Search NASA⌕ Search

SEARCH · Search NASA

Results for “Computer security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 307 records · Page 17

The Digital Assurance for High Consequence Systems (DAHCS) Mission Campaign Whitepaper

The DAHCS (pronounced “Dax”) MC is a 7-year, $\$$45 million research portfolio within Sandia’s Laboratory Directed Research and Development program. The DAHCS MC arose in response to a great need: to ensure that the use of digital technologies does not weaken our nation’s high consequence systems. Digital technologies offer many benefits in speed, cost, and flexibility, and we seek to reap those benefits without introducing new system failures. However, digital technologies cannot be evaluated the same way as analog technologies. Initiatives across the nation highlight the capability gap that prevents efficient, effective digital assurance. The Challenge Today’s digital assurance tools, techniques, and methods are inadequate to confidently characterize, assess, and manage digital risk; they are ad hoc, slow, costly, and rarely scalable to increasingly complex digital technologies. The rapidly evolving cyber threat landscape exacerbates this problem because digital assurance now must secure against digital risks now and in the future, including those introduced by rapidly evolving technologies, adversaries, and systems.

97 MATHEMATICS AND COMPUTING↗

Multigene engineering in plants: Technologies, applications, and future prospects

The emerging bioeconomy presents a promising solution to both economic and environmental challenges. Within the bioeconomy, plants serve as a renewable, sustainable, and cost-effective source of foods, fuels, chemicals, and materials. However, traditional breeding and single-gene engineering approaches fall short in addressing complex traits (e.g., drought tolerance, disease resistance, yield, nutrient use efficiency) which are controlled by multiple genes. The complexity of plant biology often necessitates the use of multigene engineering (MGE), which involves simultaneous ectopic expression, up/down-regulation, or editing of multiple genes, to enhance plant traits relevant to the bioeconomy. These genes may be associated with distinct traits or function as components of specific metabolic and regulatory pathways. This review summarizes current technologies for MGE within the synthetic biology-driven Design-Build-Test-Learn (DBTL) framework, detailing its four key stages: Design – gene construct development; Build – DNA assembly and plant transformation; Test – the molecular, biochemical, and physiological characterization of engineered plants; and Learn – computational modeling to refine, multiplex and iterate the process. Despite good progress in the applications of MGE in biofortification, metabolic engineering, and stress resilience, challenges remain in construct stability, coordinated gene expression, and regulatory predictability. We identified optimization paths and future directions to accelerate MGE deployment in sustainable agriculture, with possible societal benefits including reduced production costs, increased yield, and improved food and nutritional security.

AI-aided plant engineering↗

The Oak Ridge National Laboratory Glenn T. Seaborg Institute: 2025 highlights

The Glenn T. Seaborg Institute (GTSI) at Oak Ridge National Laboratory (ORNL) serves as a dedicated hub for advancing actinide R&D, aimed at strengthening the United States’ capabilities in actinide science. With a focus on medical, industrial, and national security applications, the ORNL GTSI seeks to foster the next generation of scientists and engineers. Collaborating closely with corresponding Seaborg Institutes at Lawrence Livermore National Laboratory (LLNL), Lawrence Berkeley National Laboratory (LBNL), Los Alamos National Laboratory (LANL), and Idaho National Laboratory, the ORNL GTSI leverages its unique strengths. These include unparalleled expertise in isotope production, handling of rare isotopes, and leadership in neutron and computational sciences. Notably, the ORNL GTSI is positioned as the nation’s cornerstone for actinide R&D, capitalizing on the exceptional capabilities of the High Flux Isotope Reactor—the premier reactor for isotope production—and the Hazard Category 2 Radiochemical Engineering Development Center, which supports advanced production, processing, and applications research. Furthermore, the GTSI is committed to serving as a national center of excellence for training across all levels of actinide science education. This report provides an overview of the activities, milestones, and accomplishments of the ORNL GTSI over the past year.

