Search NASASearch

SEARCH · Search NASA

Results for “STIX”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Nvd Search To Stix

This code is a python based application that queries the National Vulnerability Database (NVD) API search term and CPE endpoints. It then sifts through the API response and uses the STIX2 python package to create STIX SDOs, SROs, and SCOs from the applicable data. If there are CWEs associated with the bundle, it queries the OpenCVE API for information on the weakness, then translates that data to STIX as well. It then combines all the data into a STIX bundle and outputs it to a JSON file.

Beckman, BryanR [Idaho National Laboratory (INL),

Simulations of ICRF Heating for SPARC during First Campaign and Primary Reference-Like Discharge using the Stix Code

High magnetic field tokamaks, like SPARC, rely on ion cyclotron radio frequency heating (ICRF) to reach fusion relevant temperatures. The SPARC tokamak will have 14 ICRF antennas in 7 toroidal locations delivering > 20 MW of power to the plasma. New capabilities with the full wave cold plasma solver, Stix, now allow for resolving the wave-particle resonances using lower order thermal corrections to capture core absorption of Landau damping and ion resonances in devices like SPARC. Favorable comparisons to the TORIC codes give confidence in the single pass absorption of this model to accurately capture the strength of edge interactions of the RF. Using this new dielectric formulation in the Stix code, simulations of the 2D poloidal cross section of SPARC are completed for the first campaign and primary reference-like discharges (PRD-like). A scan of the minority ion concentrations of helium-3 is performed and shows the expected behavior that as the helium-3 decreases the amount of single pass absorption also decreases which is seen in both scenarios. Additionally, both scenarios show only slight differences in single-pass absorption for the range of 3% to 5% helium-3 allowing for more flexibility in experiments. This study also highlights the differences between the first campaign and PRD-like with the first campaign discharges showing much more multi-pass absorption and an effect of confining the wave to a smaller portion of the cross-section due to the fast wave cut-off. This latter result suggests that far-field sheath rectification at the high-field side would be minimal for the first campaign scenario.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY

A comparison of coupling efficiencies for a Stix coil and an m equals 1 coil

This theoretical and experimental study compares the ion-cyclotron wave generating characteristics of a Stix coil (which generates waves with azimuthal mode number m = 0) with those of a coil which produces primarily m = + or -1 ion-cyclotron modes. The theoretical work of J.E. Hipp, which predicted very good coupling for the m = 1 coil, was extended to determine the scaling laws for plasma column radius and coil wavelength. Experimentally, an m = 1 coil and an m = 0 coil were used to generate ion-cyclotron waves on a beam generated plasma column with electron density = 10 to the 12th power/cu cm. Coupling resonances with peak efficiencies of approximately 40 to 50 percent were measured for both coils in low power (approximately 10k W) experiments. For equal power transfer to the plasma, the m = 0 coil voltage was more than a factor of two greater than that for the m = 1 coil.

Sigman, D. R.

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN

Collection And Analysis Of Telemetry For The Cyote Heuristic

CATCH CLI focuses on gathering telemetry data, storing it in the Neo4j database, querying for Mitre ATT&CK patterns, and creating STIX 2.1 reports. Key Components: Analysis Modules: Analyze data to detect attack patterns. GoSTOTS Collection Engines: Collect telemetry data. These tools can be used together or individually. Analysis modules rely on data from specific engines to identify attack patterns. Source Code Organization: Engines: CATCH/catch/cmd/collection Modules: CATCH/catch/cmd/analysis CGUI Overview CATCH Graphical User Interface (CGUI) offers a graphical shell to execute CATCH CLI, allowing easy editing of: Analysis Modules Database configurations Profiles (collection and device settings) Neo4j Overview Neo4j is a graph database using the Cypher query language, storing data in JSON. It seamlessly integrates with STIX 2.1 data for: Data Submission: CATCH Collection Engines Data Querying: Analysis Modules CATCH modifies STIX 2.1 data for Neo4j submission and reverts it back during querying. STIG Overview Structured Threat Intelligence Graph (STIG) is a tool for creating, editing, querying, analyzing, and visualizing threat intelligence using STIX 2.1 and storing data in Neo4j. Usage Tools can be run: Manually (CLI): Refer to CATCH documentation User Interface: Run ./cgui/CGUI or go run ./cgui/ Additional Information Logging System: Detailed in the config documentation Further Documentation: Available for CATCH and CGUI

Madsen, MichaelJ. [Idaho National Laboratory (INL)

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION

Automated Generation of Graph-based Cyber Threat Intel

With the advancement of AI technology and tools, specifically in the cybersecurity domain, both cyber defenders and threat actors are continuously adapting the use of these capabilities to expedite their operations. With this phenomenon, threat intelligence that is up to date, refreshable, and has relevant context to a specific threat becomes more and more important as it enables cybersecurity professionals to gain insight into relevant data and relationships to guide their operations. This project enables users to frequently aggregate threat intelligence from various sources, such as vendor vulnerability advisories affecting critical infrastructure, malware reports, and adversary writeups into a centralized, standardized database. The project utilizes the Structured Threat Intelligence eXpression (STIX) for a standardized, shareable threat intelligence data format and Neo4j as a graph database solution to store STIX nodes and relationships. Initial results of the project include datasets of over 8,000 nodes and 20,000 relationships extracted from over 500 data sources that have been released within the past month.

