Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

State Government Revenue Vulnerability Index and Local Government Revenue Vulnerability Index

The State Government Revenue Vulnerability Index (SGRVI) and Local Government Revenue Vulnerability Index (LGRVI) measure the vulnerability of government revenues by estimating monthly changes relative to a January 2020 baseline. Revenues included in both indices include: taxes on products and sales, transportation and housing revenues, individual income taxes, severance taxes and royalties, and property taxes. Local government revenues also include a local revenue from state revenue sharing component. In addition, the main index for the LGRVI for county-level governments includes revenue estimates for sub-county government units, including municipalities, school districts, and special districts. This revenue data is aggregated to produce the indices.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Blueprint: Stakeholder-Specific Vulnerability Categorization Guidance

Vulnerability management is a process of discovering, analyzing, and handling new or reported security vulnerabilities in systems to prevent the systems from being exploited, to reduce risk, and to protect assets. For vulnerability analysis, handling, and response, the prioritization of organizational and analyst resources must precede. The Common Vulnerability Scoring System (CVSS) is a standard prioritization method that is used to rate the severity of security vulnerabilities in systems by assigning numerical severity scores, but it does not provide clear guidelines of how the numerical severity scores might inform decisions. The Stakeholder-Specific Vulnerability Categorization (SSVC) provides a method for prioritizing vulnerabilities based on the needs of the stakeholders involved in the vulnerability management process. Instead of the numerical scoring used in the CVSS, the SSVC focuses on contextual decision-making to determine how quickly and effectively an organization should respond to vulnerabilities. The main functionality of the SSVC accommodates the diversity of the stakeholders in the vulnerability management process, including finders, vendors, coordinators, deployers, and others. So, the SSVC should be designed to be used by any of these stakeholders, and it should be customizable to enable specific stakeholder decision models and risk appetites.

33 ADVANCED PROPULSION SYSTEMS↗

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie↗

CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure

Society and modern life are dependent on critical infrastructure that is composed of expensive, special purpose devices that have long life cycles and may be in use for decades before being replaced. There are an abundance of organizations and individuals doing vulnerability analysis on a variety of systems, but what makes the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program unique and valuable is its strategic focus on high-priority critical infrastructure, close partnership with vendors, and ability to leverage bills of materials (BOMs) to identify and relate vulnerabilities to affected systems. Creating a bill of materials is a formal way of understanding and documenting the components of a system, including everything from integrated circuits to operating systems to third-party libraries. This is beneficial for connecting known vulnerabilities to affected devices, since vulnerabilities in a specific component are often not mapped to all systems that use that vulnerable component. Additionally, CyTRICS finds novel vulnerabilities through its vulnerability testing process and works closely with vendor partners to provide vulnerability reports so that affected systems can be patched in a timely manner. This presentation will describe the interrelated technical processes CyTRICS uses to create bills of materials and conduct vulnerability analysis.

99 GENERAL AND MISCELLANEOUS↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

Development of the Contamination Distribution Centered Toxics Mobility Vulnerability Index in the Beaumont–Port Arthur Region of Texas

This study advances the Toxics Mobility Inventory (TMI) and the Toxics Mobility Vulnerability Index (TMVI) to develop a new tool to assess the movement of hazardous substances and their implications for vulnerable communities. It emphasizes the need to include contamination distribution variables in such indices to address disproportionate impacts and more accurately reflect vulnerability. The study uses the TMI framework and TMVI methodology in the Beaumont–Port Arthur region of Texas, also integrating contamination distribution considerations into the analysis to develop a new framework and process. The new Contamination Distribution Centered Toxics Mobility Vulnerability Index (CDC-TMVI) consolidates climate change and topography variables into a broader built environment vulnerability category while introducing a contamination sources category. Using ArcGIS Pro and ToxPi tools, the study evaluates 27 geospatial variables across four categories: built environment vulnerability, social vulnerability, health outcomes, and contamination sources. The results indicate significant contributions from contamination and social vulnerability variables, highlighting areas with higher risks of flooding and air pollution. This article advocates for future research and policy efforts to enhance the integration of contamination sources and their spatial distributions into toxics mobility assessments to better protect vulnerable populations. Furthermore, the unique methodology and findings serve as a basis for developing targeted measures and strategic planning to improve environmental health.

contamination↗

Security Vulnerability Profiles of Mission Critical Software: Empirical Analysis of Security Related Bug Reports

