Search NASA⌕ Search

SEARCH · Search NASA

Results for “consequence management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 361 records · Page 20

Risk of Performance and Behavioral Health Decrements Due to Inadequate Cooperation, Coordination, Communication, and Psychosocial Adaptation within a Team

A team is defined as: "two or more individuals who interact socially and adaptively, have shared or common goals, and hold meaningful task interdependences; it is hierarchically structured and has a limited life span; in it expertise and roles are distributed; and it is embedded within an organization/environmental context that influences and is influenced by ongoing processes and performance outcomes" (Salas, Stagl, Burke, & Goodwin, 2007, p. 189). From the NASA perspective, a team is commonly understood to be a collection of individuals that is assigned to support and achieve a particular mission. Thus, depending on context, this definition can encompass both the spaceflight crew and the individuals and teams in the larger multi-team system who are assigned to support that crew during a mission. The Team Risk outcomes of interest are predominantly performance related, with a secondary emphasis on long-term health; this is somewhat unique in the NASA HRP in that most Risk areas are medically related and primarily focused on long-term health consequences. In many operational environments (e.g., aviation), performance is assessed as the avoidance of errors. However, the research on performance errors is ambiguous. It implies that actions may be dichotomized into "correct" or "incorrect" responses, where incorrect responses or errors are always undesirable. Researchers have argued that this dichotomy is a harmful oversimplification, and it would be more productive to focus on the variability of human performance and how organizations can manage that variability (Hollnagel, Woods, & Leveson, 2006) (Category III1). Two problems occur when focusing on performance errors: 1) the errors are infrequent and, therefore, difficult to observe and record; and 2) the errors do not directly correspond to failure. Research reveals that humans are fairly adept at correcting or compensating for performance errors before such errors result in recognizable or recordable failures. Astronauts are notably adept high performers. Most failures are recorded only when multiple, small errors occur and humans are unable to recognize and correct or compensate for these errors in time to prevent a failure (Dismukes, Berman, Loukopoulos, 2007) (Category III). More commonly, observers record variability in levels of performance. Some teams commit no observable errors but fail to achieve performance objectives or perform only adequately, while other teams commit some errors but perform spectacularly. Successful performance, therefore, cannot be viewed as simply the absence of errors or the avoidance of failure Johnson Space Center (JSC) Joint Leadership Team, 2008). While failure is commonly attributed to making a major error, focusing solely on the elimination of error(s) does not significantly reduce the risk of failure. Failure may also occur when performance is simply insufficient or an effort is incapable of adjusting sufficiently to a contextual change (e.g., changing levels of autonomy).

Landon, Lauren Blackwell↗

Scale effects on core design, fuel costs, and spent fuel volume of pressurized water reactors

The desire to improve the economic competitiveness and deployment pace of nuclear energy through modularization, manufacturing, and series production had led to the development of smaller size reactors. As the standard 17x17 fuel technology is mainly maintained in the pressurized water reactors (PWRs) category, this translates into a lower number of fuel assemblies in the core and sometimes a reduced fuel height. To assess the impact of such scale change in core design on fuel cycle cost and spent fuel volume, a scoping analysis tool is developed based on infinite lattice calculations, leakage, fuel management reduced models, and levelized unit cost of electricity (LCOE) estimate. As such, cost dynamics driven by fuel specific power, burnup, core leakage, feed, cycle length, fuel assembly height as well as uranium market data are captured with consistent set of assumptions and analysis methods. A selection of 5 reactor designs representative of leading PWR developers is assessed and compared. Pursuing higher specific powers and optimal burnups are highlighted as the main fuel cost reduction drivers, nevertheless, practical limitations and opportunities must be evaluated to establish the feasibility of such enhanced fuel operation. In consequence, a detailed core design is performed using SIMULATE3 code for 5 PWR variations including natural and forced coolant circulation modes, two reactor scales, power densities of 73, 112, and 123 kW/l and higher discharge burnups. Design and optimization are performed at the lattice level, for the reflector, and at the core loading level. Satisfactory steady-state operation including power distribution, coolant operating limits, and reactivity requirements are analyzed and reported in this paper. The fuel economics of the detailed core designs confirm the scoping analysis findings. Despite the unlocked power uprates in small PWRs, the achievable burnup for a given fuel specific power requires more enrichment and shorter fuel height results in higher fabrication costs per mass of fuel, which makes scaling down core size a more expensive endeavor on the fuel cycle front. Spent fuel volumes are reported for the PWRs designed in this paper. Furthermore, these volumes are driven by the core average discharge burnup regardless of the scale in consideration. Additional cost and core performance aspects related to heavy reflector gains, fuel-reflector substitution, and disposal cost policy in the U.S. are examined.

