Search NASA⌕ Search

SEARCH · Search NASA

Results for “Documented Safety Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Inherent Conservatism in Deterministic Quasi-Static Structural Analysis

The cause of the long-suspected excessive conservatism in the prevailing structural deterministic safety factor has been identified as an inherent violation of the error propagation laws when reducing statistical data to deterministic values and then combining them algebraically through successive structural computational processes. These errors are restricted to the applied stress computations, and because mean and variations of the tolerance limit format are added, the errors are positive, serially cumulative, and excessively conservative. Reliability methods circumvent these errors and provide more efficient and uniform safe structures. The document is a tutorial on the deficiencies and nature of the current safety factor and of its improvement and transition to absolute reliability.

Verderaime, V.↗

A postprocessor system for the data reduction and post analysis of NASTRAN results

NASTRAN analysis results are scanned to determine maximum and minimum displacements, forces and stresses. Allowables and margins of safety are computed, and in the case of multiple loading conditions, envelopes for displacements, forces, stresses and margins of safety are also produced for specified element sets. Graphical plots of the reduced or the regular NASTRAN results may be obtained superimposed either of a developed fuselage strip or on a projection of any specified part of the finite element model. The use of the data reduction, post analysis and graphical plotting capabilities provide the analyst with a fast and convenient tool for the study of NASTRAN analysis results and their presentation for project documentation.

Raibstein, A. I.↗

Independent Orbiter Assessment (IOA): CIL issues resolution report, volume 1

The results of the Independent Orbiter Assessment (IOA) of the Failure Modes and Effects Analysis (FMEA) and Critical Items List (CIL) are presented. This report contains IOA assessment worksheets showing resolution of outstanding IOA CIL issues that were summarized in the IOA FMEA/CIL Assessment Interim Report, dated 9 March 1988. Each assessment worksheet has been updated with CIL issue resolution and rationale. The NASA and Prime Contractor post 51-L FMEA/CIL documentation assessed is believed to be technically accurate and complete. No assessment issues remain that has safety implications. Volume 1 contain worksheets for the following sybsystems: Landing and Deceleration Subsystem; Purge, Vent and Drain Subsystem; Active Thermal Control and Life Support Systems; Crew Equipment Subsystem; Instrumentation Subsystem; Data Processing Subsystem; Atmospheric Revitalization Pressure Control Subsystem; Hydraulics and Water Spray Boiler Subsystem; and Mechanical Actuation Subsystem.

Urbanowicz, Kenneth J.↗

NASA Low Visibility Landing and Surface Operations (LVLASO) Atlanta Demonstration: Surveillance Systems Performance Analysis

NASA conducted a series of flight experiments at Hartsfield Atlanta International Airport as part of the Low Visibility Landing and Surface Operations (LVLASO) Program. LVLASO is one of the subelements of the NASA Terminal Area Productivity (TAP) Program, which is focused on providing technology and operating procedures for achieving clear-weather airport capacity in instrument-weather conditions, while also improving safety. LVLASO is investigating various technologies to be applied to airport surface operations, including advanced flight deck displays and surveillance systems. The purpose of this report is to document the performance of the surveillance systems tested as part of the LVLASO flight experiment. There were three surveillance sensors tested: primary radar using Airport Surface Detection Equipment (ASDE-3) and the Airport Movement Area Safety System (AMASS), Multilateration using the Airport Surface Target Identification System (ATIDS), and Automatic Dependent Surveillance - Broadcast (ADS-B) operating at 1090 MHz. The performance was compared to the draft requirements of the ICAO Advanced Surface Movement Guidance and Control System (A-SMGCS). Performance parameters evaluated included coverage, position accuracy, and update rate. Each of the sensors was evaluated as a stand alone surveillance system.

