Search NASA⌕ Search

SEARCH · Search NASA

Results for “Network Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 487 records · Page 27

Data Descriptor: A Land Data Assimilation System for Sub-Saharan Africa Food and Water Security Applications

Seasonal agricultural drought monitoring systems, which rely on satellite remote sensing and land surface models (LSMs), are important for disaster risk reduction and famine early warning. These systems require the best available weather inputs, as well as a long-term historical record to contextualize current observations. This article introduces the Famine Early Warning Systems Network (FEWS NET) Land Data Assimilation System (FLDAS), a custom instance of the NASA Land Information System (LIS) framework. The FLDAS is routinely used to produce multi-model and multi-forcing estimates of hydro-climate states and fluxes over semi-arid, food insecure regions of Africa. These modeled data and derived products, like soil moisture percentiles and water availability, were designed and are currently used to complement FEWSNETs operational remotely sensed rainfall, evapotranspiration, and vegetation observations. The 30+ years of monthly outputs from the FLDAS simulations are publicly available from the NASA Goddard Earth Science Data and Information Services Center (GES DISC) and recommended for use in hydroclimate studies, early warning applications, and by agro-meteorological scientists in Eastern, Southern, and Western Africa.

albedo↗

A Simple XML Producer-Consumer Protocol

There are many different projects from government, academia, and industry that provide services for delivering events in distributed environments. The problem with these event services is that they are not general enough to support all uses and they speak different protocols so that they cannot interoperate. We require such interoperability when we, for example, wish to analyze the performance of an application in a distributed environment. Such an analysis might require performance information from the application, computer systems, networks, and scientific instruments. In this work we propose and evaluate a standard XML-based protocol for the transmission of events in distributed systems. One recent trend in government and academic research is the development and deployment of computational grids. Computational grids are large-scale distributed systems that typically consist of high-performance compute, storage, and networking resources. Examples of such computational grids are the DOE Science Grid, the NASA Information Power Grid (IPG), and the NSF Partnerships for Advanced Computing Infrastructure (PACIs). The major effort to deploy these grids is in the area of developing the software services to allow users to execute applications on these large and diverse sets of resources. These services include security, execution of remote applications, managing remote data, access to information about resources and services, and so on. There are several toolkits for providing these services such as Globus, Legion, and Condor. As part of these efforts to develop computational grids, the Global Grid Forum is working to standardize the protocols and APIs used by various grid services. This standardization will allow interoperability between the client and server software of the toolkits that are providing the grid services. The goal of the Performance Working Group of the Grid Forum is to standardize protocols and representations related to the storage and distribution of performance data. These standard protocols and representations must support tasks such as profiling parallel applications, monitoring the status of computers and networks, and monitoring the performance of services provided by a computational grid. This paper describes a proposed protocol and data representation for the exchange of events in a distributed system. The protocol exchanges messages formatted in XML and it can be layered atop any low-level communication protocol such as TCP or UDP Further, we describe Java and C++ implementations of this protocol and discuss their performance. The next section will provide some further background information. Section 3 describes the main communication patterns of our protocol. Section 4 describes how we represent events and related information using XML. Section 5 describes our protocol and Section 6 discusses the performance of two implementations of the protocol. Finally, an appendix provides the XML Schema definition of our protocol and event information.

Smith, Warren↗

Securing Grid-interactive Efficient Buildings (GEB) through Cyber Defense and Resilient System (CYDRES)

