Search NASA⌕ Search

SEARCH · Search NASA

Results for “Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 361 records · Page 20

Digital-Threat Bias and Psychological Distance: Barriers to Foundational Digital-Security Improvement

Modern life is held together by a web of digital dependencies that enable and provide delivery of critical services and functions—think the provision of utilities such as electricity and water, as well as our dependency on digital services for social and economic services (internet, communication, etc.). As this dependency grows, the complexity related to the delivery of these critical services increases as well. As complexity increases, the understanding of the risk and impact associated with potential disruption, degradation, or destruction—due to either malicious or non-malicious events of those digitally enabled functions—decreases. One potential explanation for the difficulty to 1) understand the risks faced and 2) address them appropriately and effectively is the abstractness and psychological distance assigned to “digital threat.” The complexity of these digitally enabled services creates a perceived complicatedness; as a result, digital threats are treated differently than similarly devasting (but more easily understood) kinetic or physical threats. How we categorize these threats also matters. Acts of cyber-enabled sabotage to critical infrastructure need to be defined as irregular warfare. By inadequately defining the threat, we compound the problem. Acknowledging this digital-threat bias is foundational to improving the ability to protect critical infrastructure. Using construal-level theory and psychological-distance concepts provides an intriguing starting point to address these issues, to reframe the challenges faced, and pursue more effective critical infrastructure security and defense policy.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Aviation security screening optimizer for risk and throughput (ASSORT)

The increasing number of air travelers each year presents a challenge as many airports are near their capacity in terms of resources and space for passenger screening. Fortunately, advancements in technologies like next-generation millimeter wave scanning offer solutions to ease this strain. The focus remains on managing risk while enhancing the passenger experience for the traveling public. The risk model presented in this paper known as the Aviation Security Screening Optimizer for Risk and Throughput (ASSORT) is designed to assess risk-based approaches for passenger screening and checkpoint operations. Additionally, ASSORT is exploring various traveler categories — general, trusted, and trusted-plus — along with different checkpoint screening Concept of Operations tailored to each traveler type. For instance, travelers with a higher trust level may experience fewer screening technologies, resulting in quicker processing times at the checkpoint. The output of ASSORT provides a risk score for predefined threat scenarios, as well as the overall risk to the checkpoint, aircraft, and airport by traveler type. In conclusion, benefits of using this tool include assessing the trade-offs between the overall risk associated with checkpoints and the throughput rate of passengers screened. We show for example the impact that different passenger volumes at the checkpoint can have on risk.

99 GENERAL AND MISCELLANEOUS↗

Dynamic security assessment of systems powered only by grid-forming power plants with uncertain dispatch using polynomial vectors

A modern challenge in power engineering is to perform the dynamic security assessment (DSA) of grids that are 100% powered by inverter-based resources (IBRs). Addressing this challenge is difficult because: (i) the dispatch of IBRs can be uncertain as a result of the variability of renewable resources and (ii) they have hard current control limits that cannot be neglected, contrasting synchronous machines. To address this problem, this paper sets forth a framework to conduct DSA of bulk power systems that are 100% powered by grid-forming IBRs. Furthermore, the framework considers that IBR operational conditions are unknown but bounded by a zonotope which is also expressed as a polynomial vector for uncertainty propagation via Dormand–Prince integration. The framework is applied to modified versions of the WSCC 9-bus and IEEE 39-bus grids.

14 SOLAR ENERGY↗

5G Securely Energized and Resilient: (5G-SER) (Final Report)

NREL's work on 5G integration with physical power systems (versus simulated systems demonstrated in task 3) under 5G-Securely Energized and Resilient (5G-SER) achieved a major milestone in with the completion of Task 4 activities. After many months (6+) of planning and development along with scaling challenges along the way, a full 5G end-to-end network with physical hardware components (physical inverter, physical power panel, physical battery, etc.) was deployed in a containerized environment. In parallel, a distributed controls architecture for a microgrid powering 5G resources was also successfully modified from its previous instantiation for a simulated environment to work with these physical components. These accomplishments set the stage to use newly setup 5G technology with physical microgrid components to test the feasibility of 5G wireless with physical systems to enable resilient communications between controls and distributed solar and storage resources while exploring ways to configure 5G components to survive power disturbances. The results detailed in the report below show that even utilizing physical components, 5G wireless systems were able to provide resilient results that were similar to the results from the simulated environment Task 3).

