Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “vulnerability analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

The Application of Remote Sensing using NASA Earth Observations paired with Sociodemographic Indicators to Identify Communities Most Susceptible to Urban Heat Exposure in Austin, Texas

In recent years, Austin, Texas has experienced an increase in population and urban development. Additionally, the City’s climate—already characterized by periods of extreme heat and drought—continues to change. As temperatures and demand for utilities and cooling resources rise, the number of heat-related deaths and illnesses in socially vulnerable populations (e.g., older, lower-income populations) is expected to increase. The City of Austin, The University of Texas at Austin (UT Austin), and The University of Texas Health Science Center at Houston (UT Health) partnered with NASA DEVELOP to examine the distribution of urban heat throughout the City. This project used land surface temperature, greenness, plant water content, and urban surface material analysis parameters derived from NASA Earth observations from Landsat 8 Operational Land Imager (OLI), Landsat 8 Thermal Infrared Sensor (TIRS), and Aqua and Terra Moderate Resolution Imaging Spectroradiometer (MODIS). The project team produced three different indices to create a spatial analysis for the study area including a social vulnerability index (SoVI), heat exposure index (HEI), and an overall heat priority index (HPI) score. This overall score was determined with a weighted analysis of heat-related environmental variables from NASA Earth observations and socioeconomic data from the 2019 American Community Survey. Based on the HPI score, the project team identified 121 census block groups out of 605 total that are designated as being most at risk of adverse impacts from extreme heat events. To test the sensitivity of the HPI, the team used a Monte Carlo analysis using different approaches for geographic scale, variable inclusion, census uncertainty, and index aggregation. Based on the sensitivity analysis, the resulting HPI score showed the metric was consistent with the baseline HPI. This provided increased confidence the score can be used as a tool to make informed infrastructure improvement plans in targeted areas (e.g., siting of cooling centers) and ensure equitable sustainable development.

Ryan Hammock↗

HAPPA: A Modular Platform for HPC Application Resilience Analysis with LLMs Embedded

High-performance computing (HPC) systems are increasingly vulnerable to soft errors, which pose significant challenges in maintaining computational accuracy and reliability. Predicting the resilience of HPC applications to these errors is crucial for robust code protection and detailed resilience analysis. In this study, we present HAppA, a modular platform designed for HPC Application Resilience Analysis. Embedding Large Language Models (LLMs), HAppA addresses understanding the context information of long code sequences typical in HPC applications. HAppA implements a novel code representation module that chunks the code into fixed-size segments and aggregates the embeddings of these segments. Three aggregation methods have been explored: MeanPooling, MaxPooling, and LSTM-based techniques. We built a DAtaset for REsilience analysis using Fault Injection (FI), named DARE. Using our DARE dataset, HAppA is trained for regression prediction tasks. Our evaluation results demonstrate the predictive accuracy of HAppA compared to other models, particularly noting that the LSTM-based aggregation method -- HAppA-LSTM -- achieves a mean squared error (MSE) of 0.078 for SDC prediction, surpassing the existing state-of-the-art PARIS model, which recorded an MSE of 0.1172. Additionally, HAppA with the KeyBERT model extracts a list of keywords representing the source code. A comprehensive importance analysis of these keywords further elucidates the code patterns contributing to the error rate. These findings highlight the effectiveness of HAppA in analyzing the resilience of HPC applications and establish a new benchmark for predictive accuracy in resilience.

Jiang, Hailong [Kent State University]↗

Automated Test Case Generation for an Autopilot Requirement Prototype

Designing safety-critical automation with robust human interaction is a difficult task that is susceptible to a number of known Human-Automation Interaction (HAI) vulnerabilities. It is therefore essential to develop automated tools that provide support both in the design and rapid evaluation of such automation. The Automation Design and Evaluation Prototyping Toolset (ADEPT) enables the rapid development of an executable specification for automation behavior and user interaction. ADEPT supports a number of analysis capabilities, thus enabling the detection of HAI vulnerabilities early in the design process, when modifications are less costly. In this paper, we advocate the introduction of a new capability to model-based prototyping tools such as ADEPT. The new capability is based on symbolic execution that allows us to automatically generate quality test suites based on the system design. Symbolic execution is used to generate both user input and test oracles user input drives the testing of the system implementation, and test oracles ensure that the system behaves as designed. We present early results in the context of a component in the Autopilot system modeled in ADEPT, and discuss the challenges of test case generation in the HAI domain.

