Search NASA⌕ Search

SEARCH · Search NASA

Results for “cyber security, mobile or remote access”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Precursor Analysis Report: Remote Access Attack on Oldsmar Water Treatment Facility 2021

The Remote Access Attack on Oldsmar Water Treatment Facility 2021 Precursor Analysis Report leverages publicly available information about the Oldsmar cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. On 5 February 2021, an adversary gained unauthorized remote access to Bruce T. Haddock Water Treatment Plant in Oldsmar, Florida, which provides treated water to 15,000 customers. The adversary accessed the facility’s Supervisory Control and Data Acquisition (SCADA) workstation and human machine interface (HMI) to change the chemical concentration of sodium hydroxide, commonly referred to as lye and used to regulate acidity levels, from 100 parts per million (PPM) to 11,100 PPM. The chemical was raised to lethal levels that if ingested could lead to serious soft tissue damage, burns, or even death. The facility, however, had redundancies and alarms in place to alert personnel of dangerous chemical levels, and facility officials stated it would have taken 24 to 36 hours for the chemical changes to affect the water supply. Researchers and analysts identified six unique techniques utilized during the attack with a total of 23 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Four of the identified techniques used during the Oldsmar cyber attack were precursors to the triggering event. Analysis identified 21 observables associated with these precursor techniques, 20 of which were assessed to have an increased likelihood of being perceived in the minutes preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Ultra: Underwater Laser Telecommunications & Remote Access (Final Report)

High speed wireless communication has proven elusive in subsea environments due to the inherent bandwidth limitations of acoustics and range limitations of other transmission modalities. A truly connected subsea system necessitates a high-speed, resilient architecture that can enable the integration of new sensor technologies and edge analytics and allow closed-loop monitoring and control of subsea operations for integrity monitoring and optimization. Like terrestrial Internet of Things applications, the realization of this “digital subsea” vision requires the application of high speed, point-to-point wireless technologies to complement rather than replace “hard-wired” communications such as optical fiber or acoustic systems. This work addresses the development of ULTRA (Underwater LASER Telemetry and Remote Access), an ultra-long range underwater laser communications system for use in critical points of the subsea communications architecture to increase reliability, operational flexibility, and reduce communication system maintenance associated with physical subsea connections.

02 PETROLEUM↗

Quantum Lock Technologies: Innovation Crossroads Final Report

At Quantum Lock Technologies, our mission is to use future-proof hardware and software to bridge the gap between physical access control and cyber security. Physical security includes access to doors, lockboxes/containers, and machinery/robots. Connecting physical access control to the cloud allows for remote detection, fast ledger updates, and mobile or remote access. However, this also opens physical security up to the world of cyber-attacks. At Quantum Lock, we use quantum random number generation to generate completely random and unpredictable digital keys to be used by connected equipment in a facility. This quantum technology is then paired with end-to-end encryption and a one-time-key communication protocol to ensure the highest level of security. Through the Innovation Crossroads program at Oak Ridge National Laboratory, we have developed benchtop prototypes of our technology, connected with utility boards as our first target customers, and prepared for our first pilot with customers (target end of summer 2022). Below is a photograph of myself at an energy substation where we plan to eventually apply our technology.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

HPC Campaign Management: Remote data access with user-defined error bound using ADIOS and ZFP

Remote access to large-scale scientific datasets, like those generated by combustion simulations or other high-performance computing (HPC) applications, presents a significant challenge. Downloading entire datasets is often impractical due to their size and the bandwidth limitations of typical networks. To address this challenge, we propose a novel approach that enables efficient remote access to large datasets distributed across multiple facilities. Our method enables technologies to download only the data values of a select variable, in a select region of interest, to a user-defined accuracy. For this purpose, we extended the ADIOS IO library to provide read functions with user-defined accuracy, a remote data server that understands multidimensional selections of specific variables, steps and accuracy from an ADIOS dataset, and which uses lossy compression on the remote site to reduce the data to be transferred back to the client. In addition, our extension of the ADIOS library collects metadata from multiple datasets in small files called Campaign Archives, which can be shared among project participants on any HPC, cloud or laptop, and which can easily facilitate the discovery of content and pointers to the data location as well as remote access to the data by local tools as if data was local. This feature called Campaign Management, enables a group of scientists to manage related datasets stored in multiple files, across multiple facilities as if it was in a single file/database. We demonstrate the effectiveness of our approach using a 1.5 TB dataset from the S3D combustion simulation on Frontier at the Oak Ridge Leadership Facility. Even a single variable from this dataset, at 64 GB, is too large to be processed on a standard laptop. We show two different reading patterns for 2D plots and 3D visualization, with careful settings that a scientist studying combustion data would do and show that running the same Python scripts on Frontier directly takes comparable time than running them on the local laptop with remote access to the data on Frontier.

