Search NASA⌕ Search

SEARCH · Search NASA

Results for “IP networks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

eCounter: Inline Per-IP Network Monitoring at Millisecond Resolution via eBPF

Scientific data acquisition (SciDAQ) systems are shifting from archive-based workflows to streaming paradigms, where real-time, fine-grained network monitoring becomes essential. While P4-enabled devices offer per-packet in-band observability, they require specialized switches and routers. Host-side tools like Prometheus exporters lack sufficient temporal granularity. To bridge this gap, we present eCounter, a lightweight, hardware-agnostic, inline telemetry agent built on extended Berkeley Packet Filter (eBPF). eCounter captures per-interface ingress and egress traffic, categorized by IP address and protocol, at millisecond to sub-millisecond resolution. In a 100 Gbps environment, it continuously exports up to 3,257 time-series bins per second with only 4% CPU utilization at a 35¿KiB/s data rate. We evaluate eCounter across diverse NIC MTU settings, hook types, CPU architectures and operating systems, and observed negligible impact on concurrent high-throughput streaming applications. Complexity analysis confirms that it can be readily scaled to distributed SciDAQ deployments.

Mei, Xinxin [Computational Sciences and Technology↗

Dtc Commercialization Software Package

This code is the complete software and firmware components supporting DTC model radios H2 and BluSDR6. This software package contains all the hardware boot up code/config files(BSP), user space Linux code (Web, Network, MAC (media access control) & drivers), the field programable gate array HDL (hardware description language) code and the build environment to compile and organize these components together to work in the aforementioned radios. Additional details of these components are as follows: • Hardware support components o Board support package and configuration files o uBoot • Linux Components: o The web components include the user interface for setup, configuration, and status components of the system. o Vulture code configures the radio’s IP network, configures radio parameters and runs the MAC layer of the radio. • The Field Programmable Gate Array HDL contains hardware drivers, interface logic to go between the software to the physical layer and the radio hardware as well as the logic for the physical layer of the radio. • Build environment includes compilers and config files that compile and organize all the other components to be able to be run on the radios.

Loera, Jose [Idaho National Laboratory (INL), Idah↗

Supporting Cyber Security of Power Distribution Systems by Detecting Differences Between Real-time Micro-Synchrophasor Measurements and Cyber-Reported SCADA (Final Report)

As modern power grids tend towards greater levels of automation and communication, the challenges of identifying and mitigating vulnerabilities to cyber-attacks are ones that are increasingly demanding attention. Today’s power system has evolved to form the foundational bedrock of modern society, and an attack on this infrastructure could prove disastrous. In this project we were tasked to investigate the use of distribution synchrophasors as an independent isolated sensor network with which we can corroborate, or flag potentially spoofed,Supervisory Control And Data Acquisition (SCADA) data. We adapted an approach to marry the underlying physical properties of power systems with the network communications used by power systems in order to offer insights unattainable by either data stream isolation. While the concept of intrusion detection systems (IDS) is well understood for monitoring network traffic and traditional IT computing systems, the approach discussed in this report is motivated by several key notions: first, current SCADA communications alone presents an incomplete view of the grid. Second, the power grid, and the equipment controlling it, is grounded by laws of physics. Given this, we leverage high-frequency physical grid measurements to understand the physical condition of the grid, and combine this with SCADA. While high-frequency physical grid measurements and SCADA communication over Internet Protocol (IP) networks are fundamentally disparate information sources, when collectively examined through appropriate lenses, they offer a much more nuanced depiction of the grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Secure NTP Implementation for Power System Synchronization

Network Time Protocol (NTP), originally developed in the 1980s, remains one of the most widely adopted protocols for synchronizing clocks over Internet Protocol (IP)-based networks. It distributes time with millisecond-level accuracy across Ethernet-based systems and continues to be a standard in both enterprise and operational technology environments.