Giannakopoulou, Dimitra↗

Natural gas maximal load delivery for multi-contingency analysis

An increasing dependence on natural gas has amplified existing vulnerabilities to the power grid, including disruptions to gas transmission networks from natural and man-made disasters. To address the operational challenges arising from these disruptions, we, in this study, consider the problem of estimating the steady-state operating capacity of a damaged gas pipeline network while ensuring the maximal delivery of load. Specifically, we formulate the mixed-integer nonconvex maximal load delivery (MLD) problem, which proves difficult to solve on large-scale networks. To address this challenge, we present a relaxation of the MLD problem and use it to determine bounds on the transport capacity of a gas pipeline system. A rigorous computational evaluation over network models ranging in size from 11 to 4,197 junctions shows that the relaxation-based method is suitable for analyzing the impacts of multi-contingency network disruptions, often converging to the optimal solution of the relaxation in less than ten seconds.

03 NATURAL GAS↗

Eev (enrich Enforce Validate) With Cpefinder

This code is designed to take an existing STIX bundle with vulnerability data and enrich it with additional potential vulnerabilities to provide further insight during threat analysis. It also acts as a launch platform for other enrichments tools. The additional tools include, WAVgraph and STIXEnforcer.

Beckman, BryanR [Idaho National Laboratory (INL), ↗

User's Manual for Space Debris Surfaces (SD_SURF)

A unique collection of computer codes, Space Debris Surfaces (SD_SURF), have been developed to assist in the design and analysis of space debris protection systems. SD_SURF calculates and summarizes a vehicle's vulnerability to space debris as a function of impact velocity and obliquity. An SD_SURF analysis will show which velocities and obliquities are the most probable to cause a penetration. This determination can help the analyst select a shield design which is best suited to the predominant penetration mechanism. The analysis also indicates the most suitable parameters for development or verification testing. The SD_SURF programs offer the option of either FORTRAN programs and Microsoft EXCEL spreadsheets and macros. The FORTRAN programs work with BUMPERII version 1.2a or 1.3 (Cosmic released). The EXCEL spreadsheets and macros can be used independently or with selected output from the SD_SURF FORTRAN programs.

Elfer, N. C.↗

Space Debris Surfaces (Computer Code): Probability of No Penetration Versus Impact Velocity and Obliquity

A unique collection of computer codes, Space Debris Surfaces (SD_SURF), have been developed to assist in the design and analysis of space debris protection systems. SD_SURF calculates and summarizes a vehicle's vulnerability to space debris as a function of impact velocity and obliquity. An SD_SURF analysis will show which velocities and obliquities are the most probable to cause a penetration. This determination can help the analyst select a shield design that is best suited to the predominant penetration mechanism. The analysis also suggests the most suitable parameters for development or verification testing. The SD_SURF programs offer the option of either FORTRAN programs or Microsoft-EXCEL spreadsheets and macros. The FORTRAN programs work with BUMPERII. The EXCEL spreadsheets and macros can be used independently or with selected output from the SD_SURF FORTRAN programs. Examples will be presented of the interaction between space vehicle geometry, the space debris environment, and the penetration and critical damage ballistic limit surfaces of the shield under consideration.

Elfer, N.↗

Identification of Worst Impact Zones for Power Grids During Extreme Weather Events Using Q-Learning: Preprint

Both the frequency and intensity of extreme weather events have been trending higher in recent years, leading to significant infrastructure loss in the electric grid. The impact of these extreme weather events is desired to be analyzed and quantified in order to help transmission and distribution system operators to prepare and prevent significant losses. In this paper, we developed an approach that models the impact of extreme weather on the power grid and identifies the worst impact zone using Q-learning (a reinforcement learning approach). The identification results reveal grid vulnerability to weather events and provide insights for system operators to help achieve optimal resource allocation and crew dispatch in order to minimize the adverse impact of extreme weather. Simulation studies are conducted on the IEEE 123-node system to demonstrate the performance of the proposed approach.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Bridgeport Urban Development: Leveraging NASA Earth Observations and Sociodemographic Data to Assess Urban Heat Vulnerability and Inform Cool Corridors in Bridgeport, Connecticut

