Search NASA⌕ Search

SEARCH · Search NASA

Results for “INFORMATION ASSURANCE”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Risk-Informed Safety Assurance and Probabilistic Assessment of Mission-Critical Software-Intensive Systems

This report validates and documents the detailed features and practical application of the framework for software intensive digital systems risk assessment and risk-informed safety assurance presented in the NASA PRA Procedures Guide for Managers and Practitioner. This framework, called herein the "Context-based Software Risk Model" (CSRM), enables the assessment of the contribution of software and software-intensive digital systems to overall system risk, in a manner which is entirely compatible and integrated with the format of a "standard" Probabilistic Risk Assessment (PRA), as currently documented and applied for NASA missions and applications. The CSRM also provides a risk-informed path and criteria for conducting organized and systematic digital system and software testing so that, within this risk-informed paradigm, the achievement of a quantitatively defined level of safety and mission success assurance may be targeted and demonstrated. The framework is based on the concept of context-dependent software risk scenarios and on the modeling of such scenarios via the use of traditional PRA techniques - i.e., event trees and fault trees - in combination with more advanced modeling devices such as the Dynamic Flowgraph Methodology (DFM) or other dynamic logic-modeling representations. The scenarios can be synthesized and quantified in a conditional logic and probabilistic formulation. The application of the CSRM method documented in this report refers to the MiniAERCam system designed and developed by the NASA Johnson Space Center.

Guarro, Sergio B.↗

Autonomous Information Unit for Fine-Grain Data Access Control and Information Protection in a Net-Centric System

As communication and networking technologies advance, networks will become highly complex and heterogeneous, interconnecting different network domains. There is a need to provide user authentication and data protection in order to further facilitate critical mission operations, especially in the tactical and mission-critical net-centric networking environment. The Autonomous Information Unit (AIU) technology was designed to provide the fine-grain data access and user control in a net-centric system-testing environment to meet these objectives. The AIU is a fundamental capability designed to enable fine-grain data access and user control in the cross-domain networking environments, where an AIU is composed of the mission data, metadata, and policy. An AIU provides a mechanism to establish trust among deployed AIUs based on recombining shared secrets, authentication and verify users with a username, X.509 certificate, enclave information, and classification level. AIU achieves data protection through (1) splitting data into multiple information pieces using the Shamir's secret sharing algorithm, (2) encrypting each individual information piece using military-grade AES-256 encryption, and (3) randomizing the position of the encrypted data based on the unbiased and memory efficient in-place Fisher-Yates shuffle method. Therefore, it becomes virtually impossible for attackers to compromise data since attackers need to obtain all distributed information as well as the encryption key and the random seeds to properly arrange the data. In addition, since policy can be associated with data in the AIU, different user access and data control strategies can be included. The AIU technology can greatly enhance information assurance and security management in the bandwidth-limited and ad hoc net-centric environments. In addition, AIU technology can be applicable to general complex network domains and applications where distributed user authentication and data protection are necessary. AIU achieves fine-grain data access and user control, reducing the security risk significantly, simplifying the complexity of various security operations, and providing the high information assurance across different network domains.

Chow, Edward T.↗

Security Vulnerability Profiles of NASA Mission Software: Empirical Analysis of Security Related Bug Reports

NASA develops, runs, and maintains software systems for which security is of vital importance. Therefore, it is becoming an imperative to develop secure systems and extend the current software assurance capabilities to cover information assurance and cybersecurity concerns of NASA missions. The results presented in this report are based on the information provided in the issue tracking systems of one ground mission and one flight mission. The extracted data were used to create three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified the software bugs that are security related and classified them in specific security classes. This information was then used to create the security vulnerability profiles (i.e., to determine how, why, where, and when the security vulnerabilities were introduced) and explore the existence of common trends. The main findings of our work include:- Code related security issues dominated both the Ground and Flight mission IVV security issues, with 95 and 92, respectively. Therefore, enforcing secure coding practices and verification and validation focused on coding errors would be cost effective ways to improve mission's security. (Flight mission Developers issues dataset did not contain data in the Issue Category.)- In both the Ground and Flight mission IVV issues datasets, the majority of security issues (i.e., 91 and 85, respectively) were introduced in the Implementation phase. In most cases, the phase in which the issues were found was the same as the phase in which they were introduced. The most security related issues of the Flight mission Developers issues dataset were found during Code Implementation, Build Integration, and Build Verification; the data on the phase in which these issues were introduced were not available for this dataset.- The location of security related issues, as the location of software issues in general, followed the Pareto principle. Specifically, for all three datasets, from 86 to 88 the security related issues were located in two to four subsystems.- The severity levels of most security issues were moderate, in all three datasets.- Out of 21 primary security classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, these classes contributed from around 80 to 90 of all security issues in each dataset. This again proves the Pareto principle of uneven distribution of security issues, in this case across CWE classes, and supports the fact that addressing these dominant security classes provides the most cost efficient way to improve missions' security. The findings presented in this report uncovered the security vulnerability profiles and identified the common trends and dominant classes of security issues, which in turn can be used to select the most efficient secure design and coding best practices compiled by the part of the SARP project team associated with the NASA's Johnson Space Center. In addition, these findings provide valuable input to the NASA IVV initiative aimed at identification of the two 25 CWEs of ground and flight missions.