97 MATHEMATICS AND COMPUTING↗

Programmable Quantum Networked Microgrids

Quantum key distribution (QKD) provides a potent solution to securely distribute keys for two parties. However, QKD itself is vulnerable to denial of service (DoS) attacks. A flexible and resilient QKD-enabled networked microgrids (NMs) architecture is needed but does not yet exist. In this article, we present a programmable quantum NMs (PQNMs) architecture. It is a novel framework that integrates both QKD and software-defined networking (SDN) techniques capable of enabling scalable, programmable, quantum-engineered, and ultra-resilient NMs. Equipped with a software-defined adaptive post-processing approach, a two-level key pool sharing strategy and an SDN-enabled event-triggered communication scheme, these PQNMs mitigate the impact of DoS attacks through programmable post-processing and secure key sharing among QKD links, a capability unattainable using existing technologies. Through comprehensive evaluations, we validate the benefits of PQNMs and demonstrate the efficacy of the presented strategies under various circumstances. Extensive results provide insightful resources for building QKD-enabled NMs in practice.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Directional Laplacian Centrality for Cyber Situational Awareness

Cyber operations is drowning in diverse, high-volume, multi-source data. To get a full picture of current operations and identify malicious events and actors, analysts must see through data generated by a mix of human activity and benign automated processes. Although many monitoring and alert systems exist, they typically use signature-based detection methods. We introduce a general method rooted in spectral graph theory to discover patterns and anomalies without a priori knowledge of signatures. We derive and propose a new graph-theoretic centrality measure based on the derivative of the graph Laplacian matrix in the direction of a vertex. To build intuition about our measure, we show how it identifies the most central vertices in standard network datasets and compare to other graph centrality measures. Finally, we focus our attention on studying its effectiveness in identifying important IP addresses in network flow data. Using both real and synthetic network flow data, we conduct several experiments to test our measure’s sensitivity to two types of injected attack profiles and show that vertices participating in injected attack profiles exhibit noticeable changes in our centrality measures, even when the injected anomalies are relatively small, and in the presence of simulated network dynamics.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Exploration of the Application of Machine Learning to the improvement of Interatomic Potentials

Current methods for atomistic simulations of material systems suffer from limitations which restrict the ability of the simulation to correctly characterize certain material behavior and physical phenomena. Small scale ab initio (AIMD) modeling is highly accurate but is computationally expensive. Classical molecular dynamics (CMD) simulations use interatomic potentials (IPs) to describe larger systems at a reduced computational cost, but with a reduced accuracy. Creating more robust IPs enable more precise CMD simulations. In this thesis, the application of a specific machine learning process,artifical neural networks (ANNs), to the improvement of IPs and MD simulation is discussed.

O'Connor, Sean↗

Moiré Patterns in Pt Overlayers on Gold: A Graph Neural Network Interatomic Potential Study

Overlayer structures in bimetallic catalysts are relevant to a variety of catalytic reactions, particularly in electrocatalysis for fuel cell applications. Previous computational studies largely consider these overlayer structures to be those of a pseudomorphic overlayer, where there is a 1:1 atomic ratio between the overlayer and the support metal. Our previous work based on density functional theory (DFT) has shown that there exist nonstoichiometric overlayer structures that are more stable than the stoichiometric ones. Here, in this work, we developed a graph neural network interatomic potential (GNN-IP) to analyze structures formed in Pt overlayers on Au(111). The GNN-IP was used to explore properties of nonstoichiometric overlayers at length scales that are prohibitively expensive to pursue with planewave DFT calculations. In particular, we examined large Pt islands on top of a 48 × 48 Au(111) unit cell to explore the influence of the rotational angle (α) between the Pt overlayer and support Au(111) on both the stability of and the preferred atomic density in the overlayer. Island structures with smaller rotational angles between the Pt overlayer and Au(111) tend to be more stable. Further, smaller rotational angles tend to result in lower atomic density in the Pt overlayer.

chemical structure↗

Microchannel-based Membrane-less Extraction of Li from Unconventional Lithium Sources & the Separation of REE

