Search NASASearch

SEARCH · Search NASA

Results for “CyberSecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Gateway Implementation of Cybersecurity Requirements

Cybersecurity threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is a critical discipline that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfil and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Cybersecurity

Gateway Implementation of Cybersecurity Requirements

Cyber threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is one of the critical subsystems that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfill and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Svetlana Hanson

Managing NASA Cybersecurity

Externally-focused, strategic presentation on how NASA's cybersecurity program aligns with NASA's overall mission and its vision for information technology. Presentation also touches on challenges to cybersecurity implementation, as well as noting publicly-reported improvements to NASA's cybersecurity program.

Cybersecurity

CyberGAN: Generating High-fidelity Cybersecurity Data With Generative Adversarial Networks

Machine learning for cyber defense offers the promise of detecting adversarial activity against the ground data systems managing critical space assets. A fundamental challenge facing machine learning research in cybersecurity is the lack of high-fidelity, shareable datasets for robust evaluation and testing of machine learning-based solutions. High-fidelity, real-world datasets are necessary for reliable benchmarking of nominal system behavior and malicious activity. Unfortunately, such realistic datasets of both nominal and adversarial activity are rarely shared publicly by data owners due to security and privacy concerns. Besides, the available adversarial data is sparse, which makes training models on malicious activity much harder. This situation has impeded and continues to impede the research and successful adoption of machine learning methods for cyber defense. Researchers have dealt with this problem by generating data within a low-fidelity lab environment, using classified and thus unshareable datasets, or downloading low-fidelity public datasets made available by others. We propose an innovative solution to the problem by employing machine learning methods to generate high-fidelity data. Specifically, we propose the use of Generative Adversarial Networks (GANs) to generate high-fidelity data for cybersecurity purposes. GANs have found successful image processing and natural language applications, but have not yet been investigated for cyber data generation. Our proposed approach first involves training the `discriminator' network of the GAN with a sample of real-world data consisting of malicious and nominal samples. We then use the `generator' network to generate new high-fidelity data samples consisting of an appropriate mix of malicious and nominal activity. We demonstrate applications of our architecture by generating high-fidelity cybersecurity data containing both malicious and nominal samples. We thoroughly evaluate the fidelity of our generated data using heuristics and evaluate its usefulness for machine learning applications using three different datasets. Overall, our approach results in high-fidelity, shareable datasets.

Zhang, Yuening

A Review on Cybersecurity Vulnerabilities for Urban Air Mobility

Recent developments of high-powered unmanned aerial vehicles (UAVs) have allowed for urban air mobility (UAM) to become a reality. While the propulsive technology of these flying cars has almost reached an economic level, the infrastructure to allow for these vehicles to operate in an urban environment is still lacking. With numerous known vulnerabilities in UAVs and commercial aircraft, manufacturers have not addressed cybersecurity in the scope of urban air mobility. This paper presents a review of several known cybersecurity vulnerabilities and previous attacks associated with the core communication systems of UAVs and aircraft. Analyzing current solutions to each threat and incorporating early concepts for UAM, this paper then presents a basic framework featuring a blockchain-based PKI with secondary navigation systems to allow for the development of secure airspace.

Urban Air Mobility

Application Software Cybersecurity Scanning

Scanning software applications for cybersecurity vulnerabilities is a crucial step is assessing the overall health of the application, but how can this kind of scan be performed to give development teams the information they need to make informed design decisions? Two pilot cybersecurity scans were conducted in an attempt to answer this question. A scanning team composed of various subject matter experts was established and worked closely with the development team to perform these scans and capture metrics throughout the process. These interactions and metrics indicate that these scans can be performed in an unobtrusive way and still provide valuable information to development teams regarding the health of their application. This work is not definitive in nature but serves as a foundation for future work.

