Model checking for software security properties
This paper describes the use of the Flexible Modeling Framework (FMF) for model checking (MC) to perform and search for vulnerabilities in the Secure Socket Layer (SSL) communication protocol.
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
This paper describes the use of the Flexible Modeling Framework (FMF) for model checking (MC) to perform and search for vulnerabilities in the Secure Socket Layer (SSL) communication protocol.
This report summarizes the presentations of the 7th IEEE Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE 2002) Enterprise Security (ES) Workshop.
Part Two expands upon Part One in an attempt to translate the methodology for ground system personnel. The goal is to build upon the methodology presented in Part One by showing examples and details on how to implement the methodology. Section 1: Ground Systems Overview; Section 2: Secure Software Development; Section 3: Defense in Depth for Ground Systems; Section 4: What Now?
The United States government has identified that application specific integrated circuit (ASIC) and field programmable gate array (FPGA) hardware are at risk from a variety of adversary attacks. This finding affects system security and trust. Consequently, processes are being developed for system mitigation and countermeasure application. The scope of this tutorial pertains to potential vulnerabilities and countermeasures within the ASIC/FPGA design cycle. The presentation demonstrates how design practices can affect the risk for the adversary to: change circuitry, steal intellectual property, and listen to data operations. An important portion of the design cycle is assuring the design is working as specified or as expected. This is accomplished by exhaustive testing of the target design. Alternatively, it has been shown that well established schemes for test coverage enhancement (design-for-verification (DFV) and design-for-test (DFT)) can create conduits for adversary accessibility. As a result, it is essential to perform a trade between robust test coverage versus reliable design implementation. The goal of this tutorial is to explain the evolution of design practices; review adversary accessibility points due to DFV and DFT circuitry insertion (back door circuitry); and to describe common engineering trade-off considerations for test versus adversary threats.
Global food production depends upon many factors that Earth observing satellites routinely measure about water, energy, weather, and ecosystems. Increasingly sophisticated, publicly-available satellite data products can improve efficiencies in resource management and provide earlier indication of environmental disruption. Satellite remote sensing provides a consistent, long-term record that can be used effectively to detect large-scale features over time, such as a developing drought. Accuracy and capabilities have increased along with the range of Earth observations and derived products that can support food security decisions with actionable information. This paper highlights major capabilities facilitated by satellite observations and physical models that have been developed and validated using remotely-sensed observations. Although we primarily focus on variables relevant to agriculture, we also include a brief description of the growing use of Earth observations in support of aquaculture and fisheries.
During the Summer 2020 session, I worked with intern Destani S. Van Arsdalen of EGS Software. Together, we co-created a tool to aid the dynamic investigation, updated over time,of the security compliance of LCS COTS and open source software. We originally planned touse spreadsheet software for management and analysis, but through this exploratoryproject, chose to use Python and JSON after receiving feedback on our project’s current anddesired capabilities at that time.At first, the project was solely designed to help on-board new COTS software, based on aquestionnaire that could be filled out for each software package. This, combined with usingthe spreadsheet application’s web-query capabilities to fetch information from the NVD,allowed presentation and analytics cells to automatically populate as elements of themanually-filled questionnaire changed. While this system was promising, we decided tochange technologies for a few reasons. In the spreadsheet, single cells could not hold complexdata like arrays and objects. The automatic population of cells and dynamic updates made itdifficult to manage and add new features. And finally, it had limited extensibility sinceadding new software required significant understanding of how both the spreadsheet wasconstructed, and the more obscure, proprietary scripting languages packaged with it.The pivot to a standard computer science database language of JSON, aided by thescripting capabilities of Python, greatly helped to improve the project’s functionality. First,and most importantly, the script’s import and analysis of database data is easilyreproducible. Additional data analysis can be modularly added without requiringmodification of the script and is capable of routine scheduling. The revised process can besplit into three parts. First, the conversion of LCS asset and software documentation into theJSON hierarchical database format. Second, the merging of this database with the NVD,forming a new data structure, using CPEs of the CVE object as a linking element betweenthem. And third, the automatically performed analytics and analysis of the combined data,in a modular and extensible format, to produce better informed business decisions. The outputted graphs, for example, are automatically generated by the Python script inconnection with the combined database. This allows updated graphs and any analytics to be re-rendered automatically following updates to the LCS’s initial asset documentation. Afinal report can then be programmatically and easily constructed from these sources to allow fully reproducible metrics for heavily evidenced risk management decisions.
Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.
• An Intersection of Challenges for Food Security • The Agricultural Model Intercomparison and Improvement Project (AgMIP) • Establishing and evaluating agricultural models • Responding to the transient signal of climate change • Understanding food systems and identifying potential for unexpected behaviors • Opportunities For a More Resilient Future
The capture and curation of all primary instrument data is a potentially valuable source of added insight into experiments or diagnostics in laboratory experiments. The data can, when properly curated, enable analysis beyond the current practice that uses just a subset of the as-measured data. Complete curated data can also be input for machine learning and other data exploration tools. Conveniently storing and accessing instrument data requires that the instruments are connected to databases and users through a networking infrastructure. This infrastructure needs to accommodate a wide array of instruments which can range from single laboratory mounted probes for environment monitoring to computers managing multiple instruments. These resources may also include mobile devices on which researchers record instrument and experiment state related notes. These varied data sources bring with them the challenges of different communications capabilities and protocols as well as the primary data typically being produced in proprietary formats. These challenges are further compounded when the instruments need to operate in secure environments such as required in national laboratories. We will discuss the SmartLab, an ongoing effort to set up a system for instrument and simulation data curation at NASA Langley Research Center. We will outline the challenges faced in managing the data sources required for ongoing research activities and the solutions that are being considered and implemented to address those challenges.