Cassell, Rick↗

Identification of Crew-Systems Interactions and Decision Related Trends

NASA Vehicle System Safety Technology (VSST) project management uses systems analysis to identify key issues and maintain a portfolio of research leading to potential solutions to its three identified technical challenges. Statistical data and published safety priority lists from academic, industry and other government agencies were reviewed and analyzed by NASA Aviation Safety Program (AvSP) systems analysis personnel to identify issues and future research needs related to one of VSST's technical challenges, Crew Decision Making (CDM). The data examined in the study were obtained from the National Transportation Safety Board (NTSB) Aviation Accident and Incident Data System, Federal Aviation Administration (FAA) Accident/Incident Data System and the NASA Aviation Safety Reporting System (ASRS). In addition, this report contains the results of a review of safety priority lists, information databases and other documented references pertaining to aviation crew systems issues and future research needs. The specific sources examined were: Commercial Aviation Safety Team (CAST) Safety Enhancements Reserved for Future Implementation (SERFIs), Flight Deck Automation Issues (FDAI) and NTSB Most Wanted List and Open Recommendations. Various automation issues taxonomies and priority lists pertaining to human factors, automation and flight design were combined to create a list of automation issues related to CDM.

Jones, Sharon Monica↗

Composite Overwrapped Pressure Vessel (COPV) Damage Tolerance Life Analysis Methodology and Test Best Practices: Appendices

The NASA Engineering and Safety Center (NESC) Deputy Director requested an independent assessment to develop data to understand the limitations of linear elastic fracture mechanics (LEFM) computational methods used to predict fatigue crack growth rate (da/dN) behavior of small detectable cracks in thin metal liners for composite overwrapped pressure vessels (COPVs). The NESC assessment team was also requested to demonstrate a test-based methodology for validating damage tolerance requirements for COPVs with elastically responding metal liners where LEFM methods are not appropriate. This document contains the appendices to the main report.

Composite Overwrapped Pressure Vessels; Linear Ela↗

Toward Synthesis, Analysis, and Certification of Security Protocols

Implemented security protocols are basically pieces of software which are used to (a) authenticate the other communication partners, (b) establish a secure communication channel between them (using insecure communication media), and (c) transfer data between the communication partners in such a way that these data only available to the desired receiver, but not to anyone else. Such an implementation usually consists of the following components: the protocol-engine, which controls in which sequence the messages of the protocol are sent over the network, and which controls the assembly/disassembly and processing (e.g., decryption) of the data. the cryptographic routines to actually encrypt or decrypt the data (using given keys), and t,he interface to the operating system and to the application. For a correct working of such a security protocol, all of these components must work flawlessly. Many formal-methods based techniques for the analysis of a security protocols have been developed. They range from using specific logics (e.g.: BAN-logic [4], or higher order logics [12] to model checking [2] approaches. In each approach, the analysis tries to prove that no (or at least not a modeled intruder) can get access to secret data. Otherwise, a scenario illustrating the &tack may be produced. Despite the seeming simplicity of security protocols ("only" a few messages are sent between the protocol partners in order to ensure a secure communication), many flaws have been detected. Unfortunately, even a perfect protocol engine does not guarantee flawless working of a security protocol, as incidents show. Many break-ins and security vulnerabilities are caused by exploiting errors in the implementation of the protocol engine or the underlying operating system. Attacks using buffer-overflows are a very common class of such attacks. Errors in the implementation of exception or error handling can open up additional vulnerabilities. For example, on a website with a log-in screen: multiple tries with invalid passwords caused the expected error message (too many retries). but let the user nevertheless pass. Finally, security can be compromised by silly implementation bugs or design decisions. In a commercial VPN software, all calls to the encryption routines were incidentally replaced by stubs, probably during factory testing. The product worked nicely. and the error (an open VPN) would have gone undetected, if a team member had not inspected the low-level traffic out of curiosity. Also, the use secret proprietary encryption routines can backfire, because such algorithms often exhibit weaknesses which can be exploited easily (see e.g., DVD encoding). Summarizing, there is large number of possibilities to make errors which can compromise the security of a protocol. In today s world with short time-to-market and the use of security protocols in open and hostile networks for safety-critical applications (e.g., power or air-traffic control), such slips could lead to catastrophic situations. Thus, formal methods and automatic reasoning techniques should not be used just for the formal proof of absence of an attack, but they ought to be used to provide an end-to-end tool-supported framework for security software. With such an approach all required artifacts (code, documentation, test cases) , formal analyses, and reliable certification will be generated automatically, given a single, high level specification. By a combination of program synthesis, formal protocol analysis, certification; and proof-carrying code, this goal is within practical reach, since all the important technologies for such an approach actually exist and only need to be assembled in the right way.

