Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Vulnerability management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Vulnerability Management for Electric Vehicle Supply Equipment

Vulnerability management for EVSE is a challenging undertaking with all the necessary stakeholders and devices that are interconnected, this presentation reviews the challenges and opportunities for conducting CVD for EVSE.

97 MATHEMATICS AND COMPUTING

When ChatGPT Meets Vulnerability Management: The Good, the Bad, and the Ugly

Vulnerability management is a very challenging and time-consuming task. For many organizations, security operators need to learn about the properties of vulnerabilities to prioritize and mitigate them. Due to the lack of automated tools for vulnerability assessment, operators usually manually search for and read related information from sources online. Recent advances in large language models, like ChatGPT, open up an opportunity for time savings and may prompt operators to use these models as vulnerability information sources. In this work, we evaluate the ability of ChatGPT and several of its siblings to accurately answer user questions about vulnerability properties as well as to provide information for how to mitigate a vulnerability. We also explore their summarization capabilities when multiple vulnerability advisory documents are provided. We find that the models perform poorly on information retrieval tasks, but they perform quite well on summarization.

McClanahan, Kylie

Cyber Security for the Spaceport Command and Control System: Vulnerability Management and Compliance Analysis

With the rapid development of the Internet, the number of malicious threats to organizations is continually increasing. In June of 2015, the United States Office of Personnel Management (OPM) had a data breach resulting in the compromise of millions of government employee records. The National Aeronautics and Space Administration (NASA) is not exempt from these attacks. Cyber security is becoming a critical facet to the discussion of moving forward with projects. The Spaceport Command and Control System (SCCS) project at the Kennedy Space Center (KSC) aims to develop the launch control system for the next generation launch vehicle in the coming decades. There are many ways to increase the security of the network it uses, from vulnerability management to ensuring operating system images are compliant with securely configured baselines recommended by the United States Government.

Cyber Security

Blueprint: Stakeholder-Specific Vulnerability Categorization Guidance

Vulnerability management is a process of discovering, analyzing, and handling new or reported security vulnerabilities in systems to prevent the systems from being exploited, to reduce risk, and to protect assets. For vulnerability analysis, handling, and response, the prioritization of organizational and analyst resources must precede. The Common Vulnerability Scoring System (CVSS) is a standard prioritization method that is used to rate the severity of security vulnerabilities in systems by assigning numerical severity scores, but it does not provide clear guidelines of how the numerical severity scores might inform decisions. The Stakeholder-Specific Vulnerability Categorization (SSVC) provides a method for prioritizing vulnerabilities based on the needs of the stakeholders involved in the vulnerability management process. Instead of the numerical scoring used in the CVSS, the SSVC focuses on contextual decision-making to determine how quickly and effectively an organization should respond to vulnerabilities. The main functionality of the SSVC accommodates the diversity of the stakeholders in the vulnerability management process, including finders, vendors, coordinators, deployers, and others. So, the SSVC should be designed to be used by any of these stakeholders, and it should be customizable to enable specific stakeholder decision models and risk appetites.

33 ADVANCED PROPULSION SYSTEMS

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY

Managing a Vulnerability Testing Program

A good vulnerability testing program can help reduce system compromises, provide a way of assessing and measuring improvements in security, and motivate everyone to get involved.

Ray, John

Failure Modes and Effects Analysis (FMEA): A Bibliography

Failure modes and effects analysis (FMEA) is a bottom-up analytical process that identifies process hazards, which helps managers understand vulnerabilities of systems, as well as assess and mitigate risk. It is one of several engineering tools and techniques available to program and project managers aimed at increasing the likelihood of safe and successful NASA programs and missions. This bibliography references 465 documents in the NASA STI Database that contain the major concepts, failure modes or failure analysis, in either the basic index of the major subject terms.

Source record

Synthetic Scenarios from CMIP5 Model Simulations for Climate Change Impact Assessments in Managed Ecosystems and Water Resources: Case Study in South Asian Countries

