using Sea Surface Temperature Anomalies

Fires in South America cause forest degradation and contribute to carbon emissions associated with land use change. Here we investigated the relationship between year-to-year changes in satellite-derived estimates of fire activity in South America and sea surface temperature (SST) anomalies. We found that the Oceanic Ni o Index (ONI) was correlated with interannual fire activity in the eastern Amazon whereas the Atlantic Multidecadal Oscillation (AMO) index was more closely linked with fires in the southern and southwestern Amazon. Combining these two climate indices, we developed an empirical model that predicted regional annual fire season severity (FSS) with 3-5 month lead times. Our approach provides the foundation for an early warning system for forecasting the vulnerability of Amazon forests to fires, thus enabling more effective management with benefits for mitigation of greenhouse gas and air pollutant emissions.

Chen, Yang↗

Safety-Critical Partitioned Software Architecture: A Partitioned Software Architecture for Robotic

The flight software on virtually every mission currently managed by JPL has several major flaws that make it vulnerable to potentially fatal software defects. Many of these problems can be addressed by recently developed partitioned operating systems (OS). JPL has avoided adopting a partitioned operating system on its flight missions, primarily because doing so would require significant changes in flight software design, and the risks associated with changes of that magnitude cannot be accepted by an active flight project. The choice of a partitioned OS can have a dramatic effect on the overall system and software architecture, allowing for realization of benefits far beyond the concerns typically associated with the choice of OS. Specifically, we believe that a partitioned operating system, when coupled with an appropriate architecture, can provide a strong infrastructure for developing systems for which reusability, modifiability, testability, and reliability are essential qualities. By adopting a partitioned OS, projects can gain benefits throughout the entire development lifecycle, from requirements and design, all the way to implementation, testing, and operations.

(Avionics Application Standard Software Interface ↗

Forecasting Fire Season Severity in South America Using Sea Surface Temperature Anomalies

Fires in South America cause forest degradation and contribute to carbon emissions associated with land use change. We investigated the relationship between year-to-year changes in fire activity in South America and sea surface temperatures. We found that the Oceanic Ni o Index was correlated with interannual fire activity in the eastern Amazon, whereas the Atlantic Multidecadal Oscillation index was more closely linked with fires in the southern and southwestern Amazon. Combining these two climate indices, we developed an empirical model to forecast regional fire season severity with lead times of 3 to 5 months. Our approach may contribute to the development of an early warning system for anticipating the vulnerability of Amazon forests to fires, thus enabling more effective management with benefits for climate and air quality.

Chen, Yang↗

Dust Hazard Management in the Outer Solar System

Most robotic missions to the outer solar system must grapple with the hazards posed by the dusty rings of the gas giants. Early assessments of these hazards led simply to ring avoidance due to insufficient data and high uncertainties on the dust population present in such rings. Recent approaches, principal among them the Cassini dust hazard management strategy, provide useful results from detailed modeling of spacecraft vulnerabilities and dust hazard regions, which along with the range of mission trajectories are used to to assess the risks posed by each passage through a zone of potential hazard. This paper shows the general approach used to implement the analysis for Cassini, with recommendations for future outer planet missions.

mission hazards↗

Digital Tools for the Preventive Conservation of Built Heritage: The Church of Santa Ana in Seville

Historic Building Information Modelling (HBIM) plays a pivotal role in heritage conservation endeavours, offering a robust framework for digitally documenting existing structures and supporting conservation practices. However, HBIM’s efficacy hinges upon the implementation of case-specific approaches to address the requirements and resources of each individual asset and context. This paper defines a flexible and generalisable workflow that encompasses various aspects (i.e., documentation, surveying, vulnerability assessment) to support risk-informed decision making in heritage management tailored to the peculiar conservation needs of the structure. This methodology includes an initial investigation covering historical data collection, metric and condition surveys and non-destructive testing. The second stage includes Finite Element Method (FEM) modelling and structural analysis. All data generated and processed are managed in a multi-purpose HBIM model. The methodology is tested on a relevant case study, namely, the church of Santa Ana in Seville, chosen for its historical significance, intricacy and susceptibility to seismic action. The defined level of detail of the HBIM model is sufficient to inform the structural analysis, being balanced by a more accurate representation of the alterations, through linked orthophotos and a comprehensive list of alphanumerical parameters. This ensures an adequate level of information, optimising the trade-off between model complexity, investigation time requirements, computational burden and reliability in the decision-making process. Field testing and FEM analysis provide valuable insight into the main sources of vulnerability in the building, including the connection between the tower and nave and the slenderness of the columns.

