Search NASA⌕ Search

SEARCH · Search NASA

Results for “Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 307 records · Page 17

NSIUWG security sub-group

The following subject areas are covered: toolkits for NSI security; security policies and documentation; and risk analysis and management.

Source record↗

National Aeronautics and Space Administration's (NASA) Automated Information Security Handbook

The NASA Automated Information Security Handbook provides NASA's overall approach to automated information systems security including discussions of such aspects as: program goals and objectives, assignment of responsibilities, risk assessment, foreign national access, contingency planning and disaster recovery, awareness training, procurement, certification, planning, and special considerations for microcomputers.

Roback, E.↗

Automating security monitoring and analysis for Space Station Freedom's electric power system

Operating a large, space power system requires classifying the system's status and analyzing its security. Conventional algorithms are used by terrestrial electric utilities to provide such information to their dispatchers, but their application aboard Space Station Freedom will consume too much processing time. A novel approach for monitoring and analysis using adaptive pattern techniques is presented. This approach yields an on-line security monitoring and analysis algorithm that is accurate and fast; and thus, it can free the Space Station Freedom's power control computers for other tasks.

Dolce, James L.↗

Integrity and security in an Ada runtime environment

A review is provided of the Formal Methods group discussions. It was stated that integrity is not a pure mathematical dual of security. The input data is part of the integrity domain. The group provided a roadmap for research. One item of the roadmap and the final position statement are closely related to the space shuttle and space station. The group's position is to use a safe subset of Ada. Examples of safe sets include the Army Secure Operating System and the Penelope Ada verification tool. It is recommended that a conservative attitude is required when writing Ada code for life and property critical systems.

Bown, Rodney L.↗

The Management and Security Expert (MASE)

The Management and Security Expert (MASE) is a distributed expert system that monitors the operating systems and applications of a network. It is capable of gleaning the information provided by the different operating systems in order to optimize hardware and software performance; recognize potential hardware and/or software failure, and either repair the problem before it becomes an emergency, or notify the systems manager of the problem; and monitor applications and known security holes for indications of an intruder or virus. MASE can eradicate much of the guess work of system management.

Miller, Mark D.↗

Integrating security in a group oriented distributed system

A distributed security architecture is proposed for incorporation into group oriented distributed systems, and in particular, into the Isis distributed programming toolkit. The primary goal of the architecture is to make common group oriented abstractions robust in hostile settings, in order to facilitate the construction of high performance distributed applications that can tolerate both component failures and malicious attacks. These abstractions include process groups and causal group multicast. Moreover, a delegation and access control scheme is proposed for use in group oriented systems. The focus is the security architecture; particular cryptosystems and key exchange protocols are not emphasized.

Reiter, Michael↗

How to securely replicate services

A method is presented for constructing replicated services that retain their availability and integrity despite several servers and clients corrupted by an intruder, in addition to others failing benignly. More precisely, a service is replicated by n servers in such a way that a correct client will accept a correct server's response if, for some prespecified parameter k, at least k servers are correct and fewer than k servers are corrupt. The issue of maintaining causality among client requests is also addressed. A security breach resulting from an intruder's ability to effect a violation of causality in the sequence of requests processed by the service is illustrated. An approach to counter this problem is proposed that requires fewer than k servers to be corrupt and that is live if at least k+b servers are correct, where b is the assumed maximum total number of corrupt servers in any system run. An important and novel feature of these schemes is that the client need not be able to identify or authenticate even a single server. Instead, the client is required only to possess at most two public keys for the service. The practicality of these schemes is illustrated through a discussion of several issues pertinent to their implementation and use, and their intended role in a secure version of the Isis system is also described.

Reiter, Michael↗

Software For Computer-Security Audits

Information relevant to potential breaches of security gathered efficiently. Automated Auditing Tools for VAX/VMS program includes following automated software tools performing noted tasks: Privileged ID Identification, program identifies users and their privileges to circumvent existing computer security measures; Critical File Protection, critical files not properly protected identified; Inactive ID Identification, identifications of users no longer in use found; Password Lifetime Review, maximum lifetimes of passwords of all identifications determined; and Password Length Review, minimum allowed length of passwords of all identifications determined. Written in DEC VAX DCL language.