Schumann, Johann↗

Spaceflight Ground Support Equipment Reliability & System Safety Data

Presented were Reliability Analysis, consisting primarily of Failure Modes and Effects Analysis (FMEA), and System Safety Analysis, consisting of Preliminary Hazards Analysis (PHA), performed to ensure that the CoNNeCT (Communications, Navigation, and Networking re- Configurable Testbed) Flight System was safely and reliably operated during its Assembly, Integration and Test (AI&T) phase. A tailored approach to the NASA Ground Support Equipment (GSE) standard, NASA-STD-5005C, involving the application of the appropriate Requirements, S&MA discipline expertise, and a Configuration Management system (to retain a record of the analysis and documentation) were presented. Presented were System Block Diagrams of selected GSE and the corresponding FMEA, as well as the PHAs. Also discussed are the specific examples of the FMEAs and PHAs being used during the AI&T phase to drive modifications to the GSE (via "redlining" of test procedures, and the placement of warning stickers to protect the flight hardware) before being interfaced to the Flight System. These modifications were necessary because failure modes and hazards were identified during the analysis that had not been properly mitigated. Strict Configuration Management was applied to changes (whether due to upgrades or expired calibrations) in the GSE by revisiting the FMEAs and PHAs to reflect the latest System Block Diagrams and Bill Of Material. The CoNNeCT flight system has been successfully assembled, integrated, tested, and shipped to the launch site without incident. This demonstrates that the steps taken to safeguard the flight system when it was interfaced to the various GSE were successful.

Fernandez, Rene↗

NESC GN&C TDT Workshop on 2D Image Motion Optical Transfer Functions, Pointing Performance Analysis, and Requirements

What You Will Learn: The focus is on payload imaging performance due to pointing motion. Some historical background on pointing performance analysis is given. The Optical Transfer Function (OTF) and Modulation Transfer Function (MTF) are defined. The imaging performance due to pointing motion is measured by image motion optical transfer functions (IM OTF). IM OTFs are defined for displacement, smear, and jitter motions, which are all rigorously defined. Deterministic and Statistical IM OTFs are briefly derived and graphically illustrated and compared. The IM OTFs are parameterized by pointing error metrics(PEM), which are means and covariances of displacement, smear, and jitter. Emphasis is on procedures and algorithms to evaluate the image motion optical transfer functions and pointing error metrics. Three procedures are covered, which depend on whether the pointing error data is from time-domain simulation, frequency-domain analysis, or stochastic modeling. A method to evaluate the relative contribution of disturbance sources and to identify the most significant contributors is presented. The presentation includes pertinent discussion of flexible structures and control-structure interaction. No single book can adequately cover this subject, so a book is not required for the course. A list of selected articles, reports, documents, and books is provided for reference and further study. Mathis kept to the minimum necessary to convey principles; lengthy derivations are left to the reference material. Graphics are used to illustrate concepts. As with any such learning endeavor, the knowledge gained will be retained and strengthened through actual practice.c©2019–2021 Mark E. Pittelkau— 5

NASA Engineering and Safety Center (NESC)↗

Reassessing Double-Ended Guillotine Break Requirements: Evidence-Based Analysis of Regulatory Assumptions After Five Decades of Nuclear Operation