Chaves, Estefanía↗

Environmental Justice Needs Assessment for Disasters: Assessing the Landscape and Capacity of Organizations & Communities Working Towards Environmental Justice with Potential to Use NASA Earth Observations to Support Equitable Disaster Management and Risk Reduction

Natural disasters pose an increasing risk to communities worldwide. Marginalized populations, in particular, experience compounding vulnerabilities that contribute to unequal burdens of natural hazards as a result of systemic inequality stemming from historical disenfranchisement, disinvestment, and discriminatory policies such as racial redlining. This project connected with community organizations working at the intersection of environmental justice (EJ) and natural disaster management throughout the United States, to assess how NASA DEVELOP can leverage geospatial science to advance EJ efforts. Our team conducted a landscape analysis, which included a literature review, annotated bibliography, and identification of organizations working in EJ and disasters. We engaged EJ organizations in discussions to understand their current resources, challenges, and geospatial needs to inform how DEVELOP and NASA Applied Sciences can support their EJ and disaster work. Findings were compiled in a synthesis report and visualized in an ArcGIS StoryMap to showcase the work of EJ organizations, provide geospatial resources for them to explore, and provide examples of how remote sensing can be utilized in EJ and disasters work. The knowledge gained and end products created support the integration of EJ in future DEVELOP projects, and the expanded use of Earth observations by communities in support of a more just tomorrow.

Julianne Liu↗

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Security engineering: systems engineering of security through the adaptation and application of risk management

Information Technology (IT) Security Risk Management is a critical task in the organization, which must protect its resources and data against the loss of confidentiality, integrity, and availability. As systems become more complex and diverse, and more vulnerabilities are discovered while attacks from intrusions and malicious content increase, it is becoming increasingly difficult to manage IT security. This paper describes an approach to address IT security risk through risk management and mitigation in both the institution and in the project life cycle.

security↗

Scalable Asset Discovery, Vulnerability Scanning, and Penetration Testing for Remote Sites and Wireless Spectrums Utilizing an Embedded Linux Plug - PwniPlug and the Raspberry Pi B+ as a Sample Pen Test

All devices attached to the NASA KSC network are subject to security vulnerability scanning and/or penetration testing. In today's changing environment, vulnerable and/or unprotected systems can easily be overlooked. Systems that are not properly managed can become a potential threat to the operational integrity of our systems and networks. This includes all NASA (internal and external) information systems within NASA KSC Internet Protocol (IP) address space, and NASA KSC facilities. The Office of the Chief Information Officer (OCIO) recommends that all NASA Centers and information systems be subject to penetration testing on a regular interval in accordance with the guidelines identified by the National Institute of Standards and Technology (NIST). (ITS-HBK-2810.04-02A) Protecting information and equipment at NASA is an area of increasing concern. In addition to the CPU's on the network; Supervisory, Control and Data Acquisition (SCADA) systems are especially vulnerable because these systems have lacked standards, use embedded controllers with little computational power and informal software, are connected to physical processes, have few operators, and are increasingly also being connected to corporate networks. The scope of work is comprised of several individual components which together build upon previous work by Drew Branch, NASA KSC Intern. The Pwn Plug is the selected COTS (Commercial-Off-The-Shelf) device chosen to test simplification of mandatory IT Security tasks. The device will be utilized to provide services to NASA KSC and enable an assessment of infrastructure soundness and regulatory compliance in an efficient, economical, and business responsive manner. The Pwn Plug is designed as a pen testing appliance which provides a hardware platform that can support commercial penetration testing efforts at significantly reduced costs. The expected outcomes are: 1) External Penetration Testing, 2) Social Engineering, 3) Procedural Documentation, 4) Recommended Remediation Action Plan, 5) System Retest & Remediation Attestation and 6) Final Reports, out briefing and Presentation. Due to physical and material constraints beyond intern and mentor control, the project was redefined as a working pen-test scenario. Limitations of lab availability and tools dictated an academic exercise. This report was developed within the scenario guidelines suggested by the project mentor. The guidelines were to be creative in developing a Pen Test program for a client.