This final report provides an overview of the Project's entire duration, covering July 1, 2021 to December 31, 2023. It primarily focuses on the achievements, technological developments, and unique challenges the team faced while working on separating and extracting Lithium from produced waters. The project's primary aim was to create an integrated, high-throughput, membrane-less, and modular microfluidic platform that could extract Lithium from unconventional sources. We have successfully met all goals and milestones envisioned in the SOPO document. The most critical primary milestones, including the Go-No-Go milestone (refer to the Gantt chart in the Appendices), were successfully accomplished. We demonstrated phase separation (>90%) and extraction (>85%) performance in the MPSE using synthetic, and representative produced water composition feed at 50 ml/min total flow through MPSE 36. We have also performed a parametric study of the MPSE operations, beyond the scope of SOPO, exploring operating conditions of current and broader interest. The extended investigation of operational parameters is concurrent with our efforts to seek further development of the MPSE technology beyond the scope of the Project. Along these lines of development, we have made efforts to be responsive to DOE calls for technological developments of other types of resources (beyond PW) for the recovery of Critical Materials and higher TRL development (beyond TRL 4). During the work on this Project, we developed and implemented three innovative technical approaches that emerged from our efforts to successfully meet the Project milestones. The innovative & original technical approaches developed and implemented in this Project are now the contributions to process engineering that could be clearly credited to the Project. First, Convergent Design Approach is a comprehensive feedforward & feedback loop of four design phases: i) design for functionality, ii) design for manufacturing, iii) design for sustainability, and iv) design for market. Next was Process Intensification. A major aim of this Project was to create an innovative phase separation & extraction microscale-based technology for Li separation – thus the words microchannel-based in the Project title. A microscale-based technology is intrinsically in the center of the Process Intensification domain as defined by its unique principles. Therefore, Process Intensification was implicitly envisioned in the Project’s SOPO. Lastly, Time Scale Analysis is a novel tool for discovering the needs and directions of Process Intensification implementations in any process technology. This Project is fully credited for developing and implementing the three novel technical approaches mentioned above. These are general contributions to process engineering that emerged from this Project. Beyond the original SOPO scope, the OSU-U.Pitt research group utilized a Convergent Design methodology, integrating first-principles mathematical modeling with experimental validation on the Minimum Development Vehicle. By creating these Digital Twins, the team rapidly assessed manufacturing iterations to support TEA analysis. This framework further enabled the development of advanced Surface Modification Techniques, where hydrophobic and oleophobic coating strategies were optimized via Digital Twin tools and validated through rigorous 100-hour longevity testing. TEA Analysis: The closing efforts of this Project were focused on the TEA analysis. TEA analysis had two primary functions: i) enabling critical assessments of design variations withing 10 the Concurrent Design Approach, thus enabling evolution of the MPSE design to reach faster- better-cheaper alternatives; and ii) to create a bridge between the accomplishments of this Project and future projects of higher TRL, beyond TRL 6 level. It is important to note that the TEA model created in the Project stirred the technological solutions for the recovery of critical materials toward a vision of a very profitable modular plant that has unique zero-waste water discharge signature. More importantly, thanks to our experimental performance data and conservative assumptions, the TEA model predicts minimal technological and investment risks. Low cost of a modular unit of a nominal capacity of [1000 tons of Li 2 CO 3 /year] positions the MPSE based technology within the reach of community investors, thus offering a paradigm shift in the development of critical technologies. The project successfully navigated two primary challenges: solvent selection and manufacturing adaptation. Restricted by the SOPO to existing literature for lithium recovery, the team identified a critical need for a "material excellence program" to develop next-generation solvents, eventually concluding with a preliminary investigation into promising Ionic Liquids (ILs). Simultaneously, COVID-19 supply chain disruptions forced a pivot from traditional manufacturing to advanced additive methods at ATAMI-OSU. By transitioning from stainless steel to 3D-printed polymer substrates, the team achieved a transformative three-order-of- magnitude reduction in manufacturing costs and compressed prototyping timelines from several months to just two days. The MPSE technology offers significant energy, environmental, and economic advantages by overcoming the traditional bottlenecks of phase-separation hardware and contactor size. Unlike conventional mixer-settlers or membrane-based systems, MPSE operates without moving parts or fouling-prone membranes, achieving robust performance even with challenging, viscous, or particulate-heavy feeds. Key performance metrics include an energy intensity reduction of 5–50x (3–40 kJ/m 3 ) compared to incumbent technologies and a dramatic reduction of processing time to under 60 seconds, which drastically reduces the physical plant footprint. These technical efficiencies translate into superior economic outcomes; for a 100 t/year Li 2 CO 3 facility, implementing MPSE is projected to nearly halve contactor CAPEX (from $\$$6.08M to $\$$3.01M) and significantly increase the project's Net Present Value (NPV), derisking new investment and enabling distributed critical-mineral processing configurations. The commercialization of MPSE technology is being spearheaded by Vigsur Dynamics Inc., which has adopted a structured, parallel approach to technical and business development since its formation in January 2026. Following extensive customer discovery and engagement with the Oregon State University accelerator, Vigsur Dynamics is working to establish a business model that transitions from pilot demonstrations to modular hardware sales, ultimately aiming for a "build-own-operate" service strategy. Current technical milestones—including 100 hours of continuous operation, superior energy efficiency, and successful 6-unit modular scale-up— provide a foundation for this transition. Backed by ongoing IP licensing and a growing network of industrial and venture advisors, the company is actively de-risking the platform to replace conventional mixer-settler systems in the critical minerals market.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Next generation experimental data access at NSLS-II