The DOE CYDRES project is driven by the urgent need to address critical research gaps in the domain of cyber-physical security of smart buildings, including Grid-interactive Efficient Buildings (GEBs). CYDRES, a real-time advanced building resilient platform, aims to enhance the cyber-attack-immune capabilities of buildings through multi-layered prevention, detection, and adaptation mechanisms. CYDRES consists of five key modules: a multi-layer network analyzer, an Automatic Fault Detection, Diagnosis, and Prognosis (AFDDP) framework, an intelligent mode selector, a cyber-resilient control framework, and a situation awareness platform. The Network Analyzer employs a data-driven framework that includes a protocol state learning tool and a CRF (Conditional Random Field) command validator. In Hardware-In-the-Loop (HIL) testbeds, it achieved 100% detection accuracy with a false alarm rate of 3%, validating its efficacy in identifying selected cyber-attacks. The AFDDP framework leverages pattern matching, PCA (Principal Component Analysis)-based strategies, and a DBN (Dynamic Bayesian Network)-based fault diagnosis approach to pinpoint the causes of physical system abnormalities using Building Automation System (BAS) data. In HIL experiments, the AFDDP module attained a detection accuracy of over 95% with a false alarm rate below 7%. Additionally, the fault detector utilized machine learning (Random Forest) and deep learning (Multi-Layer Perceptron) methods with acoustic sensor data to achieve a 100% fault detection accuracy in Heating, Ventilation, and Air-Conditioning (HVAC) equipment. The Mode Selector offered real-time impact analysis, allowing immediate actions to protect BASs in the face of emerging threats. The cyber-resilient control framework included an adaptive Model Predictive Control (MPC) and a measurement compensator, reducing temperature violations by up to 94% and improving the total demand flexibility by up to 70% in HIL experiments. Such HIL experiments covered a cyber-attack case and a physical fault case, showcasing CYDRES’ efficiency in maintaining operational continuity during threats. The situation awareness platform in Grafana enhanced real-time threat detection and response visualization, augmenting the operational awareness for building operators. CYDRES demonstrated high technical effectiveness in various test scenarios, particularly in HIL environments. The project's phased development approach ensured efficient use of resources, highlighting its practical feasibility and readiness for commercialization. By enhancing the security and resilience of building operations, CYDRES represents a significant advance in mitigating risks associated with cyber-physical systems, thereby enhancing public confidence in the safety of modern building infrastructure. Future directions for the project include expanding testing protocols, refining AFDDP methodologies, exploring more comprehensive resilient control strategies, and testing in real commercial buildings.

42 ENGINEERING↗

A Grid Infrastructure for Supporting Space-based Science Operations

Emerging technologies for computational grid infrastructures have the potential for revolutionizing the way computers are used in all aspects of our lives. Computational grids are currently being implemented to provide a large-scale, dynamic, and secure research and engineering environments based on standards and next-generation reusable software, enabling greater science and engineering productivity through shared resources and distributed computing for less cost than traditional architectures. Combined with the emerging technologies of high-performance networks, grids provide researchers, scientists and engineers the first real opportunity for an effective distributed collaborative environment with access to resources such as computational and storage systems, instruments, and software tools and services for the most computationally challenging applications.

Bradford, Robert N.↗

HPC and Cloud Convergence Beyond Technical Boundaries: Strategies for Economic Sustainability, Standardization, and Data Accessibility

At the IEEE/ACM International Conference for High-Performance Computing, Networking, Storage, and Analysis (SC23), held in Denver, experts discussed the convergence of high-performance computing and cloud computing. Experts explored how this integration could address current scientific computing limitations, enhance computational capabilities, and foster global collaboration while focusing on economic, security, technical, and community challenges and opportunities.

97 MATHEMATICS AND COMPUTING↗

DER Translate

SAND2024-13723O This software translates and maps any .xlsx-based distributed energy resource (DER) device from the SunSpec certification registry (https://sunspec.org/certified-registry/) to a JSON-based DER models map. It is then read by DER monitoring tools for applications such as network intrusion detection and system health monitoring. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Fragkos, Georgios↗

Quantum Technologies for UAS (QTech)

Harness the power of quantum technologies to assure the availability of UAS communications against disruptions. Make use of quantum computing (e.g. quantum optimization) and quantum communication (e.g. quantum key distribution) to address the availability cybersecurity challenge. Our approach is three-fold: (1) Utilize quantum optimization algorithms to design robust network with routing redundancy that can respond adaptively to dynamically changing real-time environment and disruptions, (2) Utilize quantum optimization algorithms resource allocation for detection, localization, and tracking of mobile communication disruption agents, (3) Utilize quantum key distribution (QKD) to execute secure key sharing in high data rate optical communication and/or anti-jamming protocols for secure RF communication.