Penetration Testing↗

Tool for Human-Systems Integration Assessment: HSI Scorecard

This paper describes the development and rationale for a human-systems integration (HSI) scorecard that can be used in reviews of vehicle specification and design. This tool can be used to assess whether specific HSI related criteria have been met as part of a project milestone or critical event, such as technical reviews, crew station reviews, mockup evaluations, or even review of major plans or processes. Examples of HSI related criteria include Human Performance Capabilities, Health Management, Human System Interfaces, Anthropometry and Biomechanics, and Natural and Induced Environments. The tool is not intended to evaluate requirements compliance and verification, but to review how well the human related systems have been considered for the specific event and to identify gaps and vulnerabilities from an HSI perspective. The scorecard offers common basis, and criteria for discussions among system managers, evaluators, and design engineers. Furthermore, the scorecard items highlight the main areas of system development that need to be followed during system lifecycle. The ratings provide a repeatable quantitative measure to what has been often seen as only subjective commentary. Thus, the scorecard is anticipated to be a useful HSI tool to communicate review results to the institutional and the project office management.

Whitmore, Nihriban↗

Alaska's Changing Fire Regime - Implications for the Vulnerability of Its Boreal Forests

A synthesis was carried out to examine Alaska s boreal forest fire regime. During the 2000s, an average of 767 000 ha/year burned, 50% higher than in any previous decade since the 1940s. Over the past 60 years, there was a decrease in the number of lightning-ignited fires, an increase in extreme lightning-ignited fire events, an increase in human-ignited fires, and a decrease in the number of extreme human-ignited fire events. The fraction of area burned from humanignited fires fell from 26% for the 1950s and 1960s to 5% for the 1990s and 2000s, a result from the change in fire policy that gave the highest suppression priorities to fire events that occurred near human settlements. The amount of area burned during late-season fires increased over the past two decades. Deeper burning of surface organic layers in black spruce (Picea mariana (Mill.) BSP) forests occurred during late-growing-season fires and on more well-drained sites. These trends all point to black spruce forests becoming increasingly vulnerable to the combined changes of key characteristics of Alaska s fire regime, except on poorly drained sites, which are resistant to deep burning. The implications of these fire regime changes to the vulnerability and resilience of Alaska s boreal forests and land and fire management are discussed.

Kasischke, E. S.↗

Why Do People Make Mistakes?

Multitasking is endemic in modern life and work: drivers talk on cell phones, office workers type while answering phone calls, students do homework while text messaging, nurses prepare injections while responding to doctors calls, and air traffic controllers direct aircraft in one sector while handling additional traffic in another. Whether in daily life or at work, we are constantly bombarded with multiple, concurrent interruptions and demands and we have all somehow come to believe in the myth that we can, and in fact are expected to, easily address them all - without any repercussions. However, accumulating scientific evidence is now suggesting that multitasking increases the probability of human error. This talk presents a set of NASA studies that characterize concurrent demands in one work domain, routine airline cockpit operations, in order to illustrate the ways operational task demands together with the proclivity to manage them all concurrently make human performance in this and in any domain vulnerable to potentially serious errors and to accidents.

multitasking↗

Managing radiation degradation of CCDs on the Chandra X-ray Observatory II

The CCDs on the Chandra X-ray Observatory are vulnerable to radiation damage from low-energy protons scattered off the telescope's mirrors onto the focal plane. Following unexpected damage incurred early in the mission, the Chandra Team developed, implemented, and maintains a radiation-protection program. This program - involving scheduled radiation safing during radiation-belt passes, intervention based upon real-time space-weather conditions and radiation-environment modeling, and on-board radiation monitoring with autonomous radiation safing - has successfully managed the radiation damage to the CCDs. Since implementing the program, the charge-transfer inefficiency (CTI) has increased at an average annual rate of only 2.9x10^-6 (2.3%) for the front- illuminated CCDs and 0.95x10^-6 (6.5%) for the back-illuminated CCDs. This paper describes the current status of Chandra radiation-management program.

