Search NASA⌕ Search

SEARCH · Search NASA

Results for “Computer security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

Maskman

SAND2025-04369O Maskman is a user-friendly tool designed to create hex masks, which are essential for optimizing application performance in high-performance computing environments. By converting a list of integers into binary and then hex masks, Maskman simplifies the process of setting application affinity. This ensures that software runs efficiently on specific nodes within a computing cluster. Ideal for researchers and developers, Maskman streamlines the preparation of inputs for HPC schedulers, enhancing resource management and improving overall system performance. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Pase, Douglas [Sandia National Lab. (SNL-CA), Live↗

Tailoring Microbial Fitness Through Computational Steering and CRISPRi-Driven Robustness Regulation

The widespread application of genetically modified microorganisms (GMMs) across diverse sectors underscores the pressing need for robust strategies to mitigate the risks associated with their potential uncontrolled escape. This study merges computational modeling with CRISPR interference (CRISPRi) to refine GMM metabolic robustness. Utilizing ensemble modeling, we achieved high-throughput in silico screening for enzymatic targets susceptible to expression alterations. Translating these insights, we developed functional CRISPRi, boosting fitness control via multiplexed gene knockdown. Our method, enhanced by an insulator-improved gRNA structure and an off-switch circuit controlling a compact Cas12m, resulted in rationally engineered strains with escape frequencies below National Institutes of Health standards. The effectiveness of this approach was confirmed under various conditions, showcasing its ability for secure GMM management. This research underscores the resilience of microbial metabolism, strategically modifying key nodes to halt growth without provoking significant resistance, thereby enabling more reliable and precise GMM control. A record of this paper's transparent peer review process is included in the supplemental information.

59 BASIC BIOLOGICAL SCIENCES↗

Advanced Data Science Model for Detecting Intelligent Malware

This study focused on developing a robust artificial intelligence (AI) model capable of detecting and characterizing advanced malware in Internet of Things (IoT) devices using network data. By analyzing network traffic with various machine learning (ML) models, our AI model can identify and characterize malicious activities to significantly improve malware detection accuracy and reliability as compared to traditional methods. The developed AI/ML model was trained using network data from IoT devices, leveraging classifiers such as Random Forest, Gradient Boosting, AdaBoost, and others to optimize detection performance. This project demonstrates a scalable framework for real-time malware detection and characterization in IoT networks, capable of identifying infected devices and facilitating the necessary steps to remove or isolate them, thereby preventing further infections. Although digital twin (DT) integration is not yet implemented in the current model, it represents a promising future enhancement. By creating a virtual replica of physical IoT devices, DT technology would allow for real-time monitoring and analysis without directly accessing operational technology, thus reducing the risk of compromising or reducing the performance of actual devices. This integration would further enhance the security of IoT ecosystems, combining AI technology to better flag and detect indications of malware-infected devices within a nuclear system environment.

42 ENGINEERING↗

Design of a High-Assay Low-Enriched Uranium Tri-Structural Isotropic Critical Experiment for Advanced Reactor Validation

High-assay low-enriched uranium (HALEU) fuel is a key component of many small modular reactor designs. Critical experiments are an important way to understand the neutronic performance of systems by obtaining nuclear data validations through measurements. Data reduce uncertainty and risk by showing that systems respond as predicted to changes such as temperature, subsequently advancing the overall technology readiness level of the materials within. Numerous critical experiments have been performed at the National Criticality Experiments Research Center (NCERC) operated by Los Alamos National Laboratory at the Nevada National Security Site since it became operational in 2011. However, the first experiment with HALEU fuel did not occur until 2024. Through extensive engineering, the experiment described in this paper was successfully designed and executed for the Comet vertical lift assembly at NCERC to perform measurements with HALEU tri-structural isotropic fuel that will assist in validation of nuclear data and computational modeling of small modular reactors for years to come.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Automated Programmable Logic Controller Memory Forensics Using RGB Image Analysis and Deep Learning

The introduction of Industry 4.0 and Internet-based technologies has enhanced industrial control system operations but have inadvertently increased their vulnerabilities to cyber attacks. When an industrial control system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies. Memory forensics is critical in the incident analysis process to ascertain what occurred. Approaches for analyzing the persistent memory in industrial control devices are limited and almost nonexistent for volatile memory. This chapter proposes an automated methodology for programmable logic controller memory dump analysis using computer vision and deep learning techniques. The methodology converts the sequences of bytes in a programmable logic controller memory dump to red-green-blue pixels and employs a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. The trained model is employed to automatically segment new memory images and identify forensic artifacts. Evaluation of the methodology on a Schneider Electric Modicon M221 programmable logic controller under code injection and code modification attacks demonstrates its ability to detect attack artifacts in memory dumps.