After five decades of nuclear power operation encompassing more than 20,000 reactor-years across 35 countries and 647 reactors, zero double-ended guillotine breaks (DEGBs) have been documented in commercial reactor coolant systems—despite DEGB being the fundamental design-basis assumption driving Emergency Core Cooling System (ECCS) sizing, structural protection requirements, and containment design specifications. This report examines the basis for DEGB requirements in nuclear power plant design. The DEGB postulate assumes the instantaneous, complete circumferential severance of the largest diameter pipes in reactor coolant systems, driving major design requirements under 10 Code of Federal Regulations 50.46, General Design Criterion 4 and containment design specifications. The United States (4,880 reactor-years) and France (2,505 reactor-years) contribute the largest operational datasets. Probabilistic assessments estimate direct DEGB occurrence probabilities with extremely low event frequencies, far below the 10-5/reactor-year thresholds typically used to define non-credible events in nuclear-safety analyses; i.e., events with probability this low fall into beyond-design-basis events. Current material-science knowledge demonstrates that the ductile steel materials used in nuclear piping systems exhibit stable crack-growth behavior fundamentally incompatible with instantaneous severance. International regulatory experience, particularly Germany’s comprehensive break-preclusion implementation, and successful leak-before-break (LBB) applications in almost all of U.S. pressurized water reactor units validate that alternatives can maintain safety performance while reducing economic burden. Current DEGB protection systems impose estimated lifetime costs of hundreds of millions of dollars per unit, over the life of a plant across the nuclear industry (including ongoing costs), representing substantial resource allocation toward scenarios with extremely low probability. Although this report acknowledges uncertainties regarding long-term aging effects, potential synergistic degradation mechanisms, and site-specific seismic considerations that warrant continued evaluation as regulatory policy evolves, there remains no documented evidence that a DEGB has occurred as a consequence of the conditions or mechanisms described in this report. This report acknowledges the Nuclear Regulatory Commission’s (NRC’s) recent efforts—outlined in the draft Interim Staff Guidance (ISG) NRC-DSS-ISG-2025-XX (“Treatment of Certain Loss-of-Coolant Accident Locations as Beyond-Design-Basis Accidents Draft Interim Staff Guidance”)—to reduce overly conservative requirements for large-break loss of coolant accidents through technical justifications and exemptions. However, extensive operating experience and validated methodologies—such as LBB and in-service inspection programs—demonstrate that the probability of a DEGB in reactor coolant-loop piping is extremely low, even under seismic conditions. The authors and reviewers of this report recommend that DEGB be removed as a design-basis event through formal rulemaking, rather than case-by-case exemptions, to better reflect credible failure modes, align with current data, and align with modern, risk-informed safety analysis.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Advances in Metallic Fuel Database Development and Data Qualification

The Fuels Irradiation and Physics Database (FIPD [1]) is a comprehensive repository of data and documents related to Uranium-Zirconium based metallic fuel test pins. This database stores operational conditions of these pins, calculated using a suite of Argonne National Laboratory analysis codes developed during the Integral Fast Reactor (IFR) program. Key calculated data include axial distributions of power, temperature, fluence, burnup, and isotopic densities. Additionally, the FIPD holds post-irradiation examination (PIE) data such as fission gas release, gas chemistry measurements, and axial distributions derived from profilometry, gamma scanning, and neutron radiography. Complementing these data is an extensive archive of documents related to various pins and experiments. These include raw PIE records, design details, safety analyses, and operational reports. More detail about FIPD can be found in ref. [2]. The database development is an ongoing effort covering metallic fuel experiments from the Experimental Breeder Reactor II (EBR-II) and the Fast Flux Test Facility (FFTF). The recent improvements to the database and the data QA status are summarized in this paper.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Analysis and Testing of a Composite Fuselage Shield for Open Rotor Engine Blade-Out Protection

The Federal Aviation Administration is working with the European Aviation Safety Agency to determine the certification base for proposed new engines that would not have a containment structure on large commercial aircraft. Equivalent safety to the current fleet is desired by the regulators, which means that loss of a single fan blade will not cause hazard to the Aircraft. The NASA Glenn Research Center and The Naval Air Warfare Center (NAWC), China Lake, collaborated with the FAA Aircraft Catastrophic Failure Prevention Program to design and test lightweight composite shields for protection of the aircraft passengers and critical systems from a released blade that could impact the fuselage. LS-DYNA® was used to predict the thickness of the composite shield required to prevent blade penetration. In the test, two composite blades were pyrotechnically released from a running engine, each impacting a composite shield with a different thickness. The thinner shield was penetrated by the blade and the thicker shield prevented penetration. This was consistent with pre-test LS-DYNA predictions. This paper documents the analysis conducted to predict the required thickness of a composite shield, the live fire test from the full scale rig at NAWC China Lake and describes the damage to the shields as well as instrumentation results.

