Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “vulnerability analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Q-Learning Based Impact Assessment of Propagating Extreme Weather on Distribution Grids: Preprint

Increasing number of power outage events due to extreme weather condition is hampering us socioeconomically. Preparing in advance for the extreme weather event is critical and can help utility operators to reduce grid damages, restore grid service quickly, allocate energy resources and repair crews strategically, and hence dramatically increase grid resilience. In this paper, we propose a method to identify the sequence of worst impact zones in the power grid caused by extreme weather events based on Q-learning (a reinforcement learning algorithm). To quantify weather severity and it’s effect on the grid, we model the impact of extreme weather on the grid as a function of intensity, vulnerability and exposure. A modified IEEE 123-node distribution feeder is presented in a mesh grid and experimented for sequences of zones identification. Finally, simulation results present the identified sequences and their associated impacts on the grid caused by the extreme weather events.

distribution system↗

ProvSec: Open Cybersecurity System Provenance Analysis Benchmark Dataset with Labels

System provenance forensic analysis has been studied by a large body of research work. This area needs fine granularity data such as system calls along with event fields to track the dependencies of events. While prior work on security datasets has been proposed, we found a useful dataset of realistic attacks and details that are needed for high-quality provenance tracking is lacking. We created a new dataset of eleven vulnerable cases for system forensic analysis. It includes the full details of system calls including syscall parameters. Realistic attack scenarios with real software vulnerabilities and exploits are used. For each case, we created two sets of benign and adversary scenarios which are manually labeled for supervised machine-learning analysis. In addition, we present an algorithm to improve the data quality in the system provenance forensic analysis. We demonstrate the details of the dataset events and dependency analysis of our dataset cases.

97 MATHEMATICS AND COMPUTING↗

Deciphering Discrepancies: A Comparative Analysis of Docker Image Security

As the use of microservices continues to grow and become a foundational approach to architecting software solutions, ensuring the security of microservices is paramount. Docker images have emerged as the predominant solution to containerize microservices–and thus, Docker images are becoming a large attack surface. Thus, reducing vulnerabilities in Docker images will reduce microservice cyberattacks. A common way to find vulnerabilities in Docker images employs static analysis tools like Trivy and Grype. However, these tools frequently generate disparate vulnerability reports when analyzing the same Docker image, thus causing uncertainty in tool selection. We collected 927 Docker images, analyzed them with Trivy and Grype, and compared the vulnerabilities reported in each image. Among the 865 images found to have vulnerabilities, Trivy and Grype disagreed on both the number of vulnerabilities and the vulnerability IDs found therein. Since both tools interface with external vulnerability databases, some discrepancies can be attributed to how the tools interface with these external resources. The external vulnerability databases partially overlap and frequently contradict one another, thereby creating challenges for static analysis tool developers and end users alike. This New Ideas and Emerging Results (NIER) study contains new and critical information that practitioners need for selecting and using static analysis tools–given that increases in the use of Docker technologies means increases in the size of the attack surfaces.

Boles, Brittany [Montana State University]↗

An Analysis of Post Attack Impacts and Effects of Learning Parameters on Vulnerability Assessment of Power Grid

Due to the increasing number of heterogeneous devices connected to electric power grid, the attack surface increases the threat actors. Game theory and machine learning are being used to study the power system failures caused by external manipulation. Most of existing works in the literature focus on one-shot process of attacks and fail to show the dynamic evolution of the defense strategy. In this paper, we focus on an adversarial multistage sequential game between the adversaries of the smart electric power transmission and distribution system. We study the impact of exploration rate and convergence of the attack strategies (sequences of action that creates large scale blackout based on the system capacity) based on the reinforcement learning approach. We also illustrate how the learned attack actions disrupt the normal operation of the grid by creating transmission line outages, bus voltage violations, and generation loss. This simulation studies are conducted on IEEE 9 and 39 bus systems. The results show the improvement of the defense strategy through the learning process. The results also prove the feasibility of the learned attack actions by replicating the disturbances created in simulated power system.

attack impacts↗

The vulnerability of electric equipment to carbon fibers of mixed lengths: An analysis

The susceptibility of a stereo amplifier to damage from a spectrum of lengths of graphite fibers was calculated. A simple analysis was developed by which such calculations can be based on test results with fibers of uniform lengths. A statistical analysis was applied for the conversation of data for various logical failure criteria.