Podhorszki, Norbert [ORNL] (ORCID:000000019647542X↗

CRADA Number NFE-20-08292 with Quantum Lock Technologies LLC (CRADA Final Report)

At Quantum Lock Technologies, our mission is to use future-proof hardware and software to bridge the gap between physical access control and cyber security. Physical security includes access to doors, lockboxes/containers, and machinery/robots. Connecting physical access control to the cloud allows for remote detection, fast ledger updates, and mobile or remote access. However, this also opens physical security up to the world of cyber-attacks. At Quantum Lock, we use quantum random number generation to generate completely random and unpredictable digital keys to be used by connected equipment in a facility. This quantum technology is then paired with end-to-end encryption and a one-time-key communication protocol to ensure the highest level of security. Through the Innovation Crossroads program at Oak Ridge National Laboratory, we have developed benchtop prototypes of our technology, connected with utility boards as our first target customers, and prepared for our first pilot with customers (target end of summer 2022).

97 MATHEMATICS AND COMPUTING↗

Quantum Lock Technologies: Innovation Crossroads Final CRADA Report

At Quantum Lock Technologies, our mission is to use future-proof hardware and software to bridge the gap between physical access control and cyber security. Physical security includes access to doors, lockboxes/containers, and machinery/robots. Connecting physical access control to the cloud allows for remote detection, fast ledger updates, and mobile or remote access. However, this also opens physical security up to the world of cyber-attacks. At Quantum Lock, we use quantum random number generation to generate completely random and unpredictable digital keys to be used by connected equipment in a facility. This quantum technology is then paired with end-to-end encryption and a one-time-key communication protocol to ensure the highest level of security. Through the Innovation Crossroads program at Oak Ridge National Laboratory, we have developed benchtop prototypes of our technology, connected with utility boards as our first target customers, and prepared for our first pilot with customers (target end of summer 2022). Below is a photograph of myself at an energy substation where we plan to eventually apply our technology.

42 ENGINEERING↗

Advancing Conduction-Cooled 650 MHz SRF Technology for Industrial Accelerators at Fermilab's IARC

The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator’s control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility—attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications

Ji, Y. [Fermilab] (ORCID:0000000233981752)↗

Advancing Conduction-Cooled 650 MHZ SRF Technology for Industrial Accelerators at Fermilab S IARC

The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator's control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications.

Ji, Yichen [Fermilab]↗

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Node-red Software Architecture For Soec System Control

The software workflows that have been developed are open-source and therefore can be accessed and utilized by researchers and students all around the world for free of cost. The software is flexible and easily modifiable to suit the needs for testing bench-scale to system-level setups, and is not limited to just hydrogen generation facilities. The web-interface of the code allows for easy remote access and management, which is especially useful for distributed systems. This is more challenging with traditional PLCs, which often require direct connections or specialized software, making remote troubleshooting more cumbersome. Additionally, since the underlying interface is open-source, with an active community contributing to its development, regular updates, new features, and a wealth of community support and shared solutions will keep improving the overall architecture without excessive fees for upgrades.

Shigrekar, Amey [Idaho National Laboratory (INL), ↗

DGaaS: GPU as a Service on Distributed Computing System

In the rapidly evolving landscape of scientific computing, Graphics Processing Units (GPUs) have become indispensable for their unparalleled ability to handle parallel tasks in complex calculations, simulations, and data analysis. Their utility is further magnified in machine learning and AI applications, where they significantly accelerate model training and predictive analytics. Within this context, the Triton Inference Server emerges as a pivotal open-source tool, specializing in AI inferencing and optimizing GPU utilization across various platforms and frameworks. This paper presents an in-depth study on distributed High Throughput Computing (HTC), specifically focusing on the HTCondor framework and its resource provisioning tools, GlideinWMS and HEPCloud. These systems enable large-scale scientific experiments like CMS and DUNE to efficiently access and utilize vast computational resources. The paper explores the core architectural components of GlideinWMS, including jobs, user pools, and worker nodes, and discusses their integration with GPUs and the Triton server. The primary aim of this research is to develop a solution that optimizes GPU utilization by leveraging Glideins and containers. This approach allows computational jobs, particularly those involving AI models, to use GPUs only when essential, thereby facilitating efficient sharing of limited GPU resources. To validate this architecture, the study conducted three key tests involving custom scripts, container-based servers, and Triton server deployments. However, the study faces challenges, notably in locating the Triton server and ensuring secure remote access. To address these issues, future work will focus on developing a proxy mechanism and enhancing security protocols. In conclusion, this study offers a comprehensive roadmap for effective and efficient GPU utilization in distributed High Throughput Computing. It aims to contribute significantly to the scientific community by solving pressing problems and implementing robust solutions in collaboration with the GlideinWMS and HEPCloud teams. The research sets the stage for a more efficient, scalable, and cost-effective paradigm in scientific computing.

