Search NASA⌕ Search

SEARCH · Search NASA

Results for “Vulnerability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Data-driven Vulnerability Analysis of Networked Pipeline System

This paper introduces an attack generation framework for evaluating the vulnerability of nonlinear networked pipeline systems. The vulnerability analysis is formulated as determining the presence of feasible attack sets, defined by boundary functions representing the effectiveness and stealthiness of attack signals with respect to the objective and attack detection module. The framework utilizes three data-driven models, including two discriminative models that learn the boundary functions and a generative model that produces elements of the feasible attack set. A new loss function ensures successful attack generation with high probability.

03 NATURAL GAS↗

Space Station Program threat and vulnerability analysis

An examination has been made of the physical security of the Space Station Program at the Kennedy Space Center in a peacetime environment, in order to furnish facility personnel with threat/vulnerability information. A risk-management approach is used to prioritize threat-target combinations that are characterized in terms of 'insiders' and 'outsiders'. Potential targets were identified and analyzed with a view to their attractiveness to an adversary, as well as to the consequentiality of the resulting damage.

Van Meter, Steven D.↗

Vulnerability-attention analysis for space-related activities

Techniques for representing and analyzing trouble spots in structures and processes are discussed. Identification of vulnerable areas usually depends more on particular and often detailed knowledge than on algorithmic or mathematical procedures. In some cases, machine inference can facilitate the identification. The analysis scheme proposed first establishes the geometry of the process, then marks areas that are conditionally vulnerable. This provides a basis for advice on the kinds of human attention or machine sensing and control that can make the risks tolerable.

Ford, Donnie↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Blueprint: Stakeholder-Specific Vulnerability Categorization Guidance

Vulnerability management is a process of discovering, analyzing, and handling new or reported security vulnerabilities in systems to prevent the systems from being exploited, to reduce risk, and to protect assets. For vulnerability analysis, handling, and response, the prioritization of organizational and analyst resources must precede. The Common Vulnerability Scoring System (CVSS) is a standard prioritization method that is used to rate the severity of security vulnerabilities in systems by assigning numerical severity scores, but it does not provide clear guidelines of how the numerical severity scores might inform decisions. The Stakeholder-Specific Vulnerability Categorization (SSVC) provides a method for prioritizing vulnerabilities based on the needs of the stakeholders involved in the vulnerability management process. Instead of the numerical scoring used in the CVSS, the SSVC focuses on contextual decision-making to determine how quickly and effectively an organization should respond to vulnerabilities. The main functionality of the SSVC accommodates the diversity of the stakeholders in the vulnerability management process, including finders, vendors, coordinators, deployers, and others. So, the SSVC should be designed to be used by any of these stakeholders, and it should be customizable to enable specific stakeholder decision models and risk appetites.

33 ADVANCED PROPULSION SYSTEMS↗

Asheville Urban Development II: Mapping Urban Heat to Support Cooling Initiatives and Climate Resilience Planning in the Greater Asheville Area

Asheville, North Carolina experiences the urban heat island effect, where temperatures in the city are higher than in surrounding rural areas. This effect intensifies with increased urbanization and less vegetative cover. Asheville’s urban heat island was exacerbated by population increases and tree cover decline, escalating the need for heat mitigation. We partnered with the City of Asheville’s Sustainability Department and Asheville GreenWorks whose actions prioritize sustainable city planning and equitable climate resilience. Using NASA Earth observations and ancillary datasets we spatially mapped urban heat, heat vulnerability, and cooling and adaptive capacity from 2019-2023. To map urban heat, we used Landsat 8 and 9 Operational Land Imager and Thermal Infrared Sensor for land surface temperature and albedo data and the ECOsystem Spaceborne Thermal Radiometer Experiment on Space Station for evapotranspiration data. We assessed heat vulnerability using the urban heat data andthe Centers for Disease Control and Prevention’s Social Vulnerability Index. To evaluate cooling and adaptive capacity we used the InVEST Urban Cooling Model, integrating our heat vulnerability analysis with land use and cover data from Sentinel-1 Synthetic Aperture Rada rand Sentinel-2 Multispectral Instrument. Our results revealed distinct spatial patterns of urban heat, heat vulnerability, and cooling and adaptive capacity in Asheville with downtown as the focal hotspot and an outward decreasing radial pattern. These findings highlight targeted need for interventions to reduce heat impacts, address environmental injustices, and enhance climate resilience. Our project provided research to local organizations that can be used for heat mitigation in the greater Asheville area.