38 RADIATION CHEMISTRY, RADIOCHEMISTRY, AND NUCLEA↗

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING↗

Building Cybersecurity Educational Materials for Students: The Windfarm Capture-The-Flag Exercise

Securing and protecting critical infrastructure in an increasingly digital world is vital but it is all too often an afterthought. It is especially important that students become aware of internet safety and security at an early age. However, the availability of interactive and educational cybersecurity material targeted toward students is minimal in the United States. Here we show an example of interactive cyber security educational material that an educator can use in their classroom to encourage students to think about the interaction between real-world physical objects, cyber security, and information security. By putting together a “capture-the-flag” exercise, students can see in real time how hackers and cybercriminals exploit vulnerabilities and gain access information. The students try to “capture” the “flag” (i.e., information) in the wind farm by looking for oddities in the code or by taking advantage of weaknesses in everyday protocols. Students can also see how cybersecurity interacts with the power grid through the wind farm project scenario and how a hacker could cause serious problems to a critical infrastructure sector. Our goal for the project is getting students interested in cybersecurity and help them develop an awareness of how important having robust security systems is. We also hope that this project demonstrates the importance of introducing these concepts early and inspires others to create similar projects geared toward students.

97 MATHEMATICS AND COMPUTING↗

Abbreviated Report for 25-FS-011: Switch and Stitch Similar Subgraph Synthesizer

Government institutions utilize software from a wide array of development sources, including those written by large software companies, government contractors, and open-source repositories. Avoiding installation of malicious software components is an important national security endeavor. Automated analysis of previously unseen software is an active research area, and there is much research in the design of systems that compare new software artifacts to a large set of previously seen software records organized by various behaviors they contain. One attractive approach is to turn each compiled software binary into a graph representation and apply a graph similarity model that scores pairs of binaries by their relative similarity. When a pair is deemed similar, it is useful to know why, in the sense of providing explanations to security analysts regarding which portions of the software they should look into further.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Metric DBSCAN

SAND2025-11725O Metric DBSCAN is an implementation of the popular DBSCAN clustering algorithm that works in general metric spaces. DBSCAN is a clustering algorithm, a fundamental building block in machine learning. It takes a set of objects and, given some notion of distance, identifies coherent groups of objects. With Metric DBSCAN, users can provide an arbitrary function to compute distance. Nearly all existing implementations of DBSCAN restrict distance to one of a few formulations. Metric DBScan accomplishes this cleanly and efficiently. The Python source code is on Github. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Dalbey, Keith↗

Quantum Computing and Simulations for Energy Applications

While quantum computing (QC) is considered as a paradigm shift in our basic understanding of physical computation, effective implementation of QC in energy applications also depends on progress and development in the dimensions of both QC hardware and algorithms. To fully address the status and future challenges of QC applied within the energy sector, in this presentation, we firstly summarize recent advancements on the applications of QC to energy infrastructure and materials, complex energy system processes, advanced manufacturing, and energy system security. Then, we will demonstrate the results of QC performed both on a simulator and a quantum device targeting on energy-related applications.