Quantum Computing↗

ENLIGHTEN: Electrical Network Line Inspection Guided by High-Speed Technology & Electromagnetic Navigation

Natural disasters are a major cause of power outages, primarily due to their damage to power line infrastructure. As a result, the current state of power maintenance, with a heavy reliance on manual labor, is in trouble. Its lack of speed and autonomy must be addressed to ensure power security for households and institutions worldwide. This innovative approach explores how High-Speed Unmanned Aerial Vehicle (HSUAV) technology can inspect power line infrastructure rapidly in response to natural disaster scenarios. The HSUAV technology will be accompanied by enhanced sensory equipment including light detection and ranging (LiDAR), thermal imaging, and electromagnetic field (EMF) navigation. It would also be supplemented by innovative forms of machine learning models and recharging systems to efficiently detect anomalies in power line infrastructure. The proposed system, ENLIGHTEN, can help restore power in affected communities after a devastating natural disaster, greatly improving relief efforts. In the future, ENLIGHTEN can be expanded beyond the United States and shared worldwide, effectively mitigating the consequences on a larger scale.

UAV systems, Power line management, Natural disast↗

Testbed and Experiments for Quantum-Conventional Networking

The realization of quantum networks requires the development of devices and methods unprecedented in conventional networks, and yet they critically depend on the latter for implementing foundational blocks and essential operations. We describe a testbed to support the development and testing of their functionality and performance by providing quantum and conventional data planes and devices, together with a secure conventional control plane. It incorporates a variety of entangled photon sources, qubit technologies, detector technologies, photonic components, and supporting conventional switches and workstations. It implements a novel fiber telescoping scheme that provides suites of connections using fiber spools and inground-aerial fiber loops. We briefly summarize a variety of experiments conducted over this testbed including: (i) flex-grid quantum connection experiments, (ii) quantum state and channel tomography, (iii) utilization of quantum key distribution keys to secure conventional encryption and firewall devices, (iv) comparative study of analytical capacity estimates and entanglement throughput, (v) deployed squeezing coexisting with conventional communications, and (iv) measurement of polarization time variation.

Rao, Nageswara [ORNL] (ORCID:0000000234085941)↗

Corridor Design and Analysis for UAM Operations

The Urban Air Mobility (UAM) concept is a part of Advanced Air Mobility (AAM), a joint initiative between the Federal Aviation Administration (FAA), NASA, and industry to develop an air transportation system that uses new electric (i.e., green) air vehicles in geographical areas previously underserved by traditional aviation. Market forecast studies predict that there will be demand for alternate modes of air transportation using electric Vertical Take-off and Landing aircraft. UAM expands transportation networks by introducing short flights to move people and goods around metropolitan areas​. UAM is expected to improve mobility for the public, decongest road traffic, reduce trip time, and decrease strain on existing public transportation networks. Various challenges exist to make the introduction of UAM operations successful in the U.S. National Airspace System (NAS). These include but are not limited to integration with existing airports and airspace, provision of air traffic services (e.g., separation), vehicle design and certification, and community acceptance. The focus of this paper is on integration of UAM operations into the NAS via introduction of new airspace structures. UAM will operate within a regulatory, operational, and technical environment that is incorporated into the NAS​. As per the UAM Concept of Operations (ConOps), the FAA retains regulatory authority and is responsible for establishing operational parameters and maintaining oversight. The FAA’s UAM ConOps describes flights at low altitudes (below 5,000 ft) with minimal disruption to established conventional aircraft traffic and limited voice interactions with the Air Traffic Control (ATC). Early stages of UAM may use existing procedures to safely integrate UAM with conventional flights. This would involve flying under Part 91 Visual Flight Rules (VFR) and using voice for communications. The initial UAM ecosystem will utilize the current infrastructure such as routes, helipads, and ATC services, where practicable. ​A NASA study explored the use of existing helicopter routes in Dallas Fort Worth (DFW) airspace for initial UAM operations with a Letter of Agreement (LOA) that included procedures to request a Class B (controlled airspace) clearance. The research showed that the chosen approach was feasible for near-term, low-demand UAM traffic, but was not scalable. The growth of operations in today’s aviation system has resulted in airspace reorganization and procedures to ensure safety and efficiency as traffic rates increase. One proposed operating innovation that can help with the scalability of UAM is establishing routes and corridors. This may look similar to the Area Navigation (RNAV) procedures used today to streamline operations into busy airports. However, instead of FAA automation systems and ATC managing the flow of traffic, some UAM concepts envision a third-party service provider performing this role as part of the Provider of Services for UAM (PSU) network. The FAA’s UAM ConOps posits that new airspace structures such as UAM corridors include the following design criteria: 1) Minimal impact on existing NAS operations, 2) no or minimal additional ATC services, 3) public interest considerations such as noise, safety, and security, and 4) customer needs. The airspace available in urban environments is limited by the height of buildings, the effect of weather including wind gusts, privacy needs, and a clearance envelope. The new airspace structure would need to be designed around large airports and urban areas where the initial market demand is likely to exist. NASA has started evaluating airspace in the Dallas Fort Worth area to design new airspace structures, keeping the first two design criteria in mind. It is assumed that there will be an on-board pilot-in-command, and the flights will operate under VFR in Visual Meteorological Conditions. Corridors will be required in controlled airspace, whereas UAM operations can fly in uncontrolled Class G and E airspace using current day rules. Keeler et. al identified factors and heuristics for development of routes for UAM operations for integration with airspace close to large airports such as Dallas Fort Worth and Dallas Love Field. This paper describes the heuristics applied to define the corridors, analyzes them with respect to legacy traffic and presents key results.