Barner, Lyle

Developing a Cybersecurity Architecture for Extensible Traffic Management (xTM)

This paper explores the development of a cybersecurity architecture tailored for Extensible Traffic Management (xTM) to address emerging challenges in managing diverse aerial vehicles within the National Airspace System (NAS). Driven by technological advances and the rise of uncrewed aerial systems (UAS), urban air mobility (UAM), and high-altitude traffic (ETM), the NAS is undergoing a paradigm shift. Traditional air traffic management, reliant on traditional Federal Aviation Administration (FAA) control, will give way to decentralized coordination among autonomous and semi-autonomous systems. The proposed xTM Security Architecture, designed as a high-level framework, focuses on ensuring the confidentiality, integrity, and availability of data and operations in this evolving ecosystem. Utilizing threat modeling, the research identifies potential risks across key flight phases, operations and use cases to offer security control recommendations. Key objectives include analyzing interactions between novel airspace entrants and existing NAS traffic, cataloging vulnerabilities, and developing mitigative strategies to ensure safety, operational stability, and secure data exchanges. This research lays the groundwork for regulatory and industry adaptation, providing critical insights into managing cybersecurity risks in this complex, multi-domain environment.

UAM

A Review on Cybersecurity Vulnerabilities for Urban Air Mobility

Recent developments of high-powered unmanned aerial vehicles (UAVs) have allowed for urban air mobility (UAM) to become a reality. While these flying cars' propulsive technology has almost become economically viable, the infrastructure to allow these vehicles to operate in an urban environment is still lacking. With numerous known vulnerabilities in UAVs and commercial aircraft, manufacturers have not addressed cybersecurity in the scope of urban air mobility.

UAM

A Review on Cybersecurity Vulnerabilities for Urban Air Mobility

Recent developments of high-powered unmanned aerial vehicles (UAVs) have allowed for urban air mobility (UAM) to become a reality. While these flying cars' propulsive technology has almost become economically viable, the infrastructure to allow these vehicles to operate in an urban environment is still lacking. With numerous known vulnerabilities in UAVs and commercial aircraft, manufacturers have not addressed cybersecurity in the scope of urban air mobility.

Urban Air Mobility

The Lighter Side of Things: The Inevitable Convergence of the Internet of Things and Cybersecurity

By the year 2020 it is estimated that there will be more than 50 billion devices connected to the Internet. These devices not only include traditional electronics such as smartphones and other mobile compute devices, but also eEnabled technologies such as cars, airplanes and smartgrids. The IoT brings with it the promise of efficiency, greater remote management of industrial processes and further opens the doors to world of vehicle autonomy. However, IoT enabled technology will have to operate and contend in the contested domain of cyberspace. This discussion will touch on the impact that cybersecurity has on IoT and the people, processes and technology required to mitigate cyber risks.

Internet of Things

Quantifying Cybersecurity Risk for NASA Missions

An end-to-end cyber risk assessment process is presented that is based on the combination of guidelines from the National Institute of Standards & Technology (NIST), the standard 5x5 risk matrix, and quantitative methods for generating loss exceedance curves. The NIST guidelines provide a framework for cyber risk assessment, and the standard 5x5 matrix is widely used across the industry for the representation of risk across multiple disciplines. Loss exceedance curves are a means of quantitatively assessing the loss that occurs due to a given risk profile. Combining these different techniques enables us to follow the guidelines, adhere to standard 5x5 risk management practices and develop quantitative metrics simultaneously. Our quantification process is based on the consideration of the NASA and JPL Cost Risk assessment modeling techniques as we define the cost associated with the cybersecurity risk profile of a mission as a function of the mission cost.

Miller, Robert L.

Aviation Cybersecurity Challenges

Extensible Traffic Management (xTM) is the overarching term for traffic management approaches and/or associated services that address the operation of select new entrants within flexibly allocated, designated airspace. xTM will leverage the decentralized UTM model for traffic management, creating cybersecurity challenges that are common and unique.

Cybersecurty

Cybersecurity - Host-based Intrusion Detection Systems (HIDS)

Given a set of flight trajectories, can we classify the trajectories that do not follow a normal path? By identifying abnormal trajectories, further analysis can be done to determine the reasoning for these actions. Addressing these scenarios can bring possible solutions for holding and rerouting problems when its time to incorporate UAM in the airspace.

DFR