Search NASA⌕ Search

SEARCH · Search NASA

Results for “Vulnerability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Space Station Program threat and vulnerability analysis

An examination has been made of the physical security of the Space Station Program at the Kennedy Space Center in a peacetime environment, in order to furnish facility personnel with threat/vulnerability information. A risk-management approach is used to prioritize threat-target combinations that are characterized in terms of 'insiders' and 'outsiders'. Potential targets were identified and analyzed with a view to their attractiveness to an adversary, as well as to the consequentiality of the resulting damage.

Van Meter, Steven D.↗

Vulnerability-attention analysis for space-related activities

Techniques for representing and analyzing trouble spots in structures and processes are discussed. Identification of vulnerable areas usually depends more on particular and often detailed knowledge than on algorithmic or mathematical procedures. In some cases, machine inference can facilitate the identification. The analysis scheme proposed first establishes the geometry of the process, then marks areas that are conditionally vulnerable. This provides a basis for advice on the kinds of human attention or machine sensing and control that can make the risks tolerable.

Ford, Donnie↗

Asheville Urban Development II: Mapping Urban Heat to Support Cooling Initiatives and Climate Resilience Planning in the Greater Asheville Area

Asheville, North Carolina experiences the urban heat island effect, where temperatures in the city are higher than in surrounding rural areas. This effect intensifies with increased urbanization and less vegetative cover. Asheville’s urban heat island was exacerbated by population increases and tree cover decline, escalating the need for heat mitigation. We partnered with the City of Asheville’s Sustainability Department and Asheville GreenWorks whose actions prioritize sustainable city planning and equitable climate resilience. Using NASA Earth observations and ancillary datasets we spatially mapped urban heat, heat vulnerability, and cooling and adaptive capacity from 2019-2023. To map urban heat, we used Landsat 8 and 9 Operational Land Imager and Thermal Infrared Sensor for land surface temperature and albedo data and the ECOsystem Spaceborne Thermal Radiometer Experiment on Space Station for evapotranspiration data. We assessed heat vulnerability using the urban heat data andthe Centers for Disease Control and Prevention’s Social Vulnerability Index. To evaluate cooling and adaptive capacity we used the InVEST Urban Cooling Model, integrating our heat vulnerability analysis with land use and cover data from Sentinel-1 Synthetic Aperture Rada rand Sentinel-2 Multispectral Instrument. Our results revealed distinct spatial patterns of urban heat, heat vulnerability, and cooling and adaptive capacity in Asheville with downtown as the focal hotspot and an outward decreasing radial pattern. These findings highlight targeted need for interventions to reduce heat impacts, address environmental injustices, and enhance climate resilience. Our project provided research to local organizations that can be used for heat mitigation in the greater Asheville area.

Authors not in NED but are confirmed contractors. ↗

Techniques for fire detection

An overview is given of the basis for an analysis of combustable materials and potential ignition sources in a spacecraft. First, the burning process is discussed in terms of the production of the fire signatures normally associated with detection devices. These include convected and radiated thermal energy, particulates, and gases. Second, the transport processes associated with the movement of these from the fire to the detector, along with the important phenomena which cause the level of these signatures to be reduced, are described. Third, the operating characteristics of the individual types of detectors which influence their response to signals, are presented. Finally, vulnerability analysis using predictive fire modeling techniques is discussed as a means to establish the necessary response of the detection system to provide the level of protection required in the application.

Bukowski, Richard W.↗

Utilizing Open-Source Earth Observations to Inform the Toa Baja Municipality’s Flood Risk Mitigation Efforts and Educate the Public

Global climate changes contribute to more intense and frequent tropical storms, subjecting places like Toa Baja, Puerto Rico to critical damage. Known as “the underwater city” due to its propensity to flood, residents of Toa Baja face constant flood risk. During extreme tropical storm events, such as Hurricane Maria in 2017, residents experienced up to 20 feet of inundation. The NASA DEVELOP National Program collaborated with the Municipio Autónomo de Toa Baja, ResilientSEE-PR, and the MIT Urban Risk Lab to supplement 2018 FEMA HEC-RAS flood maps that designate 63% of Toa Baja as a flood plain. This analysis provides a high-resolution interpretation of flood risk through two lenses; susceptibility and vulnerability. For this analysis, susceptibility consists of nine weighted layers: NDVI, landcover, slope, elevation, topographic wetness index, height above nearest drainage, saturated hydraulic conductivity, distance to water, and storm surge. These factors are consistently used to evaluate susceptibility to flood, but their weights vary by analysis. Vulnerability consists of population, informal settlements, and building density, which were given equal weight. Susceptibility and vulnerability were combined to map flood risk. This analysis used a bivariate legend to understand the different levels of risk along a spectrum from low susceptibility and low vulnerability (low risk) to high susceptibility and high vulnerability (high risk). Data processed in Google Earth Engine, which identified historical inundation on various occasions, were used to validate the flood susceptibility layers. Results showed 89% of areas designated as high susceptibility are located within the floodway designated by the FEMA HEC-RAS maps. The eastern region of Toa Baja is most at risk for flooding due to high susceptibility to flooding along with a high density of population, buildings, and informal settlements. The resulting map also reveals the presence of smaller high-risk areas all around the municipality. This analysis provides scientific evidence for flood risk mitigation in Toa Baja by highlighting areas that might be impacted by strong floods in the future. Additionally, these results are communicated in an Esri ArcGIS StoryMap, an accessible platform that can easily inform the public about the flood risk in their neighborhood.

