Search NASA⌕ Search

SEARCH · Search NASA

Results for “Cybersecurity Risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Quantifying Cybersecurity Risk for NASA Missions

An end-to-end cyber risk assessment process is presented that is based on the combination of guidelines from the National Institute of Standards & Technology (NIST), the standard 5x5 risk matrix, and quantitative methods for generating loss exceedance curves. The NIST guidelines provide a framework for cyber risk assessment, and the standard 5x5 matrix is widely used across the industry for the representation of risk across multiple disciplines. Loss exceedance curves are a means of quantitatively assessing the loss that occurs due to a given risk profile. Combining these different techniques enables us to follow the guidelines, adhere to standard 5x5 risk management practices and develop quantitative metrics simultaneously. Our quantification process is based on the consideration of the NASA and JPL Cost Risk assessment modeling techniques as we define the cost associated with the cybersecurity risk profile of a mission as a function of the mission cost.

Miller, Robert L.↗

Gateway Implementation of Cybersecurity Requirements

Cybersecurity threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is a critical discipline that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfil and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Cybersecurity↗

Gateway Implementation of Cybersecurity Requirements

Cyber threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is one of the critical subsystems that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfill and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Svetlana Hanson↗

Cyber Threats and Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Urban Air Mobility↗

Cyber Threats & Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Cyber Threats↗

A Survey of Cyber Threats and Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Cyber Threats↗

Developing a Cybersecurity Architecture for Extensible Traffic Management (xTM)

This paper explores the development of a cybersecurity architecture tailored for Extensible Traffic Management (xTM) to address emerging challenges in managing diverse aerial vehicles within the National Airspace System (NAS). Driven by technological advances and the rise of uncrewed aerial systems (UAS), urban air mobility (UAM), and high-altitude traffic (ETM), the NAS is undergoing a paradigm shift. Traditional air traffic management, reliant on traditional Federal Aviation Administration (FAA) control, will give way to decentralized coordination among autonomous and semi-autonomous systems. The proposed xTM Security Architecture, designed as a high-level framework, focuses on ensuring the confidentiality, integrity, and availability of data and operations in this evolving ecosystem. Utilizing threat modeling, the research identifies potential risks across key flight phases, operations and use cases to offer security control recommendations. Key objectives include analyzing interactions between novel airspace entrants and existing NAS traffic, cataloging vulnerabilities, and developing mitigative strategies to ensure safety, operational stability, and secure data exchanges. This research lays the groundwork for regulatory and industry adaptation, providing critical insights into managing cybersecurity risks in this complex, multi-domain environment.

UAM↗

A Blockchain Case Study for Urban Air Mobility Operational Intent

The next generation of aerial passenger and cargo transportation may leverage the concept of Urban Air Mobility (UAM). UAM is a concept that proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical takeoff and landing (VTOL) or short takeoff and landing (STOL) aircraft to overcome increasing surface congestion [1]. The UAM concept leverages a decentralized service-based architecture for airspace solutions. Within the environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within the UAM environment. Also, various views of UAM flight information are provided to the public and public safety entities [2]. The Federal Aviation Administration (FAA) can coordinate flight information between the FAA controlled National Airspace System (NAS) and the UAM environments through the FAA-Industry Data Exchange Protocol (FIDXP). To realize the potential of UAM, an assurance of cybersecurity is critical for public acceptance. Cybersecurity has come to the forefront highlighting the need to protect these networks and systems from cyberattacks. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. As these threats evolve, the UAM cybersecurity capabilities must adapt to these changes as well [3]. This research focuses on the secure data exchange and storage of this decentralized UAM environment to address these challenges. This research intends to leverage a permissioned blockchain approach to address cybersecurity threats that may impact a UAM environment. Blockchain technologies can be used for tracking transactions and verifying negotiated agreements between stakeholders in the NAS environment. For example, the record of the submitted flight plan and the approved flight plan could be verified using the Blockchain-based immutable ledger.

