Search NASA⌕ Search

SEARCH · Search NASA

Results for “Security Information and Event Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Mapping SIEM Vulnerabilities in STIG

SIEM (Security Information and Event Management) tools monitor network traffic and allow users to quickly detect problems in their networks. Because of the valuable information processed by SIEM tools, it is important to understand their vulnerabilities. STIG (Structured Threat Intelligence Graph) is an application created at INL used to visualize data related to cyber threats. Using STIG can allow users to understand vulnerabilities related to their SIEM products and how to protect their systems.

99 GENERAL AND MISCELLANEOUS↗

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING↗

What Happened, and Why: Toward an Understanding of Human Error Based on Automated Analyses of Incident Reports

The objective of the Aviation System Monitoring and Modeling project of NASA's Aviation Safety and Security Program was to develop technologies to enable proactive management of safety risk, which entails identifying the precursor events and conditions that foreshadow most accidents. Information about what happened can be extracted from quantitative data sources, but the experiential account of the incident reporter is the best available source of information about why an incident happened. In Volume I, the concept of the Scenario was introduced as a pragmatic guide for identifying similarities of what happened based on the objective parameters that define the Context and the Outcome of a Scenario. In this Volume II, that study continues into the analyses of the free narratives to gain understanding as to why the incident occurred from the reporter s perspective. While this is just the first experiment, the results of our approach are encouraging and indicate that it will be possible to design an automated analysis process guided by the structure of the Scenario that can achieve the level of consistency and reliability of human analysis of narrative reports.

Ferryman, Thomas A.↗

The design and implementation of EPL: An event pattern language for active databases

The growing demand for intelligent information systems requires closer coupling of rule-based reasoning engines, such as CLIPS, with advanced data base management systems (DBMS). For instance, several commercial DBMS now support the notion of triggers that monitor events and transactions occurring in the database and fire induced actions, which perform a variety of critical functions, including safeguarding the integrity of data, monitoring access, and recording volatile information needed by administrators, analysts, and expert systems to perform assorted tasks; examples of these tasks include security enforcement, market studies, knowledge discovery, and link analysis. At UCLA, we designed and implemented the event pattern language (EPL) which is capable of detecting and acting upon complex patterns of events which are temporally related to each other. For instance, a plant manager should be notified when a certain pattern of overheating repeats itself over time in a chemical process; likewise, proper notification is required when a suspicious sequence of bank transactions is executed within a certain time limit. The EPL prototype is built in CLIPS to operate on top of Sybase, a commercial relational DBMS, where actions can be triggered by events such as simple database updates, insertions, and deletions. The rule-based syntax of EPL allows the sequences of goals in rules to be interpreted as sequences of temporal events; each goal can correspond to either (1) a simple event, or (2) a (possibly negated) event/condition predicate, or (3) a complex event defined as the disjunction and repetition of other events. Various extensions have been added to CLIPS in order to tailor the interface with Sybase and its open client/server architecture.

Giuffrida, G.↗

Human Supervision of Autonomous Vehicle Fleet Operations and Associated Passenger Communications: Preprint

Advances in automated vehicle (AV) technology and expanded operations are rapidly emerging with Automated Mobility District (AMD) deployments in global cities. NLR's AMD research addresses critical elements of human supervision of AV fleet operations and associated passenger communications for vehicles in which no driver or safety attendant is present. Although sufficiently advanced AVs no longer have direct oversight by a driver, fleet management remains staffed with operations personnel at the operations command and control (OCC) facility. This paper examines the functionality of the OCC, drawing comparisons of how automated train control and automated people mover OCCs operate. Within an AMD, the OCC manages various vehicle types, sizes, and operational modes, including on-demand and fixed route service, to facilitate a 'network of networks' for transport within a metropolitan area. The OCC serves as oversight for multiple AV fleets assisting AVs via remote operation of vehicles, communication, and dispatching personnel to resolve problems. The OCC also coordinates system operation, geographically staging vehicles, and managing weather, police, and emergency events. Informed by traffic management center (TMC) strategies using highly integrated software and communications, OCCs facilitate seamless information flows. OCC personnel remotely assist passengers and oversee multi-party operation to ensure safety and security. Although social norms mitigate large-capacity unattended vehicle operations, social interaction in multi-party automated small vehicles has little precedent. This poses a new frontier for society and requires research to effectively understand and manage. Future research will monitor OCC implementations, passenger interfaces, and deployment scaling of initial AMD systems.

