Search NASA⌕ Search

SEARCH · Search NASA

Results for “vulnerability assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Assessment of Physical Security Modeling and Simulation in the Vulnerability Assessment Process

This report provides a comprehensive assessment of physical security modeling and simulation tools available for use in the vulnerability assessment (VA) process for nuclear facilities. It outlines the historical evolution of VA methodologies, emphasizing the transition from traditional layer-based approaches to a more holistic framework that integrates detection probabilities directly into combat simulations. The document details the critical components of the VA process, including the characterization of targets, threats, and protective measures, as well as the development of adversary scenarios that reflect both insider and outsider threats. It highlights the importance of performance assurance programs, emphasizing the need for continuous evaluation and testing of security systems to ensure their effectiveness against evolving threats. Additionally, the report discusses the significance of utilizing accredited modeling and simulation tools in accredited areas to accurately represent adversary actions and the corresponding responses of protective forces. By establishing a systematic approach to VA, this document aims to enhance the overall security posture of nuclear facilities, ensuring compliance with regulatory standards while effectively mitigating risks associated with potential adversarial actions.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Climate Vulnerability Assessment and Resilience Planning for Idaho National Laboratory

Idaho National Laboratory’s (INL’s) mission is to discover, demonstrate, and secure innovative nuclear energy solutions, other clean energy options, and critical infrastructure. This INL’s Climate Vulnerability Assessment and Resilience Plan (VARP) was developed to enable and sustain that mission while ensuring the viability of operations considering expected climate change impacts. The VARP was developed according to the narrative requirements from the “Vulnerability Assessment and Resilience Planning Guidance, Version 1.2” document issued in February 2022. A prescribed process was used to identify mission-critical systems and components, determine historical and expected climate impacts, and develop resilient solutions. Experts from across INL, including operations staff, researchers, and climate scientists supplied input to the process. Analyses of climate modeling sources revealed that under scenarios of higher and lower greenhouse gas emissions (Representative Concentration Pathway (RCP) 4.5 and RCP 8.5), INL anticipates an increase in climate hazards, including drought, heat waves, wildfire, and precipitation. Increased frequency and duration of climatic hazards forecasts high impacts on certain mission-critical asset and infrastructure types. Utilizing the VARP Risk Assessment Tool, projected high climate hazard impacts across multiple asset and infrastructure types at the INL include energy generation and distribution systems, Site buildings, specialized or mission-critical equipment, and transportation and fleet infrastructure. Some of these mission-critical asset and infrastructure types maintain high adaptive capacity to climatic changes; however, others may need additional adaptive capacity to withstand increased frequency and duration of climate hazards. INL identified close to 300 resilient solutions that were consolidated into 11 solution categories to be tracked in the Department of Energy Sustainability Dashboard. The identified solutions are a starting point for future project development and analysis. These data are intended to inform decision makers on climate issues and potential solutions across INL and associated communities. The VARP is not intended to be a budget tool or project decision document on its own, but rather one of many tools used by decision makers to establish resilient priorities. This initial document provides the framework and foundation to resilient solutions. In the coming years, each solution needs to be fully developed, costed, and prioritized based on mission-critical risk and funding priorities.

54 ENVIRONMENTAL SCIENCES↗

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization↗

2022 Climate Change Vulnerability Assessment and Resilience Plan Summary

Los Alamos National Laboratory (LANL, or the Laboratory) produced a Vulnerability Assessment and Resilience Plan (VARP) following Department of Energy (DOE) Guidance to assess and manage climate change related risks to the Laboratory’s assets and operations. This is a condensed summary of the Laboratory’s 2022 VARP – the full version of the document is not publicly available at this time. The VARP was led by the Pollution Prevention (P2) Program in the Environmental Protection and Compliance Division (EPC-DO) and covers the entirety of the 36-square-mile LANL site in Los Alamos, New Mexico. A Steering Committee, composed of representatives from the three main Laboratory Directorates and the Los Alamos Field Office, identified real property Critical Assets based on their Mission Dependency Index (MDI) scores. LANL used MDI scores of 70 and above, which are considered Mission-Critical, to generate a list of 141 Critical Asset facilities.

54 ENVIRONMENTAL SCIENCES↗

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Grid Utility Asset Vulnerability Assessment (GUAVA) Software Tool

Increasing demand and changes in generation portfolios is pushing power grid to operate towards the limit. However, due to lack of analytical tools for understanding various scales of impact on grid, it is becoming more vulnerable to wide scale power outages and blackouts. A vulnerable grid operating at its limit can be easily disrupted by asset failures caused by devastating hurricanes which has been known to damage transmission and distribution lines along its track. In this direction, researchers have focused on determining these assets by conducting Monte Carlo simulations of hurricanes with uncertainties and collected a large set of simulation data. To determine the infrastructure updates necessary for mitigating wide scale impact of hurricanes on the grid, we propose a software tool named “Grid Utility Asset Vulnerability Analysis” (GUAVA) framework. GUAVA presents a novel data-driven probabilistic analytical approach to (1) post-process hurricane failure scenarios, (2) identify/rank assets that are most vulnerable and critical to failing and are associated with highest impact/risk, and (3) to inform system upgrade decisions & prioritization. Based on the observed results and employed data-driven methodology, it is expected GUAVA can be adapted to provide power system planners with a recommendation engine for making informed decisions to improve resilience of grid.