The NSLS-II network and computing infrastructure has been significantly updated recently. The re-IP process in 2020-2021 enabled the NSLS-II network to be routable to the rest of the BNL campus. Then, standardization of the operating systems and deployment procedures helped to deliver a consistent environment to workstations and servers used by all NSLS-II beamlines. In particular, the RedHat Enterprise Linux 8 was deployed to 700+ machines using the RedHat Satellite infrastructure management product, and all critical services (IOCs, databases, etc.) were migrated to the new OS. NFS users’ home directories are consistent across all of the machines, which eliminates the need for the individual configuration of the user environment on each host. The standard suite of software packages is available to the beamline staff and users, which includes the system packages (deployed via RPM) as well as the conda environments for data acquisition and analysis. Security measures were implemented to comply with the industry standards, which include multi-factor authentication (using Duo), secure screen lock for the beamline machines, and advanced access control to the experimental data that is stored in shared central storage available on all hosts. These major enhancements facilitated sharing the experimental data (currently for a number of selected beamlines, with a plan to extend it to the whole facility in the nearest future) with the users via an externally facing JupyterHub instance. The beamlines keep using the Bluesky data acquisition framework to orchestrate their experiments, and the new infrastructure enabled them to use a next-generation data access library called tiled.

36 MATERIALS SCIENCE↗

Designing, Constructing, and Operating an IPv6 Network at SC23: A case study in implementing the IPv6 protocol on a heterogenous network that supports the SC23 conference

IPv6 is the current version of IP, the protocol that is used to route traffic across internet connections. This standard was originally developed as a new approach to mitigate concerns about address exhaustion and allow for near infinite scalability. While this protocol has gained significant support in mobile and broadband networks, as well as being the default for networks in emerging economies, it has yet to be fully adopted as a standard deployment model. Complications include legacy devices unable to support the proposed changes, as well as potential challenges that exist between devices that may not be able to fully implement current standards or configuration norms. The SCinet volunteers who deliver advanced networking to support the SC Conference set an ambitious goal of deploying an IPv6-only network at SC23. While the necessary technology is widely available and understood, the implications of deployment to support more than 15,000 users, each with multiple devices of different operating environments and ages, presents a unique technology and policy challenge. This paper will highlight the effort put into designing, implementing, and operating this innovative IPv6-only environment.