Composite↗

Benchmark Gap Assessment for the Manufacturing of High-Assay Low-Enriched Uranium Fuels

This document develops basic critical conditions for spheres—moderated and unmoderated, as well as reflected and unreflected—in consideration of nuclear criticality safety of a potential fuel production facility producing high-assay low-enriched uranium (HALEU) fuel of several different types like tristructural-isotropic (TRISO), uranium metal and alloys, oxide and non-metallic forms. In addition to spherical arrangements, TRISO particle manufacturing process–specific equipment is modeled as it would be for the criticality safety analysis. The objective is to develop representative systems that can then be used for comparison with existing benchmarks. SCALE/TSUNAMI is used to assess the similarity index between these systems to assess validation gaps for possible fuel production applications of proposed advanced reactors. Several different fuel types were evaluated, including TRISO, uranium metal, uranium molybdenum, uranium zirconium, uranium dioxide, uranium nitride, uranium hydride, U-ZrH, and uranium chloride. This selection of fuel types covers a breadth of proposed reactor types, as well as intermediate steps in the production and fabrication of the fuel

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

A guide for performing system safety analysis

A general guide is presented for performing system safety analyses of hardware, software, operations and human elements of an aerospace program. The guide describes a progression of activities that can be effectively applied to identify hazards to personnel and equipment during all periods of system development. The general process of performing safety analyses is described; setting forth in a logical order the information and data requirements, the analytical steps, and the results. These analyses are the technical basis of a system safety program. Although the guidance established by this document cannot replace human experience and judgement, it does provide a methodical approach to the identification of hazards and evaluation of risks to the system.

Brush, J. M.↗

Flat-plate solar array project. Volume 6: Engineering sciences and reliability

The Flat-Plate Solar Array (FSA) Project activities directed at developing the engineering technology base required to achieve modules that meet the functional, safety, and reliability requirements of large scale terrestrial photovoltaic systems applications are reported. These activities included: (1) development of functional, safety, and reliability requirements for such applications; (2) development of the engineering analytical approaches, test techniques, and design solutions required to meet the requirements; (3) synthesis and procurement of candidate designs for test and evaluation; and (4) performance of extensive testing, evaluation, and failure analysis of define design shortfalls and, thus, areas requiring additional research and development. A summary of the approach and technical outcome of these activities are provided along with a complete bibliography of the published documentation covering the detailed accomplishments and technologies developed.

Ross, R. G., Jr.↗

An Approach to Identifying Aspects of Positive Pilot Behavior within the Aviation Safety Reporting System