33 ADVANCED PROPULSION SYSTEMS↗

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management

This document provides the final report for the CYPRES project. The purpose is (1) to highlight and summarize its major accomplishments and (2) to provide guidance on how its outcomes have informed and can inform important additional research and technology transfer. The goal of CYPRES was the research, development, and demonstration of a security-oriented next generation cyber-physical EMS for electric power systems that detects malicious and abnormal events through the fusion of cyber and physical data. To achieve this, the CYPRES project team researched, developed, and built a prototype of the solution, referred to as the CYPRES EMS. The CYPRES EMS is a proof-of-concept cyber-physical platform that demonstrates the management of the energy system, communications, security, and cyber-physical grid modeling and analytics. As part of the capabilities of the CYPRES EMS, the team designed and developed a suite of power system applications for monitoring, risk analyses, detection, and control that are inherently cyberaware. At its core, the project aimed to research, develop, and demonstrate a security-oriented next-generation cyber-physical Energy Management System (EMS) capable of detecting malicious and abnormal events through the innovative fusion of cyber and physical data. This approach represents a fundamental shift from traditional EMS, reimagining how critical infrastructure can be protected through unified cyber-aware and physics-aware secure data flow pipelines. The project’s cornerstone deliverable, the CYPRES EMS, serves as a proof-of-concept cyber-physical platform that revolutionizes the management of energy systems, communications, security, and cyber-physical grid modeling and analytics. This prototype implements a comprehensive suite of power system applications for monitoring, risk analyses, detection, and control, all designed with inherent cyber awareness. The system’s architecture extends from end-devices in the field through to control center applications, establishing a secure and resilient control framework that addresses the challenges posed by diverse devices of unknown trustworthiness connecting to modern power systems. Through this innovative approach to deep cyber-physical situational awareness, the CYPRES project not only advances the state-of-the-art in energy infrastructure protection but also establishes a new paradigm for how EMS can be designed, deployed, and operated in an increasingly complex threat landscape. The findings and developments from this project provide crucial insights for stakeholders across the energy sector, offering a blueprint for enhancing the reliability and resilience of our nation’s critical energy infrastructure in the face of evolving cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Solutions Network Formulation Report. NASA's Potential Contributions in Remote Quorum Sensing and the Management of Harmful Algal Blooms

This candidate solution proposes to use the night-imaging capabilities of the HSTC from SAC-C and of the HSC from SAC-D/Aquarius to detect bioluminescent events associated with HABs (harmful algal blooms). Once detected, this information could be fed to the NOAA CSCOR (Center for Sponsored Coastal Ocean Research) Harmful Algal Bloom Event Response Program, which acts quickly to fund the mobilization of research teams and to engage local agencies in a response. The HSC/HSTC data can serve as input to the HABSOS decision support system to provide information on location, extent, and duration of HAB events. Society will benefit from improved protection of the health of humans beings, aquatic ecosystems, and coastal economies. This work supports coastal management, public health, and homeland security applications.