24 POWER TRANSMISSION AND DISTRIBUTION↗

Federal Facility Agreement and Consent Order: Nevada National Security Site Use Restriction Management Plan with ROTC 1

This Use Restriction Management Plan (URMP) provides the information needed to create, modify, and manage use restrictions (URs) for sites on the Nevada National Security Site (NNSS), and sites accessed through the NNSS main gate, that were closed using the corrective action alternative (CAA) of closure in place under the Federal Facility Agreement and Consent Order (FFACO) (1996, as amended). (Note: This pertains to those FFACO sites not managed by the U.S. Department of Energy [DOE], Legacy Management.) The closure in place alternative is used for sites closed with residual contamination at levels requiring corrective action as determined using the FFACO process. The URs contain and control all requirements for long-term monitoring. This URMP also serves as the single repository of the URs implemented under the FFACO that identify use restricted areas and contain the current requirements for inspections, maintenance, and monitoring of the UR. The requirements in these URs replace all requirements listed in previous documentation. This consolidates post-closure monitoring requirements into a single source that ensures completeness and consistency of UR requirements and information. Standardized UR forms were developed to clearly document post-closure requirements that are consistent with current protocols and to ensure consistent information is contained in the URs. Standard notification, summary, and site controls statements were developed for all URs with provisions to insert site-specific options in the text. Current protocols for Industrial Sites and Soils URs are defined in this document and in the Soils Risk-Based Corrective Action (RBCA) Evaluation Process (DOE/EMNV, 2018). The standardized UR forms that have been approved to date are listed in Appendix A. Additional UR forms will be added once the review and approval process has been completed.

54 ENVIRONMENTAL SCIENCES↗

Federal Facility Agreement and Consent Order Nevada National Security Site Use Restriction Management Plan

This Use Restriction Management Plan (URMP) provides the information needed to create, modify, and manage use restrictions (URs) for sites on the Nevada National Security Site (NNSS), and sites accessed through the NNSS main gate, that were closed using the corrective action alternative (CAA) of closure in place under the Federal Facility Agreement and Consent Order (FFACO) (1996, as amended).

54 ENVIRONMENTAL SCIENCES↗

Streamlined Approach for Environmental Restoration (SAFER) Plan for Corrective Action Unit 114: Area 25 EMAD Facility Nevada National Security Site, Nevada

This Streamlined Approach for Environmental Restoration (SAFER) Plan addresses the actions needed to achieve closure for Corrective Action Unit (CAU) 114, Area 25 EMAD Facility, identified in the Federal Facility Agreement and Consent Order (FFACO). CAU 114 comprises the following corrective action sites (CASs) located in Area 25 of the Nevada National Security Site: • 25-41-03, EMAD Facility (Building 3900) • 25-99-23, Manned Control Car (MCC) and Engine Installation Vehicle (EIV) • 25-33-05, Building 3901, Engine Transport System Maintenance Building (Train Shed) This plan provides the methodology for field activities needed to gather the necessary information for closing CAU 114. There is sufficient information and process knowledge from historical documentation and investigations of similar sites regarding the expected nature and extent of potential contaminants to recommend closure of CAU 114 using the SAFER process. Additional information will be obtained by conducting a field investigation before selecting the appropriate corrective actions for CAU 114. It is anticipated that the results of the field investigation and implementation of corrective actions will support a defensible recommendation that no further corrective action is necessary. The purpose of the corrective action investigation will be to document and verify the adequacy of existing information; to affirm the decision for either clean closure, closure in place, or no further action; and to provide sufficient data to implement the corrective action. The actual corrective action selected will be based on characterization activities implemented under this SAFER Plan. If specific conditions or findings fall outside the bounds of the conceptual site model, such as an unanticipated release, the Nevada Division of Environmental Protection (NDEP) will be consulted to determine the path forward before proceeding. Upon completion of SAFER activities, a closure report (CR) will be prepared and submitted to NDEP for review and approval. The schedule for completion of the CR will be established in consultation with NDEP.

54 ENVIRONMENTAL SCIENCES↗

Non-Resource Conservation and Recovery Act Corrective Action Unit (CAU) Post-Closure Inspection Report, Nevada National Security Site, Nevada For Calendar Year 2024

This report includes visual inspection results, descriptions of maintenance and repair activities, and recommendations for calendar year 2024 for use restrictions at corrective action sites located on the Nevada National Security Site (NNSS) and on the Nevada Test and Training Range that are accessed through the NNSS Main Gate.

54 ENVIRONMENTAL SCIENCES↗

Corrective Action Decision Document/Corrective Action Plan for Corrective Action Units 101 and 102: Central and Western Pahute Mesa Nevada National Security Site, Nevada, Revision 2

This revision was prepared to document changes to the data-collection activities. Specifically, the drilling and completion of the wells have been revised, and enhancements to the surface geophysics measurements have been included. Corrective action is needed because underground radioactive contamination exists in these areas resulting from historic underground nuclear testing. The PM CAUs are located in the northwestern portion of the Nevada National Security Site and comprise 82 corrective action sites. A total of 85 underground nuclear detonations took place within the area covered by the PM CAUs between 1965 and 1992 and resulted in the release of radionuclides in the subsurface in the vicinity of the test cavities.