Increasing population, urbanization, and associated demand for food production compounded by climate change and variability have important implications for the managed ecosystems and water resources of a region. This is particularly true for south Asia, which supports one quarter of the global population, half of whom live below the poverty line. This region is largely dependent on monsoon precipitation for water. Given the limited resources of the developing countries in this region, the objective of our study was to empirically explore climate change in south Asia up to the year 2099 using monthly simulations from 35 global climate models (GCMs) participating in the fifth phase of the Climate Model Inter-comparison Project (CMIP5) for two future emission scenarios (representative concentration pathways RCP4.5 and RCP8.5) and provide a wide range of potential climate change outcomes. This was carried out using a three-step procedure: calculating the mean annual, monsoon, and non-monsoon precipitation and temperatures; estimating the percent change from historical conditions; and developing scenario funnels and synthetic scenarios. This methodology was applied for the entire south Asia region; however, the percent change information generated at 1.5deg grid scale can be used to generate scenarios at finer spatial scales. Our results showed a high variability in the future change in precipitation (-23% to 52%, maximum in the non-monsoon season) and temperature (0.8% to 2.1%) in the region. Temperatures in the region consistently increased, especially in the Himalayan region, which could have impacts including a faster retreat of glaciers and increased floods. It could also change rivers from perennial to seasonal, leading to significant challenges in water management. Increasing temperatures could further stress groundwater reservoirs, leading to withdrawal rates that become even more unsustainable. The high precipitation variability (with higher propensity for localized intense rainfall events) observed in the region can be a key factor for managed ecosystems and water management and could also lead to more incidence of severe urban flooding. The results could be used to assess both mitigation and adaptation alternatives to reduce vulnerabilities in managed ecosystems (agricultural and urban) and water resources.

agriculture

The Role of Alerting System Failures in Loss of Control Accidents CAST SE-210 Output 2

This report is part of a series of reports that address flight deck design and evaluation, written as a response to loss of control accidents. In particular, this activity is directed at failures in airplane state awareness in which the pilot loses awareness of the airplane's energy state or attitude and enters an upset condition. In a report by the Commercial Aviation Safety Team, an analysis of accidents and incidents related to loss of airplane state awareness determined that hazard alerting was not effective in producing the appropriate pilot response to a hazard (CAST, 2014). In the current report, we take a detailed look at 28 airplane state awareness accidents and incidents to determine how well the hazard alerting worked. We describe a five-step integrated alerting-to-recovery sequence that prescribes how hazard alerting should lead to effective flight crew actions for managing the hazard. Then, for each hazard in each of the 28 events, we determine if that sequence failed and, if so, how it failed. The results show that there was an alerting failure in every one of the 28 safety events, and that the most frequent failure (20/28) was tied to the flight crew not orienting to (not being aware of) the hazard. The discussion section summarizes findings and identifies alerting issues that are being addressed and issues that are not currently being addressed. We identify a few recent upgrades that have addressed certain alerting failures. Two of these upgrades address alerting design, but one response to the safety events is to upgrade training for approach to stall and stall recovery. We also describe issues that are not being addressed adequately: better alert integration for flight path management types of hazards, airplanes in the fleet that do not meet the current alerting regulations, a lack of innovation for addressing cases of channelized attention, and existing vulnerabilities in managing data validity.

aviation safety

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization

I Can't Patch My OT Systems! A Look at CISA's KEVC Workarounds & Mitigations for OT

We examine the state of publicly available information about known exploitable vulnerabilities applicable to operational technology (OT) environments. Specifically, we analyze the Known Exploitable Vulnerabilities Catalog (KEVC) maintained by the US Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) to assess whether currently available data is sufficient for effective and reliable remediation in OT settings. Our team analyzed all KEVC entries through July 2025 to determine the extent to which OT environments can rely on existing remediation recommendations. We found that although most entries in the KEVC could affect OT environments, only 13% include vendor workarounds or mitigations as alternatives to patching. This paper also examines the feasibility of developing such alternatives based on vulnerability and exploit characteristics, and we present early evidence of success with this approach.

97 MATHEMATICS AND COMPUTING

Storm Surge and Ponding Explain Mangrove Dieback in Southwest Florida Following Hurricane Irma

Mangroves buffer inland ecosystems from hurricane winds and storm surge. However, their ability to withstand harsh cyclone conditions depends on plant resilience traits and geomorphology. Using airborne lidar and satellite imagery collected before and after Hurricane Irma, we estimated that 62% of mangroves in southwest Florida suffered canopy damage, with largest impacts in tall forests (>10 m). Mangroves on well-drained sites (83%) resprouted new leaves within one year after the storm. By contrast, in poorly-drained inland sites, we detected one of the largest mangrove diebacks on record (10,760 ha), triggered by Irma. We found evidence that the combination of low elevation (median = 9.4 cm asl), storm surge water levels (>1.4 m above the ground surface), and hydrologic isolation drove coastal forest vulnerability and were independent of tree height or wind exposure. Our results indicated that storm surge and ponding caused dieback, not wind. Tidal restoration and hydrologic management in these vulnerable, low-lying coastal areas can reduce mangrove mortality and improve resilience to future cyclones.