vulnerability↗

Gross anatomy of network security

Information security involves many branches of effort, including information assurance, host level security, physical security, and network security. Computer network security methods and implementations are given a top-down description to permit a medically focused audience to anchor this information to their daily practice. The depth of detail of network functionality and security measures, like that of the study of human anatomy, can be highly involved. Presented at the level of major gross anatomical systems, this paper will focus on network backbone implementation and perimeter defenses, then diagnostic tools, and finally the user practices (the human element). Physical security measures, though significant, have been defined as beyond the scope of this presentation.

Computer Security↗

Smashing the Stovepipe: Leveraging the GMSEC Open Architecture and Advanced IT Automation to Rapidly Prototype, Develop and Deploy Next-Generation Multi-Mission Ground Systems

Satellite/Payload Ground Systems - Typically highly-customized to a specific mission's use cases - Utilize hundreds (or thousands!) of specialized point-to-point interfaces for data flows / file transfers Documentation and tracking of these complex interfaces requires extensive time to develop and extremely high staffing costs Implementation and testing of these interfaces are even more cost-prohibitive, and documentation often lags behind implementation resulting in inconsistencies down the road With expanding threat vectors, IT Security, Information Assurance and Operational Security have become key Ground System architecture drivers New Federal security-related directives are generated on a daily basis, imposing new requirements on current / existing ground systems - These mandated activities and data calls typically carry little or no additional funding for implementation As a result, Ground System Sustaining Engineering groups and Information Technology staff continually struggle to keep up with the rolling tide of security Advancing security concerns and shrinking budgets are pushing these large stove-piped ground systems to begin sharing resources - I.e. Operational / SysAdmin staff, IT security baselines, architecture decisions or even networks / hosting infrastructure Refactoring these existing ground systems into multi-mission assets proves extremely challenging due to what is typically very tight coupling between legacy components As a result, many "Multi-Mission" ops. environments end up simply sharing compute resources and networks due to the difficulty of refactoring into true multi-mission systems Utilizing continuous integration / rapid system deployment technologies in conjunction with an open architecture messaging approach allows System Engineers and Architects to worry less about the low-level details of interfaces between components and configuration of systems GMSEC messaging is inherently designed to support multi-mission requirements, and allows components to aggregate data across multiple homogeneous or heterogeneous satellites or payloads - The highly-successful Goddard Science and Planetary Operations Control Center (SPOCC) utilizes GMSEC as the hub for it's automation and situational awareness capability Shifts focus towards getting GS to a final configuration-managed baseline, as well as multi-mission / big-picture capabilities that help increase situational awareness, promote cross-mission sharing and establish enhanced fleet management capabilities across all levels of the enterprise.

GMSEC↗

IV&V Assurance Case Design for Artemis II

As human-rated missions like those in NASA’s Artemis program continue to grow in both size and complexity, and the role of software in achieving mission objectives expands dramatically, NASA’s Independent Verification and Validation (IV&V) Teams face evolving challenges in assuring the safety and performance of the safety- and mission-critical embedded software that is essential to landing astronauts on the surface of the Moon by 2024. Key among these challenges is IV&V’s desire to present a cohesive, integrated assurance statement to its stakeholders that encapsulates and summarizes our assurance positions across the integrated Artemis systems and their combined role in support of a safe and successful flight. In order to meet this challenge, the IV&V Teams have begun a transition to using formal assurance case concepts and documentation in the Goal Structuring Notation (GSN) to build an argument in support of software assurance. IV&V recognizes significant benefits to the logical argumentation structure provided by assurance cases and GSN over our current practices for documenting and managing assurance claims. In order to reap these benefits, IV&V is integrating the use of assurance case concepts with our paradigm of follow-the-risk capability based assurance. Because of this, assurance cases created and used by IV&V are distinct from the sort of assurance case created by a development project or embedded software assurance organization. IV&V’s assurance cases depend much less upon standards and regulations, and more on evidence captured by IV&V regarding the environment, requirements, design, and implementation. IV&V constructs an independent network of claims based on an independent decomposition of arguments. Based upon the risk posture of these claims and their associated software and software artifacts, IV&V then develops and executes engineering analyses and testing, which provide evidence to either support or refute the claim. This emerging risk-informed assurance case methodology is being put into practice as IV&V plans for support of the Artemis II mission, the first flight of the Orion capsule and Space Launch System with astronauts on board.

