Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

State Government Revenue Vulnerability Index and Local Government Revenue Vulnerability Index

The State Government Revenue Vulnerability Index (SGRVI) and Local Government Revenue Vulnerability Index (LGRVI) measure the vulnerability of government revenues by estimating monthly changes relative to a January 2020 baseline. Revenues included in both indices include: taxes on products and sales, transportation and housing revenues, individual income taxes, severance taxes and royalties, and property taxes. Local government revenues also include a local revenue from state revenue sharing component. In addition, the main index for the LGRVI for county-level governments includes revenue estimates for sub-county government units, including municipalities, school districts, and special districts. This revenue data is aggregated to produce the indices.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

DPSIR-ESA Vulnerability Assessment (DEVA) Framework: Synthesis, Foundational Overview, and Expert Case Studies

Land resources are central to understanding the relationship between humans and their environment. We broadly define a land resource to include all the ecological resources of climate, water, soil, landforms, flora, and fauna, and all the socioeconomic systems that interact with agriculture, forestry, and other land uses within some system boundary. Understanding the vulnerability of land resources to changes in land management or climate forcing is critical to developing sustainable land management strategies. Vulnerability assessments are complex given the multiple uses of the assessments, the multi-disciplinary nature of the problem, limited understanding, the dynamic structure of vulnerability, scale issues, and problems with identifying effective vulnerability indicators. Here, we propose a novel conceptual framework for vulnerability assessments of land resources that combines the driver– pressure–state–impact–response (DPSIR) framework adopted by the European Environment Agency to describe interactions between society and the environment, and the exposure-sensitivity-adaptive capacity (ESA) framework used by the Intergovernmental Panel on Climate Change to assess impacts of climate change. The DPSIR-ESA Vulnerability Assessment (DEVA) framework operationalizes the process of assessing the vulnerability of a target system to external stressors. The DEVA framework includes the following elements: 1) Definition of the target system (Land resource), 2) Description of internal characteristics of the target system (State), 3) Description of target system vulnerability indicators (Adaptive capacity, Sensitivity), 4) Description of stressor characteristics (Drivers, Pressures), 5) Description of stressor vulnerability indicators (Exposure), 6) Description of target system response to stressors (Impacts), and 7) Description of modifications to target systems or stressors (Responses). In stating that they have “applied the DEVA framework”, analysts acknowledge that they have (a) considered the full breadth of each DEVA element, (b) have made conscious decisions to limit the scope and complexity of certain elements, and (c) can communicate both the rationale for these decisions and the impact of these decisions on the vulnerability assessment results and recommendations. The DEVA framework was refined during invited presentations and follow-up discussions from a series of Special Sessions with leading experts at two successive ASABE Annual International Meetings. Six case studies drawn from the sessions elaborate upon the DEVA framework and provide concrete examples of the key concepts. The DEVA approach gives engineers, planners, and analysts a new, flexible framework to apply a broad array of useful tools toward assessment of land resource system vulnerability.

Anandhi, Aauvadi↗

Blueprint: Stakeholder-Specific Vulnerability Categorization Guidance

Vulnerability management is a process of discovering, analyzing, and handling new or reported security vulnerabilities in systems to prevent the systems from being exploited, to reduce risk, and to protect assets. For vulnerability analysis, handling, and response, the prioritization of organizational and analyst resources must precede. The Common Vulnerability Scoring System (CVSS) is a standard prioritization method that is used to rate the severity of security vulnerabilities in systems by assigning numerical severity scores, but it does not provide clear guidelines of how the numerical severity scores might inform decisions. The Stakeholder-Specific Vulnerability Categorization (SSVC) provides a method for prioritizing vulnerabilities based on the needs of the stakeholders involved in the vulnerability management process. Instead of the numerical scoring used in the CVSS, the SSVC focuses on contextual decision-making to determine how quickly and effectively an organization should respond to vulnerabilities. The main functionality of the SSVC accommodates the diversity of the stakeholders in the vulnerability management process, including finders, vendors, coordinators, deployers, and others. So, the SSVC should be designed to be used by any of these stakeholders, and it should be customizable to enable specific stakeholder decision models and risk appetites.