Adriana Le Compte↗

Cyber Security for the Spaceport Command and Control System: Vulnerability Management and Compliance Analysis

With the rapid development of the Internet, the number of malicious threats to organizations is continually increasing. In June of 2015, the United States Office of Personnel Management (OPM) had a data breach resulting in the compromise of millions of government employee records. The National Aeronautics and Space Administration (NASA) is not exempt from these attacks. Cyber security is becoming a critical facet to the discussion of moving forward with projects. The Spaceport Command and Control System (SCCS) project at the Kennedy Space Center (KSC) aims to develop the launch control system for the next generation launch vehicle in the coming decades. There are many ways to increase the security of the network it uses, from vulnerability management to ensuring operating system images are compliant with securely configured baselines recommended by the United States Government.

Cyber Security↗

A probabilistic analysis of electrical equipment vulnerability to carbon fibers

The statistical problems of airborne carbon fibers falling onto electrical circuits were idealized and analyzed. The probability of making contact between randomly oriented finite length fibers and sets of parallel conductors with various spacings and lengths was developed theoretically. The probability of multiple fibers joining to bridge a single gap between conductors, or forming continuous networks is included. From these theoretical considerations, practical statistical analyses to assess the likelihood of causing electrical malfunctions was produced. The statistics obtained were confirmed by comparison with results of controlled experiments.

Elber, W.↗

Security Vulnerability Profiles of Mission Critical Software: Empirical Analysis of Security Related Bug Reports

While some prior research work exists on characteristics of software faults (i.e., bugs) and failures, very little work has been published on analysis of software applications vulnerabilities. This paper aims to contribute towards filling that gap by presenting an empirical investigation of application vulnerabilities. The results are based on data extracted from issue tracking systems of two NASA missions. These data were organized in three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified security related software bugs and classified them in specific vulnerability classes. Then, we created the security vulnerability profiles, i.e., determined where and when the security vulnerabilities were introduced and what were the dominating vulnerabilities classes. Our main findings include: (1) In IVV issues datasets the majority of vulnerabilities were code related and were introduced in the Implementation phase. (2) For all datasets, around 90 of the vulnerabilities were located in two to four subsystems. (3) Out of 21 primary classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, they contributed from 80 to 90 of vulnerabilities in each dataset.

Goseva-Popstojanova, Katerina↗

Kentucky Disasters: Multi-Hazard Approach to Mapping Flood Susceptibility and Vulnerability in Kentucky

Flooding is the most common and costly natural disaster in Kentucky, with major flood events in 2022 and 2023 highlighting the need for flood risk assessment. In partnership with the National Weather Service Jackson and Paducah Forecast Offices and the Kentucky Climate Center, we mapped flood risk in Kentucky using a multi-hazard approach that considered two dimensions of risk: flood susceptibility based on a weighted combination of seven physical factors and flood vulnerability based on 13 socioeconomic and infrastructure factors. We additionally analyzed NASA Soil Moisture Active Passive (SMAP) observations of surface soil moisture to explore the utility of SMAP observations for future analysis of flood risk. By analyzing flood susceptibility, we found that with equal rainfall, western Kentucky generally displays a higher propensity to flood than eastern Kentucky. In contrast, our flood vulnerability analysis indicated that more vulnerable areas were generally concentrated in the eastern part of the state. Through a combined perspective, our flood risk analysis identified much of the state as having moderate degrees of flood susceptibility and vulnerability. Our parallel analysis of antecedent soil moisture found that SMAP soil moisture levels were variable in the months leading up to each flood event but were drier than normal in the month prior to the 2023 event, as shown by negative soil moisture anomalies. These results were limited by challenges with weighting input parameters and a lack of validation but overall demonstrate the feasibility of using GIS and Earth observations for mapping flood risk and soil moisture.