Gerek Whitman↗

IV&V Assurance Case Design for Artemis II

As human-rated missions like those in NASA's Artemis program continue to grow in both size and complexity, and the role of software in achieving mission objectives expands dramatically, NASA's Independent Verification and Validation (IV&V) Teams face evolving challenges in assuring the safety and performance of the safety- and mission-critical embedded software that is essential to landing astronauts on the surface of the Moon by 2024. Key among these challenges is IV&V's desire to present a cohesive, integrated assurance statement to its stakeholders that encapsulates and summarizes our assurance positions across the integrated Artemis systems and their combined role in support of a safe and successful flight. In order to meet this challenge, the IV&V Teams have begun a transition to using formal assurance case concepts and documentation in the Goal Structuring Notation (GSN) to build an argument in support of software assurance. IV&V recognizes significant benefits to the logical argumentation structure provided by assurance cases and GSN over our current practices for documenting and managing assurance claims. In order to reap these benefits, IV&V is integrating the use of assurance case concepts with our paradigm of follow-the-risk capability based assurance. Because of this, assurance cases created and used by IV&V are distinct from the sort of assurance case created by a development project or embedded software assurance organization. IV&V's assurance cases depend much less upon standards and regulations, and more on evidence captured by IV&V regarding the environment, requirements, design, and implementation. IV&V constructs an independent network of claims based on an independent decomposition of arguments. Based upon the risk posture of these claims and their associated software and software artifacts, IV&V then develops and executes engineering analyses and testing, which provide evidence to either support or refute the claim. This emerging risk-informed assurance case methodology is being put into practice as IV&V plans for support of the Artemis II mission, the first flight of the Orion capsule and Space Launch System with astronauts on board.

Whitman, Gerek↗

IT Project Success w\7120 and 7123 NPRs to Achieve Project Success

This slide presentation reviews management techniques to assure information technology development project success. Details include the work products, the work breakdown structure (WBS), system integration, verification and validation (IV&V), and deployment and operations. An example, the NASA Consolidated Active Directory (NCAD), is reviewed.

Walley, Tina L.↗

Formal Verification of Air Traffic Conflict Prevention Bands Algorithms

In air traffic management, a pairwise conflict is a predicted loss of separation between two aircraft, referred to as the ownship and the intruder. A conflict prevention bands system computes ranges of maneuvers for the ownship that characterize regions in the airspace that are either conflict-free or 'don't go' zones that the ownship has to avoid. Conflict prevention bands are surprisingly difficult to define and analyze. Errors in the calculation of prevention bands may result in incorrect separation assurance information being displayed to pilots or air traffic controllers. This paper presents provably correct 3-dimensional prevention bands algorithms for ranges of track angle; ground speed, and vertical speed maneuvers. The algorithms have been mechanically verified in the Prototype Verification System (PVS). The verification presented in this paper extends in a non-trivial way that of previously published 2-dimensional algorithms.

Narkawicz, Anthony J.↗

Variability in Surface BRDF at Different Spatial Scales (30 m-500 m) Over a Mixed Agricultural Landscape as Retrieved from Airborne and Satellite Spectral Measurements