Authors not in NED but are confirmed contractors. ↗

Techniques for fire detection

An overview is given of the basis for an analysis of combustable materials and potential ignition sources in a spacecraft. First, the burning process is discussed in terms of the production of the fire signatures normally associated with detection devices. These include convected and radiated thermal energy, particulates, and gases. Second, the transport processes associated with the movement of these from the fire to the detector, along with the important phenomena which cause the level of these signatures to be reduced, are described. Third, the operating characteristics of the individual types of detectors which influence their response to signals, are presented. Finally, vulnerability analysis using predictive fire modeling techniques is discussed as a means to establish the necessary response of the detection system to provide the level of protection required in the application.

Bukowski, Richard W.↗

Utilizing Open-Source Earth Observations to Inform the Toa Baja Municipality’s Flood Risk Mitigation Efforts and Educate the Public

Global climate changes contribute to more intense and frequent tropical storms, subjecting places like Toa Baja, Puerto Rico to critical damage. Known as “the underwater city” due to its propensity to flood, residents of Toa Baja face constant flood risk. During extreme tropical storm events, such as Hurricane Maria in 2017, residents experienced up to 20 feet of inundation. The NASA DEVELOP National Program collaborated with the Municipio Autónomo de Toa Baja, ResilientSEE-PR, and the MIT Urban Risk Lab to supplement 2018 FEMA HEC-RAS flood maps that designate 63% of Toa Baja as a flood plain. This analysis provides a high-resolution interpretation of flood risk through two lenses; susceptibility and vulnerability. For this analysis, susceptibility consists of nine weighted layers: NDVI, landcover, slope, elevation, topographic wetness index, height above nearest drainage, saturated hydraulic conductivity, distance to water, and storm surge. These factors are consistently used to evaluate susceptibility to flood, but their weights vary by analysis. Vulnerability consists of population, informal settlements, and building density, which were given equal weight. Susceptibility and vulnerability were combined to map flood risk. This analysis used a bivariate legend to understand the different levels of risk along a spectrum from low susceptibility and low vulnerability (low risk) to high susceptibility and high vulnerability (high risk). Data processed in Google Earth Engine, which identified historical inundation on various occasions, were used to validate the flood susceptibility layers. Results showed 89% of areas designated as high susceptibility are located within the floodway designated by the FEMA HEC-RAS maps. The eastern region of Toa Baja is most at risk for flooding due to high susceptibility to flooding along with a high density of population, buildings, and informal settlements. The resulting map also reveals the presence of smaller high-risk areas all around the municipality. This analysis provides scientific evidence for flood risk mitigation in Toa Baja by highlighting areas that might be impacted by strong floods in the future. Additionally, these results are communicated in an Esri ArcGIS StoryMap, an accessible platform that can easily inform the public about the flood risk in their neighborhood.

Adriana Le Compte↗

Cyber Security for the Spaceport Command and Control System: Vulnerability Management and Compliance Analysis

With the rapid development of the Internet, the number of malicious threats to organizations is continually increasing. In June of 2015, the United States Office of Personnel Management (OPM) had a data breach resulting in the compromise of millions of government employee records. The National Aeronautics and Space Administration (NASA) is not exempt from these attacks. Cyber security is becoming a critical facet to the discussion of moving forward with projects. The Spaceport Command and Control System (SCCS) project at the Kennedy Space Center (KSC) aims to develop the launch control system for the next generation launch vehicle in the coming decades. There are many ways to increase the security of the network it uses, from vulnerability management to ensuring operating system images are compliant with securely configured baselines recommended by the United States Government.