Mahapatra, Kaveri↗

Aggregation in bottom-up vulnerability assessments and equity implications: The case of Jordanian households’ water supply

Bottom-up methods for water resources modeling rely on acceptability thresholds to find, through a response surface, which deeply uncertain futures lead to system failure. They commonly treat water users as aggregate actors, which may preclude analysis of the equity impacts of interventions. This paper explores how aggregation choices for large groups of water users lead to different policy recommendations in response surface assessments. Herein, two aggregation methods with varying parameters are considered: percentile satisfaction targets and generalized mean. A 2-dimensional stress-test assessment across groundwater availability and population is applied to household water supply in Jordan. The study compares six different policies covering supply enhancement and rebalancing, using a country-wide multi-agent model that characterizes households across socioeconomic strata. For different aggregation levels, policies are ordered by their associated robustness index. Results show that aggregation choices may modify response surfaces as much as policy changes and strongly determine policy preference. Modifying allocation rules can substantially reduce the disparity in household vulnerability. Preferences defined by aggregation intervals provide a finer understanding of trade-offs among water users and may improve deliberation over equity under deep uncertainty.

54 ENVIRONMENTAL SCIENCES↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

Interdisciplinary Approaches to Cyber-vulnerability Impact Assessment for Energy Critical Infrastructure

As energy infrastructure becomes more interconnected, understanding cybersecurity risks to production systems requires integrating operational and computer security knowledge. We interviewed 18 experts working in the field of energy critical infrastructure to compare what information they find necessary to assess the impact of computer vulnerabilities on energy operational technology. These experts came from two groups: 1) computer security experts and 2) energy sector operations experts. We find that both groups responded similarly for general categories of information and displayed knowledge about both domains, perhaps due to their interdisciplinary work at the same organization. Yet, we found notable differences in the details of their responses and in their stated perceptions of each group’s approaches to impact assessment. Their suggestions for collaboration across domains highlighted how these two groups can work together to help each other secure the energy grid. Our findings inform the development of interdisciplinary security approaches in critical-infrastructure contexts.

97 MATHEMATICS AND COMPUTING↗

Assessing the vulnerability of solar inverters to EMPs: Port testing, PCI modeling, and protection strategies

Renewable energy sources are becoming an ever-larger contributor to the power grid. These renewable energy sources depend upon the power electronic devices, specifically inverters, being essential for connecting Photovoltaic (PV) generation to the grid. However, the Electromagnetic Pulses (EMPs) caused by the high-altitude nuclear explosions can generate fast broad-band pulses with nanosecond rise time, potentially causing damage or destruction to electronic components. To assess the vulnerability of PV inverters to high-altitude EMPs, the port testing and Pulsed Current Injection (PCI) modeling schemes are proposed based on the port impedance analysis. Wide-band frequency measurements are achieved by fusing impedance results from three vector network analyzers. Then, a PCI model is used to simulate the induced response to EMP, with two typical immunity levels of EC5 and EC8 tested. Here, the experiment successfully excites the induced voltage and current under EMP, where the voltage and current can reach 1500V/40A and 8000V/150Aunder EC5 andEC8, respectively. The port vulnerability analysis results demonstrate that only some ports can survive under EC5. To defend against the impact of EMP, three protection strategies are discussed.

42 ENGINEERING↗

MARVEL 90% Final Design Report

This document provides documentation of the Microreactor Applications Research Validation and Evaluation Project’s (MARVEL) 90% Final Design, as required by U.S. Department of Energy (DOE) Standard-1189, “Integration of Safety into the Design Process." Per DOE-STD-1189-2016, the 90% Final Design documentation focuses on design completion, at a level capable of supporting procurement, construction, testing, and operation. At this phase, the design organization finalizes the hazards and accident analyses, Fire Hazard Analysis (FHA), security vulnerability assessments, and other supporting analyses for design completion. The objective of this report is to provide a high-level summary of the design thus far and provide references including, but not limited to, the following design deliverables: • Complete final drawings, specifications and commercial grade dedications that may be released for bid and/or construction. • Clearly defined testing plans for the safety and functionality of all subsystems. • Quality Assurance Program for Design, Testing and Procurement. • Software Quality Assurance Plan. • Code of Record (COR), applicable design requirements including codes and standards. • Final design that meets all the requirements stipulated in the COR. • Final design review, consisting of final validation of comment resolution from previous reviews, and a review of any additional developments since the last review. • Updated Safety Design Strategy. • Hazard Analysis. • Fire Hazard Analysis. • Accident analysis. • Security vulnerability assessment. • Current and detailed cost estimate. • Current construction schedule, and • Risk & Opportunities Assessment.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