Elber, W.↗

PathTrace and MPVEASI: A Path Analysis Comparative Validation Study

Developed in 2018, PathTrace is a software package built with the intention of making path analysis simple and intuitive. PathTrace is a top-down pathway analysis software where a user is able to explore vulnerable pathways into a facility. The intention of utilizing a software tool like PathTrace is to characterize an existing physical protection system (PPS) and to upgrade the system to achieve a high level of response interruption, or probability of interruption (P I ) of the adversary. There are four steps for conducting path analysis using PathTrace. The first step is to identify an image to use to build the model and scale the model within PathTrace using a section of known distance (wall or fence perimeter, for example). The scaling process will produce a grid of cells through which the user is able to build a model. The second step is to fill out the grid of cells with four categories of materials: Barriers, Detection Areas, Jumps, and Targets. These materials apply associated delay and detection values to the cells in which they are applied. The third step is to represent the adversary and response forces. The adversaries are represented by their capabilities in interacting with the materials identified in step two, and the response is represented by how quickly they will be able to respond to an adversary attack. Finally, the user is able to take all of the information from the previous three steps and perform a Most Vulnerable Path (MVP) analysis. In this stage, the user is able to visualize vulnerable adversary pathways and reason about how to upgrade these pathways to provide a high level of P I .

97 MATHEMATICS AND COMPUTING↗

An Extreme-Value Approach to Anomaly Vulnerability Identification

The objective of this paper is to present a method for importance analysis in parametric probabilistic modeling where the result of interest is the identification of potential engineering vulnerabilities associated with postulated anomalies in system behavior. In the context of Accident Precursor Analysis (APA), under which this method has been developed, these vulnerabilities, designated as anomaly vulnerabilities, are conditions that produce high risk in the presence of anomalous system behavior. The method defines a parameter-specific Parameter Vulnerability Importance measure (PVI), which identifies anomaly risk-model parameter values that indicate the potential presence of anomaly vulnerabilities, and allows them to be prioritized for further investigation. This entails analyzing each uncertain risk-model parameter over its credible range of values to determine where it produces the maximum risk. A parameter that produces high system risk for a particular range of values suggests that the system is vulnerable to the modeled anomalous conditions, if indeed the true parameter value lies in that range. Thus, PVI analysis provides a means of identifying and prioritizing anomaly-related engineering issues that at the very least warrant improved understanding to reduce uncertainty, such that true vulnerabilities may be identified and proper corrective actions taken.

Everett, Chris↗

Wichita Climate II: Quantifying and Mapping Urban Heat to Inform Equitable and Sustainable Urban Planning Initiatives in Wichita, Kansas

Wichita, Kansas is experiencing a host of climate threats, particularly extreme heat manifested through Urban Heat Islands (UHI). Heat is unevenly distributed within cities due to factors such as income inequality, historical discriminatory practices like redlining, and divestment in neighborhoods of color. This leads to less vegetation and more heat-absorbing infrastructure in specific communities. Moreover, adverse effects of heat, including heat-related morbidity and mortality, disproportionately impact populations that experience vulnerability through social inequities and structural discrimination. Heat vulnerability is a combination of the factors of heat exposure, sensitivity, and adaptive capacity, and can be harnessed to guide urban heat interventions. This DEVELOP project partnered with the City of Wichita to understand the spatial distribution and drivers of UHIs and heat vulnerability indicators. The team modeled outcomes of tree cover interventions using Landsat 8’s Thermal Infrared Sensor (TIRS) and Operational Land Imager (OLI), Landsat 9 TIRS-2 and OLI-2, and the International Space Station’s Ecosystem Spaceborne Thermal Radiometer Experiment on the International Space Station (ECOSTRESS) sensor, along with the Integrated Valuation of Ecosystem Services and Tradeoffs (InVEST) Urban Cooling model. The team also leveraged statistical analysis by implementing principal component analysis to develop a heat vulnerability index (HVI) specific to Wichita. Ultimately, the project’s outputs will inform the City of Wichita’s Climate Adaptation and Mitigation Plan, identify priority areas for heat mitigation initiatives, and be used in public-facing communications to educate communities on the impacts of urban heat.

