Search NASASearch

SEARCH · Search NASA

Results for “security controls”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Optimal Inflatable Space Towers with 3 - 100 km Height

Theory and computations are provided for building inflatable space towers up to one hundred kilometers in height. These towers can be used for tourism, scientific observation of space, observation of the Earth's surface, weather and upper atmosphere, and for radio, television, and communication transmissions. These towers can also be used to launch space ships and Earth satellites. These projects are not expensive and do not require rockets. They require thin strong films composed from artificial fibers and fabricated by current industry. The towers can be built using present technology. The towers can be used (for tourism, communication, etc.) during the construction process and provide self-financing for further construction. The tower design does not require work at high altitudes; all construction can be done at the Earth's surface. The transport system for a tower consists of a small engine (used only for friction compensation) located at the Earth's surface. The tower is separated into sections and has special protection mechanisms in case of damage. Problems involving security, control, repair, and stability of the proposed towers are addressed in other publications. The author is prepared to discuss these and other problems with serious organizations desiring to research and develop these projects.

Bolonkin, Alexander

Pharmacovigilance in Space: Stability Payload Compliance Procedures

Pharmacovigilance is the science of, and activities relating to the detection, assessment, understanding, and prevention of drug-related problems. Over the lase decade, pharmacovigilance activities have contributed to the development of numerous technological and conventional advances focused on medication safety and regulatory intervention. The topics discussed include: 1) Proactive Pharmacovigilance; 2) A New Frontier; 3) Research Activities; 4) Project Purpose; 5) Methods; 6) Flight Stability Kit Components; 7) Experimental Conditions; 8) Research Project Logistics; 9) Research Plan; 10) Pharmaceutical Stability Research Project Pharmacovigilance Aspects; 11) Security / Control; 12) Packaging/Containment Actions; 13) Shelf-Life Assessments; 14) Stability Assessment Parameters; 15) Chemical Content Analysis; 16) Preliminary Results; 17) Temperature/Humidity; 18) Changes in PHysical and Chemical Assessment Parameters; 19) Observations; and 20) Conclusions.

Daniels, Vernie R.

NASA Biological Specimen Repository

The NASA Biological Specimen Repository (NBSR) has been established to collect, process, annotate, store, and distribute specimens under the authority of the NASA/JSC Committee for the Protection of Human Subjects. The International Space Station (ISS) provides a platform to investigate the effects of microgravity on human physiology prior to lunar and exploration class missions. The NBSR is a secure controlled storage facility that is used to maintain biological specimens over extended periods of time, under well-controlled conditions, for future use in approved human spaceflight-related research protocols. The repository supports the Human Research Program, which is charged with identifying and investigating physiological changes that occur during human spaceflight, and developing and implementing effective countermeasures when necessary. The storage of crewmember samples from many different ISS flights in a single repository will be a valuable resource with which researchers can validate clinical hypotheses, study space-flight related changes, and investigate physiological markers All samples collected require written informed consent from each long duration crewmember. The NBSR collects blood and urine samples from all participating long duration ISS crewmembers. These biological samples are collected pre-flight at approximately 45 days prior to launch, during flight on flight days 15, 30, 60 120 and within 2 weeks of landing. Postflight sessions are conducted 3 and 30 days following landing. The number of inflight sessions is dependent on the duration of the mission. Operations began in 2007 and as of October 2009, 23 USOS crewmembers have completed or agreed to participate in this project. As currently planned, these human biological samples will be collected from crewmembers covering multiple ISS missions until the end of U.S. presence on the ISS or 2017. The NBSR will establish guidelines for sample distribution that are consistent with ethical principles, protection of crewmember confidentiality, prevailing laws and regulations, intellectual property policies, and consent form language. A NBSR Advisory Board composed of representatives of all participating agencies will be established to evaluate each request by an investigator for use of the samples to ensure the request reflects the mission of the NBSR.

Pietrzyk, Robert

L-Band Digital Aeronautical Communications System Engineering - Initial Safety and Security Risk Assessment and Mitigation

This document is being provided as part of ITT's NASA Glenn Research Center Aerospace Communication Systems Technical Support (ACSTS) contract NNC05CA85C, Task 7: "New ATM Requirements--Future Communications, C-Band and L-Band Communications Standard Development." ITT has completed a safety hazard analysis providing a preliminary safety assessment for the proposed L-band (960 to 1164 MHz) terrestrial en route communications system. The assessment was performed following the guidelines outlined in the Federal Aviation Administration Safety Risk Management Guidance for System Acquisitions document. The safety analysis did not identify any hazards with an unacceptable risk, though a number of hazards with a medium risk were documented. This effort represents a preliminary safety hazard analysis and notes the triggers for risk reassessment. A detailed safety hazards analysis is recommended as a follow-on activity to assess particular components of the L-band communication system after the technology is chosen and system rollout timing is determined. The security risk analysis resulted in identifying main security threats to the proposed system as well as noting additional threats recommended for a future security analysis conducted at a later stage in the system development process. The document discusses various security controls, including those suggested in the COCR Version 2.0.

