Integrating Earth Observations and Socioeconomic Data to Address Converging Social and Environmental Vulnerabilities at a Local Level: Lessons Learned from NASA DEVELOP
Explore the source record for details and available documents.
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.
As the use of microservices continues to grow and become a foundational approach to architecting software solutions, ensuring the security of microservices is paramount. Docker images have emerged as the predominant solution to containerize microservices–and thus, Docker images are becoming a large attack surface. Thus, reducing vulnerabilities in Docker images will reduce microservice cyberattacks. A common way to find vulnerabilities in Docker images employs static analysis tools like Trivy and Grype. However, these tools frequently generate disparate vulnerability reports when analyzing the same Docker image, thus causing uncertainty in tool selection. We collected 927 Docker images, analyzed them with Trivy and Grype, and compared the vulnerabilities reported in each image. Among the 865 images found to have vulnerabilities, Trivy and Grype disagreed on both the number of vulnerabilities and the vulnerability IDs found therein. Since both tools interface with external vulnerability databases, some discrepancies can be attributed to how the tools interface with these external resources. The external vulnerability databases partially overlap and frequently contradict one another, thereby creating challenges for static analysis tool developers and end users alike. This New Ideas and Emerging Results (NIER) study contains new and critical information that practitioners need for selecting and using static analysis tools–given that increases in the use of Docker technologies means increases in the size of the attack surfaces.
Abstract. Fire is a fundamental part of the Earth system, with impacts on vegetation structure, biomass, and community composition, the latter mediated in part via key fire-tolerance traits, such as bark thickness. Due to anthropogenic climate change and land use pressure, fire regimes are changing across the world, and fire risk has already increased across much of the tropics. Projecting the impacts of these changes at global scales requires that we capture the selective force of fire on vegetation distribution through vegetation functional traits and size structure. We have adapted the fire behavior and effects module, SPITFIRE (SPread and InTensity of FIRE), for use with the Functionally Assembled Terrestrial Ecosystem Simulator (FATES), a size-structured vegetation demographic model. We test how climate, fire regime, and fire-tolerance plant traits interact to determine the biogeography of tropical forests and grasslands. We assign different fire-tolerance strategies based on crown, leaf, and bark characteristics, which are key observed fire-tolerance traits across woody plants. For these simulations, three types of vegetation compete for resources: a fire-vulnerable tree with thin bark, a vulnerable deep crown, and fire-intolerant foliage; a fire-tolerant tree with thick bark, a thin crown, and fire-tolerant foliage; and a fire-promoting C4 grass. We explore the model sensitivity to a critical parameter governing fuel moisture and show that drier fuels promote increased burning, an expansion of area for grass and fire-tolerant trees, and a reduction of area for fire-vulnerable trees. This conversion to lower biomass or grass areas with increased fuel drying results in increased fire-burned area and its effects, which could feed back to local climate variables. Simulated size-based fire mortality for trees less than 20 cm in diameter and those with fire-vulnerable traits is higher than that for larger and/or fire-tolerant trees, in agreement with observations. Fire-disturbed forests demonstrate reasonable productivity and capture observed patterns of aboveground biomass in areas dominated by natural vegetation for the recent historical period but have a large bias in less disturbed areas. Though the model predicts a greater extent of burned fraction than observed in areas with grass dominance, the resulting biogeography of fire-tolerant, thick-bark trees and fire-vulnerable, thin-bark trees corresponds to observations across the tropics. In areas with more than 2500 mm of precipitation, simulated fire frequency and burned area are low, with fire intensities below 150 kW m−1, consistent with observed understory fire behavior across the Amazon. Areas drier than this demonstrate fire intensities consistent with those measured in savannas and grasslands, with high values up to 4000 kW m−1. The results support a positive grass–fire feedback across the region and suggest that forests which have existed without frequent burning may be vulnerable at higher fire intensities, which is of greater concern under intensifying climate and land use pressures. The ability of FATES to capture the connection between fire disturbance and plant fire-tolerance strategies in determining biogeography provides a useful tool for assessing the vulnerability and resilience of these critical carbon storage areas under changing conditions across the tropics.
This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.