Urban Air Mobility↗

Adopting Internet Standards for Orbital Use

After a year of testing and demonstrating a Cisco mobile access router intended for terrestrial use onboard the low-Earth-orbiting UK-DMC satellite as part of a larger merged ground/space IP-based internetwork, we reflect on and discuss the benefits and drawbacks of integration and standards reuse for small satellite missions. Benefits include ease of operation and the ability to leverage existing systems and infrastructure designed for general use, as well as reuse of existing, known, and well-understood security and operational models. Drawbacks include cases where integration work was needed to bridge the gaps in assumptions between different systems, and where performance considerations outweighed the benefits of reuse of pre-existing file transfer protocols. We find similarities with the terrestrial IP networks whose technologies we have adopted and also some significant differences in operational models and assumptions that must be considered.

Wood, Lloyd↗

Problems With Deployment of Multi-Domained, Multi-Homed Mobile Networks

This document describes numerous problems associated with deployment of multi-homed mobile platforms consisting of multiple networks and traversing large geographical areas. The purpose of this document is to provide insight to real-world deployment issues and provide information to groups that are addressing many issues related to multi-homing, policy-base routing, route optimization and mobile security - particularly those groups within the Internet Engineering Task Force.

Ivancic, William D.↗

Securing Smart Manufacturing: Detection of Cyber-Physical Attacks in CNC-Based Systems

As Industry 4.0 advances, the integration of computer numerical control (CNC) machines and advanced manufacturing technologies is transforming production into smart manufacturing systems that blend physical and digital processes as cyber-physical systems. However, this increased cyber-physical connectivity exposes manufacturing systems to cyber threats that can cause severe operational and financial disruptions. This paper presents a comparative study on cyber attacks and anomaly detection techniques in manufacturing, focusing on network traffic from CNC machines. The data extracted from network packets includes machine commands and control signals exchanged between the machine's interface and control system, crucial for maintaining operational integrity. We explore two types of cyber attacks, design modification and command injection, which pose substantial risks to CNC machine productivity and system integrity. Our investigation involves experiments on a real CNC system, highlighting the urgent need for effective detection mechanisms. To address these threats, we evaluate three anomaly detection methods: dynamic time warping (DTW), rolling average, and a deep learning, long short-term memory (LSTM) time-series-based autoencoder. Each is assessed for its effectiveness in identifying anomalous behaviors caused by the attacks. Our findings demonstrate the unique strengths and limitations of each detection technique, providing a deeper understanding of their applicability in realworld manufacturing environments. The comparative analysis indicates that while certain methods are highly effective against specific attack types, others offer broader applicability across different attacks. This study contributes to the accurate detection of anomalies in CNC machining processes, thereby enhancing the reliability and security of smart manufacturing systems against diverse cyber threats.