Zelkin, Natalie

Secure, Autonomous, Intelligent Controller for Integrating Distributed Sensor Webs

This paper describes the infrastructure and protocols necessary to enable near-real-time commanding, access to space-based assets, and the secure interoperation between sensor webs owned and controlled by various entities. Select terrestrial and aeronautics-base sensor webs will be used to demonstrate time-critical interoperability between integrated, intelligent sensor webs both terrestrial and between terrestrial and space-based assets. For this work, a Secure, Autonomous, Intelligent Controller and knowledge generation unit is implemented using Virtual Mission Operation Center technology.

Ivancic, William D.

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere was heightened from Airports to the communication among the military branches legionnaires. With advanced persistent threats (APTs) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning and configuration of network devices i.e. routers and IDSsIPSs. In addition I will be completing security assessments on software and hardware, vulnerability assessments and reporting, conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, policies and procedures.

computer information security

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere has heightened from airports to the communication among the military branches legionnaires. With advanced persistent threats (APT's) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning, and configuration of network devices i.e. routers and IDS's/IPS's. In addition, I will be completing security assessments on software and hardware, vulnerability assessments and reporting, and conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out the tasks stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, as well as policies and procedures.

security

Achievable Performance and Effective Interrogator Design for SAW RFID Sensor Tags

For many NASA missions, remote sensing is a critical application that supports activities such as environmental monitoring, planetary science, structural shape and health monitoring, non-destructive evaluation, etc. The utility of the remote sensing devices themselves is greatly increased if they are passive V that is, they do not require any on-board power supply such as batteries V and if they can be identified uniquely during the sensor interrogation process. Additional passive sensor characteristics that enable greater utilization in space applications are small size and weight, long read ranges with low interrogator power, ruggedness, and operability in extreme environments (vacuum, extreme high/low temperature, high radiation, etc.) In this paper, we consider one very promising passive sensor technology, called surface acoustic wave (SAW) radio-frequency identification (RFID), that satisfies all of these criteria. In general, RFID is a method of identifying items using radio waves to interrogate tags encoded with a unique identifier that are affixed to the items of interest. In the case of passive tags, only the interrogator, which transmits power to the tags in the form of radio-frequency electromagnetic radiation, requires access to a power supply. Passive RFID technologies are used today in many applications, including asset tracking and management, security and access control, and remote sensing. To date, most of the development and application in RFID technology has focused on either asset/inventory tracking and control or security and access control because these are the largest commercial application areas. Recently however, there has been growing interest in using passive RFID technology for remote sensing applications, and SAW devices are at the forefront of RFID sensing technology development. Although SAW RFID tags have great potential for use in numerous space-based remote sensing applications, the limited collision resolution capability of current generation tags limits the performance in a cluttered sensing environment. That is, as more SAW-based sensors are added to the environment, numerous tag responses are superimposed at the receiver and decoding all or even a subset of the telemetry becomes increasingly difficult. Background clutter generated by reflectors other than the sensors themselves is also a problem, as is multipath interference and signal distortion, but the limiting factor in many remote sensing applications can be expected to be tag mutual interference. This problem may be greatly mitigated by proper design of the SAW tag waveform, but that remains an open research problem, and in the meantime, several other related questions remain to be answered including: (1) What are the fundamental relationships between tag parameters such as bit-rate, time-bandwidth-product, SNR, and achievable collision resolution? (2) What are the differences in optimal or near-optimal interrogator designs between noise-limited environments and interference-limited environments? (3) What are the performance characteristics of different interrogator designs in term of parameters such as transmitter power level, range, and number of interfering tags? In this paper, we will present the results of a research effort aimed at providing at least partial answers to all of these questions.

Barton Richard J.