Asmar Awad, Rima [ORNL] (ORCID:0000000233407742)↗

scANN

SAND2025-00656O scANN, also known as sampling by coinflips artificial neural networks, is a software tool that estimates uncertainty in artificial intelligence by performing Monte Carlo analysis on the weight matrices of feedforward neural networks. This computationally intensive process aims to explore the potential value added by future probabilistic hardware. The program’s output helps researchers gain insights into how probabilistic neural networks work. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

SciDAC↗

The Digital Assurance for High Consequence Systems (DAHCS) Mission Campaign Whitepaper

The DAHCS (pronounced “Dax”) MC is a 7-year, $\$$45 million research portfolio within Sandia’s Laboratory Directed Research and Development program. The DAHCS MC arose in response to a great need: to ensure that the use of digital technologies does not weaken our nation’s high consequence systems. Digital technologies offer many benefits in speed, cost, and flexibility, and we seek to reap those benefits without introducing new system failures. However, digital technologies cannot be evaluated the same way as analog technologies. Initiatives across the nation highlight the capability gap that prevents efficient, effective digital assurance. The Challenge Today’s digital assurance tools, techniques, and methods are inadequate to confidently characterize, assess, and manage digital risk; they are ad hoc, slow, costly, and rarely scalable to increasingly complex digital technologies. The rapidly evolving cyber threat landscape exacerbates this problem because digital assurance now must secure against digital risks now and in the future, including those introduced by rapidly evolving technologies, adversaries, and systems.

97 MATHEMATICS AND COMPUTING↗

Multigene engineering in plants: Technologies, applications, and future prospects

The emerging bioeconomy presents a promising solution to both economic and environmental challenges. Within the bioeconomy, plants serve as a renewable, sustainable, and cost-effective source of foods, fuels, chemicals, and materials. However, traditional breeding and single-gene engineering approaches fall short in addressing complex traits (e.g., drought tolerance, disease resistance, yield, nutrient use efficiency) which are controlled by multiple genes. The complexity of plant biology often necessitates the use of multigene engineering (MGE), which involves simultaneous ectopic expression, up/down-regulation, or editing of multiple genes, to enhance plant traits relevant to the bioeconomy. These genes may be associated with distinct traits or function as components of specific metabolic and regulatory pathways. This review summarizes current technologies for MGE within the synthetic biology-driven Design-Build-Test-Learn (DBTL) framework, detailing its four key stages: Design – gene construct development; Build – DNA assembly and plant transformation; Test – the molecular, biochemical, and physiological characterization of engineered plants; and Learn – computational modeling to refine, multiplex and iterate the process. Despite good progress in the applications of MGE in biofortification, metabolic engineering, and stress resilience, challenges remain in construct stability, coordinated gene expression, and regulatory predictability. We identified optimization paths and future directions to accelerate MGE deployment in sustainable agriculture, with possible societal benefits including reduced production costs, increased yield, and improved food and nutritional security.

AI-aided plant engineering↗

The Oak Ridge National Laboratory Glenn T. Seaborg Institute: 2025 highlights

The Glenn T. Seaborg Institute (GTSI) at Oak Ridge National Laboratory (ORNL) serves as a dedicated hub for advancing actinide R&D, aimed at strengthening the United States’ capabilities in actinide science. With a focus on medical, industrial, and national security applications, the ORNL GTSI seeks to foster the next generation of scientists and engineers. Collaborating closely with corresponding Seaborg Institutes at Lawrence Livermore National Laboratory (LLNL), Lawrence Berkeley National Laboratory (LBNL), Los Alamos National Laboratory (LANL), and Idaho National Laboratory, the ORNL GTSI leverages its unique strengths. These include unparalleled expertise in isotope production, handling of rare isotopes, and leadership in neutron and computational sciences. Notably, the ORNL GTSI is positioned as the nation’s cornerstone for actinide R&D, capitalizing on the exceptional capabilities of the High Flux Isotope Reactor—the premier reactor for isotope production—and the Hazard Category 2 Radiochemical Engineering Development Center, which supports advanced production, processing, and applications research. Furthermore, the GTSI is committed to serving as a national center of excellence for training across all levels of actinide science education. This report provides an overview of the activities, milestones, and accomplishments of the ORNL GTSI over the past year.