Threat Intelligence

A Privacy-Preserving Cyber Threat Intelligence Sharing System

Cyber Threat Intelligence (CTI) is a key resource for developing defensive strategies against potential cyber adversaries. Entities typically access CTI through open-source platforms, national agencies, or specialized commercial services. However, the bi-directional exchange of CTI is hindered by organizational trust boundaries, which complicate the sharing processes between entities and CTI providers. Centralized CTI services benefit from receiving suspicious cyber observables such as IP addresses, domain names, and email addresses from various entities. The aggregation allows for the correlation of widespread adversarial activities to enhance the alert and response mechanisms across the network of involved parties. Despite these benefits, openly sharing such observables incurs potential legal, regulatory, and reputational risks for the disclosing entities.This paper introduces a system designed to facilitate the secure exchange of cyber observables across trust boundaries without compromising the anonymity of the sharing entities. Here, we propose an architecture that leverages common web protocols alongside zero-knowledge proofs to authenticate members while maintaining anonymity. Additionally, we outline a privacy model tailored for STIX (Structured Threat Information eXpression) cyber observables to minimize the risk of inadvertently disclosing private information. Through our threat models, we assess the privacy implications of our proposed system and demonstrate its potential to enhance collaborative cyber defense efforts without exposing entities to undue risk.

BBS+ Signatures

Evidence-based Graph Adversary Mapping (EGRAM) [Poster]

Cybersecurity companies such as CrowdStrike, Dragos, Microsoft and Unit 42 categorize Advanced Persistent Threats (APTs) using their own naming schemes. As a result, these APTs are mapped to different malware sources and campaigns, all from differing sources, leading to inconsistent mapping. Inconsistent mapping causes confusion and adds further obscurity around these groups, making it difficult to track and mitigate APT cyberattacks. The Evidence-based Graph Adversary Mapping (EGRAM) tool remediates the mapping challenge by collecting, updating and converting adversary data and their sources into a valid, codified STIX v2.1 bundle which is then stored in a Neo4j graph database. It utilizes graph traversal methods and centrality analysis to generate actionable information as a Structured Threat Intelligence Graph (STIG), based on user queries. EGRAM exists as Python code and a Jupyter Notebook that acts as a searchable, evidence-based, source of intelligence for APT groups’ artifacts and cyber campaigns.

24 - POWER TRANSMISSION AND DISTRIBUTION

Power coupled to the slow wave resonance cone in cold plasma

We consider the power coupled to the plasma from a cylindrical source emitting resonance cones, propagative slow waves which exist in low density magnetized plasmas when the signs of the Stix parameters S and P differ. In this work, we calculate this power for the first time for any collisionality, and show that it remains finite in the cold collisionless limit, even as the radiofrequency electric field itself, and the associated power absorption density, is singular. We give the main parameter dependencies of the coupled power.

Tierens, Wouter [ORNL] (ORCID:0000000269798140)

Eev (enrich Enforce Validate) With Cpefinder

This code is designed to take an existing STIX bundle with vulnerability data and enrich it with additional potential vulnerabilities to provide further insight during threat analysis. It also acts as a launch platform for other enrichments tools. The additional tools include, WAVgraph and STIXEnforcer.

Beckman, BryanR [Idaho National Laboratory (INL),

Operating features of an ion-cyclotron-wave plasma apparatus running in the RF-sustained mode

An experimental study has been made of an ion-cyclotron-wave apparatus operated in the RF-sustained mode. This is a mode in which the Stix RF coil both propagates the waves and maintains the plasma. Problems associated with this method of operation are presented. Some factors that are important to the coupling of RF power are noted. In general, the wave-propagation and wave-damping data agree with theory. Some irregularities in wave fields are observed. Maximum ion temperature is 870 eV at a density of 5 times 10 to the 12th power per cubic centimeter and RF power of 90 kW. Coupling efficiency is 70 percent.

Swett, C. C.

Performance of an ion-cyclotron-wave plasma apparatus operated in the radiofrequency sustained mode

An experimental study has been made of an ion-cyclotron-wave apparatus operated in the RF-sustained mode, that is, a mode in which the Stix RF coil both propagates the waves and maintains the plasma. Problems associated with this method of operation are presented. Some factors that are important to the coupling of RF power are noted. In general, the wave propagation and wave damping data agree with theory. Some irregularities in wave fields are observed. Maximum ion temperature is 870 eV at a density of five times 10 to the 12th power cu cm and RF power of 90 kW. Coupling efficiency is 70 percent.

Swett, C. C.

Small amplitude waves in a hot relativistic two-fluid plasma

The dispersion relation for small amplitude waves in a hot relativistic plasma embedded in a uniform magnetic field is derived. Four plasma modes exist for propagation oblique to the magnetic field, and the mode properties are summarized in a hot relativistic generalization of the cold plasma pond diagram of Stix (1962). The two-fluid approximation is considered, and two-fluid equations are applied in this procedure which summarizes properties of linear waves in an unbounded magnetized relativistic plasma by means of a parameter-space diagram of wave phase velocity.

Hyun, S.