Search NASASearch

SEARCH · Search NASA

Results for “security verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Using software security analysis to verify the secure socket layer (SSL) protocol

nal Aeronautics and Space Administration (NASA) have tens of thousands of networked computer systems and applications. Software Security vulnerabilities present risks such as lost or corrupted data, information the3, and unavailability of critical systems. These risks represent potentially enormous costs to NASA. The NASA Code Q research initiative 'Reducing Software Security Risk (RSSR) Trough an Integrated Approach '' offers, among its capabilities, formal verification of software security properties, through the use of model based verification (MBV) to address software security risks. [1,2,3,4,5,6] MBV is a formal approach to software assurance that combines analysis of software, via abstract models, with technology, such as model checkers, that provide automation of the mechanical portions of the analysis process. This paper will discuss: The need for formal analysis to assure software systems with respect to software and why testing alone cannot provide it. The means by which MBV with a Flexible Modeling Framework (FMF) accomplishes the necessary analysis task. An example of FMF style MBV in the verification of properties over the Secure Socket Layer (SSL) communication protocol as a demonstration.

software

Spinoff 2010

Topics covered include: Burnishing Techniques Strengthen Hip Implants; Signal Processing Methods Monitor Cranial Pressure; Ultraviolet-Blocking Lenses Protect, Enhance Vision; Hyperspectral Systems Increase Imaging Capabilities; Programs Model the Future of Air Traffic Management; Tail Rotor Airfoils Stabilize Helicopters, Reduce Noise; Personal Aircraft Point to the Future of Transportation; Ducted Fan Designs Lead to Potential New Vehicles; Winglets Save Billions of Dollars in Fuel Costs; Sensor Systems Collect Critical Aerodynamics Data; Coatings Extend Life of Engines and Infrastructure; Radiometers Optimize Local Weather Prediction; Energy-Efficient Systems Eliminate Icing Danger for UAVs; Rocket-Powered Parachutes Rescue Entire Planes; Technologies Advance UAVs for Science, Military; Inflatable Antennas Support Emergency Communication; Smart Sensors Assess Structural Health; Hand-Held Devices Detect Explosives and Chemical Agents; Terahertz Tools Advance Imaging for Security, Industry; LED Systems Target Plant Growth; Aerogels Insulate Against Extreme Temperatures; Image Sensors Enhance Camera Technologies; Lightweight Material Patches Allow for Quick Repairs; Nanomaterials Transform Hairstyling Tools; Do-It-Yourself Additives Recharge Auto Air Conditioning; Systems Analyze Water Quality in Real Time; Compact Radiometers Expand Climate Knowledge; Energy Servers Deliver Clean, Affordable Power; Solutions Remediate Contaminated Groundwater; Bacteria Provide Cleanup of Oil Spills, Wastewater; Reflective Coatings Protect People and Animals; Innovative Techniques Simplify Vibration Analysis; Modeling Tools Predict Flow in Fluid Dynamics; Verification Tools Secure Online Shopping, Banking; Toolsets Maintain Health of Complex Systems; Framework Resources Multiply Computing Power; Tools Automate Spacecraft Testing, Operation; GPS Software Packages Deliver Positioning Solutions; Solid-State Recorders Enhance Scientific Data Collection; Computer Models Simulate Fine Particle Dispersion; Composite Sandwich Technologies Lighten Components; Cameras Reveal Elements in the Short Wave Infrared; Deformable Mirrors Correct Optical Distortions; Stitching Techniques Advance Optics Manufacturing; Compact, Robust Chips Integrate Optical Functions; Fuel Cell Stations Automate Processes, Catalyst Testing; Onboard Systems Record Unique Videos of Space Missions; Space Research Results Purify Semiconductor Materials; and Toolkits Control Motion of Complex Robotics.