Urban environments face hotter temperatures than suburban and rural areas due to higher concentrations of impervious surfaces, heat-retaining buildings, and lack of green space. Bridgeport, Connecticut, which was formerly a national manufacturing hub, is now the densest and most populous city in the state. Bridgeport experiences hotter temperatures, exposing its residents to more extreme temperatures than the surrounding affluent suburbs. Extreme heat affects the health of those exposed to it and intensifies energy demands. Understanding temperature differences is the first step in effectively directing mitigation efforts. Our partner, Groundwork Bridgeport, along with the Yale Urban Design Workshop, are planning a “cool corridors” project, implementing cooling infrastructure to combat urban heat. We used Landsat 8 Thermal Infrared Sensor and Landsat 9 Thermal Infrared Sensor-2 data to conduct a Land Surface Temperature analysis in Google Earth Engine for the county of Fairfield. A Principal Component Analysis was performed to identify indicators of social vulnerability in Bridgeport. We used the SOlar and LongWave Environmental Irradiance Geometry model to identify felt heat on the block level to inform where the partner should locate their cooling interventions to ensure they are most effective and equitable. We focused on the East Side of Bridgeport, which we found was 10 degrees hotter than other areas of Bridgeport and the neighboring town of Fairfield. We integrated our findings using Earth observations and additional sociodemographic and climate data into final communication products for our partners which will facilitate their selection of candidate locations for their Cool Corridors project.

Silas Kirsch↗

System Health and Status Reporting is Used to Improve Infrastructure Systems at the Hanford Site - 20449

Reliable physical infrastructure systems are vital to completing the clean-up mission and the start-up and commissioning of new nuclear waste processing facilities at the Hanford Site. Key infrastructure systems at Hanford include water, sewer, and electrical utilities, roads, telecommunications/network systems, and fire systems. All of the infrastructure systems are non-nuclear, General Service systems that are being maintained under formal engineering configuration control and none are specifically credited in any documented safety analysis (DSA). Starting in calendar year 2017, the Hanford Site's infrastructure and services contractor started producing system health and status reports for a total of 15 critical infrastructure systems as means to get a better understanding of each system's health and how it could be improved to ensure better and more reliable service delivery. As the reporting, tracking, and use of the metrics has matured, the number of systems for which reports are being developed has been expanded to a total of 23. Each of the critical infrastructure systems are assigned primary and alternate design authorities that complete qualifications on each assigned system. The design authorities actively manage and maintain configuration control on each of their systems and track metrics associated with availability, maintenance (corrective and preventive), and configuration of the technical baseline. The metrics are based on the principles established in Chapter V of DOE O 420.1C, Facility Safety, [1] and have been tailored as appropriate to each of the key infrastructure systems. An overall assessment of system health is performed and documented on a routine basis (e.g., quarterly). Included in this documentation is a quantitative score for each of the metrics (i.e., availability, maintenance, configuration management) along with results of system walk-downs, description of any permanent design modifications, identification of new or emerging issues and vulnerabilities affecting the system, and an assessment by the design authority of actions necessary to improve the system health score. The overall status scores are calculated using a formula and based on a pre-determined grading scale, a color is assigned for simple presentation. The information gained from developing the reports is being used to (1) assist with making timely and better informed decisions through the use of solid technical bases that are increasing the overall reliability and capabilities of the Site's infrastructure systems as new expense and capital projects in the Reliability Projects Investment Portfolio (RPIP) are prioritized and executed; (2) feed the risk management program, and (3) integrate the technical content of Master Plans that describe the Site's needs for the system and the system's capabilities to meet those future needs. (authors)

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Impacts of Climate Change on Global Food Trade Networks

Countries' reliance on global food trade networks implies that regionally different climate change impacts on crop yields will be transmitted across borders. This redistribution constitutes a significant challenge for climate adaptation planning and may affect how countries engage in cooperative action. This paper investigates the long-term (2070–2099) potential impacts of climate change on global food trade networks of three key crops: wheat, rice and maize. We propose a simple network model to project how climate change impacts on crop yields may be translated into changes in trade. Combining trade and climate impact data, our analysis proceeds in three steps. First, we use network community detection to analyse how the concentration of global production in present-day trade communities may become disrupted with climate change impacts. Second, we study how countries may change their network position following climate change impacts. Third, we study the total climate-induced change in production plus import within trade communities. Results indicate that the stability of food trade network structures compared to today differs between crops, and that countries' maize trade is least stable under climate change impacts. Results also project that threats to global food security may depend on production change in a few major global producers, and whether trade communities can balance production and import loss in some vulnerable countries. Overall, our model contributes a baseline analysis of cross-border climate impacts on food trade networks.

climate change↗

Digital Tools for the Preventive Conservation of Built Heritage: The Church of Santa Ana in Seville