Arndt, Kate↗

NASA Automatic Information Security Handbook

This handbook details the Automated Information Security (AIS) management process for NASA. Automated information system security is becoming an increasingly important issue for all NASA managers and with rapid advancements in computer and network technologies and the demanding nature of space exploration and space research have made NASA increasingly dependent on automated systems to store, process, and transmit vast amounts of mission support information, hence the need for AIS systems and management. This handbook provides the consistent policies, procedures, and guidance to assure that an aggressive and effective AIS programs is developed, implemented, and sustained at all NASA organizations and NASA support contractors.

Source record↗

Random Vibration and Torque Tests of Fasteners Secured With Locking Cable, Room Temperature Vulcanized (RTV) Rubber, and Closed Cell Foam to Support the Launch of STS-82

During a walkdown of the Space Transportation System (STS) orbiter for the 82nd Space Shuttle flight (STS-82), technicians found several safety cables for bolts with missing or loose ferrules. Typically, two or three bolts are secured with a cable which passes through one of the holes in the head of each bolt and a ferrule is crimped on each end of the cable to prevent it from coming out of the holes. The purpose of the cable is to prevent bolts from rotating should they become untightened. Other bolts are secured with either a locking cable or wire which is covered with RTV and foam. The RTV and foam would have to be removed to inspect for missing or loose ferrules. To determine whether this was necessary, vibration and torque test fixtures and tests were made to determine whether or not bolts with missing or loose ferrules would unloosen. These tests showed they would not, and the RTV and foam was not removed.

Yost, V. H.↗

Strategy for IT Security

This viewgraph presentation provides information on the importance of information technology (IT) security (ITS) to NASA's mission. Several points are made concerning the subject. In order for ITS to be successful, it must be supported by management. NASA, while required by law to keep the public informed of its pursuits, must take precautions due to possible IT-based incursions by computer hackers and other malignant persons. Fear is an excellent motivation for establishing and maintaining a robust ITS policy. The ways in which NASA ITS personnel continually increase security are manifold, however a great deal relies upon the active involvement of the entire NASA community.

Santiago, S. Scott↗

Security System Software

C Language Integration Production System (CLIPS), a NASA-developed expert systems program, has enabled a security systems manufacturer to design a new generation of hardware. C.CURESystem 1 Plus, manufactured by Software House, is a software based system that is used with a variety of access control hardware at installations around the world. Users can manage large amounts of information, solve unique security problems and control entry and time scheduling. CLIPS acts as an information management tool when accessed by C.CURESystem 1 Plus. It asks questions about the hardware and when given the answer, recommends possible quick solutions by non-expert persons.

Source record↗

Secure Remote Access Issues in a Control Center Environment

The ISS finally reached an operational state and exists for local and remote users. Onboard payload systems are managed by the Huntsville Operations Support Center (HOSC). Users access HOSC systems by internet protocols in support of daily operations, preflight simulation, and test. In support of this diverse user community, a modem security architecture has been implemented. The architecture has evolved over time from an isolated but open system to a system which supports local and remote access to the ISS over broad geographic regions. This has been accomplished through the use of an evolved security strategy, PKI, and custom design. Through this paper, descriptions of the migration process and the lessons learned are presented. This will include product decision criteria, rationale, and the use of commodity products in the end architecture. This paper will also stress the need for interoperability of various products and the effects of seemingly insignificant details.

Pitts, Lee↗

Securing Mobile Networks in an Operational Setting

This paper describes a network demonstration and three month field trial of mobile networking using mobile-IPv4. The network was implemented as part of the US Coast Guard operational network which is a ".mil" network and requires stringent levels of security. The initial demonstrations took place in November 2002 and a three month field trial took place from July through September of 2003. The mobile network utilized encryptors capable of NSA-approved Type 1 algorithms, mobile router from Cisco Systems and 802.11 and satellite wireless links. This paper also describes a conceptual architecture for wide-scale deployment of secure mobile networking in operational environments where both private and public infrastructure is used. Additional issues presented include link costs, placement of encryptors and running routing protocols over layer-3 encryption devices.