42 ENGINEERING↗

Model-based Hierarchical Reinforcement Learning for Improved Physical Security Design: A Prototype

Prior work in FY24 developed an adversarial AI agent aid in path analysis of physical protection systems. This agent, trained using a model-based reinforcement learning algorithm, was able to successfully learn the most vulnerable path in facilities. It was able to extend the current state of practice for physical protection design by exhibiting dynamic behavior based on current environmental conditions. Whereas PathTrace largely performs a static, graph-based analysis, the AI agent was able to make decisions based on relative position in the facility, current conditions (was the adversarial agnet discovered?), and proximity to secondary targets. The agent demonstrated some novel capabilities, but had limitations that need to be resolved before it can be used for production purposes. For example, the adversarial agent generalizes poorly and takes a relatively long time to train. Nonetheless, there is still considerable promise for developing the adversarial agent further in order to explore even richer, more dynamic behaviors (e.g., adversary motivations, environmental debris, and more). This work considers a complementary idea; development of a planning agent. The planning agent is envisioned as an auto-complete-like tool that can help accelerate security system design by human experts. The agent would respect existing barriers and sensors placed by a human expert while offering cost-effective suggestions (i.e., implicitly balancing effectiveness with cost) to improve the design. The goal is for this agent to be part of an expert’s toolbox, not to totally upend the current state-of-practice, or to displace human experts. The ultimate goal would be concurrent training of both the adversarial and planning agent together, to learn entirely through self-play. This would represent an entirely new way of performing system deign. We selected a hierarchical, model-based reinforcement learning algorithm to serve as the planning agent. This is an extension of concepts used in the prior FY24 adversarial agent work. There, we had a single agent acting an environment. Here, we have two different sub-agents (policies), working together, to form a complete agent. There is a manager policy, which can select abstract goals on slower time scales, and a worker, which performs primitive actions to reach goals selected by the manager. It is worth noting that this class of algorithm is challenging to work with. From our understanding, our work is one of the first successful uses of model-based reinforcement learning (MBRL) in nuclear energy1 , and likely the first hierarchical model-based reinforcement learning application in nuclear energy. Further, this work is one of the first known attempts to apply AI to perform a design tasks in nuclear energy. Consequently, there were significant implementation challenges and the bulk of the work was focused on successful implementation and algorithm design. The results presented here are very low technology readiness level as a consequence of the lack of related literature, but still represent a significant step forward in the pursuit of applied AI for design.