38 RADIATION CHEMISTRY, RADIOCHEMISTRY, AND NUCLEA↗

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING↗

Building Cybersecurity Educational Materials for Students: The Windfarm Capture-The-Flag Exercise

Securing and protecting critical infrastructure in an increasingly digital world is vital but it is all too often an afterthought. It is especially important that students become aware of internet safety and security at an early age. However, the availability of interactive and educational cybersecurity material targeted toward students is minimal in the United States. Here we show an example of interactive cyber security educational material that an educator can use in their classroom to encourage students to think about the interaction between real-world physical objects, cyber security, and information security. By putting together a “capture-the-flag” exercise, students can see in real time how hackers and cybercriminals exploit vulnerabilities and gain access information. The students try to “capture” the “flag” (i.e., information) in the wind farm by looking for oddities in the code or by taking advantage of weaknesses in everyday protocols. Students can also see how cybersecurity interacts with the power grid through the wind farm project scenario and how a hacker could cause serious problems to a critical infrastructure sector. Our goal for the project is getting students interested in cybersecurity and help them develop an awareness of how important having robust security systems is. We also hope that this project demonstrates the importance of introducing these concepts early and inspires others to create similar projects geared toward students.

97 MATHEMATICS AND COMPUTING↗

Abbreviated Report for 25-FS-011: Switch and Stitch Similar Subgraph Synthesizer

Government institutions utilize software from a wide array of development sources, including those written by large software companies, government contractors, and open-source repositories. Avoiding installation of malicious software components is an important national security endeavor. Automated analysis of previously unseen software is an active research area, and there is much research in the design of systems that compare new software artifacts to a large set of previously seen software records organized by various behaviors they contain. One attractive approach is to turn each compiled software binary into a graph representation and apply a graph similarity model that scores pairs of binaries by their relative similarity. When a pair is deemed similar, it is useful to know why, in the sense of providing explanations to security analysts regarding which portions of the software they should look into further.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Quantum Computing and Simulations for Energy Applications

While quantum computing (QC) is considered as a paradigm shift in our basic understanding of physical computation, effective implementation of QC in energy applications also depends on progress and development in the dimensions of both QC hardware and algorithms. To fully address the status and future challenges of QC applied within the energy sector, in this presentation, we firstly summarize recent advancements on the applications of QC to energy infrastructure and materials, complex energy system processes, advanced manufacturing, and energy system security. Then, we will demonstrate the results of QC performed both on a simulator and a quantum device targeting on energy-related applications.

Paudel, Hari P.↗

Hydraulic Conductivity Measurements, Utqiagvik (Barrow), Alaska, 2014

Six individual ice cores were collected from the Barrow Environmental Observatory in Barrow, Alaska, in May of 2013 as part of the Next Generation Ecosystem Experiment (NGEE). Each core was drilled at a different location to varying depths. After drilling, the cores were stored in coolers packed with dry ice and flown to Lawrence Berkeley National Laboratory (LBNL) in Berkeley, CA. 3-dimensional images of the cores were constructed using medical X-ray computed tomography (CT) scanner at 120kV. Hydraulic conductivity samples were extracted from these cores at LBNL Richmond Field Station in Richmond, CA, in February 2014 by cutting 5 to 8 inch segments using a chop saw. Samples were packed individually and stored at -20C freezing temperatures to minimize any changes in structure or loss of ice content prior to analysis. Hydraulic conductivity was determined through falling head tests using a permeameter [ELE International, Model #: K-770B] (Appendix A). Samples were placed in a latex membrane via a membrane stretcher while frozen. Use of a membrane stretcher made the membranes easier to secure and minimized contact with the sample. A clear polycarbonate sleeve, fabricated with a stainless steel ring at the bottom to keep the sleeve from floating, was placed around the sample inside the permeameter to minimize deformation during analysis. The permeameter was filled with water and 1.0 PSI of air was applied for confining pressure during sample defrost. Outflow valves were left open to allow for incremental thawing and samples were left to thaw for approximately 12 hours. After approximately 12 hours of thaw, initial falling head tests were performed. When the flow was significantly too fast or too slow, the analysis was stopped and the burette size was adjusted accordingly (i.e. a larger diameter burette was used for flows that were faster than desired or a smaller diameter burette was used for flows that were slower than desired). Two to four measurements were collected on each sample and collection stopped when the applied head load exceeded 25% change from the original load. Analyses were performed between 2 to 3 times for each sample. The final hydraulic conductivity calculations were computed using methodology of Das et al., 1985.The Next-Generation Ecosystem Experiments: Arctic (NGEE Arctic), was a 15-year research effort (2012-2027) to reduce uncertainty in Earth System Models by developing a predictive understanding of carbon-rich Arctic ecosystems and feedbacks to climate. NGEE Arctic was supported by the Department of Energy's Office of Biological and Environmental Research. The NGEE Arctic project had two field research sites: 1) located within the Arctic polygonal tundra coastal region on the Barrow Environmental Observatory (BEO) and the North Slope near Utqiagvik (Barrow), Alaska and 2) multiple areas on the discontinuous permafrost region of the Seward Peninsula north of Nome, Alaska. Through observations, experiments, and synthesis with existing datasets, NGEE Arctic provided an enhanced knowledge base for multi-scale modeling and contributed to improved process representation at global pan-Arctic scales within the Department of Energy's Earth system Model (the Energy Exascale Earth System Model, or E3SM), and specifically within the E3SM Land Model component (ELM).