Source record

Impact of light output on the timing resolution of organic glass scintillator bars in a dual-ended readout configuration

The effectiveness of detector system modeling and validation depends on the quality of characterization performed on the system. For nuclear nonproliferation applications, which require detectors to address complex and variable field conditions, access to accurate system models is essential. This study presents the timing characterization of organic glass scintillator bars used in an imaging system developed at the University of Michigan. 137 Cs and 60 Co gamma-ray sources were used to determine the coincidence time resolution as a function of measured light output for two Compton scatter events between two organic glass scintillator bars. Timing resolution for two events, each with light output ranging from 100 to 1100 keVee were characterized. The resulting data were fit to a parametric function that was validated to agree with experimental results within ±25 ps. Simulations were performed to establish appropriate calibration points for each organic scintillator, thereby ensuring accurate calibration of light output values during analysis. This work successfully characterized the light output dependence of the coincidence timing resolution of a pair of organic glass detectors for use in an imaging system. Depending on the amount of scintillation light output from the events, the full width at half maximum of the measured coincidence time resolution ranged from 653.2 ± 16.1 ps for low light yields, 100 keVee, to 121.0 ± 8.4 ps for higher yields at 1100 keVee. The insights obtained from the timing resolution behavior will allow for accurate simulation capabilities in future security and verification efforts using scatter-based imaging systems.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND

Storage Field Development Plan: One Earth Energy

This Storage Field Development plan presents the Storage Complex characterization results, construction, monitoring, and operational plans, and costs associated with the proposed One Earth Sequestration Carbon Capture and Storage (OES-CCS) site in McLean County, Illinois, near Gibson City. The proposed storage complex, known as the Mt. Simon Storage Complex, comprises the Cambrian Mt. Simon Sandstone reservoir and the primary seal, the Cambrian Eau Claire Formation. The lowermost Underground Source of Drinking Water (USDW) identified for the site is the Ordovician St. Peter Sandstone. Geologic characterization of the Mt. Simon Storage Complex at the OES-CCS site was performed by the Illinois Storage Corridor CarbonSAFE Phase III project, which also prepared and submitted three UIC Class VI applications to construct three injection wells; the permit applications were submitted and are in the federal EPA review process. A characterization well, OEE #1, was drilled to collect site-specific data. These data were analyzed and used to develop the UIC Class VI applications. The OEE #1 well will be converted to an in-zone monitoring (IZM) well for the injection phase. The proposed buildout for the OES-CCS site includes (1) three injection wells (OES #1, OES #2, and OES #3), (2) two IZM wells, (3) two above confining zone (ACZ) monitoring wells, one of which will be used to monitor the lowermost USDW, (4) capture and compression facilities, and (5) transportation facilities, i.e., pipelines. A pre-operational testing program was proposed in the Class VI permit application and will be employed at the site pending approval. Additional pre-injection (baseline), syn-injection, and post-injection monitoring and site care procedures will be followed by OES to ensure that injection activities are protective of human health and the environment. Injection is scheduled to begin in 2025, distributed across the three injection wells in accordance with the permit operating conditions. One Earth Sequestration intends to inject up to 90 million tonnes of CO 2 over a period of approximately 20 years. Injection will begin at approximately 0.5 million tonnes of CO 2 annually and ramp up to a maximum of 4.5 million tonnes annually. Daily injection rates are expected to range from 1,400 to 1,500 tonnes per day initially and reach a maximum of approximately 4,225 tonnes per day, depending on site geology and injectivity at each injection well location, and CO 2 availability. The costs associated with the OES-CCS project include pre-operational costs (e. g. additional seismic data acquisition and well drilling), capture and transportation facility and equipment costs, predicted field operating expenditures (OpEx), and decommissioning and post-injection site care (PISC) costs. The risks associated with project activities, such as site construction, injection operations, and verification of secure storage were evaluated, and mitigation strategies proposed to alleviate those risks.

09 BIOMASS FUELS

Managing information technology security risk

Information Technology (IT) Security Risk Management is a critical task for the organization to protect against the loss of confidentiality, integrity and availability of IT resources. As systems bgecome more complex and diverse and and attacks from intrusions and malicious content increase, it is becoming increasingly difficult to manage IT security risk. This paper describes a two-pronged approach in addressing IT security risk and risk management in the organization: 1) an institutional enterprise appraoch, and 2) a project life cycle approach.

security toolset

Countering Weapons of Mass Destruction (CWMD) Zero Trust Framework: CWMD Zero Trust Principles Model