While some prior research work exists on characteristics of software faults (i.e., bugs) and failures, very little work has been published on analysis of software applications vulnerabilities. This paper aims to contribute towards filling that gap by presenting an empirical investigation of application vulnerabilities. The results are based on data extracted from issue tracking systems of two NASA missions. These data were organized in three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified security related software bugs and classified them in specific vulnerability classes. Then, we created the security vulnerability profiles, i.e., determined where and when the security vulnerabilities were introduced and what were the dominating vulnerabilities classes. Our main findings include: (1) In IVV issues datasets the majority of vulnerabilities were code related and were introduced in the Implementation phase. (2) For all datasets, around 90 of the vulnerabilities were located in two to four subsystems. (3) Out of 21 primary classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, they contributed from 80 to 90 of vulnerabilities in each dataset.

Goseva-Popstojanova, Katerina↗

Establishing nationwide power system vulnerability index across US counties using interpretable machine learning

Power outages have become increasingly frequent, intense, and prolonged in the US due to climate change, aging electrical grids, and rising energy demand. However, largely due to the absence of granular spatiotemporal outage data, we lack data-driven evidence and analytics-based metrics to quantify power system vulnerability. This limitation has hindered the ability to effectively evaluate and address vulnerability to power outages in US communities. Here, in this work, we collected ∼179 million power outage records at 15-min intervals across 3022 US contiguous counties (96.15 % of the area) from 2014 to 2023. We developed a power system vulnerability assessment framework based on three dimensions (intensity, frequency, and duration) and applied interpretable machine learning models (XGBoost and SHAP) to compute Power System Vulnerability Index (PSVI) at the county level. Our analysis reveals a consistent increase in power system vulnerability across the US counties over the past decade. We identified 318 counties across 45 states as hotspots for high power system vulnerability, particularly in the West Coast (California and Washington), the East Coast (Florida and the Northeast area), the Great Lakes megalopolis (Chicago-Detroit metropolitan areas), and the Gulf of Mexico (Texas). Our heterogeneity analysis indicates that urban counties and those located along regional transmission boundaries tend to exhibit significantly higher vulnerability. Our results highlight the significance of the proposed PSVI for evaluating the vulnerability of communities to power outages. The findings underscore the widespread and pervasive impact of power outages across the country and offer crucial insights to support infrastructure operators, policymakers, and emergency managers in formulating policies and programs aimed at enhancing the resilience of the US power infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Method for Measuring Coupled Individual and Social Vulnerability to Environmental Hazards

Although models of social vulnerability to environmental hazards are commonly developed to support policy interventions in emergencies and disasters, their utility is hindered by a lack of contextual information on individuals exposed to and affected by hazards. We develop a novel approach to model social vulnerability that couples individuals and their varying forms of protective capacity with the social fabric of the communities in which they reside. The backbone of our model is the Public-Use Microdata Sample (PUMS), a product of the U.S. Census Bureau that preserves a representative sample of completed responses to the American Community Survey (ACS). The PUMS enables us to understand the full range of individual protective capacities against a hazard in an exposed area, which we term individual vulnerability profiles (IVPs). In this case, we examine IVPs in the Coney Island-Brighton Beach section of New York City, which suffered severe impacts during Hurricane Sandy in 2012. To manage the large number of unique IVPs in Coney Island-Brighton Beach, we perform a segmentation analysis to generalize them into thematic cohort vulnerability profiles (CVPs) representing a typology of vulnerable people in Coney Island-Brighton Beach during Sandy. From synthetic populations of CVPs, we then estimate how individuals in varying housing types were coexposed to Sandy at the census tract level by classifying these areas into community social vulnerability profiles (SVPs). Our results provide a topology of social vulnerability that simultaneously links individual, community, and population-wide concerns, enabling a more holistic understanding of resources and interventions beneficial to human security during events like Sandy than is attainable with area-level metrics.