UAM↗

NASA’s Secured Airspace for Urban Air Mobility (UAM)

The Urban Air Mobility (UAM) architecture is leveraged from the Unmanned Traffic Management (UTM) concept of operations. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within that environment. As a recognized need, various views of UAM flight information are provided to the public and public safety entities. To accomplish this, among other goals, the Federal Aviation Administration (FAA) can coordinate flight information between the FAA controlled National Airspace System (NAS) and the UAM environments through the FAA-Industry Data Exchange Protocol (FIDXP). This concept of UAM proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical take-off and landing (VTOL) or short take-off and landing (STOL) aircraft to overcome increasing surface congestion. To garner the support of UAM and to realize its potential, an assurance of cybersecurity is critical for public acceptance. Understanding the various components communicating with one-another cybersecurity, like in other industries, has come to the forefront highlighting the need to protect these networks and systems from cyberattacks. With the planned growth and reach of UAM systems, it’s clear that the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. Consequently, as these threats evolve, the UAM cybersecurity capabilities must adapt to these changes as well. While learning is always the goal, the overall intent of this workshop is to make recommendations on the following: (1) how future UAM environments can be protected against cyber-attacks, and (2) what mechanisms should be put in place to detect attacks against UAM environments.

UAM↗

A Blockchain Case Study for Urban Air Mobility Operational Intent

To realize the potential of Urban Air Mobility (UAM), an assurance of cybersecurity is critical for public acceptance. UAM is a concept that proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical takeoff and landing (VTOL) aircraft to overcome increasing surface congestion. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. The intent of this work is to leverage a permissioned blockchain to simulate secure data exchange and storage for the UAM operational intent use case. In this case study, two vehicle operators are operating in the same airspace. Their intent is to fly vehicles that land at a shared vertiport, securely.

Urban Air Mobility↗

A Blockchain Case Study for Urban Air Mobility Operational Intent

To realize the potential of Urban Air Mobility (UAM), an assurance of cybersecurity is critical for public acceptance. UAM is a concept that proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical takeoff and landing (VTOL) aircraft to overcome increasing surface congestion. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. The intent of this work is to leverage a permissioned blockchain to simulate secure data exchange and storage for the UAM operational intent use case.

UAM↗

A Blockchain Case Study for Urban Air Mobility Operational Intent

To realize the potential of Urban Air Mobility (UAM), an assurance of cybersecurity is critical for public acceptance. UAM is a concept that proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical takeoff and landing (VTOL) aircraft to overcome increasing surface congestion. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. The intent of this work is to leverage a permissioned blockchain to simulate secure data exchange and storage for the UAM operational intent use case.

UAM↗

Immutable Secure Data Exchange and Storage for Urban Air Mobility Environments

Urban air mobility (UAM) is a concept that proposes to develop short-range aerial vehicles to overcome increasing surface congestion. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within the UAM environment. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. To address these challenges, this research focuses on the secure data exchange and storage of this decentralized UAM environment. The intent of this research is to leverage a permissioned blockchain approach to address cybersecurity threats that may impact a UAM environment.

Urban Air Mobility↗

Immutable Secure Data Exchange and Storage for Urban Air Mobility Environments

Urban air mobility (UAM) is a concept that proposes to develop short-range aerial vehicles to overcome increasing surface congestion. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within the UAM environment. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. To address these challenges, this research focuses on the secure data exchange and storage of this decentralized UAM environment. The intent of this research is to leverage a permissioned blockchain approach to address cybersecurity threats that may impact a UAM environment.

Urban Air Mobility↗

NASA Blue Team: Determining Operational Security Posture of Critical Systems and Networks

Emergence of Cybersecurity has increased the focus on security risks to Information Technology (IT) assets going beyond traditional Information Assurance (IA) concerns: More sophisticated threats have emerged from increasing sources as advanced hacker tools and techniques have emerged and proliferated to broaden the attack surface available across globally interconnected networks.

cybersecurity↗

The Lighter Side of Things: The Inevitable Convergence of the Internet of Things and Cybersecurity

By the year 2020 it is estimated that there will be more than 50 billion devices connected to the Internet. These devices not only include traditional electronics such as smartphones and other mobile compute devices, but also eEnabled technologies such as cars, airplanes and smartgrids. The IoT brings with it the promise of efficiency, greater remote management of industrial processes and further opens the doors to world of vehicle autonomy. However, IoT enabled technology will have to operate and contend in the contested domain of cyberspace. This discussion will touch on the impact that cybersecurity has on IoT and the people, processes and technology required to mitigate cyber risks.

Internet of Things↗