As technology and security measures improve, hackers keep looking for new techniques and vulnerabilities that allow them to gain access to sensitive data. This includes but is not limited to: user accounts, personal information, databases, operating systems, developmental and testing systems, and operational systems. A hacker is an individual that uses technology such as computers, tablets, and phones for unauthorized access to data. As technology becomes more robust at preventing known attacks, new vulnerabilities always exists. These vulnerabilities usually go unnoticed by developers and could potentially be exploited by an attacker. To prevent hackers from stealing sensitive and potentially harmful information, we must protect our systems and data against these criminals by developing new methods to mitigate the damage caused by these vulnerabilities and prevent them from occurring in the first place. An excellent way to discover how hackers compromise systems is by identifying and analyzing existing vulnerabilities and patching them. The National Aeronautics and Space Administration (NASA) is one of the many federal agencies that operates under a constant threat by hackers. NASA puts a tremendous amount of effort to maintain and improve their security measures, protect critical systems, and secure sensitive information from attackers who would attempt to use it against our nation's interests.
Global climate changes contribute to more intense and frequent tropical storms, subjecting places like Toa Baja, Puerto Rico to critical damage. Known as “the underwater city” due to its propensity to flood, residents of Toa Baja face constant flood risk. During extreme tropical storm events, such as Hurricane Maria in 2017, residents experienced up to 20 feet of inundation. The NASA DEVELOP National Program collaborated with the Municipio Autónomo de Toa Baja, ResilientSEE-PR, and the MIT Urban Risk Lab to supplement 2018 FEMA HEC-RAS flood maps that designate 63% of Toa Baja as a flood plain. This analysis provides a high-resolution interpretation of flood risk through two lenses; susceptibility and vulnerability. For this analysis, susceptibility consists of nine weighted layers: NDVI, landcover, slope, elevation, topographic wetness index, height above nearest drainage, saturated hydraulic conductivity, distance to water, and storm surge. These factors are consistently used to evaluate susceptibility to flood, but their weights vary by analysis. Vulnerability consists of population, informal settlements, and building density, which were given equal weight. Susceptibility and vulnerability were combined to map flood risk. This analysis used a bivariate legend to understand the different levels of risk along a spectrum from low susceptibility and low vulnerability (low risk) to high susceptibility and high vulnerability (high risk). Data processed in Google Earth Engine, which identified historical inundation on various occasions, were used to validate the flood susceptibility layers. Results showed 89% of areas designated as high susceptibility are located within the floodway designated by the FEMA HEC-RAS maps. The eastern region of Toa Baja is most at risk for flooding due to high susceptibility to flooding along with a high density of population, buildings, and informal settlements. The resulting map also reveals the presence of smaller high-risk areas all around the municipality. This analysis provides scientific evidence for flood risk mitigation in Toa Baja by highlighting areas that might be impacted by strong floods in the future. Additionally, these results are communicated in an Esri ArcGIS StoryMap, an accessible platform that can easily inform the public about the flood risk in their neighborhood.
Software applications become more complicated over time as they depend on many third-party, open-source libraries. The Freddie Platform Services team actively improves software security by addressing software bugs and vulnerabilities that negatively impact software applications, especially those providing real-time operations and services for the federal partners and industries. In order to detect bugs and patch vulnerabilities in software development and maintenance cycles, an automated and systematic approach is needed. This document describes what bugs and vulnerabilities are, and how they can be detected by using static code analyzers and software composition analysis tools. Once vulnerabilities are detected, the patching approaches, such as upgrading direct and transitive dependencies and loading custom classes first, are presented together with their strengths and weaknesses. In addition, patching walkthrough, example code, lessons learned throughout the vulnerability patching process and the recommended practices are discussed.
Asheville, North Carolina experiences the urban heat island effect, where temperatures in the city are higher than in surrounding rural areas. This effect intensifies with increased urbanization and less vegetative cover. Asheville’s urban heat island was exacerbated by population increases and tree cover decline, escalating the need for heat mitigation. We partnered with the City of Asheville’s Sustainability Department and Asheville GreenWorks whose actions prioritize sustainable city planning and equitable climate resilience. Using NASA Earth observations and ancillary datasets we spatially mapped urban heat, heat vulnerability, and cooling and adaptive capacity from 2019-2023. To map urban heat, we used Landsat 8 and 9 Operational Land Imager and Thermal Infrared Sensor for land surface temperature and albedo data and the ECOsystem Spaceborne Thermal Radiometer Experiment on Space Station for evapotranspiration data. We assessed heat vulnerability using the urban heat data andthe Centers for Disease Control and Prevention’s Social Vulnerability Index. To evaluate cooling and adaptive capacity we used the InVEST Urban Cooling Model, integrating our heat vulnerability analysis with land use and cover data from Sentinel-1 Synthetic Aperture Rada rand Sentinel-2 Multispectral Instrument. Our results revealed distinct spatial patterns of urban heat, heat vulnerability, and cooling and adaptive capacity in Asheville with downtown as the focal hotspot and an outward decreasing radial pattern. These findings highlight targeted need for interventions to reduce heat impacts, address environmental injustices, and enhance climate resilience. Our project provided research to local organizations that can be used for heat mitigation in the greater Asheville area.