Robinson, Kate↗

Mitigate: An Adaptive Network Data Anonymization Tool Using Condensation-Based Differential Privacy

Modern network devices collect a large amount of data that can be analyzed to identify bottlenecks, anomalies, cyber-attacks, etc. Therefore, there is often a need to analyze such collections of network data quite often by an external expert or by the research community. However, these collections of data contain sensitive, proprietary information. In order for the network data to be shared, it must first be anonymized. The overall objective of this project is to develop an innovative privacy management tool to anonymize network data and achieve sufficient privacy, acceptable data utility, and efficient data analysis at the same time. No existing anonymization methods can achieve all of these at the same time. The core of this technology is a differential private clustering algorithm that provides strong privacy protection, preserves data properties important for subsequent analysis, and allows the party receiving the anonymized data to conduct analysis directly on anonymized data without the need of decryption or any extra processing. The research carried out was to design, implement and verify a solution to this problem by completing the following tasks: 1) developing the core technology; 2) developing a context based method that automatically recommends fields that must be anonymized; 3) conducted experiments showing superior results using our approach compared to existing tools, and 4) developed an intuitive but basic user interface. The research that was conducted generated novel algorithmic techniques that utilize state-of-the-art methods such as condensation, differential privacy preservation, clustering, automated tuning based on contextual awareness, and recommendation techniques to specify columns to users for anonymization leading to optimal privacy that allows research analysis on the dataset. Experiments were conducted to evaluate the efficacy of these novel algorithmic techniques by performing analysis on original non-anonymized datasets, then conducting analysis on the same yet anonymized datasets and comparing the results of the analyses. Overall, the anonymized analysis results were within 1% of the original results, verifying that the generated technology not only guarantees a high level of privacy but also enables research analysis as if it were conducted on the original dataset. Potential applications of this technology include anonymization of any type of structured network datasets that contain sensitive identifiers, such as IP addresses, that can be used in multiple applications. For example, to create an AI or machine learning model for cyber security, e.g., to detect attacks, or for performance analysis, e.g., identify bottlenecks or predict performance. In addition, a market analysis that was conducted for potential applications of this technology identified a broader range of applications of our anonymization technology beyond the network sector that includes healthcare, banking, insurance, securities, finance (FISB), data brokering, cloud services, ad sales, and government.

97 MATHEMATICS AND COMPUTING↗

Artificial Diversity and Defense Security (ADDSec)

Artificial Diversity and Defense Security (ADDSec) machine learning algorithms are used to classify and cluster threats so that an appropriate response can be initiated as a mitigation strategy. The package includes an ensemble of machine learning algorithms such as Support Vector Machines, naïve bayes, logistic regression, and random forest that evolve with the data to recognize anomalous behavior at the host and network levels. Inputs into the machine learning algorithms include end host system calls, system utilization, packet captures, and syslog messages. The machine learning algorithms can be retrained based on user defined intervals or on the number of packets received. ADDSEC's threat responses include Internet Protocol (IP) Address randomization, application port number randomization, and application library randomization. The IP randomization implementation is built on top of a Software Defined Networking (SDN) framework. The SDN controller installs flows on each of the SDN switches with randomized source and destination IP addresses. The application port numbers are randomized using iptables. The application library randomization is created with a LLVM compiler. All randomization schemes are transparent to the endpoints on the network. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525. SAND2021-3379 O

Cox, RebeccaE.↗

Videoshare

SAND2023-05132O Videoshare is an application that allows users to communicate in a variety of ways, including voice, video, and text, over a local network without having to use a central server or an internet connection. The software features: • Screen-sharing and connecting to external IP cameras. • Ability to hold group calls on computers running the same software and network. • Ability to connect to other computers running the same software. • Curating potential connections and manually adding IP addresses to available connections. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