33 ADVANCED PROPULSION SYSTEMS↗

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie↗

CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure

Society and modern life are dependent on critical infrastructure that is composed of expensive, special purpose devices that have long life cycles and may be in use for decades before being replaced. There are an abundance of organizations and individuals doing vulnerability analysis on a variety of systems, but what makes the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program unique and valuable is its strategic focus on high-priority critical infrastructure, close partnership with vendors, and ability to leverage bills of materials (BOMs) to identify and relate vulnerabilities to affected systems. Creating a bill of materials is a formal way of understanding and documenting the components of a system, including everything from integrated circuits to operating systems to third-party libraries. This is beneficial for connecting known vulnerabilities to affected devices, since vulnerabilities in a specific component are often not mapped to all systems that use that vulnerable component. Additionally, CyTRICS finds novel vulnerabilities through its vulnerability testing process and works closely with vendor partners to provide vulnerability reports so that affected systems can be patched in a timely manner. This presentation will describe the interrelated technical processes CyTRICS uses to create bills of materials and conduct vulnerability analysis.

99 GENERAL AND MISCELLANEOUS↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

Non-invasive imaging reveals convergence in root and stem vulnerability to cavitation across five tree species

Root vulnerability to cavitation is challenging to measure and under-represented in current datasets. This gap limits the precision of models used to predict plant responses to drought because roots comprise the critical interface between plant and soil. In this study, we measured vulnerability to drought-induced cavitation in woody roots and stems of five tree species (Acacia aneura, Cedrus deodara, Eucalyptus crebra, Eucalytus saligna, and Quercus palustris) with a wide range of xylem anatomies. X-ray microtomography was used to visualize the accumulation of xylem embolism in stems and roots of intact plants that were naturally dehydrated to varying levels of water stress. Vulnerability to cavitation, defined as the water potential causing a 50% loss of hydraulic function (P 50 ), varied broadly among the species (–4.51 MPa to –11.93 MPa in stems and –3.13 MPa to –9.64 MPa in roots). The P 50 of roots and stems was significantly related across species, with species that had more vulnerable stems also having more vulnerable roots. While there was strong convergence in root and stem vulnerability to cavitation, the P 50 of roots was significantly higher than the P 50 of stems in three species. However, the difference in root and stem vulnerability for these species was small; between 1% and 31% of stem P 50 . Thus, while some differences existed between organs, roots were not dramatically more vulnerable to embolism than stems, and the differences observed were less than those reported in previous studies. Further study is required to evaluate the vulnerability across root orders and to extend these conclusions to a greater number of species and xylem functional types.

59 BASIC BIOLOGICAL SCIENCES↗

Development of the Contamination Distribution Centered Toxics Mobility Vulnerability Index in the Beaumont–Port Arthur Region of Texas

This study advances the Toxics Mobility Inventory (TMI) and the Toxics Mobility Vulnerability Index (TMVI) to develop a new tool to assess the movement of hazardous substances and their implications for vulnerable communities. It emphasizes the need to include contamination distribution variables in such indices to address disproportionate impacts and more accurately reflect vulnerability. The study uses the TMI framework and TMVI methodology in the Beaumont–Port Arthur region of Texas, also integrating contamination distribution considerations into the analysis to develop a new framework and process. The new Contamination Distribution Centered Toxics Mobility Vulnerability Index (CDC-TMVI) consolidates climate change and topography variables into a broader built environment vulnerability category while introducing a contamination sources category. Using ArcGIS Pro and ToxPi tools, the study evaluates 27 geospatial variables across four categories: built environment vulnerability, social vulnerability, health outcomes, and contamination sources. The results indicate significant contributions from contamination and social vulnerability variables, highlighting areas with higher risks of flooding and air pollution. This article advocates for future research and policy efforts to enhance the integration of contamination sources and their spatial distributions into toxics mobility assessments to better protect vulnerable populations. Furthermore, the unique methodology and findings serve as a basis for developing targeted measures and strategic planning to improve environmental health.

contamination↗

Establishing nationwide power system vulnerability index across US counties using interpretable machine learning

Power outages have become increasingly frequent, intense, and prolonged in the US due to climate change, aging electrical grids, and rising energy demand. However, largely due to the absence of granular spatiotemporal outage data, we lack data-driven evidence and analytics-based metrics to quantify power system vulnerability. This limitation has hindered the ability to effectively evaluate and address vulnerability to power outages in US communities. Here, in this work, we collected ∼179 million power outage records at 15-min intervals across 3022 US contiguous counties (96.15 % of the area) from 2014 to 2023. We developed a power system vulnerability assessment framework based on three dimensions (intensity, frequency, and duration) and applied interpretable machine learning models (XGBoost and SHAP) to compute Power System Vulnerability Index (PSVI) at the county level. Our analysis reveals a consistent increase in power system vulnerability across the US counties over the past decade. We identified 318 counties across 45 states as hotspots for high power system vulnerability, particularly in the West Coast (California and Washington), the East Coast (Florida and the Northeast area), the Great Lakes megalopolis (Chicago-Detroit metropolitan areas), and the Gulf of Mexico (Texas). Our heterogeneity analysis indicates that urban counties and those located along regional transmission boundaries tend to exhibit significantly higher vulnerability. Our results highlight the significance of the proposed PSVI for evaluating the vulnerability of communities to power outages. The findings underscore the widespread and pervasive impact of power outages across the country and offer crucial insights to support infrastructure operators, policymakers, and emergency managers in formulating policies and programs aimed at enhancing the resilience of the US power infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Method for Measuring Coupled Individual and Social Vulnerability to Environmental Hazards