Cyber Security↗

Forensic Analysis of SOHO Router Binaries

Small Office/Home Office (SOHO) routers are used by millions of consumers across the United States, and are commensurately vulnerable. Forensic analysis of SOHO router firmware helps to understand and mitigate those vulnerabilities. This poster focused particularly on analysis of BusyBox executables, a software suite that provides several Unix utilities in a single file. Three main tools were used to analyze the binaries. BinWalk was used to extract the files, but also to build entropy graphs, extract Linux kernel images, and identify CPU architectures; WiiBin processed the binaries to find endianness, architecture, the percent compressed/encrypted, and compiler data; and @DisCo, a machine learning tool used to determine function similarity in disassembled binaries, analyzed similarities and determined versions of extracted BusyBox files from each router. These tools found that venders from all five routers utilized the same version of the BusyBox software across different firmware updates, demonstrating the importance of constant firmware scrutiny to protect against security vulnerabilities.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A probabilistic analysis of electrical equipment vulnerability to carbon fibers

The statistical problems of airborne carbon fibers falling onto electrical circuits were idealized and analyzed. The probability of making contact between randomly oriented finite length fibers and sets of parallel conductors with various spacings and lengths was developed theoretically. The probability of multiple fibers joining to bridge a single gap between conductors, or forming continuous networks is included. From these theoretical considerations, practical statistical analyses to assess the likelihood of causing electrical malfunctions was produced. The statistics obtained were confirmed by comparison with results of controlled experiments.

Elber, W.↗

Security Vulnerability Profiles of Mission Critical Software: Empirical Analysis of Security Related Bug Reports

While some prior research work exists on characteristics of software faults (i.e., bugs) and failures, very little work has been published on analysis of software applications vulnerabilities. This paper aims to contribute towards filling that gap by presenting an empirical investigation of application vulnerabilities. The results are based on data extracted from issue tracking systems of two NASA missions. These data were organized in three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified security related software bugs and classified them in specific vulnerability classes. Then, we created the security vulnerability profiles, i.e., determined where and when the security vulnerabilities were introduced and what were the dominating vulnerabilities classes. Our main findings include: (1) In IVV issues datasets the majority of vulnerabilities were code related and were introduced in the Implementation phase. (2) For all datasets, around 90 of the vulnerabilities were located in two to four subsystems. (3) Out of 21 primary classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, they contributed from 80 to 90 of vulnerabilities in each dataset.

Goseva-Popstojanova, Katerina↗

Geospatial Capabilities to Couple Hazard and Social Vulnerability Data in Water Distribution Criticality Analysis

A resilience analysis of a water distribution system is greatly enhanced by the integration of up-to-date geospatial data describing the water system, hazards, and surrounding community. The Water Network Tool for Resilience (WNTR), an open-source Python package designed to simulate and analyze the resilience of water distribution systems, was recently updated to incorporate geographic information system (GIS) data into the resilience analysis. This paper describes the GIS capabilities and includes a case study using the drinking water distribution system model for a large city in Pennsylvania. The case study focuses on potential pipe damage from landslides and on pipes that are particularly difficult to repair. The analysis couples data on hazards, social vulnerability, and the location of emergency services to identify and prioritize high-impact critical infrastructure for mitigation. Results demonstrate that pipes can be prioritized for mitigation based on water shortage and vulnerable populations that are affected. In conclusion, the methods can be adopted for general use and are available as part of the WNTR software.

GIS, landslide↗

FIND: A Synthetic weather generator to control drought Frequency, Intensity, and Duration

Water systems worldwide are experiencing climate change-induced shifts in drought properties like frequency, intensity, and duration, affecting water security and reliability. To develop and test effective drought preparedness plans, researchers often use synthetic weather generators to create hydrological scenarios that explore drought variability beyond historical records. Existing weather generators typically allow users to adjust streamflow statistics like percentiles or temporal correlation but do not directly control drought properties of frequency, intensity, and duration. To fill this gap, we propose FIND (Frequency, INtensity, and Duration) synthetic weather generator. FIND incorporates a standardized drought index to directly and in dependently control drought frequency, intensity, and duration in generated streamflow time series while preserving observed hydrological variability. Use cases for FIND include i) water systems analysis applications that seek to train and test drought strategies under historical and plausible future drought conditions, and ii) bottom-up vulnerability studies relating system vulnerability outcomes to specific changes in drought properties of frequency, intensity, and duration. Here, we demonstrate FIND’s versatility through three experiments: replicating historically observed drought properties, generating streamflow scenarios for multiple sites preserving correlation between their drought conditions, and generating a set of scenarios with direct and independent changes in drought properties. FIND source code is openly available for applications beyond the scope of this paper.

42 ENGINEERING↗