42 ENGINEERING↗

Automated Platform Management System Scheduling

The Platform Management System was established to coordinate the operation of platform systems and instruments. The management functions are split between ground and space components. Since platforms are to be out of contact with the ground more than the manned base, the on-board functions are required to be more autonomous than those of the manned base. Under this concept, automated replanning and rescheduling, including on-board real-time schedule maintenance and schedule repair, are required to effectively and efficiently meet Space Station Freedom mission goals. In a FY88 study, we developed several promising alternatives for automated platform planning and scheduling. We recommended both a specific alternative and a phased approach to automated platform resource scheduling. Our recommended alternative was based upon use of exactly the same scheduling engine in both ground and space components of the platform management system. Our phased approach recommendation was based upon evolutionary development of the platform. In the past year, we developed platform scheduler requirements and implemented a rapid prototype of a baseline platform scheduler. Presently we are rehosting this platform scheduler rapid prototype and integrating the scheduler prototype into two Goddard Space Flight Center testbeds, as the ground scheduler in the Scheduling Concepts, Architectures, and Networks Testbed and as the on-board scheduler in the Platform Management System Testbed. Using these testbeds, we will investigate rescheduling issues, evaluate operational performance and enhance the platform scheduler prototype to demonstrate our evolutionary approach to automated platform scheduling. The work described in this paper was performed prior to Space Station Freedom rephasing, transfer of platform responsibility to Code E, and other recently discussed changes. We neither speculate on these changes nor attempt to predict the impact of the final decisions. As a consequence some of our work and results may be outdated when this paper is published.

Hull, Larry G.↗

Timing the Flames: Geostationary Satellite Detection of Diurnally Shifting Stubble Burning in Northwestern India

Post-monsoon open-field stubble burning in northwestern (NW) India—a key agricultural region known as the “breadbasket”—is a longstanding practice used to clear fields. Satellite observations spanning over two decades have revealed significant upward trends in crop production, vegetative greenness, and the frequency of post-harvest fires, with this last contributing to hazardous air quality during the peak burning season (mid-October to mid-November). Since 2022, thermal anomaly data from Aqua-MODIS and SNPP-VIIRS sensors have shown a sharp decline in reported fire events—an observation that contrasts starkly with the concurrent rise in regional aerosol loading detected from space. This apparent discrepancy became particularly pronounced in 2024–2025, prompting a closer examination using high-temporal-resolution imagery from the Advanced Meteorological Imager (AMI) on the geostationary satellite GEO-KOMPSAT-2A. These observations revealed a clear spike in fire-related signals occurring around and after 4:00 p.m. local time, i.e., outside the typical noon to 2:00 p.m. detection window of the MODIS and VIIRS. A fire detection algorithm exploiting the fire-sensitive shortwave-infrared 3.8 μm signal and its contrast to 11.2 μm infrared observations is designed to adopt AMI observations and applied to its multi-year observations (2019–2025). The resulting fire dataset unambiguously shows a gradual shift in stubble burning activity toward the late afternoon hours beginning in 2022 which is underreported by polar-orbiting satellites. The orbital drift of NASA’s MODIS sensor on the Aqua platform allows detection of some of the gradually shifting fires during afternoon hours, but the MODIS still misses a large number of fires occurring around and after 4 p.m. The AMI’s relatively coarse spatial resolution (~4 km), a consequence of its slant viewing geometry over NW India, imposes inherent limitations on quantifying the full extent of fire occurrences. The operational air quality forecasting models currently assimilate satellite fire detections predominantly captured during early afternoon overpasses of the MODIS and VIIRS. The temporal shift in fire activity complicates such forecast, leading to a substantial underestimation of emissions. Intense stubble burning and the resulting air pollution highlight the need for effective crop residue management practices for mitigating the frequency of open biomass burning and thereby reducing episodic degradation of air quality and its associated public health and economic impacts.

