Engineering PapersSearch

SEARCH · Engineering Papers

Results for “vulnerability”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Blueprint: Stakeholder-Specific Vulnerability Categorization Guidance

Vulnerability management is a process of discovering, analyzing, and handling new or reported security vulnerabilities in systems to prevent the systems from being exploited, to reduce risk, and to protect assets. For vulnerability analysis, handling, and response, the prioritization of organizational and analyst resources must precede. The Common Vulnerability Scoring System (CVSS) is a standard prioritization method that is used to rate the severity of security vulnerabilities in systems by assigning numerical severity scores, but it does not provide clear guidelines of how the numerical severity scores might inform decisions. The Stakeholder-Specific Vulnerability Categorization (SSVC) provides a method for prioritizing vulnerabilities based on the needs of the stakeholders involved in the vulnerability management process. Instead of the numerical scoring used in the CVSS, the SSVC focuses on contextual decision-making to determine how quickly and effectively an organization should respond to vulnerabilities. The main functionality of the SSVC accommodates the diversity of the stakeholders in the vulnerability management process, including finders, vendors, coordinators, deployers, and others. So, the SSVC should be designed to be used by any of these stakeholders, and it should be customizable to enable specific stakeholder decision models and risk appetites.

33 ADVANCED PROPULSION SYSTEMS

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip

Development of the Contamination Distribution Centered Toxics Mobility Vulnerability Index in the Beaumont–Port Arthur Region of Texas

This study advances the Toxics Mobility Inventory (TMI) and the Toxics Mobility Vulnerability Index (TMVI) to develop a new tool to assess the movement of hazardous substances and their implications for vulnerable communities. It emphasizes the need to include contamination distribution variables in such indices to address disproportionate impacts and more accurately reflect vulnerability. The study uses the TMI framework and TMVI methodology in the Beaumont–Port Arthur region of Texas, also integrating contamination distribution considerations into the analysis to develop a new framework and process. The new Contamination Distribution Centered Toxics Mobility Vulnerability Index (CDC-TMVI) consolidates climate change and topography variables into a broader built environment vulnerability category while introducing a contamination sources category. Using ArcGIS Pro and ToxPi tools, the study evaluates 27 geospatial variables across four categories: built environment vulnerability, social vulnerability, health outcomes, and contamination sources. The results indicate significant contributions from contamination and social vulnerability variables, highlighting areas with higher risks of flooding and air pollution. This article advocates for future research and policy efforts to enhance the integration of contamination sources and their spatial distributions into toxics mobility assessments to better protect vulnerable populations. Furthermore, the unique methodology and findings serve as a basis for developing targeted measures and strategic planning to improve environmental health.

contamination

Security Vulnerability Profiles of Mission Critical Software: Empirical Analysis of Security Related Bug Reports

While some prior research work exists on characteristics of software faults (i.e., bugs) and failures, very little work has been published on analysis of software applications vulnerabilities. This paper aims to contribute towards filling that gap by presenting an empirical investigation of application vulnerabilities. The results are based on data extracted from issue tracking systems of two NASA missions. These data were organized in three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified security related software bugs and classified them in specific vulnerability classes. Then, we created the security vulnerability profiles, i.e., determined where and when the security vulnerabilities were introduced and what were the dominating vulnerabilities classes. Our main findings include: (1) In IVV issues datasets the majority of vulnerabilities were code related and were introduced in the Implementation phase. (2) For all datasets, around 90 of the vulnerabilities were located in two to four subsystems. (3) Out of 21 primary classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, they contributed from 80 to 90 of vulnerabilities in each dataset.