David Lagomasino

The Hurricane-Flood-Landslide Continuum

In August 2004, representatives from NOAA, NASA, the USGS, and other government agencies convened in San Juan, Puerto Rim for a workshop to discuss a proposed research project called the Hurricane-Flood-Landslide Continuum (HFLC). The essence of the HFLC is to develop and integrate tools across disciplines to enable the issuance of regional guidance products for floods and landslides associated with major tropical rain systems, with sufficient lead time that local emergency managers can protect vulnerable populations and infrastructure. All three lead agencies are independently developing precipitation-flood-debris flow forecasting technologies, and all have a history of work on natural hazards both domestically and overseas. NOM has the capability to provide tracking and prediction of storm rainfall, trajectory and landfall and is developing flood probability and magnTtude capabilities. The USGS has the capability to evaluate the ambient stability of natural and man-made landforms, to assess landslide susceptibilities for those landforms, and to establish probabilities for initiation of landslides and debris flows. Additionally, the USGS has well-developed operational capacity for real-time monitoring and reporting of streamflow across distributed networks of automated gaging stations (http://water.usgs.gov/waterwatch/). NASA has the capability to provide sophisticated algorithms for satellite remote sensing of precipitation, land use, and in the future, soil moisture. The Workshop sought to initiate discussion among three agencies regarding their specific and highly complimentary capabilities. The fundamental goal of the Workshop was to establish a framework that will leverage the strengths of each agency. Once a prototype system is developed for example, in relatively data-rich Puerto Rim, it could be adapted for use in data-poor, low-infrastructure regions such as the Dominican Republic or Haiti. This paper provides an overview of the Workshop s goals, presentations and recommendations with respect to the development of the HFLC.

Negri, Andrew J.

Bias Correction of Hydrologic Projections Strongly Impacts Inferred Climate Vulnerabilities in Institutionally Complex Water Systems

Water-resources planners use regional water management models (WMMs) to identify vulnerabilities to climate change. Frequently, dynamically downscaled climate inputs are used in conjunction with land-surface models (LSMs) to provide hydrologic streamflow projections, which serve as critical inputs for WMMs. Here, we show how even modest projection errors can strongly affect assessments of water availability and financial stability for irrigation districts in California. Specifically, our results highlight that LSM errors in projections of flood and drought extremes are highly interactive across timescales, path-dependent, and can be amplified when modeling infrastructure systems (e.g., misrepresenting banked groundwater). Common strategies for reducing errors in deterministic LSM hydrologic projections (e.g., bias correction) can themselves strongly distort projected climate vulnerabilities and misrepresent their inferred financial consequences. Overall, our results indicate a need to move beyond standard deterministic climate projection and error management frameworks that are dependent on single simulated climate change scenario outcomes.

Keyvan Malek

Enhancing Power Resilience for Remote Communities: A Comprehensive Renewable Energy Solution for Itbayat Island

The island of Itbayat, Philippines, faces significant challenges in maintaining a reliable and resilient power supply due to its current reliance on a vulnerable power distribution system managed by a local electric cooperative. The existing infrastructure, which includes diesel generators and a radial network configuration with some above-ground lines, is highly susceptible to frequent typhoons and adverse weather conditions. These factors, combined with inadequate staffing and high operational costs, result in frequent power outages that disrupt daily life and hinder economic development. This white paper proposes a comprehensive solution to enhance the resilience and reliability of Itbayat's power system by integrating renewable energy sources, specifically solar photovoltaic (PV) systems, battery storage, and a microgrid controller. The proposed solution aims to reduce dependency on diesel fuel, optimize energy use, and provide a sustainable and robust power supply for the island. Key components of the solution include: 1. Solar PV Installation: Deploying solar PV panels to harness abundant solar energy, reducing reliance on diesel fuel. 2. Battery Storage Systems: Installing battery storage to store excess solar energy and ensure a continuous power supply during low solar generation periods. 3. Microgrid Controller: Implementing a microgrid controller to manage and optimize the integration of solar PV, battery storage, and existing diesel generators. The proposed solution addresses several critical issues, including system vulnerability, generator dependency, and operational inefficiencies. By adopting this innovative approach, Itbayat Island can achieve a more resilient, efficient, and sustainable energy infrastructure, ensuring a stable power supply for its residents and enhancing overall energy security.

14 SOLAR ENERGY

Threat Landscape for BESS and IBR

The cyber risk landscape for BESS and IBR can be broken up by threats, vulnerabilities, and consequences for these systems. This presentation walks through the cyber risk landscape for BESS through the lens of consequence-informed awareness and mitigation for each risk factor. Threats with varying capabilities have been demonstrated in real-world events. Though threat actors can rarely be directly influenced by organizations, exposure of systems to adversaries can be limited (a known issue with IBR systems) to reduce likelihood of adversaries accessing systems with disruptive consequences. Common trends in disclosed IBR vulnerabilities include weak password generation or managements for various devices or services and web portal vulnerabilities that provide unauthorized access to data or capabilities or elevated user privileges. Understanding these common vulnerabilities and considering the consequences if these types of vulnerabilities were to occur can help mitigate risk. Consequences range from loss-of-view events that have no reliability impact to asset damage or grid stability impacts. Five case studies are briefly shared to highlight trends in real-world events affecting IBR.

14 - SOLAR ENERGY