The National Airspace System (NAS) is constantly evolving as air traffic continues to ramp up to pre-pandemic numbers and projected to grow to unprecedented levels in the coming years. As well as increasing demand to the current system, emerging operations such as Unmanned Autonomous Systems are also expected to add to complexity in the airspace. To address these issues, the industry and government agencies supporting the NAS will need to rely upon additional automation and new technologies to address future operational requirements, while continuing to be a world-leading safe transportation system. As these new technologies are implemented, the system continues to rely on human pilots and controllers in the loop to monitor the system and intervene in situations the automation cannot handle. The goal of proactively addressing safety is of foremost concern to ensure passenger confidence. The industry has implemented various Safety Monitoring Systems to identify safety risks and proactively address them before they result in a serious incident or accident. One such program is the Aviation Safety Reporting System (ASRS). ASRS is a long-established system where pilots and controllers voluntarily and anonymously report safety incidents they experienced and observed during line operations by providing rich text narratives describing the events, the environment, and conditions leading to the safety event of concern. These narratives provide insight and context around events of interest and can be used to identify emerging problems. They can trigger investigations within Flight Operational Quality Assurance or Flight Data Monitoring programs. However, this process typically focuses on the adverse events and the unsafe aspects of the operations surrounding the reported or detected events. This perspective of investigating factors that went wrong around an adverse event is commonly referred to as Safety I. Alternatively, characterizing successful actions that operators perform every day under varying conditions that keep the system within safe operating bounds is a concept referred to as Safety II. The benefit of the Safety II view is that the scope is much larger than that of Safety I since a vast majority of the operations result in successful flights. Many of the successful techniques used to manage operational threats are not documented in standard operating procedures or taught during training. They are typically acquired over time by working with experienced pilots during line operations or in many cases after experiencing a problem for the first time and reacting to it in situ, drawing from years of experience to manage the threat. In an attempt to quantify these positive actions, we are proposing an approach to extracting key behaviors within ASRS reports that can support the Safety II concept. Our analysis assumes that ASRS reports contain some descriptions of corrective actions that operators performed to prevent a situation from leading to an accident. Leveraging recent advances in Natural Language Process modeling, we have developed an approach to extract positive sentiment from reports, embed these positive statements in a vector space where they can be numerically analyzed, and clustering these statements into similar contextual categories. From these contextualized categories we can attempt to summarized and distilled aspects of the positive behavior. The goal is to identify categories of behavior that describe consistent operator techniques that supports the Safety II concept. With this information, airlines may enable learning from these positive actions, or address procedures that need to be changed to avoid having pilots implement a workaround. These insights can provide a lens into what is “going right” in the operations that may otherwise not be known widely within the community. It is envisioned that this approach can be extended to other narrative programs such as Line Operation Safety Audit or Learning Improvement Team reports where similar observed behavior can be analyzed to extract positive actions and inform the overall operations.

NLP↗

An Approach to Identifying Aspects of Positive Pilot Behavior within the Aviation Safety Reporting System

The National Airspace System (NAS) is constantly evolving as air traffic continues to ramp up to pre-pandemic numbers and projected to grow to unprecedented levels in the coming years. As well as increasing demand to the current system, emerging operations such as Unmanned Autonomous Systems are also expected to add to complexity in the airspace. To address these issues, the industry and government agencies supporting the NAS will need to rely upon additional automation and new technologies to address future operational requirements, while continuing to be a world-leading safe transportation system. As these new technologies are implemented, the system continues to rely on human pilots and controllers in the loop to monitor the system and intervene in situations the automation cannot handle. The goal of proactively addressing safety is of foremost concern to ensure passenger confidence. The industry has implemented various Safety Monitoring Systems to identify safety risks and proactively address them before they result in a serious incident or accident. One such program is the Aviation Safety Reporting System (ASRS). ASRS is a long-established system where pilots and controllers voluntarily and anonymously report safety incidents they experienced and observed during line operations by providing rich text narratives describing the events, the environment, and conditions leading to the safety event of concern. These narratives provide insight and context around events of interest and can be used to identify emerging problems. They can trigger investigations within Flight Operational Quality Assurance or Flight Data Monitoring programs. However, this process typically focuses on the adverse events and the unsafe aspects of the operations surrounding the reported or detected events. This perspective of investigating factors that went wrong around an adverse event is commonly referred to as Safety I. Alternatively, characterizing successful actions that operators perform every day under varying conditions that keep the system within safe operating bounds is a concept referred to as Safety II. The benefit of the Safety II view is that the scope is much larger than that of Safety I since a vast majority of the operations result in successful flights. Many of the successful techniques used to manage operational threats are not documented in standard operating procedures or taught during training. They are typically acquired over time by working with experienced pilots during line operations or in many cases after experiencing a problem for the first time and reacting to it in situ, drawing from years of experience to manage the threat. In an attempt to quantify these positive actions, we are proposing an approach to extracting key behaviors within ASRS reports that can support the Safety II concept. Our analysis assumes that ASRS reports contain some descriptions of corrective actions that operators performed to prevent a situation from leading to an accident. Leveraging recent advances in Natural Language Process modeling, we have developed an approach to extract positive sentiment from reports, embed these positive statements in a vector space where they can be numerically analyzed, and clustering these statements into similar contextual categories. From these contextualized categories we can attempt to summarized and distilled aspects of the positive behavior. The goal is to identify categories of behavior that describe consistent operator techniques that supports the Safety II concept. With this information, airlines may enable learning from these positive actions, or address procedures that need to be changed to avoid having pilots implement a workaround. These insights can provide a lens into what is “going right” in the operations that may otherwise not be known widely within the community. It is envisioned that this approach can be extended to other narrative programs such as Line Operation Safety Audit or Learning Improvement Team reports where similar observed behavior can be analyzed to extract positive actions and inform the overall operations.