McIlraith, Aiden↗

Real-World Cyber Security Demonstration for Networked Electric Drives

In this article, we present the design and implementation of a cyber-physical security testbed for networked electric drive systems, aimed at conducting real-world security demonstrations. To our knowledge, this is one of the first security testbeds for networked electric drives, seamlessly integrating the domains of power electronics and computer science, and cybersecurity. By doing so, the testbed offers a comprehensive platform to explore and understand the intricate and often complex interactions between cyber and physical systems. The core of our testbed consists of four electric machine drives, meticulously configured to emulate small-scale but realistic information technology (IT) and operational technology (OT) networks. This setup both provides a controlled environment for simulating a wide array of cyber-attacks, and mirrors potential real-world attack scenarios with a high degree of fidelity. The testbed serves as an invaluable resource for the study of cyber-physical security, offering a practical and dynamic platform for testing and validating cybersecurity measures in the context of networked electric drive systems. As a concrete example of the testbed's capabilities, we have developed and implemented a Python-based script designed to execute step-stone attacks over a wireless local area network (WLAN). This script leverages a sequence of target IP addresses, simulating a real-world attack vector that could be exploited by adversaries. To counteract such threats, we demonstrate the efficacy of our developed cyber-attack detection algorithms, which are integral to our testbed's security framework. Furthermore, the testbed incorporates a real-time visualization system using InfluxDB and Grafana, providing a dynamic and interactive representation of networked electric drives and their associated security monitoring mechanisms. This visualization component not only enhances the testbed's usability but also offers insightful, real-time data for researchers and practitioners, thereby facilitating a deeper understanding of cyber-physical security dynamics in networked electric drive systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Network Anomaly Detection Using Federated Learning

The internet is turning out to be an integral part of every-one's lives as more and more devices are being connected to serve societal needs. Our work is motivated by two ma-jor observations. Firstly, one drawback of connecting to the network is the threat of network attacks that can compromise users' private information, leading to data loss and adversely affecting productivity. There are several traditional security mechanisms to defend against these attacks, such as firewalls, virtual private networks (VPNs), demilitarized zones (DMZs), and vulnerability scanners. One way to prevent these attacks is early detection and prevention. However, these kinds of architecture do not scale very well because of their centralized nature. Secondly, we observe from heuristics and data set distributions that the majority of the requests made to a server are innocuous. Therefore, almost all server request data sets are highly imbalanced, weighted highly towards the harmless requests.

Marfo, William↗

Network Architecture Verification & Validation Tool

The NAVV Tool is an automation of Linux commands run Zeek IDS software on a packet capture to create a Microsoft Excel spreadsheet table breaking down network traffic observed. The tool automates the Zeek software analysis, the collation of logs, and then the dissection of the Conn.log and DNS.logs to create a summary table within a Excel. This spreadsheet can then be updated with network segments using CIDR formatting and labels along with inventory information including name and IP address. Using the tool again will integrate these label and color coding into the existing analysis table to aid in conducting an evaluation of the network traffic.

Nichols, DonovanW↗

Effect of different manufacturing methods on polyamide reverse-osmosis membranes for desalination: Insights from molecular dynamics simulations

Membranes are a key technology platform for a broad application of energy-efficient separations. To best serve the separation demands of industry, the manufacturing processes for these membranes are garnering increasing attention. In particular, for water desalination, the industry leading polyamide (PA) reverse osmosis (RO) membranes can be manufactured via molecular layer-by-layer (mLBL) deposition, interfacial polymerization (IP), and 3D-printing technique. However, the influence of different manufacturing methods on PA membrane’s properties is far from understood. Here, in this study, we present the high-pressure transport behavior of water and salt ions for PA membranes formed with IP, mLBL, and 3D-printing through non-equilibrium molecular dynamics simulations. Studies show that membranes fabricated with 3D-printing have similar performances to those manufactured using mLBL, quantified by water permeability, rejection of salt ions, structural integrity, and porosity features. However, the membranes formed with IP exhibit faster water transport, lower rejection, worse structural integrity, and more inhomogeneous network pores than those constructed using mLBL and 3D-printing. The unconnected water-accessible space governs water transport for PA membranes formed with mLBL and 3D-printing, which offers the impermanent open-closed pores that enable water to jump through PA membranes. In contrast, the permeated water-enterable space plays a prominent role in water movement across the PA membrane formed with IP, providing a continuous transport channel at high pressure. Importantly, we observe the more significant compaction features at high pressure for PA membranes formed with IP than mLBL and 3D printing. In short, these findings provide a comprehensive understanding of existing membrane preparation technologies. It also provides a guide for developing the new membrane preparation process at the molecular level.

3D-printing↗