Over the past decade, the role of multiangle remote sensing has been central to the development of algorithms for the retrieval of global land surface properties including models of the bidirectional reflectance distribution function (BRDF), albedo, land cover/dynamics, burned area extent, as well as other key surface biophysical quantities represented by the anisotropic reflectance characteristics of vegetation. In this study, a new retrieval strategy for fine-to-moderate resolution multiangle observations was developed, based on the operational sequence used to retrieve the Moderate Resolution Imaging Spectroradiometer (MODIS) Collection 5 reflectance and BRDF/albedo products. The algorithm makes use of a semiempirical kernel-driven bidirectional reflectance model to provide estimates of intrinsic albedo (i.e., directional-hemispherical reflectance and bihemispherical reflectance), model parameters describing the BRDF, and extensive quality assurance information. The new retrieval strategy was applied to NASA's Cloud Absorption Radiometer (CAR) data acquired during the 2007 Cloud and Land Surface Interaction Campaign (CLASIC) over the well-instrumented Atmospheric Radiation Measurement Program (ARM) Southern Great Plains (SGP) Cloud and Radiation Testbed (CART) site in Oklahoma, USA. For the case analyzed, we obtained approx.1.6 million individual surface bidirectional reflectance factor (BRF) retrievals, from nadir to 75 off-nadir, and at spatial resolutions ranging from 3 m - 500 m. This unique dataset was used to examine the interaction of the spatial and angular characteristics of a mixed agricultural landscape; and provided the basis for detailed assessments of: (1) the use of a priori knowledge in kernel-driven BRDF model inversions; (2) the interaction between surface reflectance anisotropy and instrument spatial resolution; and (3) the uncertain ties that arise when sub-pixel differences in the BRDF are aggregated to a moderate resolution satellite pixel. Results offer empirical evidence concerning the influence of scale and spatial heterogeneity in kernel-driven BRDF models; providing potential new insights into the behavior and characteristics of different surface radiative properties related to land/use cover change and vegetation structure.

Roman, Miguel O.↗

Variability in Surface BRDF at Different Spatial Scales (30m-500m) Over a Mixed Agricultural Landscape as Retrieved from Airborne and Satellite Spectral Measurements

Over the past decade, the role of multiangle 1 remote sensing has been central to the development of algorithms for the retrieval of global land surface properties including models of the bidirectional reflectance distribution function (BRDF), albedo, land cover/dynamics, burned area extent, as well as other key surface biophysical quantities represented by the anisotropic reflectance characteristics of vegetation. In this study, a new retrieval strategy for fine-to-moderate resolution multiangle observations was developed, based on the operational sequence used to retrieve the Moderate Resolution Imaging Spectroradiometer (MODIS) Collection 5 reflectance and BRDF/albedo products. The algorithm makes use of a semiempirical kernel-driven bidirectional reflectance model to provide estimates of intrinsic albedo (i.e., directional-hemispherical reflectance and bihemispherical reflectance), model parameters describing the BRDF, and extensive quality assurance information. The new retrieval strategy was applied to NASA's Cloud Absorption Radiometer (CAR) data acquired during the 2007 Cloud and Land Surface Interaction Campaign (CLASIC) over the well-instrumented Atmospheric Radiation Measurement Program (ARM) Southern Great Plains (SGP) Cloud and Radiation Testbed (CART) site in Oklahoma, USA. For the case analyzed, we obtained approx.1.6 million individual surface bidirectional reflectance factor (BRF) retrievals, from nadir to 75deg off-nadir, and at spatial resolutions ranging from 3 m - 500 m. This unique dataset was used to examine the interaction of the spatial and angular 18 characteristics of a mixed agricultural landscape; and provided the basis for detailed assessments of: (1) the use of a priori knowledge in kernel-driven BRDF model inversions; (2) the interaction between surface reflectance anisotropy and instrument spatial resolution; and (3) the uncertainties that arise when sub-pixel differences in the BRDF are aggregated to a moderate resolution satellite pixel. Results offer empirical evidence concerning the influence of scale and spatial heterogeneity in kernel-driven BRDF models; providing potential new insights into the behavior and characteristics of different surface radiative properties related to land/use cover change and vegetation structure.

Roman, Miguel O.↗

The Human Dimension of Closing the Training Gap for Fifth-Generation Fighters

Based on a review of the recent technical literature there is little question that a serious training gap exists for fifth-generation fighters, primarily arising from the need to provide their own red-air. There are several methods for reducing this gap, including injecting virtual and constructive threats into the live cockpit. This live-virtual-constructive (LVC) training approach provides a cost effective means for addressing training needs but faces several challenges. Technical challenges include data links and information assurance. A more serious challenge may be the human factors dimension of representing virtual and constructive entities in the cockpit while ensuring safety-of-flight. This also needs to happen without increasing pilot workload. This paper discusses the methods Rockwell Collins and the University of Iowa's Operator Performance Lab use to assess pilot workload and training fidelity measures in an LVC training environment and the research we are conducting in safety-of-flight requirements of integrated LVC symbology.

Hoke, Jaclyn↗

NASA Blue Team: Determining Operational Security Posture of Critical Systems and Networks

Emergence of Cybersecurity has increased the focus on security risks to Information Technology (IT) assets going beyond traditional Information Assurance (IA) concerns: More sophisticated threats have emerged from increasing sources as advanced hacker tools and techniques have emerged and proliferated to broaden the attack surface available across globally interconnected networks.

cybersecurity↗

TPSAS-NF1676L-32546-DND

These slides provide visual aids for a panel presentation on the question of "How can organization of Safety Assurance information be improved, so that various parties can identify the residual uncertainties and reason about their effects on the safety conclusion efficiently." The purpose of the panel is to generate discussion among the participants.