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION

Towards Provable Security in Industrial Control Systems Via Dynamic Protocol Attestation

Industrial control systems (ICSs) increasingly rely on digital technologies vulnerable to cyber attacks. Cyber attackers can infiltrate ICSs and execute malicious actions. Individually, each action seems innocuous. But taken together, they cause the system to enter an unsafe state. These attacks have resulted in dramatic consequences such as physical damage, economic loss, and environmental catastrophes. This paper introduces a methodology that restricts actions using protocols. These protocols only allow safe actions to execute. Protocols are written in a domain specific language we have embedded in an interactive theorem prover (ITP). The ITP enables formal, machine-checked proofs to ensure protocols maintain safety properties. We use dynamic attestation to ensure ICSs conform to their protocol even if an adversary compromises a component. Since protocol conformance prevents unsafe actions, the previously mentioned cyber attacks become impossible. We demonstrate the effectiveness of our methodology using an example from the Fischertechnik Industry 4.0 platform. We measure dynamic attestation's impact on latency and throughput. Our approach is a starting point for studying how to combine formal methods and protocol design to thwart attacks intended to cripple ICSs.

97 MATHEMATICS AND COMPUTING

Control and Non-Payload Communications (CNPC) Prototype Radio - Generation 2 Security Architecture Lab Test Report

NASA Glenn Research Center, in cooperation with Rockwell Collins, is working to develop a prototype Control and Non-Payload Communications (CNPC) radio platform as part of NASA Integrated Systems Research Program's (ISRP) Unmanned Aircraft Systems (UAS) Integration in the National Airspace System (NAS) project. A primary focus of the project is to work with the FAA and industry standards bodies to build and demonstrate a safe, secure, and efficient CNPC architecture that can be used by industry to evaluate the feasibility of deploying a system using these technologies in an operational capacity. GRC has been working in conjunction with these groups to assess threats, identify security requirements, and to develop a system of standards-based security controls that can be applied to the current GRC prototype CNPC architecture as a demonstration platform. The security controls were integrated into a lab test bed mock-up of the Mobile IPv6 architecture currently being used for NASA flight testing, and a series of network tests were conducted to evaluate the security overhead of the controls compared to the baseline CNPC link without any security. The aim of testing was to evaluate the performance impact of the additional security control overhead when added to the Mobile IPv6 architecture in various modes of operation. The statistics collected included packet captures at points along the path to gauge packet size as the sample data traversed the CNPC network, round trip latency, jitter, and throughput. The effort involved a series of tests of the baseline link, a link with Robust Header Compression (ROHC) and without security controls, a link with security controls and without ROHC, and finally a link with both ROHC and security controls enabled. The effort demonstrated that ROHC is both desirable and necessary to offset the additional expected overhead of applying security controls to the CNPC link.

Communication Networks

IT Security Support for the Spaceport Command Control System Development

My job title is IT Security support for the Spaceport Command & Control System Development. As a cyber‐security analyst it is my job to ensure NASA's information stays safe from cyber threats, such as, viruses, malware and denial-of-service attacks by establishing and enforcing system access controls. Security is very important in the world of technology and it is used everywhere from personal computers to giant networks ran by Government agencies worldwide. Without constant monitoring analysis, businesses, public organizations and government agencies are vulnerable to potential harmful infiltration of their computer information system. It is my responsibility to ensure authorized access by examining improper access, reporting violations, revoke access, monitor information request by new programming and recommend improvements. My department oversees the Launch Control System and networks. An audit will be conducted for the LCS based on compliance with the Federal Information Security Management Act (FISMA) and The National Institute of Standards and Technology (NIST). I recently finished analyzing the SANS top 20 critical controls to give cost effective recommendations on various software and hardware products for compliance. Upon my completion of this internship, I will have successfully completed my duties as well as gain knowledge that will be helpful to my career in the future as a Cyber Security Analyst.

IT Security

Cloud Governance at Scale

Operating and maintaining a large multi-tenant ecosystem in the cloud requires scalable solutions to unique technical and process challenges. The Cloud Computing model grants significant permissions to development teams that traditionally were reserved for Data-Center Administrators and Supply-Chain Managers. Earthdata Cloud has worked to re-cast traditional data-center management into a sensible cloud-first model. This talk discusses some of our challenges, solutions, and way ahead.

financial controls

Control and Non-Payload Communications (CNPC) Prototype Radio - Generation 2 Security Flight Test Report