54 ENVIRONMENTAL SCIENCES↗

Towards Automatic Mapping of Vulnerabilities to Attack Patterns using Large Language Models

With the advent of new devices and applications, cyber attack surface is continuously evolving due to the emergence of new attack techniques and vulnerabilities. Hence, security management tool must assess the cyber risk of an enterprise at regular interval basis through comprehensively identifying associations among attack techniques, weakness, and vulnerabilities. However, existing repositories providing such associations are incomplete (i.e., missing associations), inducing the likelihood of undermining the risk of particular set of attack techniques. Moreover, such associations still rely on manual interpretation, which is slow compared to attack speed and ineffective for the increasing list of vulnerabilities and attack actions. Therefore, there is an urge to develop methodologies for automatically associating vulnerabilities to all relevant attack techniques. In this paper, we present a framework, named VWC-MAP, that can automatically identify all relevant attack techniques of a vulnerability via weakness based on their text descriptions, applying natural language process (NLP) techniques. To achieve that, we present a novel two-tiered classification approach, where the first tier classifies vulnerabilities to weakness, and the second tier classifies weakness to attack techniques. This research has improved the scalability of the current state-of-the-art tool to make vulnerability to weakness mapping significantly faster. Moreover, this paper presents two novel approaches for weakness to attack technique mapping applying Text-to-Text and link prediction techniques. Our experiment results cross-validated through cyber-security experts show that VWC-MAP can associate vulnerabilities to weakness types with 87% accuracy and to new attack patterns with 80% accuracy.

Das, Siddhartha Shankar↗

When ChatGPT Meets Vulnerability Management: The Good, the Bad, and the Ugly

Vulnerability management is a very challenging and time-consuming task. For many organizations, security operators need to learn about the properties of vulnerabilities to prioritize and mitigate them. Due to the lack of automated tools for vulnerability assessment, operators usually manually search for and read related information from sources online. Recent advances in large language models, like ChatGPT, open up an opportunity for time savings and may prompt operators to use these models as vulnerability information sources. In this work, we evaluate the ability of ChatGPT and several of its siblings to accurately answer user questions about vulnerability properties as well as to provide information for how to mitigate a vulnerability. We also explore their summarization capabilities when multiple vulnerability advisory documents are provided. We find that the models perform poorly on information retrieval tasks, but they perform quite well on summarization.

McClanahan, Kylie↗

An Extreme-Value Approach to Anomaly Vulnerability Identification

The objective of this paper is to present a method for importance analysis in parametric probabilistic modeling where the result of interest is the identification of potential engineering vulnerabilities associated with postulated anomalies in system behavior. In the context of Accident Precursor Analysis (APA), under which this method has been developed, these vulnerabilities, designated as anomaly vulnerabilities, are conditions that produce high risk in the presence of anomalous system behavior. The method defines a parameter-specific Parameter Vulnerability Importance measure (PVI), which identifies anomaly risk-model parameter values that indicate the potential presence of anomaly vulnerabilities, and allows them to be prioritized for further investigation. This entails analyzing each uncertain risk-model parameter over its credible range of values to determine where it produces the maximum risk. A parameter that produces high system risk for a particular range of values suggests that the system is vulnerable to the modeled anomalous conditions, if indeed the true parameter value lies in that range. Thus, PVI analysis provides a means of identifying and prioritizing anomaly-related engineering issues that at the very least warrant improved understanding to reduce uncertainty, such that true vulnerabilities may be identified and proper corrective actions taken.

Everett, Chris↗

Vulnerability and resilience of urban energy ecosystems to extreme climate events: A systematic review and perspectives

We reviewed the present studies on the vulnerability and resilience of the energy ecosystem (most parts of the energy ecosystem), considering extreme climate events. This study revealed that the increased interactions formed during the transformation of the energy landscape into an ecosystem could notably increase the vulnerability of the energy infrastructure. Such complex ecosystem cannot be assessed using the present state of the art models used by the energy system modelers. Therefore, this study introduces a novel analogy known as the COVID analogy to understand the propagation of disruption within and beyond the energy ecosystem and organized the present state of the art based on the COVID analogy. The analogy helps to categorize the vulnerability of the energy infrastructure into three stages. The study revealed that although there are many publications covering the vulnerability and resilience of the energy infrastructure, considering extreme climate events, the majority are focused on the direct impact of extreme climate on the energy ecosystem. In addition, most of the studies do not consider the impact of future climate variations during this assessment. The propagation of disruptions was assessed mainly for wildfires and hurricanes. Further, there is a clear research gap in considering vulnerability assessment for interconnected energy infrastructure. Here, the transformation of energy systems into a complex ecosystem notably increases the complexity, making it difficult to assess vulnerability and resilience. A shift from a centralized to decentralized modeling architecture could be beneficial when considering the complexities brought by that transformation. Hybrid models consisting of both physical and data-driven machine learning techniques could also be beneficial in this context.