Historic Building Information Modelling (HBIM) plays a pivotal role in heritage conservation endeavours, offering a robust framework for digitally documenting existing structures and supporting conservation practices. However, HBIM’s efficacy hinges upon the implementation of case-specific approaches to address the requirements and resources of each individual asset and context. This paper defines a flexible and generalisable workflow that encompasses various aspects (i.e., documentation, surveying, vulnerability assessment) to support risk-informed decision making in heritage management tailored to the peculiar conservation needs of the structure. This methodology includes an initial investigation covering historical data collection, metric and condition surveys and non-destructive testing. The second stage includes Finite Element Method (FEM) modelling and structural analysis. All data generated and processed are managed in a multi-purpose HBIM model. The methodology is tested on a relevant case study, namely, the church of Santa Ana in Seville, chosen for its historical significance, intricacy and susceptibility to seismic action. The defined level of detail of the HBIM model is sufficient to inform the structural analysis, being balanced by a more accurate representation of the alterations, through linked orthophotos and a comprehensive list of alphanumerical parameters. This ensures an adequate level of information, optimising the trade-off between model complexity, investigation time requirements, computational burden and reliability in the decision-making process. Field testing and FEM analysis provide valuable insight into the main sources of vulnerability in the building, including the connection between the tower and nave and the slenderness of the columns.

Chaves, Estefanía↗

Cyber-Informed Engineering (CIE) Workbook: End-of-Train (EoT) / Head-of-Train (HoT) Communications

This workbook presents a vulnerability (CVE-2025-1727 ) found in train applications and guides a digital risk assessment and mitigation analysis and application of Cyber-Informed Engineering principles to mitigate the potential consequences and ultimately the hazard through the engineering discipline because of exploiting this vulnerability. Workshop participants are encouraged to use the workbook to capture insights and lessons learned. The workbook guides the participant to: • Understand the HE communication vulnerability • Map digital threats to physical consequences • Use bowtie analysis to illustrate both “security” and “engineering” barriers • Apply CIE principles to ensure that even if communications are compromised, the physical engineered system still behaves safely. • Produce an actionable set of engineered and infosec controls for implementation

42 - ENGINEERING↗

IT Security Support for the Spaceport Command Control System Development

My job title is IT Security support for the Spaceport Command & Control System Development. As a cyber‐security analyst it is my job to ensure NASA's information stays safe from cyber threats, such as, viruses, malware and denial-of-service attacks by establishing and enforcing system access controls. Security is very important in the world of technology and it is used everywhere from personal computers to giant networks ran by Government agencies worldwide. Without constant monitoring analysis, businesses, public organizations and government agencies are vulnerable to potential harmful infiltration of their computer information system. It is my responsibility to ensure authorized access by examining improper access, reporting violations, revoke access, monitor information request by new programming and recommend improvements. My department oversees the Launch Control System and networks. An audit will be conducted for the LCS based on compliance with the Federal Information Security Management Act (FISMA) and The National Institute of Standards and Technology (NIST). I recently finished analyzing the SANS top 20 critical controls to give cost effective recommendations on various software and hardware products for compliance. Upon my completion of this internship, I will have successfully completed my duties as well as gain knowledge that will be helpful to my career in the future as a Cyber Security Analyst.

IT Security↗

Geothermal Sector Cybersecurity Vulnerability Assessment

A review of geothermal sector-specific cybersecurity vulnerabilities and risks (consequences) was conducted at the request of the Geothermal Technologies Office (GTO). The vulnerabilities and risks reviewed in this study have relevance to achieving the 2019 GeoVision Report (DOE GTO 2019) technological advancements and expected sector growth. The study offers areas for consideration but does not quantify the likelihood (frequency) of the consequences. This cybersecurity analysis project represents a proactive effort to identify areas to enhance cybersecurity in geothermal development and operations. It was not initiated to address any immediate threat or specific known risk. Of the eight identified vulnerabilities analyzed, the review identified reservoir data system monitoring as one that is unique to geothermal systems and may warrant further investigation to better understand risk and mitigation. A detailed analysis of the other vulnerabilities may highlight additional uniqueness relative to other industries. Further research actions are recommended to better quantify risk and enhance cybersecurity preparedness of the sector. As the geothermal industry grows, the cybersecurity strategies to be deployed will be of increasing importance to ensure resilient, reliable, and secure clean energy for years to come.

cyber-physical security↗

Employing NASA Earth Observations and Socioeconomic Data to Conduct Site Suitability Analyses on Residential Tree Planting Initiatives in Phoenix, Arizona