Goseva-Popstojanova, Katerina

Establishing nationwide power system vulnerability index across US counties using interpretable machine learning

Power outages have become increasingly frequent, intense, and prolonged in the US due to climate change, aging electrical grids, and rising energy demand. However, largely due to the absence of granular spatiotemporal outage data, we lack data-driven evidence and analytics-based metrics to quantify power system vulnerability. This limitation has hindered the ability to effectively evaluate and address vulnerability to power outages in US communities. Here, in this work, we collected ∼179 million power outage records at 15-min intervals across 3022 US contiguous counties (96.15 % of the area) from 2014 to 2023. We developed a power system vulnerability assessment framework based on three dimensions (intensity, frequency, and duration) and applied interpretable machine learning models (XGBoost and SHAP) to compute Power System Vulnerability Index (PSVI) at the county level. Our analysis reveals a consistent increase in power system vulnerability across the US counties over the past decade. We identified 318 counties across 45 states as hotspots for high power system vulnerability, particularly in the West Coast (California and Washington), the East Coast (Florida and the Northeast area), the Great Lakes megalopolis (Chicago-Detroit metropolitan areas), and the Gulf of Mexico (Texas). Our heterogeneity analysis indicates that urban counties and those located along regional transmission boundaries tend to exhibit significantly higher vulnerability. Our results highlight the significance of the proposed PSVI for evaluating the vulnerability of communities to power outages. The findings underscore the widespread and pervasive impact of power outages across the country and offer crucial insights to support infrastructure operators, policymakers, and emergency managers in formulating policies and programs aimed at enhancing the resilience of the US power infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION

When ChatGPT Meets Vulnerability Management: The Good, the Bad, and the Ugly

Vulnerability management is a very challenging and time-consuming task. For many organizations, security operators need to learn about the properties of vulnerabilities to prioritize and mitigate them. Due to the lack of automated tools for vulnerability assessment, operators usually manually search for and read related information from sources online. Recent advances in large language models, like ChatGPT, open up an opportunity for time savings and may prompt operators to use these models as vulnerability information sources. In this work, we evaluate the ability of ChatGPT and several of its siblings to accurately answer user questions about vulnerability properties as well as to provide information for how to mitigate a vulnerability. We also explore their summarization capabilities when multiple vulnerability advisory documents are provided. We find that the models perform poorly on information retrieval tasks, but they perform quite well on summarization.

McClanahan, Kylie

An Extreme-Value Approach to Anomaly Vulnerability Identification

The objective of this paper is to present a method for importance analysis in parametric probabilistic modeling where the result of interest is the identification of potential engineering vulnerabilities associated with postulated anomalies in system behavior. In the context of Accident Precursor Analysis (APA), under which this method has been developed, these vulnerabilities, designated as anomaly vulnerabilities, are conditions that produce high risk in the presence of anomalous system behavior. The method defines a parameter-specific Parameter Vulnerability Importance measure (PVI), which identifies anomaly risk-model parameter values that indicate the potential presence of anomaly vulnerabilities, and allows them to be prioritized for further investigation. This entails analyzing each uncertain risk-model parameter over its credible range of values to determine where it produces the maximum risk. A parameter that produces high system risk for a particular range of values suggests that the system is vulnerable to the modeled anomalous conditions, if indeed the true parameter value lies in that range. Thus, PVI analysis provides a means of identifying and prioritizing anomaly-related engineering issues that at the very least warrant improved understanding to reduce uncertainty, such that true vulnerabilities may be identified and proper corrective actions taken.

Everett, Chris

Assessing Environmental and Socioeconomic Factors of Urban Flood Vulnerability in Kansas City, Kansas

Pluvial flooding, over-saturated ground, and drainage systems disproportionately impact historically marginalized urban neighborhoods during extreme rainfall events. These communities are impacted by physical and socioeconomic factors that make them vulnerable to flooding events, such as high concentrations of impervious landcover, high precipitation rates, and a combined sewer system framework. Despite known vulnerability to environmental hazards, understanding potential pluvial street-level flooding events are largely unknown. Using the open-source National Capital Project’s Integrated Valuation of Ecosystem Services and Tradeoffs (InVEST) Urban Flood Risk Mitigation model, NASA DEVELOP examined neighborhood scale runoff retention and potential economic damages for risk mapping throughout Kansas City, Kansas. The generated outputs aid in identifying vulnerable neighborhoods susceptible to flooding and in need of future intervention. Previous studies have applied this model framework to understand urban flood vulnerability regarding ecosystem services, urban planning, and flood mitigation strategies. We utilized the InVEST outputs to develop indices pertaining to environmental justice factors of race, socioeconomic status, social vulnerability, and health. The findings indicate that historically redlined neighborhoods in Kansas City, Kansas face disproportional impacts from flood events and are subject to greater environmental stressors. This research provides an approach to utilizing an open-source flood vulnerability model to empower neighborhood-scale environmental justice analysis, enhancing the local communities' understanding of present-day impacts of historical environmental injustices.