54 ENVIRONMENTAL SCIENCES↗

Security Vulnerability and Mitigation in Photovoltaic Systems

Software and firmware vulnerabilities pose security threats to photovoltaic (PV) systems. When patches are not available or cannot be timely applied to fix vulnerabilities, it is important to mitigate vulnerabilities such that they cannot be exploited by attackers or their impacts will be limited when exploited. However, the vulnerability mitigation problem for PV systems has received little attention. This paper analyzes known security vulnerabilities in PV systems, proposes a multi-level mitigation framework and various mitigation strategies including neural network-based attack detection inside inverters, and develops a prototype system as a proof-of-concept for building vulnerability mitigation into PV system design.

14 SOLAR ENERGY↗

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Assessing Environmental and Socioeconomic Factors of Urban Flood Vulnerability in Kansas City, Kansas

Pluvial flooding, over-saturated ground, and drainage systems disproportionately impact historically marginalized urban neighborhoods during extreme rainfall events. These communities are impacted by physical and socioeconomic factors that make them vulnerable to flooding events, such as high concentrations of impervious landcover, high precipitation rates, and a combined sewer system framework. Despite known vulnerability to environmental hazards, understanding potential pluvial street-level flooding events are largely unknown. Using the open-source National Capital Project’s Integrated Valuation of Ecosystem Services and Tradeoffs (InVEST) Urban Flood Risk Mitigation model, NASA DEVELOP examined neighborhood scale runoff retention and potential economic damages for risk mapping throughout Kansas City, Kansas. The generated outputs aid in identifying vulnerable neighborhoods susceptible to flooding and in need of future intervention. Previous studies have applied this model framework to understand urban flood vulnerability regarding ecosystem services, urban planning, and flood mitigation strategies. We utilized the InVEST outputs to develop indices pertaining to environmental justice factors of race, socioeconomic status, social vulnerability, and health. The findings indicate that historically redlined neighborhoods in Kansas City, Kansas face disproportional impacts from flood events and are subject to greater environmental stressors. This research provides an approach to utilizing an open-source flood vulnerability model to empower neighborhood-scale environmental justice analysis, enhancing the local communities' understanding of present-day impacts of historical environmental injustices.

Hadwynne Gross↗

An Interpretable Index of Social Vulnerability to Environmental Hazards

Index-based measures of social vulnerability to environmental hazards are commonly modeled from composites of population-level risk factors. These models overlook individual context in communities' experiences of environmental hazards, producing metrics that may hinder spatial decision support for mitigating and responding to hazards. This paper introduces an interpretable, high-resolution model for generating an individual-oriented social vulnerability index (IOSVI) for the United States built on synthetic populations that couples individual and social determinants of vulnerability. The IOSVI combines an individual vulnerability index (IVI) that ranks individuals in an area’s synthetic population based on intersecting risk factors, with a social vulnerability index (SVI) based on the population’s cumulative distribution of IVI scores. Interpretability of the IOSVI procedure is demonstrated through examples of national, metropolitan, and neighborhood (census tract) level spatial variation in index scores and IVI themes, as well as an exploratory analysis examining risk factors affecting a specific sub-population (military veterans) in areas of high social and environmental vulnerability.

Tuccillo, Joe↗

Community vulnerability is the key determinant of diverse energy burdens in the United States

Low-income households generally experience a high energy burden; however, the factors influencing energy burdens are beyond socio-economics. This study explores the relationships between the multidimensionality of community vulnerability factors and energy burden across multiple geospatial levels in the United States. Our study found the distribution of energy burden in 2020 showed a great deal of variety, ranging from a minimum of 2.93 % to a maximum of 30.45 % across 3142 counties. The results of non-spatial and spatial regressions showed that the vulnerability ranks of socioeconomic, household composition and disability, minority and language, household type and transportation, and COVID mortality rate are significant predictors of energy burdens at the national level. However, at the regional level, only socioeconomic, minority and language significantly influence energy burdens. Minority and language negatively impact energy burdens except for the South East-Central region. Additionally, our analyses highlight the need to consider community vulnerability indicators' spatial homogeneity and heterogeneity. At the national level, only the epidemiological factors index is a spatially homogeneous predictor; on the regional and state level, the spatially homogeneous predictors such as socioeconomic status, household composition and disability, and household type and transportation vary by region. Such a region-sensitive relationship between energy burden and the predictors indicates spatial heterogeneity. Here this study suggests policy recommendations through the lens of the multidimensionality of community vulnerability factors. Implementing flexible national energy policies while making particular energy assistance policies for the vulnerable population at the regional or state levels is essential.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