Ivancic, William D.↗

Secure Payload Access to the International Space Station

The ISS finally reached an operational state and exists for local and remote users. Onboard payload systems are managed by the Huntsville Operations Support Center (HOSC). Users access HOSC systems by internet protocols in support of daily operations, preflight simulation, and test. In support of this diverse user community, a modem security architecture has been implemented. The architecture has evolved over time from an isolated but open system to a system which supports local and remote access to the ISS over broad geographic regions. This has been accomplished through the use of an evolved security strategy, PKI, and custom design. Through this paper, descriptions of the migration process and the lessons learned are presented. This will include product decision criteria, rationale, and the use of commodity products in the end architecture. This paper will also stress the need for interoperability of various products and the effects of seemingly insignificant details.

Pitts, R. Lee↗

Securing Sensitive Flight and Engine Simulation Data Using Smart Card Technology

NASA Glenn Research Center has developed a smart card prototype capable of encrypting and decrypting disk files required to run a distributed aerospace propulsion simulation. Triple Data Encryption Standard (3DES) encryption is used to secure the sensitive intellectual property on disk pre, during, and post simulation execution. The prototype operates as a secure system and maintains its authorized state by safely storing and permanently retaining the encryption keys only on the smart card. The prototype is capable of authenticating a single smart card user and includes pre simulation and post simulation tools for analysis and training purposes. The prototype's design is highly generic and can be used to protect any sensitive disk files with growth capability to urn multiple simulations. The NASA computer engineer developed the prototype on an interoperable programming environment to enable porting to other Numerical Propulsion System Simulation (NPSS) capable operating system environments.

Blaser, Tammy M.↗

Secure Networks for First Responders and Special Forces

When NASA needed help better securing its communications with orbiting satellites, the Agency called on Western DataCom Co., Inc., to help develop a prototype Internet Protocol (IP) router. Westlake, Ohio-based Western DataCom designs, develops, and manufactures hardware that secures voice, video, and data transmissions over any IP-based network. The technology that it jointly developed with NASA is now serving as a communications solution in military and first-response situations.

Source record↗

Should We Enhance the Observing Systems or Improve Coordination Among the Operating Agencies: What is Needed the Most for Security--A Philosophical Discussion

As an integrated observing strategy, the concept of sensorweb for Earth observations is appealing in many aspects. For instance, by increasing the spatial and temporal coverage of observations from space and other vantage points, one can eventually aid in increasing the accuracy of the atmospheric models which are precursor to hurricane track prediction, volcanic eruption forecast, and trajectory path of transcontinental transport of dust, harmful nuclear and chemical plumes. In reality, there is little analysis available in terms of benefits, costs and optimized set of sensors needed to make these necessary observations. This is a complex problem that must be carefully studied and balanced over many boundaries such as science, defense, early warning, security, and surveillance. Simplistically, the sensorweb concept from the technological point of view alone has a great appeal in the defense, early warning and security applications. In fact, it can be relatively less expensive in per unit cost as opposed to building and deploying it for the scientific use. However, overall observing approach should not be singled out and aligned somewhat orthogonally to serve a particular need. On the other hand, the sensorweb should be designed and deployed to serve multiple subject areas and customers simultaneously; and can behave as directed measuring systems for both science and operational entities. Sensorweb can be designed to act as expert systems, and/or also provide a dedicated integrated surveillance network. Today, there is no system in the world that is fully integrated in terms of reporting timely multiple hazards warnings, computing the loss of life and property damage estimates, and is also designed to cater to everyone's needs. It is not an easier problem to undertake and more so is not practically solvable. At this time due to some recent events in the world, the scientific community, social scientists, and operational agencies are more cognizant and getting together to address such colossal problems. Increasing our knowledge of the home planet, via amplified set of observations, is certainly a right step in a right direction. Furthermore, this is a pre-requisite in understanding multiple hazard phenomenas. This paper examines various sensorweb options and observing architectures that can be useful specifically in addressing some of these complex issues. The ultimate goal is to serve the society by providing potential natural hazards information to the decision makers in the most expeditious manner so they can prepare themselves to mitigate potential risks to human life, livestock and property.

Habib, Shahid↗