Environmental Justice↗

Utilizing Airborne and Space-Based Remote Sensing Imagery to Implement the Unvegetated-Vegetated Ratio to Assess Salt Marsh Vulnerability in South Carolina

Among the most productive ecosystems on earth, salt marshes provide crucial ecosystem services including water filtration, shoreline protection, storm surge buffering, and flood mitigation. Marshes are largely dependent on their sediment budget which can significantly vary across a region and can be used to determine the life span of the marsh. Upstream land use change near Charleston, South Carolina, along with rising sea levels, are expected to alter sediment budgets and threaten marsh stability and long-term health. The unvegetated-vegetated ratio (UVVR), developed by researchers at USGS, is a scalable and efficient method to assess vulnerability. The NASA DEVELOP National Program collaborated with the South Carolina Department of Natural Resources, the South Carolina Department of Health and Environmental Control, and the United States Geological Survey Woods Hole Coastal and Marine Science Center to apply the UVVR method within Google Earth Engine. Marsh vulnerability was analyzed using UVVR derived from clustering and manual interpretation of National Agriculture Imagery Program (NAIP) high-resolution aerial imagery. NAIP derived UVVR was aggregated to Landsat 8 Operational Land Imager (OLI) and Landsat 7 Enhanced Thematic Mapper (ETM+) resolution and projection. A Random Forest Regression between Landsat derived data and UVVR was modeled to estimate a potential relationship. The estimation of this relationship was used to produce temporal change analysis maps of salt marsh vulnerability back to 1984. The NAIP imagery processed through Google Earth Engine allowed us to make detailed UVVR maps for 2009, 2015, 2017, and 2019 for decision making within South Carolina. Google Earth Engine scripting provided a novel approach to UVVR methodology that will allow decision makers to input new marsh regions and easily calculate marsh vulnerability without external data downloading. These results were used to understand what areas of the marsh need most resource allocation in the future.

NASA DEVELOP↗

Considering Risk and Resilience in Decision-Making

This paper examines the concepts of decision-making, risk analysis, uncertainty and resilience analysis. The relation between risk, vulnerability, and resilience is analyzed. The paper describes how complexity, uncertainty, and ambiguity are the most critical factors in the definition of the approach and criteria for decision-making. Uncertainty in its various forms is what limits our ability to offer definitive answers to questions about the outcomes of alternatives in a decision-making process. It is shown that, although resilience-informed decision-making would seem fundamentally different from risk-informed decision-making, this is not the case as resilience-analysis can be easily incorporated within existing analytic-deliberative decision-making frameworks.

Torres-Pomales, Wilfredo↗

A Novel Framework for Parametric Analysis of Coastal Transition Zone Modeling

Abstract Vulnerability of coastal regions to extreme events motivates an operational coupled inland‐coastal modeling strategy focusing on the coastal transition zone (CTZ), an area between the coast and upland river. To tackle this challenge, we propose a top‐down framework for investigating the contribution of different processes to the hydrodynamics of CTZs with various geometrical shapes, different physical properties, and under several forcing conditions. We further propose a novel method, called tidal vanishing point (TVP), for delineating the extent of CTZs through the upland. We demonstrate the applicability of our framework over the United States East and Gulf coasts. We categorize CTZs in the region into three classes, namely, without estuary (direct river–coast connection), triangular‐, and trapezoidal‐shaped estuary. The results show that although semidiurnal tidal constituents are dominant in most cases, diurnal tidal constituents become more prevalent in the river segment as the discharge increases. Also, decreasing the bed roughness value promotes more significant changes in the results than increasing it by the same value. Additionally, the estuary promotes tidal energy attenuation and consequently decreases the reach of tidal signals through the upland. The proposed framework is generic and extensible to any coastal region.

Chegini, Taher↗

Large-Scale Hydrogen Storage Cyber Risk Assessment

Hydrogen storage systems may become more widely deployed throughout the country, and so it is possible that individual and interconnected systems will be exposed to cyber-attacks. These events can cause physical and financial harm to employees, people in the vicinity of the facility, and the company that owns the facility. The two main ways bad actors may access information or control from a hydrogen storage facility are through information technology and operations technology devices, the former of which refers to data and information from networked devices and the latter of which refers to onsite controls for the physical system. Both types of entryways into the system should be considered when companies conduct cyber risk assessments and when regulators develop or revise relevant codes and standards. This report analyzes cybersecurity risks associated with a generic hydrogen storage system by outlining the system's purpose and the importance of its cybersecurity. The hydrogen storage system architecture and communication protocols are provided to understand potential cyber vulnerabilities. Later, an event tree analysis is performed on hydrogen operation to identify system weaknesses by outlining potential attack scenarios. This report also identifies critical cyber assets related to different hydrogen operations followed by an examination of potential threats, and the impact of cyber assets on those operational assets.