Quantifying Risk Reduction Achieved by OT Security Controls
This Nevada National Security Site Environmental Report (NNSSER) summarizes actions taken in 2024 to protect the environment and the public while achieving the NNSA/NFO mission goals. It is prepared for the public and our stakeholders in hopes that it is readily understandable and usable. It is a key component in our efforts to keep the public informed of environmental conditions at the NNSS and its support facilities in Las Vegas, Nevada.
This Nevada National Security Site Environmental Report (NNSSER) summarizes actions taken in 2024 to protect the environment and the public while achieving the NNSA/NFO mission goals. It is prepared for the public and our stakeholders in hopes that it is readily understandable and usable. It is a key component in our efforts to keep the public informed of environmental conditions at the NNSS and its support facilities in Las Vegas, Nevada. This supplemental Summary report provides an abbreviated version of the full report.
The Transportation Secure Data Center is a centralized repository for detailed transportation data from travel and transit surveys and studies conducted across the nation. It makes vital transportation data broadly available to users while preserving the privacy of survey participants. Hundreds of datasets from surveys and studies of household travel and transit passenger travel are archived in the TSDC, including surveys and studies conducted by state departments of transportation, metropolitan planning organizations, transit agencies, cities, and other public agencies. Detailed data from travel surveys and studies are extremely valuable for research purposes. However, the fine-grained information they contain could potentially be misused to identify individual travelers, so access to these data should only be granted with safeguards in place to protect participant privacy. The TSDC was created to address this challenge and to relieve public agencies from the burden of archiving their data and responding to data requests.
A method of adding physical layer security to a class of spread spectrum systems has been recently proposed. In this paper, we look into the rate at which an eavesdropper may gain information about the system to decipher the data symbols. The Shannon mutual information is used to measure the rate of information that may be gained by an eavesdropper. The k-nearest neighbors (k-NN) method is used to obtain estimates of relevant entropy values, which will then be used to quantify the rate of information recovery as more data is transmitted. It turns out that such information recovery requires the adoption of special methods that avoid any destructive bias in the estimates. Details of these methods are also presented.
Explore the source record for details and available documents.
We investigate the link between quantum position-verification (QPV) and holography established in [1] using holographic quantum error correcting codes as toy models. By inserting the “temporal” scaling of the AdS metric by hand via the bulk Hamiltonian interaction strength, we recover a toy model with consistent causality structure. This leads to an interesting implication between two topics in quantum information: if position-based verification is secure against attacks with small entanglement then there are new fundamental lower bounds for resources required for one Hamiltonian to simulate another.
Drought is a major driver of crop production loss, threatening global food security as the population rises toward 9 billion by 2050. Using a process-based crop model within an Earth system model, we assess drought-related impacts on maize, soybean, rice, and wheat production at global and country levels. We then develop a food insecurity index combining drought impacts with socio-economic factors. Our results indicate that by 2050, globally averaged drought losses for combined maize, soybean, rice, and wheat production are <2%, though soybean losses reach 3.6%. Despite these small average changes at the global scale, 62 countries experience maximum production losses over 10%, and 24 countries over 20%. Our index identifies regions at greatest risk, including large parts of South America, Africa, Eastern Europe, and Southeast Asia. These results illustrate the need for drought adaptation to mitigate future drought impacts on crop production.
As Industry 4.0 advances, the integration of computer numerical control (CNC) machines and advanced manufacturing technologies is transforming production into smart manufacturing systems that blend physical and digital processes as cyber-physical systems. However, this increased cyber-physical connectivity exposes manufacturing systems to cyber threats that can cause severe operational and financial disruptions. This paper presents a comparative study on cyber attacks and anomaly detection techniques in manufacturing, focusing on network traffic from CNC machines. The data extracted from network packets includes machine commands and control signals exchanged between the machine's interface and control system, crucial for maintaining operational integrity. We explore two types of cyber attacks, design modification and command injection, which pose substantial risks to CNC machine productivity and system integrity. Our investigation involves experiments on a real CNC system, highlighting the urgent need for effective detection mechanisms. To address these threats, we evaluate three anomaly detection methods: dynamic time warping (DTW), rolling average, and a deep learning, long short-term memory (LSTM) time-series-based autoencoder. Each is assessed for its effectiveness in identifying anomalous behaviors caused by the attacks. Our findings demonstrate the unique strengths and limitations of each detection technique, providing a deeper understanding of their applicability in realworld manufacturing environments. The comparative analysis indicates that while certain methods are highly effective against specific attack types, others offer broader applicability across different attacks. This study contributes to the accurate detection of anomalies in CNC machining processes, thereby enhancing the reliability and security of smart manufacturing systems against diverse cyber threats.