NASA Glenn Research Center (GRC), in cooperation with Rockwell Collins, is working to develop a prototype Control and Non-Payload Communications (CNPC) radio platform as part of NASA Integrated Systems Research Program's (ISRP) Unmanned Aircraft Systems (UAS) Integration in the National Airspace System (NAS) project. A primary focus of the project is to work with the Federal Aviation Administration (FAA) and industry standards bodies to build and demonstrate a safe, secure, and efficient CNPC architecture that can be used by industry to evaluate the feasibility of deploying a system using these technologies in an operational capacity. GRC has been working in conjunction with these groups to assess threats, identify security requirements, and to develop a system of standards-based security controls that can be applied to the GRC prototype CNPC architecture as a demonstration platform. The proposed security controls were integrated into the GRC flight test system aboard our S-3B Viking surrogate aircraft and several network tests were conducted during a flight on November 15th, 2014 to determine whether the controls were working properly within the flight environment. The flight test was also the first to integrate Robust Header Compression (ROHC) as a means of reducing the additional overhead introduced by the security controls and Mobile IPv6. The effort demonstrated the complete end-to-end secure CNPC link in a relevant flight environment.

Communication Networks

Mitigation for roof alterations to building 06-cp-65 at the area 6 control point, nevada national security site, nye county, nevada

Building 06-CP-65 has been determined to be a contributing element to the Area 6 Control Point Historic District (O’Neill et al. 2021; Reed 2022). It contributes to the significance of the historic district under Criterion A as one of the principal buildings that supported timing and firing operations for nuclear testing on the NNSS from 1966 to 1992. As such, the building served as a major warehouse with office space within the district. It was used by both REECo, a long-time general contractor at the NNSS, as well as EG&G, which provided technical support to the national laboratories and the DOD. The building served as an important staging area and electrical power supply point for the NNSS diagnostic trailer fleet and its unique location immediately along Mercury Highway allowed easy accessibility to the forward areas of the NNSS. The building also contributes to the historic district under Criterion C as it is one of the large, unadorned, precast concrete buildings at the Control Point. These types of buildings were the prominent elements of the compound that convey the district’s overall utilitarian, military-industrial character. Building 06-CP-65 retains all aspects of integrity to a high degree and easily conveys its significance as a warehouse that supported Control Point operations. Building 06-CP-65 is not recommended eligible for listing in the NRHP as an individual resource. While it served an important support function as part of the Control Point Historic District, an archival and literature review did not reveal information linking it to any specific test, series of tests, programs, or for any specific role on the NNSS other than as a warehouse (Criterion A). It has no direct association with any important individual (Criterion B). It also is not architecturally significant in its own right beyond reflecting the overall aesthetic of the Control Point Historic District (Criterion C), and it does not have potential to yield information important to the history of nuclear testing beyond what can be learned from historic texts, drawings, and other documents (Criterion D).

54 ENVIRONMENTAL SCIENCES

IT Security Support for Spaceport Command and Control System

During the fall 2013 semester, I worked at the Kennedy Space Center as an IT Security Intern in support of the Spaceport Command and Control System under the guidance of the IT Security Lead Engineer. Some of my responsibilities included assisting with security plan documentation collection, system hardware and software inventory, and malicious code and malware scanning. Throughout the semester, I had the opportunity to work on a wide range of security related projects. However, there are three projects in particular that stand out. The first project I completed was updating a large interactive spreadsheet that details the SANS Institutes Top 20 Critical Security Controls. My task was to add in all of the new commercial of the shelf (COTS) software listed on the SANS website that can be used to meet their Top 20 controls. In total, there are 153 unique security tools listed by SANS that meet one or more of their 20 controls. My second project was the creation of a database that will allow my mentor to keep track of the work done by the contractors that report to him in a more efficient manner by recording events as they occur throughout the quarter. Lastly, I expanded upon a security assessment of the Linux machines being used on center that I began last semester. To do this, I used a vulnerability and configuration tool that scans hosts remotely through the network and presents the user with an abundance of information detailing each machines configuration. The experience I gained from working on each of these projects has been invaluable, and I look forward to returning in the spring semester to continue working with the IT Security team.

computer security

DSS Security Assessment

The Discovery and Synchronization service (DSS) has implemented some reasonable technical controls that help improve security and there are very few technical findings. The use of Docker and Kubernetes helps simplify the deployment process, and the DSS uses mutual TLS (mTLS) to connect. Much of the security risk across the DSS is a factor of its nature, a distributed environment that relies on all members to secure their parts correctly. As such, the DSS team should attempt to emphasize security controls that reduce complexity for securing entities’ Cockroach DB (CRDB) instances properly and improve coordination among DSS members for things like security patching, incident response, detecting, and removing bad actors. The DSS team must recognize that operating a DSS instance securely will require a combination of technical and procedural controls. Each DSS entity must configure their instance properly and follow standard operating procedures to ensure that the DSS service is secure.

threat modeling