Fletcher, Rose↗

Hungary 908 Event - Risk Based Graded Approach to ITM

This presentation, Risk-Based, Graded Approach to Insider Threat Mitigation: Human Measures, introduces a structured framework for managing insider threat risk using internationally recognized guidance from the International Atomic Energy Agency (IAEA) Nuclear Security Series No. 8-G (Rev. 1) and the Joint Statement on Mitigating Insider Threats (INFCIRC/908). The presentation emphasizes that effective insider threat mitigation (ITM) depends on both positional controls, which manage inherent risk based on access, authority, and knowledge, and human measures, which address residual risk reflected in behavior, motivation, and reliability. Using a risk-informed and graded approach, the presentation outlines methods for identifying and prioritizing high-risk positions, applying layered organizational controls, and integrating human reliability mechanisms such as the Behavior Observation Program (BOP), Fitness-for-Duty (FFD) evaluations, Employee Assistance Programs (EAP), and Nuclear Security Culture (NSC). The human-focused portion examines behavioral and organizational indicators of opportunity, vulnerability, motivation, and crisis, demonstrating how early detection, deterrence, and response can prevent insider events. The session concludes with a case review of the Millstone Nuclear Power Station incident involving engineer George Galatis. The case illustrates how weak leadership and a poor safety culture can create conditions for failure and how a comprehensive ITM framework could have altered the outcome. The objective of this presentation is to help practitioners apply a risk-based, graded philosophy to human factors and promote a culture of accountability, communication, and resilience within nuclear organizations.

99 - GENERAL AND MISCELLANEOUS↗

Supply Chain Management in Cyber Grid Guard Framework

Grid modernization has impeded innovative power grid applications and energy resources that are increasingly distributed. Blockchain/distributed ledger technology (DLT) has the potential to enhance the resilience of the electric infrastructure, particularly in a decentralized and distributed environment. The benefits of blockchain are to ensure asset information and lifecycle events are secure and traceable and identify potential malicious modification of data. Oak Ridge National Laboratory (ORNL) has developed a framework, Cyber Grid Guard (CGG), incorporating blockchain. The system implements a low-energy, fast, and robust enhancement to system trustworthiness within and across electric grid systems, including substations, control centers, and metering infrastructures. Currently, one of the major concerns is supply chain attacks. There have been several recent attacks that have significantly impacted critical infrastructures and organizations around the world. This document focuses on how CGG can be used to address the supply chain issue.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Dose Coefficient Calculation for Use in Dosimetry Assessment of a Fission-Based Weapon

In the event of a fission-based weapon or improvised nuclear device (IND) detonation, dose coefficients can be harnessed to provide dose assessments for defense, emergency preparedness, and consequence management, as well as to prospectively inform the assessment of radiation biomarkers and development of medical prophylaxis countermeasures for defense and homeland security stakeholders and decision-makers. Although dose coefficients have previously been calculated for this group, they would apply specifically to the studied population, the 1945 Japanese cohort, after which their anthropomorphic computational phantoms were modeled. For this reason, applications to other populations may be limited, and instead, an assessment of a more standardized population is desired. We employed a series of computational human phantoms representing international reference individuals: UF/NCI voxel phantom series containing newborn, 1-, 5-, 10-, 15-, and 35-year-old males and females. Irradiation of the phantoms was simulated using the Monte Carlo N-Particle transport code to determine organ dose coefficients under four idealized irradiation geometries at three distances from the detonation hypocenter at Hiroshima and Nagasaki using DS02 free-in-air prompt neutron and photon fluence spectra. Through these simulations, age-specific dose coefficients were determined for individual organs. Various articulated PIMAL stylized phantoms were simulated as well to estimate the effect of body posture on dose coefficients and determine the effect of posture on dosimetric estimation and reconstruction. Results additionally demonstrate that 137 Cs and the Watt fission spectra are not ideal general surrogate sources for fission weapons, which may be considered for experimental testing of medical countermeasures. Supplementary data provided tabulates the compilation of organ dose-rate coefficients in this study.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Information Systems Coordinate Emergency Management