Williams, Bethanie [Tennessee Technological Univer↗

CIE Analysis Process for Engineered Systems

"CIE Analysis Process for Engineered Systems" outlines a comprehensive methodology for integrating Cyber-Informed Engineering (CIE) principles into both new and existing engineered systems. Sponsored by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER), the process aims to achieve cyber-informed decisions by producing functional security requirements for new systems and retrofitting existing systems to mitigate digital risks. The document details a step-by-step approach, including mission and function definition, digital asset awareness, consequence analysis, and mitigation analysis. It emphasizes the importance of documenting mechanical, electrical, programmable, and network components to protect system functions and provides examples and considerations for each step. The ultimate goal is to ensure that engineered systems remain resilient against cyber threats, maintaining safety, performance, and reliability.

42 - ENGINEERING↗

Space Station Information System - Concepts and international issues

The Space Station Information System (SSIS) is outlined in terms of its functions and probable physical facilities. The SSIS includes flight element systems as well as existing and planned institutional systems such as the NASA Communications System, the Tracking and Data Relay Satellite System, and the data and communications networks of the international partners. The SSIS strives to provide both a 'user friendly' environment and a software environment which will allow for software transportability and interoperability across the SSIS. International considerations are discussed as well as project management, software commonality, data communications standards, data security, documentation commonality, transaction management, data flow cross support, and key technologies.

Williams, R. B.↗

Organizing Diverse, Distributed Project Information

SemanticOrganizer is a software application designed to organize and integrate information generated within a distributed organization or as part of a project that involves multiple, geographically dispersed collaborators. SemanticOrganizer incorporates the capabilities of database storage, document sharing, hypermedia navigation, and semantic-interlinking into a system that can be customized to satisfy the specific information-management needs of different user communities. The program provides a centralized repository of information that is both secure and accessible to project collaborators via the World Wide Web. SemanticOrganizer's repository can be used to collect diverse information (including forms, documents, notes, data, spreadsheets, images, and sounds) from computers at collaborators work sites. The program organizes the information using a unique network-structured conceptual framework, wherein each node represents a data record that contains not only the original information but also metadata (in effect, standardized data that characterize the information). Links among nodes express semantic relationships among the data records. The program features a Web interface through which users enter, interlink, and/or search for information in the repository. By use of this repository, the collaborators have immediate access to the most recent project information, as well as to archived information. A key advantage to SemanticOrganizer is its ability to interlink information together in a natural fashion using customized terminology and concepts that are familiar to a user community.

Keller, Richard M.↗

Rapid neutron and gamma-ray source localization using machine learning

Rapid localization of radiation sources is critical for applications including nuclear emergency response, safeguards, and security. However, conventional imaging systems such as neutron scatter cameras and Compton cameras depend on rare coincidence events, which often result in long acquisition times. In this work, we address the challenge of rapid source localization by developing a machine learning approach to predict the direction of a single radiation source using only count rates from an array of neutron and gamma-ray detectors. The proposed model is a fully connected neural network (FCNN) trained using Monte Carlo simulation data from a 252 Cf source. The model hyperparameters are optimized with a small set of routine 252 Cf measurements. We benchmarked the performance of the trained and optimized machine learning model using additional 252 Cf , 137 Cs , and PuBe measurements under laboratory conditions with varying source-detector configurations. For these measurements, the machine learning model achieved a mean localization error smaller than 30° with 3 x 10 3 system counts, corresponding to 8 s measurement time for the imaging system used in this work. In this low-statistics regime, the method outperformed traditional scatter-based imaging by more than 75% in localization accuracy for the evaluated measurement configurations. These results demonstrate that a machine learning-based approach can significantly reduce the time required for accurate single-source localization, providing a robust and computationally efficient alternative to traditional imaging systems in time-critical nuclear security and emergency response scenarios.

Gamma-ray imaging↗

Site selection criteria for the optical atmospheric visibility monitoring telescopes

A description of each of the criteria used to decide where to locate the Atmospheric Visibility Monitoring (AVM) telescope systems is given, along with a weighting factor for each of them. These criteria include low probability of clouds, fog, smog, haze, low scattering, low turbulence, availability of security and maintenance, and suitability of a site for a potential optical reception station. They will be used to determine which three of several sites under consideration will be used for monitoring visibility through the atmosphere as it applies to an optical ground-based receiving network as may be used in NASA space missions in decades to come.

Cowles, K.↗