Paudel, Hari P.↗

Hydraulic Conductivity Measurements, Utqiagvik (Barrow), Alaska, 2014

Six individual ice cores were collected from the Barrow Environmental Observatory in Barrow, Alaska, in May of 2013 as part of the Next Generation Ecosystem Experiment (NGEE). Each core was drilled at a different location to varying depths. After drilling, the cores were stored in coolers packed with dry ice and flown to Lawrence Berkeley National Laboratory (LBNL) in Berkeley, CA. 3-dimensional images of the cores were constructed using medical X-ray computed tomography (CT) scanner at 120kV. Hydraulic conductivity samples were extracted from these cores at LBNL Richmond Field Station in Richmond, CA, in February 2014 by cutting 5 to 8 inch segments using a chop saw. Samples were packed individually and stored at -20C freezing temperatures to minimize any changes in structure or loss of ice content prior to analysis. Hydraulic conductivity was determined through falling head tests using a permeameter [ELE International, Model #: K-770B] (Appendix A). Samples were placed in a latex membrane via a membrane stretcher while frozen. Use of a membrane stretcher made the membranes easier to secure and minimized contact with the sample. A clear polycarbonate sleeve, fabricated with a stainless steel ring at the bottom to keep the sleeve from floating, was placed around the sample inside the permeameter to minimize deformation during analysis. The permeameter was filled with water and 1.0 PSI of air was applied for confining pressure during sample defrost. Outflow valves were left open to allow for incremental thawing and samples were left to thaw for approximately 12 hours. After approximately 12 hours of thaw, initial falling head tests were performed. When the flow was significantly too fast or too slow, the analysis was stopped and the burette size was adjusted accordingly (i.e. a larger diameter burette was used for flows that were faster than desired or a smaller diameter burette was used for flows that were slower than desired). Two to four measurements were collected on each sample and collection stopped when the applied head load exceeded 25% change from the original load. Analyses were performed between 2 to 3 times for each sample. The final hydraulic conductivity calculations were computed using methodology of Das et al., 1985.The Next-Generation Ecosystem Experiments: Arctic (NGEE Arctic), was a 15-year research effort (2012-2027) to reduce uncertainty in Earth System Models by developing a predictive understanding of carbon-rich Arctic ecosystems and feedbacks to climate. NGEE Arctic was supported by the Department of Energy's Office of Biological and Environmental Research. The NGEE Arctic project had two field research sites: 1) located within the Arctic polygonal tundra coastal region on the Barrow Environmental Observatory (BEO) and the North Slope near Utqiagvik (Barrow), Alaska and 2) multiple areas on the discontinuous permafrost region of the Seward Peninsula north of Nome, Alaska. Through observations, experiments, and synthesis with existing datasets, NGEE Arctic provided an enhanced knowledge base for multi-scale modeling and contributed to improved process representation at global pan-Arctic scales within the Department of Energy's Earth system Model (the Energy Exascale Earth System Model, or E3SM), and specifically within the E3SM Land Model component (ELM).

54 ENVIRONMENTAL SCIENCES↗

Transitioning GlideinWMS, a multi domain distributed workload manager, from GSI proxies to tokens and other granular credentials

GlideinWMS is a distributed workload manager that has been used in production for many years to provision resources for experiments like CERN’s CMS, many Neutrino experiments, and the OSG. Its security model was based mainly on GSI (Grid Security Infrastructure), using X.509 certificate proxies and VOMS (Virtual Organization Membership Service) extensions. Even when other credentials, like SSH keys, were used to authenticate with resources, proxies were also added all the time, to establish the identity of the requestor and the associated memberships or privileges. This single credential was used for everything and was, often implicitly, forwarded wherever needed. The addition of identity and access tokens and the phase-out of GSI forced us to reconsider the security model of GlideinWMS, to handle multiple credentials which can differ in type, technology, and functionality. Both identity tokens and access tokens are supported. GSI proxies even if no more mandatory, are still used, together with various JWT (JSON Web Token) based tokens and other certificates. The functionality of the credentials, defined by issuer, audience, and scope, also differ: a credential can allow access to a computing resource, or can protect the GlideinWMS framework from tampering, or can grant read or write access to storage, can provide an identity for accounting or auditing, or can provide a combination of any the formers. Furthermore, the tools in use do not include automatic forwarding and renewal of the new credentials so credential lifetime and renewal requirements became part of the discussion as well. In this paper, we will present how GlideinWMS was able to change its design and code to respond to all these changes.

97 MATHEMATICS AND COMPUTING↗

Harnessing large language models’ zero-shot and few-shot learning capabilities for regulatory research