Although models of social vulnerability to environmental hazards are commonly developed to support policy interventions in emergencies and disasters, their utility is hindered by a lack of contextual information on individuals exposed to and affected by hazards. We develop a novel approach to model social vulnerability that couples individuals and their varying forms of protective capacity with the social fabric of the communities in which they reside. The backbone of our model is the Public-Use Microdata Sample (PUMS), a product of the U.S. Census Bureau that preserves a representative sample of completed responses to the American Community Survey (ACS). The PUMS enables us to understand the full range of individual protective capacities against a hazard in an exposed area, which we term individual vulnerability profiles (IVPs). In this case, we examine IVPs in the Coney Island-Brighton Beach section of New York City, which suffered severe impacts during Hurricane Sandy in 2012. To manage the large number of unique IVPs in Coney Island-Brighton Beach, we perform a segmentation analysis to generalize them into thematic cohort vulnerability profiles (CVPs) representing a typology of vulnerable people in Coney Island-Brighton Beach during Sandy. From synthetic populations of CVPs, we then estimate how individuals in varying housing types were coexposed to Sandy at the census tract level by classifying these areas into community social vulnerability profiles (SVPs). Our results provide a topology of social vulnerability that simultaneously links individual, community, and population-wide concerns, enabling a more holistic understanding of resources and interventions beneficial to human security during events like Sandy than is attainable with area-level metrics.

54 ENVIRONMENTAL SCIENCES↗

Towards Automatic Mapping of Vulnerabilities to Attack Patterns using Large Language Models

With the advent of new devices and applications, cyber attack surface is continuously evolving due to the emergence of new attack techniques and vulnerabilities. Hence, security management tool must assess the cyber risk of an enterprise at regular interval basis through comprehensively identifying associations among attack techniques, weakness, and vulnerabilities. However, existing repositories providing such associations are incomplete (i.e., missing associations), inducing the likelihood of undermining the risk of particular set of attack techniques. Moreover, such associations still rely on manual interpretation, which is slow compared to attack speed and ineffective for the increasing list of vulnerabilities and attack actions. Therefore, there is an urge to develop methodologies for automatically associating vulnerabilities to all relevant attack techniques. In this paper, we present a framework, named VWC-MAP, that can automatically identify all relevant attack techniques of a vulnerability via weakness based on their text descriptions, applying natural language process (NLP) techniques. To achieve that, we present a novel two-tiered classification approach, where the first tier classifies vulnerabilities to weakness, and the second tier classifies weakness to attack techniques. This research has improved the scalability of the current state-of-the-art tool to make vulnerability to weakness mapping significantly faster. Moreover, this paper presents two novel approaches for weakness to attack technique mapping applying Text-to-Text and link prediction techniques. Our experiment results cross-validated through cyber-security experts show that VWC-MAP can associate vulnerabilities to weakness types with 87% accuracy and to new attack patterns with 80% accuracy.

Das, Siddhartha Shankar↗

When ChatGPT Meets Vulnerability Management: The Good, the Bad, and the Ugly

Vulnerability management is a very challenging and time-consuming task. For many organizations, security operators need to learn about the properties of vulnerabilities to prioritize and mitigate them. Due to the lack of automated tools for vulnerability assessment, operators usually manually search for and read related information from sources online. Recent advances in large language models, like ChatGPT, open up an opportunity for time savings and may prompt operators to use these models as vulnerability information sources. In this work, we evaluate the ability of ChatGPT and several of its siblings to accurately answer user questions about vulnerability properties as well as to provide information for how to mitigate a vulnerability. We also explore their summarization capabilities when multiple vulnerability advisory documents are provided. We find that the models perform poorly on information retrieval tasks, but they perform quite well on summarization.