The rescue crews have been searching for the woman for nearly a week. Hurricane Katrina devastated Hancock County, the southernmost point in Mississippi, and the woman had stayed through the storm in her beach house. There is little hope of finding her alive; the search teams know she is gone because the house is gone. Late at night in the art classroom of the school that is serving as the county s emergency operations center, Craig Harvey is discussing the search with the center s commander. Harvey is the Chief Operating Officer of a unique company called NVision Solutions Inc., based at NASA s Stennis Space Center in Bay St. Louis, only a couple of miles away. He and his entire staff have set up a volunteer operation in the art room, supporting the emergency management efforts using technology and capabilities the company developed through its NASA partnerships. As he talks to the commander, Harvey feels an idea taking shape that might lead them to the woman s location. Working with surface elevation data and hydrological principles, Harvey creates a map showing how the floodwaters from the storm would have flowed along the topography of the region around the woman s former home. Using the map, search crews find the woman s body in 15 minutes. Recovering individuals who have been lost is a sad reality of emergency management in the wake of a disaster like Hurricane Katrina in 2005. But the sooner answers can be provided, the sooner a community s overall recovery can take place. When damage is extensive, resources are scattered, and people are in dire need of food, shelter, and medical assistance, the speed and efficiency of emergency operations can be the key to limiting the impact of a disaster and speeding the process of recovery. And a key to quick and effective emergency planning and response is geographic information. With a host of Earth-observing satellites orbiting the globe at all times, NASA generates an unmatched wealth of data about our ever-changing planet. This information can be captured, analyzed, and visualized by geographic information systems (GIS) to produce maps, charts, and other tools that can reveal information essential to a wide variety of applications including emergency management. Knowing precise, real-time information about the size, location, environmental conditions, and resulting damage of an event like a flood or wildfire as well as the location and numbers of emergency responders and other resources contributes directly to the effectiveness of disaster mitigation. The need for such information is also evident when responding to homeland security threats, such as a terrorist attack. Recognizing the value of its geospatial information resources for this and other purposes, in 1998 Stennis and the state of Mississippi partnered to form what became the Enterprise for Innovative Geospatial Solutions (EIGS) industry cluster, supporting the growth of remote sensing and GIS-based research and business. As part of EIGS, several companies partnered with NASA through dual use and Small Business Innovation Research (SBIR) contracts. Among those was NVision.

Source record↗

Space Shuttle security policies and programs

The Space Shuttle vehicle consists of the orbiter, external tank, and two solid rocket boosters. In dealing with security two major protective categories are considered, taking into account resource protection and information protection. A review is provided of four basic programs which have to be satisfied. Aspects of science and technology transfer are discussed. The restrictions for the transfer of science and technology information are covered under various NASA Management Instructions (NMI's). There were two major events which influenced the protection of sensitive and private information on the Space Shuttle program. The first event was a manned space flight accident, while the second was the enactment of a congressional bill to establish the rights of privacy. Attention is also given to national resource protection and national defense classified operations.

Keith, E. L.↗

What Happened, and Why: Toward an Understanding of Human Error Based on Automated Analyses of Incident Reports

The objective of the Aviation System Monitoring and Modeling (ASMM) project of NASA s Aviation Safety and Security Program was to develop technologies that will enable proactive management of safety risk, which entails identifying the precursor events and conditions that foreshadow most accidents. This presents a particular challenge in the aviation system where people are key components and human error is frequently cited as a major contributing factor or cause of incidents and accidents. In the aviation "world", information about what happened can be extracted from quantitative data sources, but the experiential account of the incident reporter is the best available source of information about why an incident happened. This report describes a conceptual model and an approach to automated analyses of textual data sources for the subjective perspective of the reporter of the incident to aid in understanding why an incident occurred. It explores a first-generation process for routinely searching large databases of textual reports of aviation incident or accidents, and reliably analyzing them for causal factors of human behavior (the why of an incident). We have defined a generic structure of information that is postulated to be a sound basis for defining similarities between aviation incidents. Based on this structure, we have introduced the simplifying structure, which we call the Scenario as a pragmatic guide for identifying similarities of what happened based on the objective parameters that define the Context and the Outcome of a Scenario. We believe that it will be possible to design an automated analysis process guided by the structure of the Scenario that will aid aviation-safety experts to understand the systemic issues that are conducive to human error.