analytic hierarchy process↗

Freddie Software Security Patching

Software applications become more complicated over time as they depend on many third-party, open-source libraries. The Freddie Platform Services team actively improves software security by addressing software bugs and vulnerabilities that negatively impact software applications, especially those providing real-time operations and services for the federal partners and industries. In order to detect bugs and patch vulnerabilities in software development and maintenance cycles, an automated and systematic approach is needed. This document describes what bugs and vulnerabilities are, and how they can be detected by using static code analyzers and software composition analysis tools. Once vulnerabilities are detected, the patching approaches, such as upgrading direct and transitive dependencies and loading custom classes first, are presented together with their strengths and weaknesses. In addition, patching walkthrough, example code, lessons learned throughout the vulnerability patching process and the recommended practices are discussed.

Chok Fung Lai↗

Vulnerabilities, Influences and Interaction Paths: Failure Data for Integrated System Risk Analysis

We describe graph-based analysis methods for identifying and analyzing cross-subsystem interaction risks from subsystem connectivity information. By discovering external and remote influences that would be otherwise unexpected, these methods can support better communication among subsystem designers at points of potential conflict and to support design of more dependable and diagnosable systems. These methods identify hazard causes that can impact vulnerable functions or entities if propagated across interaction paths from the hazard source to the vulnerable target. The analysis can also assess combined impacts of And-Or trees of disabling influences. The analysis can use ratings of hazards and vulnerabilities to calculate cumulative measures of the severity and importance. Identification of cross-subsystem hazard-vulnerability pairs and propagation paths across subsystems will increase coverage of hazard and risk analysis and can indicate risk control and protection strategies.

Malin, Jane T.↗

Security Vulnerability Profiles of NASA Mission Software: Empirical Analysis of Security Related Bug Reports

NASA develops, runs, and maintains software systems for which security is of vital importance. Therefore, it is becoming an imperative to develop secure systems and extend the current software assurance capabilities to cover information assurance and cybersecurity concerns of NASA missions. The results presented in this report are based on the information provided in the issue tracking systems of one ground mission and one flight mission. The extracted data were used to create three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified the software bugs that are security related and classified them in specific security classes. This information was then used to create the security vulnerability profiles (i.e., to determine how, why, where, and when the security vulnerabilities were introduced) and explore the existence of common trends. The main findings of our work include:- Code related security issues dominated both the Ground and Flight mission IVV security issues, with 95 and 92, respectively. Therefore, enforcing secure coding practices and verification and validation focused on coding errors would be cost effective ways to improve mission's security. (Flight mission Developers issues dataset did not contain data in the Issue Category.)- In both the Ground and Flight mission IVV issues datasets, the majority of security issues (i.e., 91 and 85, respectively) were introduced in the Implementation phase. In most cases, the phase in which the issues were found was the same as the phase in which they were introduced. The most security related issues of the Flight mission Developers issues dataset were found during Code Implementation, Build Integration, and Build Verification; the data on the phase in which these issues were introduced were not available for this dataset.- The location of security related issues, as the location of software issues in general, followed the Pareto principle. Specifically, for all three datasets, from 86 to 88 the security related issues were located in two to four subsystems.- The severity levels of most security issues were moderate, in all three datasets.- Out of 21 primary security classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, these classes contributed from around 80 to 90 of all security issues in each dataset. This again proves the Pareto principle of uneven distribution of security issues, in this case across CWE classes, and supports the fact that addressing these dominant security classes provides the most cost efficient way to improve missions' security. The findings presented in this report uncovered the security vulnerability profiles and identified the common trends and dominant classes of security issues, which in turn can be used to select the most efficient secure design and coding best practices compiled by the part of the SARP project team associated with the NASA's Johnson Space Center. In addition, these findings provide valuable input to the NASA IVV initiative aimed at identification of the two 25 CWEs of ground and flight missions.

vulnerability↗

FTMP - A highly reliable Fault-Tolerant Multiprocessor for aircraft

The FTMP (Fault-Tolerant Multiprocessor) is a complex multiprocessor computer that employs a form of redundancy related to systems considered by Mathur (1971), in which each major module can substitute for any other module of the same type. Despite the conceptual simplicity of the redundancy form, the implementation has many intricacies owing partly to the low target failure rate, and partly to the difficulty of eliminating single-fault vulnerability. An extensive analysis of the computer through the use of such modeling techniques as Markov processes and combinatorial mathematics shows that for random hard faults the computer can meet its requirements. It is also shown that the maintenance scheduled at intervals of 200 hr or more can be adequate most of the time.