The cyber risk landscape for BESS and IBR can be broken up by threats, vulnerabilities, and consequences for these systems. This presentation walks through the cyber risk landscape for BESS through the lens of consequence-informed awareness and mitigation for each risk factor. Threats with varying capabilities have been demonstrated in real-world events. Though threat actors can rarely be directly influenced by organizations, exposure of systems to adversaries can be limited (a known issue with IBR systems) to reduce likelihood of adversaries accessing systems with disruptive consequences. Common trends in disclosed IBR vulnerabilities include weak password generation or managements for various devices or services and web portal vulnerabilities that provide unauthorized access to data or capabilities or elevated user privileges. Understanding these common vulnerabilities and considering the consequences if these types of vulnerabilities were to occur can help mitigate risk. Consequences range from loss-of-view events that have no reliability impact to asset damage or grid stability impacts. Five case studies are briefly shared to highlight trends in real-world events affecting IBR.
Wichita, Kansas is experiencing a host of climate threats, particularly extreme heat manifested through Urban Heat Islands (UHI). Heat is unevenly distributed within cities due to factors such as income inequality, historical discriminatory practices like redlining, and divestment in neighborhoods of color. This leads to less vegetation and more heat-absorbing infrastructure in specific communities. Moreover, adverse effects of heat, including heat-related morbidity and mortality, disproportionately impact populations that experience vulnerability through social inequities and structural discrimination. Heat vulnerability is a combination of the factors of heat exposure, sensitivity, and adaptive capacity, and can be harnessed to guide urban heat interventions. This DEVELOP project partnered with the City of Wichita to understand the spatial distribution and drivers of UHIs and heat vulnerability indicators. The team modeled outcomes of tree cover interventions using Landsat 8’s Thermal Infrared Sensor (TIRS) and Operational Land Imager (OLI), Landsat 9 TIRS-2 and OLI-2, and the International Space Station’s Ecosystem Spaceborne Thermal Radiometer Experiment on the International Space Station (ECOSTRESS) sensor, along with the Integrated Valuation of Ecosystem Services and Tradeoffs (InVEST) Urban Cooling model. The team also leveraged statistical analysis by implementing principal component analysis to develop a heat vulnerability index (HVI) specific to Wichita. Ultimately, the project’s outputs will inform the City of Wichita’s Climate Adaptation and Mitigation Plan, identify priority areas for heat mitigation initiatives, and be used in public-facing communications to educate communities on the impacts of urban heat.
When a vulnerability is reported by the National Vulnerability Database (NVD), affected products are listed in the structured Common Platform Enumeration (CPE) format. Unfortunately, if the vulnerability is in a software library (e.g., Log4j), it will not include CPEs for each product containing that library. In these cases, security operators need to manually read the vendor's or third-party security advisories to see if their product is affected. However, these advisories do not report affected products in a structured format, which prevents automated processing, This paper makes the first effort towards automatically constructing structured CPEs for the vulnerable products in a non-NVD security advisory from the unstructured data in the advisory. Since this is a very challenging problem, this paper specifically focuses on the initial but key step of matching the un-structured vendor names in security advisories to the structured vendor representations in the standard CPE format. We explore the feasibility of using string similarity to solve the problem. The basic idea is to compare a vendor name from the non-NVD advisory with each vendor in the official CPE dictionary. The CPE vendor with the highest similarity score to the advisory's vendor will be considered as the match. We first conduct an experimental, comparative study of multiple mainstream string similarity metrics for this matching problem. To improve the performance, we then design a new string similarity metric that is adapted from an existing metric by weighing different tokens in the advisory's vendor name differently.