Abstract Large language models (LLMs) are sophisticated AI-driven models trained on vast sources of natural language data. They are adept at generating responses that closely mimic human conversational patterns. One of the most notable examples is OpenAI's ChatGPT, which has been extensively used across diverse sectors. Despite their flexibility, a significant challenge arises as most users must transmit their data to the servers of companies operating these models. Utilizing ChatGPT or similar models online may inadvertently expose sensitive information to the risk of data breaches. Therefore, implementing LLMs that are open source and smaller in scale within a secure local network becomes a crucial step for organizations where ensuring data privacy and protection has the highest priority, such as regulatory agencies. As a feasibility evaluation, we implemented a series of open-source LLMs within a regulatory agency’s local network and assessed their performance on specific tasks involving extracting relevant clinical pharmacology information from regulatory drug labels. Our research shows that some models work well in the context of few- or zero-shot learning, achieving performance comparable, or even better than, neural network models that needed thousands of training samples. One of the models was selected to address a real-world issue of finding intrinsic factors that affect drugs' clinical exposure without any training or fine-tuning. In a dataset of over 700 000 sentences, the model showed a 78.5% accuracy rate. Our work pointed to the possibility of implementing open-source LLMs within a secure local network and using these models to perform various natural language processing tasks when large numbers of training examples are unavailable.

Biochemistry & Molecular Biology↗

A Novel Authentication Management for the Data Security of Smart Grid

Bidirectional wireless communication is employed in various smart grid components such as smart meters and control and monitoring applications where security is vital. The Trusted Third Party (TTP) and wireless connectivity between the smart meter and the third party in the key management-based encryption techniques for the smart grid are expected to be totally trustworthy and dependable. In a wired/wireless medium, however, a man-in-the-middle may seek to disrupt, monitor and manipulate the network, or simply execute a replay attack, revealing its vulnerability. Recognizing this, this study presents a novel authentication management (model) comprised of two layer security schema. The first layer implements an efficient novel encryption method for secure data exchange between meters and control center with the help of two partially trusted simple servers (constitutes the TTP). In this setting, one server handles the data encryption between the meter and control center/central database, and the other server administers the random sequence of data transmission. The second layer monitors and verifies exchanged data packets among smart meters. It detects abnormal packets from suspicious sources. To implement this node-to-node authentication, One class support vector machine algorithm is proposed which takes advantages of the location information as well as the data transmission history (node identification, packet size, and data transmission frequency). This schema secures data communication, and imposes a comprehensive privacy throughout the system without considerably extending the complexity of the conventional key management scheme.

24 POWER TRANSMISSION AND DISTRIBUTION↗

PLC Vulnerabilities and Mitigations

Programmable Logic Controllers (PLCs) are used extensively in many high-importance industrial and nonindustrial settings including controlling elevators, manufacturing machines, and utility facilities such as power and natural gas, however cybersecurity protection for them has been neglected. Within recent years, PLCs have been put under more security scrutiny and experts have advocated for changes from the addition of protocol encryption and network segmentation to intrusion detection systems on the PLCs themselves. While PLC security is critical, a large portion of the PLCs available today will never receive these changes due to being legacy or the difficulty of overhauling the security on existing systems. Due to the infeasibility of applying many recommended security measures towards currently available machines, we aim to provide realistic and affordable best practices for hardening PLCs. We will first conduct security analysis and consider attack vectors within our target PLC. Once we’ve analyzed the device’s security, we will evaluate a variety of mitigation methods and create guidelines to effectively reduce the threat posed by PLC attacks with minimal disruption to operations.

42 ENGINEERING↗

Optimization of Scrap Melting Using an Electric Arc in Steel Manufacturing

Steel industry is crucial to the national economy and security. Around 67% of crude steel in the U.S is produced in electric arc furnaces (EAF), which is energy intensive. Around 140 EAFs operate in the U.S., consuming about 8.6x10 7 MMBtu/year of electricity. One of major challenges for EAFs includes maximizing the efficiency of the electrical energy provided in the form of electric arcs to melt various scrap mixes. To address this issue, a computational fluid dynamics (CFD) methodology is chosen to analyze scrap melting using the electric arc. Due to complex furnace phenomena and the wide variety of potential scenarios, high performance computing (HPC) is essential to yield comprehensive and detailed CFD analyses and systematic parametric studies for optimized EAF operation. The objectives are to 1) simulate scrap melting using electric arc, 2) evaluate electrode/arc position for optimum scrap melting and 3) establish reduced order model for CFD data-base for fast model calculation.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Modular Autonomous Experimentation for Biological Applications (Full Report)