post-monsoon stubble burning; northwestern India;↗

Polyphenol rewiring of the microbiome reduces methane emissions

Methane mitigation is regarded as a critical strategy to combat the scale of global warming. Currently, ~40% of methane emissions originate from microbial sources, which is causing strategies to suppress methanogens—either through direct toxic effects or by diverting their substrates and energy—to gain traction. Problematically, current microbial methane mitigation knowledge lacks detailed microbiome-centered insights, limiting translation across conditions and ecosystems. Here we utilize genome-resolved metatranscriptomes and metabolomes to assess the impact of a proposed methane inhibitor, catechin, on greenhouse gas emissions for high-methane-emitting peatlands. In microcosms, catechin drastically reduced methane emissions by 72%–84% compared to controls. Longitudinal sampling allowed for reconstruction of a catechin degradation pathway involving Actinomycetota and Clostridium, which break down catechin into smaller phenolic compounds within the first 21 days, followed by degradation of phenolic compounds by Pseudomonas_E from Days 21 to 35. These genomes co-expressed hydrogen-uptake genes, suggesting hydrogenases may act as a hydrogen sink during catechin degradation and consequently reduce hydrogen availability to methanogens. In support of this idea, there was decreased gene expression by hydrogenotrophic and hydrogen-dependent methylotrophic methanogens under catechin treatment. There was also reduced gene expression from genomes inferred to be functioning syntrophically with hydrogen-utilizing methanogens. We propose that catechin metabolic redirection effectively starves hydrogen-utilizing methanogens, offering a potent avenue for curbing methane emissions across diverse environments including ruminants, landfills, and constructed or managed wetlands.

54 ENVIRONMENTAL SCIENCES↗

MACCS User Guide - Version 5.2

MACCS is used by the Nuclear Regulatory Commission (NRC) and various national and international organizations for probabilistic consequence analysis of nuclear power accidents. This user guide is intended to assist analysts in understanding the MACCS/MACCS-UI User Interface (UI) model and to provide information regarding the code. This user guide version describes MACCS Version 5.2, model history, explains how to set up and execute a problem, and informs the user of the definition of various input parameters and any constraints placed on those parameters. This report is part of a series of reports documenting MACCS. Other reports include the MACCS Theory Manual, MACCS Verification Report, Technical Bases for Consequence Analyses Using MACCS, as well as documentation for preprocessor codes including SecPop, MelMACCS, and COMIDA2.

54 ENVIRONMENTAL SCIENCES↗

Risk Balance: A Key Tool for Mission Operations Assurance

The Mission Operations Assurance (MOA) discipline actively participates as a project member to achieve their common objective of full mission success while also providing an independent risk assessment to the Project Manager and Office of Safety and Mission Success staff. The cornerstone element of MOA is the independent assessment of the risks the project faces in executing its mission. Especially as the project approaches critical mission events, it becomes imperative to clearly identify and assess the risks the project faces. Quite often there are competing options for the project to select from in deciding how to execute the event. An example includes choices between proven but aging hardware components and unused but unproven components. Timing of the event with respect to visual or telecommunications visibility can be a consideration in the case of Earth reentry or hazardous maneuver events. It is in such situations that MOA is called upon for a risk balance assessment or risk trade study to support their recommendation to the Project Manager for a specific option to select. In the following paragraphs we consider two such assessments, one for the Stardust capsule Earth return and the other for the choice of telecommunications system configuration for the EPOXI flyby of the comet Hartley 2. We discuss the development of the trade space for each project's scenario and characterize the risks of each possible option. The risk characterization we consider includes a determination of the severity or consequence of each risk if realized and the likelihood of its occurrence. We then examine the assessment process to arrive at a MOA recommendation. Finally we review each flight project's decision process and the outcome of their decisions.

operations↗

An Approach for Uncertainty Quantification and Management of Unmanned Aerial Vehicle Health

The increasing interest in low-altitude unmanned aerial vehicle (UAV) operations is bringing along safety concerns. Performance of small, low-cost UAVs drastically changes with type, size and controller of the vehicle. Their reliability is lower when compared to reliability of commercial aircrafts, and the availability of on-board sensors for health and state awareness is extremely limited due to their size and propulsion capabilities. Uncertainty plays a dominant role in such a scenario, where a variety of UAVs of different size, propulsion systems, dynamic performance and reliability enters the low-altitude airspace. Unexpected failures could have dangerous consequences for both equipment and humans within that same airspace. As a result, a number of research works and methodologies are being proposed in the area of UAV dynamic modeling, health and safety monitoring, but uncertainty quantification is rarely addressed. Thus, this paper pro- poses a perspective towards uncertainty quantification for autonomous systems, giving special emphasis to a UAV health monitoring application. A formal approach to classify uncertainty is presented; it is utilized to identify the uncertainty sources in UAVs health and operations, and then map uncertainty within a predictive process. To show the application of the methodology proposed here, the design of a model-based powertrain health monitoring algorithm for small-size UAVs is used as case study. The example illustrates how the uncertainty quantification approach can help the modeling strategy, as well as the assessment of diagnostic and prognostic performance.

