Search NASASearch

SEARCH · Search NASA

Results for “STIG”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Intern Poster: STIG Shouldn't Drop ACID

STIG (Structured Threat Intelligence Graph) is an open-source graph database tool from INL. It’s used to create and process cyber intelligence graphs, which are shared in the cyber threat intelligence community and used to train INL machine learning products like @DisCo. For quality machine learning and critical infrastructure defense, STIG’s database must be ACID: Atomic, Consistent, Isolated, Durable. Various ACID tests were designed and applied to STIG to ensure its behavior follows these properties.

99 - GENERAL AND MISCELLANEOUS

Collection And Analysis Of Telemetry For The Cyote Heuristic

CATCH CLI focuses on gathering telemetry data, storing it in the Neo4j database, querying for Mitre ATT&CK patterns, and creating STIX 2.1 reports. Key Components: Analysis Modules: Analyze data to detect attack patterns. GoSTOTS Collection Engines: Collect telemetry data. These tools can be used together or individually. Analysis modules rely on data from specific engines to identify attack patterns. Source Code Organization: Engines: CATCH/catch/cmd/collection Modules: CATCH/catch/cmd/analysis CGUI Overview CATCH Graphical User Interface (CGUI) offers a graphical shell to execute CATCH CLI, allowing easy editing of: Analysis Modules Database configurations Profiles (collection and device settings) Neo4j Overview Neo4j is a graph database using the Cypher query language, storing data in JSON. It seamlessly integrates with STIX 2.1 data for: Data Submission: CATCH Collection Engines Data Querying: Analysis Modules CATCH modifies STIX 2.1 data for Neo4j submission and reverts it back during querying. STIG Overview Structured Threat Intelligence Graph (STIG) is a tool for creating, editing, querying, analyzing, and visualizing threat intelligence using STIX 2.1 and storing data in Neo4j. Usage Tools can be run: Manually (CLI): Refer to CATCH documentation User Interface: Run ./cgui/CGUI or go run ./cgui/ Additional Information Logging System: Detailed in the config documentation Further Documentation: Available for CATCH and CGUI

Madsen, MichaelJ. [Idaho National Laboratory (INL)

Evidence-based Graph Adversary Mapping (EGRAM) [Poster]

Cybersecurity companies such as CrowdStrike, Dragos, Microsoft and Unit 42 categorize Advanced Persistent Threats (APTs) using their own naming schemes. As a result, these APTs are mapped to different malware sources and campaigns, all from differing sources, leading to inconsistent mapping. Inconsistent mapping causes confusion and adds further obscurity around these groups, making it difficult to track and mitigate APT cyberattacks. The Evidence-based Graph Adversary Mapping (EGRAM) tool remediates the mapping challenge by collecting, updating and converting adversary data and their sources into a valid, codified STIX v2.1 bundle which is then stored in a Neo4j graph database. It utilizes graph traversal methods and centrality analysis to generate actionable information as a Structured Threat Intelligence Graph (STIG), based on user queries. EGRAM exists as Python code and a Jupyter Notebook that acts as a searchable, evidence-based, source of intelligence for APT groups’ artifacts and cyber campaigns.

24 - POWER TRANSMISSION AND DISTRIBUTION

Zapiary: Creating Visibility in IOT Networks

Zigbee and Z-Wave are the main networking protocols used by low-power Internet of Things (IOT) devices. These protocols use low frequencies. Mesh architecture, and unique address formats that make them not compatible with traditional network traffic tools like IX-Discovery Tools. Zapiary is a software that takes CSV files with Zigbee and Z-Wave traffic and generates Structured Threat Information eXpression (STIX) JSON bundles illustrating the communication within IOT networks. The bundles can then be viewed within Structured Threat Intelligence Graph (STIG) or used with AI/ML models to provide deeper visibility into nodes that make up the network and the ability to trend the mesh network over time.

24 POWER TRANSMISSION AND DISTRIBUTION

Unraveling plant–microbe symbioses using single-cell and spatial transcriptomics

Plant-microbe symbioses require intense interaction and genetic coordination to successfully establish in specific cell types of the host and symbiont. Traditional RNA-seq methodologies lack the cellular resolution to fully capture these complexities, but single-cell and spatial transcriptomics (ST) are now allowing scientists to probe symbiotic interactions at an unprecedented level of detail. Here, we discuss the advantages that novel spatial and single-cell transcriptomic technologies provide in studying plant-microbe endosymbioses and highlight key recent studies. Finally, we consider the remaining limitations of applying these approaches to symbiosis research, which are mainly related to the simultaneous capture of both plant and microbial transcripts within the same cells.

59 BASIC BIOLOGICAL SCIENCES

Defect Complexes in CrSBr Revealed Through Electron Microscopy and Deep Learning

Atomic defects underpin the properties of van der Waals materials, and their understanding is essential for advancing quantum and energy technologies. Scanning transmission electron microscopy is a powerful tool for defect identification in atomically thin materials, and extending it to multilayer and beam-sensitive materials would accelerate their exploration. Here, we establish a comprehensive defect library in a bilayer of the magnetic quasi-1D semiconductor CrSBr by combining atomic-resolution imaging, deep learning, and calculations. We apply a custom-developed machine learning work flow to detect, classify, and average point vacancy defects. This classification enables us to uncover several distinct Cr interstitial defect complexes, combined Cr and Br vacancy defect complexes, and lines of vacancy defects that extend over many unit cells. We show that their occurrence is in agreement with our computed structures and binding energy densities, reflecting the intriguing layer interlocked crystal structure of CrSBr. Our ab initio calculations show that the interstitial defect complexes give rise to highly localized electronic states. These states are of particular interest due to the reduced electronic dimensionality and magnetic properties of CrSBr and are, furthermore, predicted to be optically active. Our results broaden the scope of defect studies in challenging materials and reveal new defect types in bilayer CrSBr that can be extrapolated to the bulk and to over 20 materials belonging to the same FeOCl structural family.

deep learning

SEAFORML (Smart Exploration and Analysis For Optimal and Robust Machine Learning)

The poster discusses data analysis of the WAVgraph database and applied machine learning methods for it. The database is a long-term project that seeks to be a comprehensive repository of information on cyber threats and is updated regularly. It was previously unanalyzed and unexplored. The goal was to learn more about it and its contents in order to have a better understanding and enable better use. The data analysis and discovery enabled further exploration through natural language processing, similarity, and clustering methods. The poster shows some of the insights from the analysis and explains the methods used for the machine learning applications.

24 - POWER TRANSMISSION AND DISTRIBUTION