Phoenix, Arizona is the hottest large city in the United States with an average summer daytime temperature of 106°F. Temperatures in Phoenix continue to climb due to increasing global greenhouse gas concentrations and regional urbanization. The impacts of high temperatures, including heat-related illnesses and deaths, are disproportionately concentrated in low-income neighborhoods often characterized by little tree canopy, lack of green space, and insufficient access to shade. The City of Phoenix’s Office of Heat Response and Mitigation and Arizona State University’s Urban Climate Research Center, partnered with NASA DEVELOP to identify residential neighborhoods and parcels within qualified census tracts (QCTs) to be prioritized for tree planting initiatives using funding from the American Rescue Plan Act (ARPA). This project conducted analyses using NASA Earth observations, socioeconomic data from the 2019 American Community Survey, and local tree canopy and mobility data. For Earth observations, daytime land surface temperature, vegetation, and land cover were obtained from the Landsat 8 Thermal Infrared Sensor (TIRS) and Operational Land Imager (OLI). The project team incorporated these data into a heat vulnerability index (HVI) with an emphasis on tree canopy and social vulnerability to rank block groups within QCTs and focused on the resulting top 25 block group HVI scores. These top 25 most vulnerable block groups were then processed through a parcel analysis to determine the feasibility of residential tree planting based on building footprints on each parcel. Within the top 25 block groups, 2,411 parcels were analyzed, and 3,133 existing trees were identified averaging 1.3 trees per parcel with 90% of parcels having 3 trees or less. Homes with 2 trees or fewer were considered high priority for future planting efforts. Based on the City’s goals for increased tree canopy the project team determined that <10,000 additional trees would need to be planted within the most vulnerable 25 block groups. The project findings have helped initiate community engagement efforts and have contributed to the approval of tree planting funds in Phoenix.

Ryan Hammock↗

Using Machine Learning to Understand Electric and Hybrid Vehicles Ownership in Burdened and Nonburdened Communities

Transitioning to electric and hybrid vehicles (EHVs) for all communities is a pivotal step toward sustainable transportation and environmental conservation. This paper aims to understand the adoption of EHVs, focusing on burdened communities (BCs) in the United States. The EHV ownership-based analysis combines two datasets—behavioral data from the Puget Sound Regional Travel Survey integrated with BCs (Justice40) data covering transportation insecurity, environmental burden, social vulnerability, health vulnerability, and climate and disaster risk burden. After creating this unique database, descriptive analysis and modeling are used to analyze the data and predict EHV ownership in the future. Specifically, we use a new method that combines particle swarm optimization (PSO) with a stacking model named PSO-Stacking, which incorporates heterogeneous base learners of machine learning and deep learning. PSO applies a customized objective function to select the optimal hyperparameters for heterogeneous learners within the stacking model, effectively addressing challenges such as multicollinearity, data imbalance, nonlinearity, and overfitting. The proposed solution covers more accurate results than standard benchmark models for EHV ownership in BCs and non-BCs. In addition, the results of the PSO-Stacking method are explained using the local interpretable model-agnostic explanations technique. Results show a negative correlation between the BCs indicators, that is, higher transportation insecurity associated with lower EHV ownership. Furthermore, BCs have higher future climate risk scores, diesel particulate matter levels, and PM2.5 in the air than non-BCs because of higher conventional vehicle ownership. These communities are at higher risk and can benefit from electrification, EV infrastructure, and EV policies to address environmental challenges.

Aslam, Zeeshan [ORNL]↗

Vulcan-Forge: Architecture and Design of a Multi-Modal Forensic Analysis Plugin for CALDERA

Forge and VULCAN together describe an open-architecture cybersecurity analysis ecosystem that unifies forensic artifact processing, detection engineering, and vulnerability intelligence within integrated platforms. Forge operates as a plugin for MITRE CALDERA, ingesting diverse evidence formats—including EVTX, PCAP/PCAPNG, CSV, JSON, YAML, XML, binaries, and archives—to construct a unified artifact graph enriched with severity scoring, TLP classification, and audit trails. It provides subsystems for artifact parsing, streaming structured-data visualization, NetworkMiner-based packet inspection, PE/.NET binary analysis, and LLM-assisted triage and rule generation, with outputs validated against CCCS-YARA and pySigma schemas. VULCAN complements this by serving as a cybersecurity analyst platform that integrates a Neo4j knowledge graph, Qdrant vector retrieval, SSVC-based triage, and a local LLM to deliver CVE intelligence and forensic analysis through a multi-source ingest pipeline drawing from NVD, CISA KEV, EPSS, MITRE ATT&CK, and CAPEC. Together, they bridge structured threat intelligence with automated forensic analysis and detection workflows.

97 MATHEMATICS AND COMPUTING↗