Health Monitoring↗

National Energy Water Treatment & Speciation (NEWTS): A Water & Critical Mineral Database and Dashboard

The scarcity of water resources, the need for beneficial water reuse, and the challenges of wastewater treatment are becoming increasingly pressing in economic, social, and environmental domains. Addressing these concerns requires effective treatment strategies to manage wastewater streams and tackle environmental and economic issues. Furthermore, the recovery of critical minerals from the waste streams associated with energy production holds the promise of offsetting treatment costs and securing local sources of valuable minerals. However, relevant data on these waste streams are dispersed and challenging to locate. The process of ingesting such data into modeling software often involves multiple steps, requiring data restructuring to meet software-input requirements. The non-standardized reporting of water data makes data aggregation and reformatting a time-consuming process. Additionally, essential attributes necessary for modeling water treatment and mineral scale formation are frequently missing. Moreover, data gaps vary depending on the region of interest. Consequently, there is a pressing need for high-quality energy-water composition data that can be easily imported into water chemistry modeling software. To address this need, the National Energy Technology Laboratory has created the National Energy Water Treatment and Speciation (NEWTS) Database and Dashboard—a free online tool catering to community leaders and water researchers. NEWTS facilitates a comprehensive understanding of the composition of energy-related wastewater streams in the United States. The datasets provide detailed concentrations and speciation of major and minor aqueous compounds in energy-related wastewater streams, including power plant leachate, acid mine drainage, brackish water, and oil and gas produced water across the United States. Many of the aqueous species are critical minerals (Li, REEs) in high demand to modernize the world’s energy infrastructure. Many of the datasets also contain volumetric flow-rates needed to model the treatment and reuse scenarios in advanced aqueous chemistry software programs. The NEWTS Database and Dashboard offer public access to hitherto challenging-to-access datasets, presented in a standardized format that is tailored for easy input into aqueous chemistry modeling software. By performing the work needed to transform dispersed, disparate data sources into unified, model-ready datasets, NEWTS serves as an essential resource in advancing water treatment research and sustainable water resource management.

produced water management↗

ON THE LANGUAGE OF RELIABILITY: A SYSTEM ENGINEER PERSPECTIVE

In its classical definition, risk is defined by three elements: what can go wrong, what are its consequences and how likely is it to occur. While this definition makes sense in a regulatory based framework to estimate risk associated to power plants (in terms of core damage frequency and large early release frequency), this approach does not provide a useful snapshot of the health of the plant. A possible alternate path can start by redefining the word “risk” to a broader meaning that better reflects the needs of a system health and asset management decision making process. Rather than asking how likely an event can occur (in probabilistic terms), we can ask how far this event is from occurring. We will show how, given the data available from plant equipment reliability and monitoring/diagnostic/prognostic centers, a margin can be described and determined for all type of maintenance approaches (e.g., corrective or predictive maintenance). We will show how to link SSC margin-based reliability models to system reliability models (i.e., fault trees) in order to assess system/plant health and how to perform margin-based system calculations. These calculations are not solved using classical probabilistic calculations applied to sets (as performed by any PRA code) but, instead, through metric spaces operations (i.e., distance/margin based approach).

97 - MATHEMATICS AND COMPUTING↗

Simulation and Modeling Concepts for Secure Airspace Operations

This paper examines cyber security vulnerabilities of Urban Air Mobility operations. With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, and the cyber resiliency of the current and future air traffic management system.