Michael Holloway↗

MODIS Snow-Cover Products

On December 18, 1999, the Terra satellite was launched with a complement of five instruments including the Moderate Resolution Imaging Spectroradiometer (MODIS). Many geophysical products are derived from MODIS data including global snow-cover products. These products have been available through the National Snow and Ice Data Center (NSIDC) Distributed Active Archive Center (DAAC) since September 13, 2000. MODIS snow-cover products represent potential improvement to the currently available operation products mainly because the MODIS products are global and 500-m resolution, and have the capability to separate most snow and clouds. Also the snow-mapping algorithms are automated which means that a consistent data set is generated for long-term climates studies that require snow-cover information. Extensive quality assurance (QA) information is stored with the product. The snow product suite starts with a 500-m resolution swath snow-cover map which is gridded to the Integerized Sinusoidal Grid to produce daily and eight-day composite tile products. The sequence then proceeds to a climate-modeling grid product at 5-km spatial resolution, with both daily and eight-day composite products. A case study from March 6, 2000, involving MODIS data and field and aircraft measurements, is presented. Near-term enhancements include daily snow albedo and fractional snow cover.

Hall, Dorothy K.↗

MODIS Snow-Cover Products

On December 18, 1999, the Terra satellite was launched with a complement of five instruments including the Moderate Resolution Imaging Spectroradiometer (MODIS). Many geophysical products are derived from MODIS data including global snow-cover products. MODIS snow and ice products have been available through the National Snow and Ice Data Center (NSIDC) Distributed Active Archive Center (DAAC) since September 13, 2000. MODIS snow-cover products represent potential improvement to or enhancement of the currently-available operational products mainly because the MODIS products are global and 500-m resolution, and have the capability to separate most snow and clouds. Also the snow-mapping algorithms are automated which means that a consistent data set may be generated for long-term climate studies that require snow-cover information. Extensive quality assurance (QA) information is stored with the products. The MODIS snow product suite begins with a 500-m resolution, 2330-km swath snow-cover map which is then gridded to an integerized sinusoidal grid to produce daily and 8-day composite tile products. The sequence proceeds to a climate-modeling grid (CMG) product at about 5.6-km spatial resolution, with both daily and 8-day composite products. Each pixel of the CMG contains fraction of snow cover from 40 - 100%. Measured errors of commission in the CMG are low, for example, on the continent of Australia in the spring, they vary from 0.02 - 0.10%. Near-term enhancements include daily snow albedo and fractional snow cover. A case study from March 6, 2000, involving MODIS data and field and aircraft measurements, is presented to show some early validation work.

Hall, Dorothy K.↗

Implementing an Objectives-Driven, Risk-Informed, and Case-Assured Approach to Safety and Mission Success at NASA

NASA is developing a “Standard for Assurance of Space Flight Safety and Mission Success” that implements an objectives-driven, risk-informed, and case-assured approach to safety and mission success (S&MS) for NASA space flight programs and projects. The standard aligns with the philosophy of risk leadership that has recently been established in NASA policy to assure acceptable levels of flight crew safety and mission success risk. It is consistent with existing NASA risk management requirements and is compatible with NASA program management and systems engineering requirements. The methodology described in the standard is presented in terms of an S&MS assurance framework that is designed to allow substantial flexibility in the specific means by which programs and projects achieve acceptable mission S&MS risk. Such flexibility is necessary to accommodate the increasingly broad range of acquisition strategies employed by NASA, including commercial transportation services, as well as to accommodate the increasingly rapid evolution of space flight-related technologies and practices. A key feature of the S&MS assurance framework is the specification of S&MS success criteria for each life-cycle review (LCR). The S&MS assurance case is structured around these criteria, the satisfaction of which indicates that the program/project is adhering to the S&MS risk posture. This enables the evolving S&MS assurance case to be used as a fundamental program/project submittal at each LCR, where its inherent structure of argument, supported by evidence, directly supports the evaluation of the program/project with respect to the S&MS success criteria, and by extension, the S&MS risk posture. As such, the S&MS assurance case is integral to program/project systems engineering, risk management, and S&MS oversight activities, and provides the principal basis for S&MS risk acceptance by the Decision Authority throughout the program/project life cycle.

Risk Posture↗