McClanahan, Kylie↗

Vulnerability and resilience of urban energy ecosystems to extreme climate events: A systematic review and perspectives

We reviewed the present studies on the vulnerability and resilience of the energy ecosystem (most parts of the energy ecosystem), considering extreme climate events. This study revealed that the increased interactions formed during the transformation of the energy landscape into an ecosystem could notably increase the vulnerability of the energy infrastructure. Such complex ecosystem cannot be assessed using the present state of the art models used by the energy system modelers. Therefore, this study introduces a novel analogy known as the COVID analogy to understand the propagation of disruption within and beyond the energy ecosystem and organized the present state of the art based on the COVID analogy. The analogy helps to categorize the vulnerability of the energy infrastructure into three stages. The study revealed that although there are many publications covering the vulnerability and resilience of the energy infrastructure, considering extreme climate events, the majority are focused on the direct impact of extreme climate on the energy ecosystem. In addition, most of the studies do not consider the impact of future climate variations during this assessment. The propagation of disruptions was assessed mainly for wildfires and hurricanes. Further, there is a clear research gap in considering vulnerability assessment for interconnected energy infrastructure. Here, the transformation of energy systems into a complex ecosystem notably increases the complexity, making it difficult to assess vulnerability and resilience. A shift from a centralized to decentralized modeling architecture could be beneficial when considering the complexities brought by that transformation. Hybrid models consisting of both physical and data-driven machine learning techniques could also be beneficial in this context.

54 ENVIRONMENTAL SCIENCES↗

Security Vulnerability and Mitigation in Photovoltaic Systems

Software and firmware vulnerabilities pose security threats to photovoltaic (PV) systems. When patches are not available or cannot be timely applied to fix vulnerabilities, it is important to mitigate vulnerabilities such that they cannot be exploited by attackers or their impacts will be limited when exploited. However, the vulnerability mitigation problem for PV systems has received little attention. This paper analyzes known security vulnerabilities in PV systems, proposes a multi-level mitigation framework and various mitigation strategies including neural network-based attack detection inside inverters, and develops a prototype system as a proof-of-concept for building vulnerability mitigation into PV system design.

14 SOLAR ENERGY↗

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

An Interpretable Index of Social Vulnerability to Environmental Hazards

Index-based measures of social vulnerability to environmental hazards are commonly modeled from composites of population-level risk factors. These models overlook individual context in communities' experiences of environmental hazards, producing metrics that may hinder spatial decision support for mitigating and responding to hazards. This paper introduces an interpretable, high-resolution model for generating an individual-oriented social vulnerability index (IOSVI) for the United States built on synthetic populations that couples individual and social determinants of vulnerability. The IOSVI combines an individual vulnerability index (IVI) that ranks individuals in an area’s synthetic population based on intersecting risk factors, with a social vulnerability index (SVI) based on the population’s cumulative distribution of IVI scores. Interpretability of the IOSVI procedure is demonstrated through examples of national, metropolitan, and neighborhood (census tract) level spatial variation in index scores and IVI themes, as well as an exploratory analysis examining risk factors affecting a specific sub-population (military veterans) in areas of high social and environmental vulnerability.

Tuccillo, Joe↗

Community vulnerability is the key determinant of diverse energy burdens in the United States

Low-income households generally experience a high energy burden; however, the factors influencing energy burdens are beyond socio-economics. This study explores the relationships between the multidimensionality of community vulnerability factors and energy burden across multiple geospatial levels in the United States. Our study found the distribution of energy burden in 2020 showed a great deal of variety, ranging from a minimum of 2.93 % to a maximum of 30.45 % across 3142 counties. The results of non-spatial and spatial regressions showed that the vulnerability ranks of socioeconomic, household composition and disability, minority and language, household type and transportation, and COVID mortality rate are significant predictors of energy burdens at the national level. However, at the regional level, only socioeconomic, minority and language significantly influence energy burdens. Minority and language negatively impact energy burdens except for the South East-Central region. Additionally, our analyses highlight the need to consider community vulnerability indicators' spatial homogeneity and heterogeneity. At the national level, only the epidemiological factors index is a spatially homogeneous predictor; on the regional and state level, the spatially homogeneous predictors such as socioeconomic status, household composition and disability, and household type and transportation vary by region. Such a region-sensitive relationship between energy burden and the predictors indicates spatial heterogeneity. Here this study suggests policy recommendations through the lens of the multidimensionality of community vulnerability factors. Implementing flexible national energy policies while making particular energy assistance policies for the vulnerable population at the regional or state levels is essential.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