Hadwynne Gross

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization

Spatiotemporal Associations Between Social Vulnerability, Environmental Measurements, and COVID-19 in the Conterminous United States

This study summarizes the results from fitting a Bayesian hierarchical spatiotemporal model to coronavirus disease 2019 (COVID-19) cases and deaths at the county level in the United States for the year 2020. Two models were created, one for cases and one for deaths, utilizing a scaled Besag, York, Mollié model with Type I spatial-temporal interaction. Each model accounts for 16 social vulnerability and 7 environmental variables as fixed effects. The spatial pattern between COVID-19 cases and deaths is significantly different in many ways. The spatiotemporal trend of the pandemic in the United States illustrates a shift out of many of the major metropolitan areas into the United States Southeast and Southwest during the summer months and into the upper Midwest beginning in autumn. Analysis of the major social vulnerability predictors of COVID-19 infection and death found that counties with higher percentages of those not having a high school diploma, having non-White status and being Age 65 and over to be significant. Among the environmental variables, above ground level temperature had the strongest effect on relative risk to both cases and deaths. Hot and cold spots, areas of statistically significant high and low COVID-19 cases and deaths respectively, derived from the convolutional spatial effect show that areas with a high probability of above average relative risk have significantly higher Social Vulnerability Index composite scores. The same analysis utilizing the spatiotemporal interaction term exemplifies a more complex relationship between social vulnerability, environmental measurements, COVID-19 cases, and COVID-19 deaths.

spatial epidemiology

Portland Urban Development: Quantifying and Visualizing Urban Heat with Compounding Vulnerabilities to Support Community Depaving Initiatives

Urban heat is a pressing concern in Portland, Oregon as climate change induced heat waves increase. Cities experience higher temperatures due to the urban heat island effect (UHI), and environmental injustice and disenfranchisement in minority communities expose low-income and Black, Indigenous, and People of Color (BIPOC) residents to more extreme and debilitating heat events. Our team identified Portland’s communities on the frontlines of urban heat impacts by overlapping environmental and social vulnerabilities using NASA Earth observations. We partnered with Depave, a Portland-based nonprofit that works alongside communities to replace pavement with greenspace in historically disenfranchised areas. Using Landsat 8 Thermal Infrared Sensor (TIRS) imagery, we mapped Land Surface Temperature (LST) and developed a heat-specific Social Vulnerability Index (SVI) through a Principal Component Analysis (PCA) to identify Portland’s communities with the highest potential heat vulnerability. Then, we calculated the temperature change of depaving in six case studies to quantify Depave's efforts in heat mitigation and environmental justice. Our analysis demonstrated that, throughout Portland, there are frontline communities experiencing high potential social vulnerability to extreme temperatures due to environmental injustices and over-pavement. Finally, Depave’s impact on urban heat is observable and quantifiable using remote-sensing data and tools, with an average of 1ºF LST decrease across the six case studies. We illustrated the significance of local urban heat mitigation efforts and propose next steps for conducting inclusive and intentional research that highlights the lived experiences and resilience of frontline communities.

Environmental justice

V-INT: Automated Vulnerability Intelligence and Risk Assessment

The project team, including the University of Arkansas (UA) as the lead, the University of Arkansas at Little Rock (UALR), Network Perception (NP), and Bastazo, has successfully researched, developed, and demonstrated the V-INT toolset, and also integrated it into the commercial products of NP (i.e., NP-View) and Bastazo (i.e., Spartan). The end product is a cybersecurity software tool for energy utilities that can automatically assess the risks of software vulnerabilities in an organization’s assets considering the organization’s firewall policies. It allows security operators to identify the small portion of vulnerabilities that poses true threats to their system (i.e., those that are not protected by firewall policies) and prioritize the mitigation of these vulnerabilities to minimize risks. It also allows security operators to identify the vulnerability-induced attack paths under their organization’s firewall policy, providing effective decision supports for mitigating potential attacks.