Maille, Nicolas P.↗

A Simple XML Producer-Consumer Protocol

There are many different projects from government, academia, and industry that provide services for delivering events in distributed environments. The problem with these event services is that they are not general enough to support all uses and they speak different protocols so that they cannot interoperate. We require such interoperability when we, for example, wish to analyze the performance of an application in a distributed environment. Such an analysis might require performance information from the application, computer systems, networks, and scientific instruments. In this work we propose and evaluate a standard XML-based protocol for the transmission of events in distributed systems. One recent trend in government and academic research is the development and deployment of computational grids. Computational grids are large-scale distributed systems that typically consist of high-performance compute, storage, and networking resources. Examples of such computational grids are the DOE Science Grid, the NASA Information Power Grid (IPG), and the NSF Partnerships for Advanced Computing Infrastructure (PACIs). The major effort to deploy these grids is in the area of developing the software services to allow users to execute applications on these large and diverse sets of resources. These services include security, execution of remote applications, managing remote data, access to information about resources and services, and so on. There are several toolkits for providing these services such as Globus, Legion, and Condor. As part of these efforts to develop computational grids, the Global Grid Forum is working to standardize the protocols and APIs used by various grid services. This standardization will allow interoperability between the client and server software of the toolkits that are providing the grid services. The goal of the Performance Working Group of the Grid Forum is to standardize protocols and representations related to the storage and distribution of performance data. These standard protocols and representations must support tasks such as profiling parallel applications, monitoring the status of computers and networks, and monitoring the performance of services provided by a computational grid. This paper describes a proposed protocol and data representation for the exchange of events in a distributed system. The protocol exchanges messages formatted in XML and it can be layered atop any low-level communication protocol such as TCP or UDP Further, we describe Java and C++ implementations of this protocol and discuss their performance. The next section will provide some further background information. Section 3 describes the main communication patterns of our protocol. Section 4 describes how we represent events and related information using XML. Section 5 describes our protocol and Section 6 discusses the performance of two implementations of the protocol. Finally, an appendix provides the XML Schema definition of our protocol and event information.

Smith, Warren↗

Development of a Framework for Data Integration, Assimilation, and Learning for Geological Carbon Sequestration (DIAL-GCS) (Final Report)

This project aimed to develop and demonstrate a Data Integration, Assimilation, and Learning framework for geologic carbon sequestration projects (DIAL-GCS). DIAL-GCS is an intelligence monitoring system (IMS) for automating GCS closed-loop management by leveraging recent developments in machine learning technologies, complex event processing (CEP), and reduced-order modeling. The safe and efficient operation of GCS repositories requires integrated monitoring to track the injected CO¬2 as it moves within a storage reservoir. GCS projects are data intensive, as a result of proliferation of digital instrumentation and smart-sensing technologies. GCS projects are also resource intensive, often requiring multidisciplinary teams performing different monitoring, verification, accounting (MVA) tasks throughout the lifecycle of a project to ensure secure containment of injected CO2. The success of GCS thus depends in a large part on our ability to access, assimilate, and analyze heterogeneous data and information sources in a timely manner. This project included a number of meaningful and necessary tasks to transform the human domain knowledge into machine-interpretable rules for automating knowledge extraction and discovery in GCS. The specific technical objectives of the proposed DIAL-GCS project were to develop an ontology-driven GCS data management module for storing, querying, and exchanging GCS data (both historic and live sensor data) from multiple sources and in heterogeneous formats. Incorporate a CEP engine for detecting abnormal situations by seamlessly combining expert knowledge, rule-based reasoning, and machine learning. Enable uncertainty quantification and predictive analytics using a combination of coupled-process modeling, AI/ML methods, and reduced-order modeling, and integrate and demonstrate the system’s capabilities with both real and simulated data. As far as we know, this is one of the first projects aimed to develop intelligent monitoring systems (IMS) targeting the GCS. Under this project, the team had developed a large number of web applications and scientific algorithms that contribute the main theme of intelligent monitoring. The team has published more than a dozen peer reviewed papers and disseminated the research results at multiple technical meetings.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Development of Integrated Safety and Security Models for Comprehensive Reliability and Resiliency Evaluation