The research focuses on the critical need for enhanced cybersecurity within the Countering Weapons of Mass Destruction (CWMD) Office, specifically targeting Chemical, Biological, Radiological, and Nuclear devices. Traditional perimeter-based security models are insufficient against modern cyber threats, prompting a shift toward Zero Trust principles (ZTP) that emphasize continuous verification and stringent security for all devices. Federal directives mandate the adoption of Zero Trust (ZT) across agencies, supported by guidelines from National Institute of Standards and Technology (NIST), U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Defense (DoD) and National Security Agency (NSA). The research involved mapping ZT guidance from these agencies to develop tailored CWMD ZTP. The study identified gaps and areas for improvement, including clear transitional guidance from traditional to ZT architectures and the focus on explicit cross cutting capabilities. Design improvements are recommended to ensure increased comprehensive protection and resilience against sophisticated cyber threats for Chemical, Biological, Radiological, and Nuclear (CBRN) devices. Collaborative efforts among federal agencies are essential for the successful deployment of an optimized ZT guidance.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF

Security Vulnerability Profiles of NASA Mission Software: Empirical Analysis of Security Related Bug Reports

NASA develops, runs, and maintains software systems for which security is of vital importance. Therefore, it is becoming an imperative to develop secure systems and extend the current software assurance capabilities to cover information assurance and cybersecurity concerns of NASA missions. The results presented in this report are based on the information provided in the issue tracking systems of one ground mission and one flight mission. The extracted data were used to create three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified the software bugs that are security related and classified them in specific security classes. This information was then used to create the security vulnerability profiles (i.e., to determine how, why, where, and when the security vulnerabilities were introduced) and explore the existence of common trends. The main findings of our work include:- Code related security issues dominated both the Ground and Flight mission IVV security issues, with 95 and 92, respectively. Therefore, enforcing secure coding practices and verification and validation focused on coding errors would be cost effective ways to improve mission's security. (Flight mission Developers issues dataset did not contain data in the Issue Category.)- In both the Ground and Flight mission IVV issues datasets, the majority of security issues (i.e., 91 and 85, respectively) were introduced in the Implementation phase. In most cases, the phase in which the issues were found was the same as the phase in which they were introduced. The most security related issues of the Flight mission Developers issues dataset were found during Code Implementation, Build Integration, and Build Verification; the data on the phase in which these issues were introduced were not available for this dataset.- The location of security related issues, as the location of software issues in general, followed the Pareto principle. Specifically, for all three datasets, from 86 to 88 the security related issues were located in two to four subsystems.- The severity levels of most security issues were moderate, in all three datasets.- Out of 21 primary security classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, these classes contributed from around 80 to 90 of all security issues in each dataset. This again proves the Pareto principle of uneven distribution of security issues, in this case across CWE classes, and supports the fact that addressing these dominant security classes provides the most cost efficient way to improve missions' security. The findings presented in this report uncovered the security vulnerability profiles and identified the common trends and dominant classes of security issues, which in turn can be used to select the most efficient secure design and coding best practices compiled by the part of the SARP project team associated with the NASA's Johnson Space Center. In addition, these findings provide valuable input to the NASA IVV initiative aimed at identification of the two 25 CWEs of ground and flight missions.

vulnerability

Analyzing the security of an existing computer system

Most work concerning secure computer systems has dealt with the design, verification, and implementation of provably secure computer systems, or has explored ways of making existing computer systems more secure. The problem of locating security holes in existing systems has received considerably less attention; methods generally rely on thought experiments as a critical step in the procedure. The difficulty is that such experiments require that a large amount of information be available in a format that makes correlating the details of various programs straightforward. This paper describes a method of providing such a basis for the thought experiment by writing a special manual for parts of the operating system, system programs, and library subroutines.

Bishop, M.

Reliable Design Versus Trust

This presentation focuses on reliability and trust for the users portion of the FPGA design flow. It is assumed that the manufacturer prior to hand-off to the user tests FPGA internal components. The objective is to present the challenges of creating reliable and trusted designs. The following will be addressed: What makes a design vulnerable to functional flaws (reliability) or attackers (trust)? What are the challenges for verifying a reliable design versus a trusted design?

Field Programmable Gate Aray (FPGA)