54 ENVIRONMENTAL SCIENCES↗

Transitioning GlideinWMS, a multi domain distributed workload manager, from GSI proxies to tokens and other granular credentials

GlideinWMS is a distributed workload manager that has been used in production for many years to provision resources for experiments like CERN’s CMS, many Neutrino experiments, and the OSG. Its security model was based mainly on GSI (Grid Security Infrastructure), using X.509 certificate proxies and VOMS (Virtual Organization Membership Service) extensions. Even when other credentials, like SSH keys, were used to authenticate with resources, proxies were also added all the time, to establish the identity of the requestor and the associated memberships or privileges. This single credential was used for everything and was, often implicitly, forwarded wherever needed. The addition of identity and access tokens and the phase-out of GSI forced us to reconsider the security model of GlideinWMS, to handle multiple credentials which can differ in type, technology, and functionality. Both identity tokens and access tokens are supported. GSI proxies even if no more mandatory, are still used, together with various JWT (JSON Web Token) based tokens and other certificates. The functionality of the credentials, defined by issuer, audience, and scope, also differ: a credential can allow access to a computing resource, or can protect the GlideinWMS framework from tampering, or can grant read or write access to storage, can provide an identity for accounting or auditing, or can provide a combination of any the formers. Furthermore, the tools in use do not include automatic forwarding and renewal of the new credentials so credential lifetime and renewal requirements became part of the discussion as well. In this paper, we will present how GlideinWMS was able to change its design and code to respond to all these changes.

97 MATHEMATICS AND COMPUTING↗

Harnessing large language models’ zero-shot and few-shot learning capabilities for regulatory research

Abstract Large language models (LLMs) are sophisticated AI-driven models trained on vast sources of natural language data. They are adept at generating responses that closely mimic human conversational patterns. One of the most notable examples is OpenAI's ChatGPT, which has been extensively used across diverse sectors. Despite their flexibility, a significant challenge arises as most users must transmit their data to the servers of companies operating these models. Utilizing ChatGPT or similar models online may inadvertently expose sensitive information to the risk of data breaches. Therefore, implementing LLMs that are open source and smaller in scale within a secure local network becomes a crucial step for organizations where ensuring data privacy and protection has the highest priority, such as regulatory agencies. As a feasibility evaluation, we implemented a series of open-source LLMs within a regulatory agency’s local network and assessed their performance on specific tasks involving extracting relevant clinical pharmacology information from regulatory drug labels. Our research shows that some models work well in the context of few- or zero-shot learning, achieving performance comparable, or even better than, neural network models that needed thousands of training samples. One of the models was selected to address a real-world issue of finding intrinsic factors that affect drugs' clinical exposure without any training or fine-tuning. In a dataset of over 700 000 sentences, the model showed a 78.5% accuracy rate. Our work pointed to the possibility of implementing open-source LLMs within a secure local network and using these models to perform various natural language processing tasks when large numbers of training examples are unavailable.

Biochemistry & Molecular Biology↗

A Novel Authentication Management for the Data Security of Smart Grid

Bidirectional wireless communication is employed in various smart grid components such as smart meters and control and monitoring applications where security is vital. The Trusted Third Party (TTP) and wireless connectivity between the smart meter and the third party in the key management-based encryption techniques for the smart grid are expected to be totally trustworthy and dependable. In a wired/wireless medium, however, a man-in-the-middle may seek to disrupt, monitor and manipulate the network, or simply execute a replay attack, revealing its vulnerability. Recognizing this, this study presents a novel authentication management (model) comprised of two layer security schema. The first layer implements an efficient novel encryption method for secure data exchange between meters and control center with the help of two partially trusted simple servers (constitutes the TTP). In this setting, one server handles the data encryption between the meter and control center/central database, and the other server administers the random sequence of data transmission. The second layer monitors and verifies exchanged data packets among smart meters. It detects abnormal packets from suspicious sources. To implement this node-to-node authentication, One class support vector machine algorithm is proposed which takes advantages of the location information as well as the data transmission history (node identification, packet size, and data transmission frequency). This schema secures data communication, and imposes a comprehensive privacy throughout the system without considerably extending the complexity of the conventional key management scheme.

24 POWER TRANSMISSION AND DISTRIBUTION↗