08 HYDROGEN↗

Large-Scale Hydrogen Storage Cyber Risk Assessment

Hydrogen storage systems are becoming more widely deployed throughout the country, and as their presence continues to grow, it is possible that individual and interconnected systems will be exposed to cyber-attacks. These events can cause physical and financial harm to employees, people in the vicinity, and to the company that owns the facility. The two main mechanisms malicious actors may access information or control from a hydrogen storage facility are through information technology and operations technology devices, the former of which refers to data and information from networked devices and the latter of which refers to onsite controls for the physical system. Both types of entryways into the system should be considered when facility managers conduct cyber risk assessments and when regulators develop or revise relevant codes and standards. This report analyzes cybersecurity risks applicable to a wide variety of hydrogen storage systems by outlining the system's purpose and the importance of its cybersecurity. The hydrogen storage system architecture and communication protocols are provided to understand potential cyber vulnerabilities. Later, an event tree analysis is performed on hydrogen operation to identify system weaknesses by outlining potential attack scenarios. This report also identifies critical cyber assets related to different hydrogen operations followed by an examination of potential threats, and the impact of cyber assets on those operational assets.

08 HYDROGEN↗

Yonkers Urban Development: Utilizing NASA Earth Observations to Identify Environmental and Social Drivers of Urban Heat Vulnerability and Model Urban Cooling Interventions in Yonkers, New York

The City of Yonkers, New York, is located directly north of the Bronx in Westchester County and currently hosts a population of nearly 200,000. In response to increasing hot-weather episodes, the risk of heat-related illnesses and mortality is disproportionately affecting neighborhoods in Yonkers historically subjected to race-based housing segregation. NASA DEVELOP collaborated with Groundwork Hudson Valley to determine regions within Yonkers that are experiencing the most intense urban heat island effects, identify and rank sociodemographic and environmental determinants of increasing community-level vulnerability, map these vulnerabilities as a combined vulnerability index, complete a proximity analysis of walkability to local cooling centers and health facility locations, and model potential cooling strategies. The study area consisted of Yonkers, NY and the analyses used data from 2015-2020 (June through August). The project utilized NASA Earth observation products including Landsat 4 and 5 Thematic Mapper (TM), Landsat 7 Enhanced Thematic Mapper Plus (ETM+), Landsat 8 Operational Land Imager (OLI) and Thermal Infrared Sensor (TIRS), Terra Advanced Spaceborne Thermal Emission and Reflection Radiometer (ASTER), and ECOsystem Spaceborne Thermal Radiometer Experiment on Space Station (ECOSTRESS). We assessed the benefits of different heat-mitigation scenarios by utilizing the Integrated Valuation of Ecosystem Services and Tradeoffs (InVEST) urban cooling model. Results from these analyses can be used by Groundwork Hudson Valley, supporting the New York State’s Climate Safe Communities Certifiable Planning Actions, expanding knowledge on the relationship between historic redlining and environmental equity, and informing their Climate Safe Neighborhoods initiative to identify and prioritize mitigation efforts to abate the worst impacts of extreme heat.

Jillian Walechka↗

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN↗

Automated Vulnerability Detection (AVUD) for Compiled Smart Grid Software

This project developed and implemented a system for conducting cybersecurity vulnerability detection of smart grid components and systems by performing static analysis of compiled software (“firmware”). The resulting system for automated vulnerability detection (AVUD) was implemented as part of Oak Ridge National Laboratory’s existing test bed for smart meters, the Sustainable Campus Initiative. The work consisted of two phases: the first phase implemented the necessary software and computational models to perform the analysis, and the second phase demonstrated the system on example firmware in partnership with smart meter manufacturer Sensus USA, Inc. The resulting system won an R&D 100 award and has been successfully commercialized, winning a National Laboratory Consortium Commercialization Award.

97 MATHEMATICS AND COMPUTING↗

Models of Human-Automation Systems: Initial Analysis of the Boeing 737MAX Design

We describe a formal approach to identifying human factors design vulnerabilities and usability concerns in the context of automated control systems. We present an initial analysis of the design of the B737MAX that has suffered two fatal accidents. We highlight two main design vulnerabilities and one usability concern. Key formal generic properties used to identify these vulnerabilities and usability concerns are defined. These generic properties, and others referenced in the paper, can be applied to the analysis of any human-automation system.

HSI↗