NLP↗

An Approach to Identifying Aspects of Positive Pilot Behavior within the Aviation Safety Reporting System

The National Airspace System (NAS) is constantly evolving as air traffic continues to ramp up to pre-pandemic numbers and projected to grow to unprecedented levels in the coming years. As well as increasing demand to the current system, emerging operations such as Unmanned Autonomous Systems are also expected to add to complexity in the airspace. To address these issues, the industry and government agencies supporting the NAS will need to rely upon additional automation and new technologies to address future operational requirements, while continuing to be a world-leading safe transportation system. As these new technologies are implemented, the system continues to rely on human pilots and controllers in the loop to monitor the system and intervene in situations the automation cannot handle. The goal of proactively addressing safety is of foremost concern to ensure passenger confidence. The industry has implemented various Safety Monitoring Systems to identify safety risks and proactively address them before they result in a serious incident or accident. One such program is the Aviation Safety Reporting System (ASRS). ASRS is a long-established system where pilots and controllers voluntarily and anonymously report safety incidents they experienced and observed during line operations by providing rich text narratives describing the events, the environment, and conditions leading to the safety event of concern. These narratives provide insight and context around events of interest and can be used to identify emerging problems. They can trigger investigations within Flight Operational Quality Assurance or Flight Data Monitoring programs. However, this process typically focuses on the adverse events and the unsafe aspects of the operations surrounding the reported or detected events. This perspective of investigating factors that went wrong around an adverse event is commonly referred to as Safety I. Alternatively, characterizing successful actions that operators perform every day under varying conditions that keep the system within safe operating bounds is a concept referred to as Safety II. The benefit of the Safety II view is that the scope is much larger than that of Safety I since a vast majority of the operations result in successful flights. Many of the successful techniques used to manage operational threats are not documented in standard operating procedures or taught during training. They are typically acquired over time by working with experienced pilots during line operations or in many cases after experiencing a problem for the first time and reacting to it in situ, drawing from years of experience to manage the threat. In an attempt to quantify these positive actions, we are proposing an approach to extracting key behaviors within ASRS reports that can support the Safety II concept. Our analysis assumes that ASRS reports contain some descriptions of corrective actions that operators performed to prevent a situation from leading to an accident. Leveraging recent advances in Natural Language Process modeling, we have developed an approach to extract positive sentiment from reports, embed these positive statements in a vector space where they can be numerically analyzed, and clustering these statements into similar contextual categories. From these contextualized categories we can attempt to summarized and distilled aspects of the positive behavior. The goal is to identify categories of behavior that describe consistent operator techniques that supports the Safety II concept. With this information, airlines may enable learning from these positive actions, or address procedures that need to be changed to avoid having pilots implement a workaround. These insights can provide a lens into what is “going right” in the operations that may otherwise not be known widely within the community. It is envisioned that this approach can be extended to other narrative programs such as Line Operation Safety Audit or Learning Improvement Team reports where similar observed behavior can be analyzed to extract positive actions and inform the overall operations.

NLP↗