The security of the electric grid and supporting energy systems is crucial to national security. One of the complexities in analyzing the security of energy systems is the safety consequences that may result from accidents. For energy systems, the goal is to ensure that they operate as intended and that any consequences are mitigated or prevented. The integration of safety and security is paramount to protecting these systems from attacks and ensuring that large consequences are prevented. This report describes an integrated safety and security methodology to evaluate cybersecurity events that can lead to large consequences. This novel approach first describes how Systems-Theoretic Process Analysis (STPA) provides a digital causal analysis for Bayesian Networks (BNs). The use of STPA causal analysis provides a systematic approach to constructing BNs that adequately model cyber scenarios that result in consequences. When combined with the technical principles described in Risk-Informed Management of Enterprise Systems (RIMES), a comprehensive risk-informed cybersecurity analysis results that allows decision-makers to prioritize systems that most impact risk.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Lightning Initiation Forecasting: An Operational Dual-Polarimetric Radar Technique

The objective of this NASA MSFC and NOAA CSTAR funded study is to develop and test operational forecast algorithms for the prediction of lightning initiation utilizing the C-band dual-polarimetric radar, UAHuntsville's Advanced Radar for Meteorological and Operational Research (ARMOR). Although there is a rich research history of radar signatures associated with lightning initiation, few studies have utilized dual-polarimetric radar signatures (e.g., Z(sub dr) columns) and capabilities (e.g., fuzzy-logic particle identification [PID] of precipitation ice) in an operational algorithm for first flash forecasting. The specific goal of this study is to develop and test polarimetric techniques that enhance the performance of current operational radar reflectivity based first flash algorithms. Improving lightning watch and warning performance will positively impact personnel safety in both work and leisure environments. Advanced warnings can provide space shuttle launch managers time to respond appropriately to secure equipment and personnel, while they can also provide appropriate warnings for spectators and players of leisure sporting events to seek safe shelter. Through the analysis of eight case dates, consisting of 35 pulse-type thunderstorms and 20 non-thunderstorm case studies, lightning initiation forecast techniques were developed and tested. The hypothesis is that the additional dual-polarimetric information could potentially reduce false alarms while maintaining high probability of detection and increasing lead-time for the prediction of the first lightning flash relative to reflectivity-only based techniques. To test the hypothesis, various physically-based techniques using polarimetric variables and/or PID categories, which are strongly correlated to initial storm electrification (e.g., large precipitation ice production via drop freezing), were benchmarked against the operational reflectivity-only based approaches to find the best compromise between forecast skill and lead-time. Forecast skill is determined by statistical analysis of probability of detection (POD), false alarm ratio (FAR), Operational Utility Index (OUI), and critical success index (CSI).

Woodard, Crystal J.↗

Resilient Information Architecture Platform for Smart Grid (RIAPS)

A number of emerging trends will substantially alter the operation and control of the electric grid over the next several decades. These trends include ensuring resiliency under severe weather events, increasing integration of renewable electricity generation, supporting changing electricity demand patterns, and the improving cost effectiveness of distributed energy resources. To address these challenges, the future “Smart Grid” management will need to transition from centralized to coordinated distributed control paradigm. Reliable operation of the Smart Grid depends on distributed intelligence realized through software applications that run on distributed computing devices attached to the power system to collect data and collaboratively manage resources. However, much of the existing software for Smart Grid-enabled devices is either proprietary or developed with custom solutions, which limits interoperability among the heterogeneous devices and hinders the ability to manage system-level reliability, security, and resiliency requirements. Additionally, this approach makes Smart Grid applications hard to maintain, evolve, verify, and replace; resulting in high development and deployment costs. Further development of the Smart Grid requires a reusable software base-layer to move from hard-coded functionality to a plug-and-play architecture capable of managing system-level objectives and constraints in addition to providing consistent common services across heterogeneous devices and applications. Vanderbilt University, in collaboration with North Carolina State University and Washington State University has developed a foundation ‘software platform’ for developing and deploying robust, reliable, effective and secure software applications for the Smart Grid. The Resilient Information Architecture Platform for the Smart Grid (RIAPS) provides core services for building effective and powerful smart grid applications. It offers unique services for real-time data dissemination, fault tolerance, and coordination across apps distributed over the network.

24 POWER TRANSMISSION AND DISTRIBUTION↗