O'Dell, Stephen L.↗

Managing Radiation Degradation of CCDs on the Chandra X-Ray Observatory--III

The CCDs on the Chandra X-ray Observatory are vulnerable to radiation damage from low-energy protons scattered off the telescope's mirrors onto the focal plane. Following unexpected damage incurred early in the mission, the Chandra team developed, implemented, and maintains a radiation-protection program. This program--involving scheduled radiation safing during radiation-belt passes, intervention based upon real-time space-weather conditions and radiation-environment modeling, and on-board radiation monitoring with autonomous radiation safing--has successfully managed the radiation damage to the CCDs. Since implementing the program, the charge-transfer inefficiency (CTI) has increased at an average annual rate of only 3.2x 10(exp -6) (2.3 percent) for the front-illuminated CCDs and 1.0x10(exp -6) (6.7 percent) for the back-illuminated CCDs. This paper describes the current status of the Chandra radiation-management program, emphasizing enhancements implemented since the previous papers.

O'Dell, Stephen L.↗

Cognitive Engineering in Training: Monitoring and Pilot-Automation Coordination in Complex Environments

This paper reports our investigation of flight path monitoring in aviation. We interviewed experienced pilots to understand the knowledge and skills underlying effective monitoring and we developed an example learning environment to improve these skills. We explore how design of pilot training and learning, like the design of interfaces and of the underlying automation, benefits from cognitive engineering methods and perspective. In aviation, monitoring and managing flight path are critical activities. The influences on flight path are complex and come from the autoflight system, from control actions by the pilot, and from external factors, including weather and Air Traffic Control (ATC). Indeed, inadequate flight path monitoring is a current aviation concern as it has been implicated in accidents and incidents. Effective piloting depends on strategies for noticing, understanding, and anticipating these influences to monitor and manage flight path. Lack of such skills reduces pilots' ability to maintain safety margin and resilience. Although flightdeck automation is intended to aid pilot understanding and prediction, the Fight Management Systems (FMS) can mislead as well as aid the pilot's understanding and projection of what will happen. In dynamic conditions, FMS predictions may be based on old or incomplete information. Understanding such vulnerabilities is an important part of pilot-autoflight coordination. The learning environment we developed is designed to help pilots proactively monitor and manage flight path. We consider how a broad cognitive engineering approach might inform the "what" and "how" of learning in dynamic work domains.

pilot-monitoring↗

The Story of Multitasking

Multitasking is endemic in modern life and work: drivers talk on cell phones, office workers type while answering phone calls, students do homework while text messaging...but, nurses also prepare injections while responding to doctor's calls, and air traffic controllers direct aircraft in one sector while handling aircraft additional traffic in another. Whether in daily life or at work, we are constantly bombarded with multiple, concurrent interruptions and demands and we have all somehow come to believe in the myth that we can, and in fact are expected to, easily address them all - without any repercussions. Accumulating However, accumulating scientific evidence is now suggesting that multitasking increases the probability of human error. This talk presents a set of NASA studies that characterize concurrent demands in one work domain, routine airline cockpit operations, in order to illustrate the ways operational task demands together with the natural proclivity to manage them all concurrently make human performance in this and in any work domain vulnerable to potentially serious errors and to accidents.

Barshi, Immanuel↗

Blueprint: Coordinated Vulnerability Disclosure (CVD) Adaption and Adoption Guide for Industry To Create Their Own CVD Program

This guide provides a series of steps and guidance for electric vehicle supply equipment (EVSE) industry members to set up their own coordinated vulnerability disclosure (CVD) program by utilizing the Software Engineering Institute/Computer Emergency Response Team (SEI/CERT)’s CVD how-to guide. Due to the complexity of CVD, and with the existing resources out there, this guide is intended that this portion of the blueprint is an extension of the CVD how-to guide, not meant as a replacement. This guide is meant to outline a process for what to do when you discover a vulnerability on EVSE equipment. It is written for developers, vendors and security researchers as well as management. This is not a technical document. It is meant to be accessible for both technical and non-technical roles.

33 ADVANCED PROPULSION SYSTEMS↗

Fallible humans and vulnerable systems - Lessons learned from aviation

It is suggested that the problems being experienced in complex automatic systems are essentially due to the failure of information management and communication. The failure covers the entire spectrum: display devices and techniques, coding information so as to reduce human error, and information economy, i.e., resisting the temptation to bombard the operator with unlimited information simply because the system possesses the capability to do so. Since there has been great progress in hardware engineering, it is suggested that further attention is needed in the 'soft' side of systems. The approach should focus on (1) preventing human cognitive slips and (2) making the systems less vulnerable to such slips when they do occur. Most of the examples are taken from studies of cockpit automation.

Wiener, Earl L.↗