Urban Air Mobility↗

Simulation and Modeling Concepts for Secure Airspace Operations

This paper examines cyber security vulnerabilities of Urban Air Mobility operations. With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, and the cyber resiliency of the current and future air traffic management system.

Urban Air Mobility↗

Concepts, requirements, and design approaches for building successful planning and scheduling systems

Traditional practice of systems engineering management assumes requirements can be precisely determined and unambiguously defined prior to system design and implementation; practice further assumes requirements are held static during implementation. Human-computer decision support systems for service planning and scheduling applications do not conform well to these assumptions. Adaptation to the traditional practice of systems engineering management are required. Basic technology exists to support these adaptations. Additional innovations must be encouraged and nutured. Continued partnership between the programmatic and technical perspective assures proper balance of the impossible with the possible. Past problems have the following origins: not recognizing the unusual and perverse nature of the requirements for planning and scheduling; not recognizing the best starting point assumptions for the design; not understanding the type of system that being built; and not understanding the design consequences of the operations concept selected.

Hornstein, Rhoda Shaller↗

The Pathway to a Safe and Effective Spaceflight Medication Formulary: Expert Review Panel Recommendations

Exploration spaceflight poses several challenges to the provision of a comprehensive medication formulary. This formulary must accommodate the size and space limitations of the spacecraft, while addressing individual medication needs and preferences of the crew, consequences of a degrading inventory over time, the inability to resupply used or expired medications, and the need to forecast the best possible medication candidates to treat conditions that may occur. The Exploration Medical Capability (ExMC) Element's Pharmacy Project Team has developed a research plan (RP) that is focused on evidence-based models and theories as well as new diagnostic tools, treatments, or preventive measures aimed to ensure an available, safe, and effective pharmacy sufficient to manage potential medical threats during exploration spaceflight. Here, we will discuss the ways in which the ExMC Pharmacy Project Team pursued expert evaluation and guidance, and incorporated acquired insight into an achievable research pathway, reflected in the revised RP.

Daniels, V. R.↗

Neural mechanisms of kinesthesia

Our primary interest is in where the signals for position and movement of the limbs originate and how the information is encoded. Humans can independently sense the positions and movements of their limbs in the absence of vision, and their senses are derived from mechanoreceptors located in the limbs. Receptors in muscles, skin and joints are potential sources of position and movement signals, but how (and whether) each of these groups contributes to kinesthesia remains uncertain. Recent evidence indicates that a sense of static-position derives from length receptors in muscle, whereas receptors in the skin, and possibly though not likely the joints, can signal movement of a limb but not its static position. At present, we are examining the consequences of not having a static-position sense at the fingers apart from an inability to detect very slow displacements. Using a more demanding test, we have found no substantial difference in the accuracy of reproducing target positions passively imposed on the MCP joint and the proximal interphalangeal (PIP) joint of the index finger. Our working hypothesis is that subjects normally use movement sense mechanisms to detect displacements, probably because they are faster, but how (or whether) subjects manage to obtain an absolute position reference with only a movement sense available remains unknown and is an issue under investigation.

Clark, Francis J.↗

Application of MODIS Products to Infer Possible Relationships Between Basin Land Cover and Coastal Waters Turbidity Using the Magdalena River, Colombia, as a Case Study