54 ENVIRONMENTAL SCIENCES↗

Securing Solar for the Grid (S2G) (Final Project Report) [Slides]

This is the final technical report for the SETO-funded project Securing Solar for the Grid (S2G) from FY22-24. The project scope included development and dissemination of standards' requirements, best practices, equipment testing procedures, assessment tools, as well as education and training materials for cyber defense, posture and maturity tailored to solar technologies. The outcomes for this work include: co-led the development of cybersecurity certification standard (UL2941), co-led the development of cybersecurity guide (IEEE1547.3), development of recommendations for supply chain cybersecurity, and development of cybersecurity risk profiles and recommendations for DERMS.

14 SOLAR ENERGY↗

Closure Report for Corrective Action Unit 366: Area 11 Plutonium Valley Dispersion Sites, Nevada National Security Site, Nevada with ROTC 1

This Closure Report presents information supporting closure of Corrective Action Unit (CAU) 366, Area 11 Plutonium Valley Dispersion Sites, and provides documentation supporting the completed corrective actions and confirmation that closure objectives for CAU 366 were met. CAU 366 consists of the following six Corrective Action Sites (CASs), located in Area 11 of the Nevada National Security Site: • CAS 11-08-01, Contaminated Waste Dump #1 • CAS 11-08-02, Contaminated Waste Dump #2 • CAS 11-23-01, Radioactively Contaminated Area A • CAS 11-23-02, Radioactively Contaminated Area B • CAS 11-23-03, Radioactively Contaminated Area C • CAS 11-23-04, Radioactively Contaminated Area D

54 ENVIRONMENTAL SCIENCES↗

Calendar Year 2024 Underground Test Area Annual Sampling Letter Report, Nevada National Security Site, Nevada, Rev. 1

The Underground Test Area (UGTA) Sampling Plan for Corrective Action Units (CAUs) 101 and 102: Central and Western Pahute Mesa, Nevada National Security Site (NNSS), Nevada (referred to herein as “the Plan”) (DOE/EMNV, 2025) describes the approach for collecting and analyzing groundwater samples to meet the objectives of the U.S. Department of Energy (DOE), Environmental Management (EM) Nevada Program’s UGTA Activity. The Plan is designed to ensure compliance with the UGTA Quality Assurance Plan (QAP) (DOE/EMNV, 2024), and the Federal Facility Agreement and Consent Order (FFACO) (1996, as amended).

54 ENVIRONMENTAL SCIENCES↗

Submittal of The Final Calendar Year (Cy) 2025 Post-Closure Monitoring Letter Report, Nevada National Security Site, Nevada, Revision 1, April 2026

This letter serves as the annual post-closure letter for CAU 98, Frenchman Flat; CAU 97, Yucca Flat/Climax Mine; and CAU 99, Rainier Mesa/Shoshone Mountain for calendar year 2025. This letter will discuss the post-closure monitoring activities that occurred during CY 2025, identify any triggers reached, and summarize water usage on the Nevada National Security Site and surrounding hydrographic basins at the three CAUs.

54 ENVIRONMENTAL SCIENCES↗

Non-Resource Conservation and Recovery Act Corrective Action Unit (CAU) Post-Closure Inspection Report, Nevada National Security Site, Nevada For Calendar Year 2025

This report includes visual inspection results, descriptions of maintenance and repair activities, and recommendations for CY 2025 for use restrictions (URs) at corrective action sites (CASs) located on the Nevada National Security Site and on the Nevada Test and Training Range (NTTR) that are accessed through the NNSS Main Gate. This document is arranged by project activity (i.e., Industrial Sites, Soils, and Defense Threat Reduction Agency [DTRA]); then by corrective action unit (CAU); and then by CAS. Post-closure UR inspections are performed on an annual basis, unless as noted in text. Post-closure UR inspections verify the condition of physical controls required by each UR, which may include the following activities: • Visual verification of the legibility of signs • Visual inspection of fencing, signs, monuments, and/or markers for indications of wear • Visual inspection of soil covers for indications of subsidence, erosion, or unauthorized use Deficiencies in UR requirements that were identified during CY 2024 inspections and not addressed in the CY 2024 report are addressed in this CY 2025 report.

54 ENVIRONMENTAL SCIENCES↗

Deny-by-Default Network Port Security: SPaRC Technical Bulletin #002

Operational Technology (OT) networks [e.g., industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems] have unique cyber security challenges due to their decades long service life, high availability requirements, and limited visibility. OT networks often take credit for being “air gapped” (i.e. disconnected from the Internet) and all devices within the OT network can “talk” to each other—even if they should not. This SPaRC Technical Bulletin describes how the unique limitations of OT networks can become strengths when it comes to cybersecurity.

Cybersecurity↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Model checking for software security properties

This paper describes the use of the Flexible Modeling Framework (FMF) for model checking (MC) to perform and search for vulnerabilities in the Secure Socket Layer (SSL) communication protocol.

model checking formal methods software security↗

Summary report on the enterprise security workshop

This report summarizes the presentations of the 7th IEEE Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE 2002) Enterprise Security (ES) Workshop.

software security cryptography authentication acce↗