The Modular Autonomous Research System (MARS) was developed to address the pressing need for faster, more reliable, and more adaptable scientific discovery. Traditional experimentation is limited by manual labor, long cycle times, and fragmented data streams, which constrain the ability to explore complex chemical and materials design spaces. To overcome these limitations, we created an integrated, modular platform that combines laboratory robotics, diverse measurement instruments, and a central data infrastructure with artificial intelligence–driven decision-making. The system links liquid handling robots, robotic arms, and optical plate readers into a closed loop where experiments are executed automatically, data is analyzed in real time, and subsequent experimental conditions are adaptively chosen to maximize information gain. Over the course of the project, MARS was validated on two primary test cases—spectroscopic metal–ligand binding assays and peptide-directed mineralization—which highlighted the system’s ability to handle uncertainty and variability in experimental measurements. To further demonstrate modularity and extensibility, we also established additional testbeds in electrochemistry for catalyst discovery and electrolyte formulation for advanced batteries. The results show that MARS can reliably conduct autonomous campaigns with minimal human intervention, adapt to distinct scientific domains, and provide a scalable model for future self-driving laboratories. This work establishes new capabilities for modular, uncertainty-aware automation and directly supports the need for advanced, data-driven research platforms capable of accelerating discovery across a wide range of scientific and national security missions.

59 BASIC BIOLOGICAL SCIENCES↗

Mesh Computing Remote Automatic Workflow

The software suite uses a microservice architecture using Docker and `docker-compose`. The microservices are as follows: 1. User interface. This interface is written in JavaScript using the Svelte framework. It exposes form elements and a 3D visualizer to prompt the user through the definition of microstructure parameters, and setting parameters for mesh generation and refinement. 2. Mesh generator. This is a container running the Python package for DREAM3D to generate a voxelized mesh that represents a microstructure defined by the user in the interface. 3. Cubit runner. This is a secure shell protocol tool that makes the submitting the DREAM mesh to an HPC instance and starts to run Cubit shell commands to smooth the grain boundaries with its `sculpt` library, applies user-defined boundary node sets, and bundles and returns the simulation-ready meshes and input files as a zipped directory.

Harris, BrennanKay↗

Cyber-Informed Engineering (CIE) Benefits Quantification: Recommendations for Consideration

Cyber-Informed Engineering (CIE) integrates engineering principles into the design, development, and operation of cyber-physical systems (CPS) to mitigate or eliminate the impact of cyber-enabled attacks. In July 2024, Idaho National Laboratory (INL) engaged MITRE researchers to investigate methods for systematically measuring the benefits of CIE implementation. This included evaluating the success and outcomes of CIE, identifying and quantifying the value of early adoption, and determining the business justification for its implementation, especially in existing infrastructure. MITRE reviewed existing methods in engineering and cybersecurity to understand how organizations prioritize security investments, considering their strengths, weaknesses, and relevance to CIE stakeholders. Based on this analysis, MITRE proposed potential approaches for quantifying CIE benefits and provided recommendations for INL's consideration.

42 ENGINEERING↗

Privacy-Aware RAG-Enabled LLMs for Collaborative AI in Organizations

Recent advancements in Large Language Models (LLMs) based on Transformer architectures have significantly improved capabilities in natural language processing and generation. However, deploying LLMs for inter-organizational communication poses challenges, in ensuring privacy and facilitating effective collaboration. This paper introduces a novel decentralized inference meta-agent chatbot that leverages privacy-aware Retrieval-Augmented Generation (RAG)-enabled LLMs for collaborative AI communication across organizations. Built on Microsoft’s Autogen, the platform enables LLMs to autonomously refine responses, enhancing accuracy and relevance. It incorporates advanced hallucination mitigation techniques using Uptrain and a privacy-focused RAG framework that employs synthetic document generation to protect sensitive information. Comprehensive evaluations demonstrate the platform’s effectiveness in maintaining contextual relevance and stringent privacy standards, effectively addressing critical challenges in LLM-enhanced collaborative AI communication. This work represents a significant step toward secure and efficient inter-organizational collaboration using advanced generative AI technologies.

97 - MATHEMATICS AND COMPUTING↗