Basin development and consequent change in basin land cover have been often associated with an increased turbidity in coastal waters because of sediment yield and nutrients loading. The later leads to phytoplankton abundance further exacerbating water turbidity. This subsequently affects biological and physical processes in coastal estuaries by interfering with sun light penetration to coral reefs and sea grass, and even affecting public health. Therefore, consistent estimation of land cover changes and turbidity trend lines is crucial to design environmental and restoration management plans, to predict fate of possible pollutants, and to estimate sedimentary fluxes into the ocean. Ground solely methods to estimate land cover change would be unpractical and traditional methods of monitoring in situ water turbidity can be very expensive and time consuming. Accurate monitoring on the status and trends of basin land cover as well as the water quality of the receiving water bodies are required for analysis of relationships between the two variables. Use of remote sensing (RS) technology provides a great benefit for both fields of study, facilitating monitoring of changes in a timely and cost effective manner and covering wide areas with long term measurements. In this study, the Magdalena River basin and fixed geographical locations in the estuarine waters of its delta are used as a case to study the temporal trend lines of both, land cover change and the reflectance of the water turbidity using satellite technology. Land cover data from a combined product between sensors Terra and Aqua (MCD12Q1) from MODIS will be adapted to the conditions in the Magdalena basin to estimate changes in land cover since year 2000 to 2009. Surface reflectance data from a MODIS, Terra (MOD09GQ), band 1, will be used in lieu of in situ water turbidity for the time period between 2000 and present. Results will be compared with available existing data.

Madrinan, Max Jacobo Moreno↗

Cyber-Threat Assessment for the Air Traffic Management System: A Network Controls Approach

Air transportation networks are being disrupted with increasing frequency by failures in their cyber- (computing, communication, control) systems. Whether these cyber- failures arise due to deliberate attacks or incidental errors, they can have far-reaching impact on the performance of the air traffic control and management systems. For instance, a computer failure in the Washington DC Air Route Traffic Control Center (ZDC) on August 15, 2015, caused nearly complete closure of the Centers airspace for several hours. This closure had a propagative impact across the United States National Airspace System, causing changed congestion patterns and requiring placement of a suite of traffic management initiatives to address the capacity reduction and congestion. A snapshot of traffic on that day clearly shows the closure of the ZDC airspace and the resulting congestion at its boundary, which required augmented traffic management at multiple locations. Cyber- events also have important ramifications for private stakeholders, particularly the airlines. During the last few months, computer-system issues have caused several airlines fleets to be grounded for significant periods of time: these include United Airlines (twice), LOT Polish Airlines, and American Airlines. Delays and regional stoppages due to cyber- events are even more common, and may have myriad causes (e.g., failure of the Department of Homeland Security systems needed for security check of passengers, see [3]). The growing frequency of cyber- disruptions in the air transportation system reflects a much broader trend in the modern society: cyber- failures and threats are becoming increasingly pervasive, varied, and impactful. In consequence, an intense effort is underway to develop secure and resilient cyber- systems that can protect against, detect, and remove threats, see e.g. and its many citations. The outcomes of this wide effort on cyber- security are applicable to the air transportation infrastructure, and indeed security solutions are being implemented in the current system. While these security solutions are important, they only provide a piecemeal solution. Particular computers or communication channels are protected from particular attacks, without a holistic view of the air transportation infrastructure. On the other hand, the above-listed incidents highlight that a holistic approach is needed, for several reasons. First, the air transportation infrastructure is a large scale cyber-physical system with multiple stakeholders and diverse legacy assets. It is impractical to protect every cyber- asset from known and unknown disruptions, and instead a strategic view of security is needed. Second, disruptions to the cyber- system can incur complex propagative impacts across the air transportation network, including its physical and human assets. Also, these implications of cyber- events are exacerbated or modulated by other disruptions and operational specifics, e.g. severe weather, operator fatigue or error, etc. These characteristics motivate a holistic and strategic perspective on protecting the air transportation infrastructure from cyber- events. The analysis of cyber- threats to the air traffic system is also inextricably tied to the integration of new autonomy into the airspace. The replacement of human operators with cyber functions leaves the network open to new cyber threats, which must be modeled and managed. Paradoxically, the mitigation of cyber events in the airspace will also likely require additional autonomy, given the fast time scale and myriad pathways of cyber-attacks which must be managed. The assessment of new vulnerabilities upon integration of new autonomy is also a key motivation for a holistic perspective on cyber threats.

Complex Networks↗