Hopkins, A. L., Jr.↗

CubeSAT Security Attack Tree Analysis

Once a novelty, small satellites, often referred to as CubeSats, have become important tools for a variety of space activities ranging from exploration to defense. Their relative affordability and short development timeline have made them attractive options to complement larger space vehicles, conduct reconnaissance and other finite tasks. The specialized nature of many CubeSat missions do not make their security any less important as their missions could easily be matters of national security. This paper demonstrates the use of attack tree analysis to assess vulnerabilities of a CubeSat. First, we abstract and build an architectural model of an operational CubeSat. We then create a series of attack trees for the abstracted architecture to illustrate a series of potential attack vectors for small satellites. We conclude by discussing some strategies that could be employed to improve CubeSat resilience.

Santangelo, Andrew↗

Spatiotemporal Associations Between Social Vulnerability, Environmental Measurements, and COVID-19 in the Conterminous United States

This study summarizes the results from fitting a Bayesian hierarchical spatiotemporal model to coronavirus disease 2019 (COVID-19) cases and deaths at the county level in the United States for the year 2020. Two models were created, one for cases and one for deaths, utilizing a scaled Besag, York, Mollié model with Type I spatial-temporal interaction. Each model accounts for 16 social vulnerability and 7 environmental variables as fixed effects. The spatial pattern between COVID-19 cases and deaths is significantly different in many ways. The spatiotemporal trend of the pandemic in the United States illustrates a shift out of many of the major metropolitan areas into the United States Southeast and Southwest during the summer months and into the upper Midwest beginning in autumn. Analysis of the major social vulnerability predictors of COVID-19 infection and death found that counties with higher percentages of those not having a high school diploma, having non-White status and being Age 65 and over to be significant. Among the environmental variables, above ground level temperature had the strongest effect on relative risk to both cases and deaths. Hot and cold spots, areas of statistically significant high and low COVID-19 cases and deaths respectively, derived from the convolutional spatial effect show that areas with a high probability of above average relative risk have significantly higher Social Vulnerability Index composite scores. The same analysis utilizing the spatiotemporal interaction term exemplifies a more complex relationship between social vulnerability, environmental measurements, COVID-19 cases, and COVID-19 deaths.

spatial epidemiology↗

Portland Urban Development: Quantifying and Visualizing Urban Heat with Compounding Vulnerabilities to Support Community Depaving Initiatives

Urban heat is a pressing concern in Portland, Oregon as climate change induced heat waves increase. Cities experience higher temperatures due to the urban heat island effect (UHI), and environmental injustice and disenfranchisement in minority communities expose low-income and Black, Indigenous, and People of Color (BIPOC) residents to more extreme and debilitating heat events. Our team identified Portland’s communities on the frontlines of urban heat impacts by overlapping environmental and social vulnerabilities using NASA Earth observations. We partnered with Depave, a Portland-based nonprofit that works alongside communities to replace pavement with greenspace in historically disenfranchised areas. Using Landsat 8 Thermal Infrared Sensor (TIRS) imagery, we mapped Land Surface Temperature (LST) and developed a heat-specific Social Vulnerability Index (SVI) through a Principal Component Analysis (PCA) to identify Portland’s communities with the highest potential heat vulnerability. Then, we calculated the temperature change of depaving in six case studies to quantify Depave's efforts in heat mitigation and environmental justice. Our analysis demonstrated that, throughout Portland, there are frontline communities experiencing high potential social vulnerability to extreme temperatures due to environmental injustices and over-pavement. Finally, Depave’s impact on urban heat is observable and quantifiable using remote-sensing data and tools, with an average of 1ºF LST decrease across the six case studies. We illustrated the significance of local urban heat mitigation efforts and propose next steps for conducting inclusive and intentional research that highlights the lived experiences and resilience of frontline communities.

Environmental justice↗

Radiation and Plasma Environments for Lunar Missions

Space system design for lunar orbit and extended operations on the lunar surface requires analysis of potential system vulnerabilities to plasma and radiation environments to minimize anomalies and assure that environmental failures do not occur during the mission. Individual environments include the trapped particles in Earth s radiation belts, solar energetic particles and galactic cosmic rays, plasma environments encountered in transit to the moon and on the lunar surface (solar wind, terrestrial magnetosheath and magnetotail, and lunar photoelectrons), and solar ultraviolet and extreme ultraviolet photons. These are the plasma and radiation environments which contribute to a variety of effects on space systems including total ionizing dose and dose rate effects in electronics, degradation of materials in the space environment, and charging of spacecraft and lunar dust. This paper provides a survey of the relevant charged particle and photon environments of importance to lunar mission design ranging from the lowest (approx.few 10 s eV) photoelectron energies to the highest (approx.GeV) cosmic ray energies.

Minow, Joseph I.↗