97 MATHEMATICS AND COMPUTING

Vulnerability

The discussion of vulnerability begins with a description of some of the electrical characteristics of fibers before definiting how vulnerability calculations are done. The vulnerability results secured to date are presented. The discussion touches on post exposure vulnerability. After a description of some shock hazard work now underway, the discussion leads into a description of the planned effort and some preliminary conclusions are presented.

Taback, I.

Vulnerabilities, Influences and Interaction Paths: Failure Data for Integrated System Risk Analysis

We describe graph-based analysis methods for identifying and analyzing cross-subsystem interaction risks from subsystem connectivity information. By discovering external and remote influences that would be otherwise unexpected, these methods can support better communication among subsystem designers at points of potential conflict and to support design of more dependable and diagnosable systems. These methods identify hazard causes that can impact vulnerable functions or entities if propagated across interaction paths from the hazard source to the vulnerable target. The analysis can also assess combined impacts of And-Or trees of disabling influences. The analysis can use ratings of hazards and vulnerabilities to calculate cumulative measures of the severity and importance. Identification of cross-subsystem hazard-vulnerability pairs and propagation paths across subsystems will increase coverage of hazard and risk analysis and can indicate risk control and protection strategies.

Malin, Jane T.

Disturbance Distance: Quantifying Forests' Vulnerability to Disturbance Under Current and Future Conditions

Disturbances, both natural and anthropogenic, are critical determinants of forest structure, function, and distribution. The vulnerability of forests to potential changes in disturbance rates remains largely unknown. Here, we developed a framework for quantifying and mapping the vulnerability of forests to changes in disturbance rates. By comparing recent estimates of observed forest disturbance rates over a sample of contiguous US forests to modeled rates of disturbance resulting in forest loss, a novel index of vulnerability, Disturbance Distance, was produced. Sample results indicate that 20% of current US forestland could be lost if disturbance rates were to double, with southwestern forests showing highest vulnerability. Under a future climate scenario, the majority of US forests showed capabilities of withstanding higher rates of disturbance then under the current climate scenario, which may buffer some impacts of intensified forest disturbance.

Dolan, Katelyn A.

Utilizing Airborne and Space-Based Remote Sensing Imagery to Implement the Unvegetated-Vegetated Ratio to Assess Salt Marsh Vulnerability in South Carolina

Among the most productive ecosystems on earth, salt marshes provide crucial ecosystem services including water filtration, shoreline protection, storm surge buffering, and flood mitigation. Marshes are largely dependent on their sediment budget which can significantly vary across a region and can be used to determine the life span of the marsh. Upstream land use change near Charleston, South Carolina, along with rising sea levels, are expected to alter sediment budgets and threaten marsh stability and long-term health. The unvegetated-vegetated ratio (UVVR), developed by researchers at USGS, is a scalable and efficient method to assess vulnerability. The NASA DEVELOP National Program collaborated with the South Carolina Department of Natural Resources, the South Carolina Department of Health and Environmental Control, and the United States Geological Survey Woods Hole Coastal and Marine Science Center to apply the UVVR method within Google Earth Engine. Marsh vulnerability was analyzed using UVVR derived from clustering and manual interpretation of National Agriculture Imagery Program (NAIP) high-resolution aerial imagery. NAIP derived UVVR was aggregated to Landsat 8 Operational Land Imager (OLI) and Landsat 7 Enhanced Thematic Mapper (ETM+) resolution and projection. A Random Forest Regression between Landsat derived data and UVVR was modeled to estimate a potential relationship. The estimation of this relationship was used to produce temporal change analysis maps of salt marsh vulnerability back to 1984. The NAIP imagery processed through Google Earth Engine allowed us to make detailed UVVR maps for 2009, 2015, 2017, and 2019 for decision making within South Carolina. Google Earth Engine scripting provided a novel approach to UVVR methodology that will allow decision makers to input new marsh regions and easily calculate marsh vulnerability without external data downloading. These results were used to understand what areas of the marsh need most resource allocation in the future.

NASA DEVELOP