97 MATHEMATICS AND COMPUTING↗

Extending Rucio with modern cloud storage support

Rucio is a software framework designed to facilitate scientific collaborations in efficiently organising, managing, and accessing extensive volumes of data through customizable policies. The framework enables data distribution across globally distributed locations and heterogeneous data centres, integrating various storage and network technologies into a unified federated entity. Rucio offers advanced features like distributed data recovery and adaptive replication, and it exhibits high scalability, modularity, and extensibility. Originally developed to meet the requirements of the high-energy physics experiment ATLAS, Rucio has been continuously expanded to support LHC experiments and diverse scientific communities. Recent R&D projects within these communities have evaluated the integration of both private and commercially-provided cloud storage systems, leading to the development of additional functionalities for seamless integration within Rucio. Furthermore, the underlying systems, FTS and GFAL/Davix, have been extended to cater to specific use cases. This contribution focuses on the technical aspects of this work, particularly the challenges encountered in building a generic interface for self-hosted cloud storage, such as MinIO or CEPH S3 Gateway, and established providers like Google Cloud Storage and Amazon Simple Storage Service. Additionally, the integration of decentralised clouds like SEAL is explored. Key aspects, including authentication and authorisation, direct and remote access, throughput and cost estimation, are highlighted, along with shared experiences in daily operations.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

Scalable fabrication of an array-type fixed-target device for automated room temperature X-ray protein crystallography

X-ray crystallography is one of the leading tools to analyze the 3-D structure, and therefore, function of proteins and other biological macromolecules. Traditional methods of mounting individual crystals for X-ray diffraction analysis can be tedious and result in damage to fragile protein crystals. Furthermore, the advent of multi-crystal and serial crystallography methods explicitly require the mounting of larger numbers of crystals. To address this need, we have developed a device that facilitates the straightforward mounting of protein crystals for diffraction analysis, and that can be easily manufactured at scale. Inspired by grid-style devices that have been reported in the literature, we have developed an X-ray compatible microfluidic device that can be used to trap protein crystals in an array configuration, while also providing excellent optical transparency, a low X-ray background, and compatibility with the robotic sample handling and environmental controls used at synchrotron macromolecular crystallography beamlines. At the Stanford Synchrotron Radiation Lightsource (SSRL), these capabilities allow for fully remote-access data collection at controlled humidity conditions. Furthermore, we have demonstrated continuous manufacturing of these devices via roll-to-roll fabrication to enable cost-effective and efficient large-scale production.

chemical engineering↗

The extended ‘stellar halo’ of the Ursa Minor dwarf galaxy

Stellar candidates in the Ursa Minor (UMi) dwarf galaxy have been found using a new Bayesian algorithm applied to Gaia EDR3 data. Five of these targets are located in the extreme outskirts of UMi, from ∼5 to 12 elliptical half-light radii (r h ), where r h (UMi) = 17.32 ± 0.11 arcmin, and have been observed with the high-resolution Gemini Remote Access to CFHT ESPaDOnS Spectrograph at the Gemini North telescope. Precise radial velocities (σ RV < 2 km s −1 ) and metallicities (σ [Fe/H] < 0.2 dex) confirm their memberships of UMi. Detailed analysis of the brightest and outermost star (Target 1, at ∼12r h ), yields precision chemical abundances for the α (Mg, Ca, and Ti), odd-Z (Na, K, and Sc), Fe-peak (Fe, Ni, and Cr), and neutron-capture (Ba) elements. With data from the literature and APOGEE data release 17, we find the chemical patterns in UMi are consistent with an outside-in star-formation history that includes yields from core-collapse supernovae, asymptotic giant branch stars, and Type Ia supernovae. Evidence for a knee in the [α/Fe] ratios near [Fe/H] ∼ −2.1 indicates a low star-formation efficiency similar to that in other dwarf galaxies. Detailed analysis of the surface number density profile shows evidence that UMi’s outskirts have been populated by tidal effects, likely as a result of completing multiple orbits around the Galaxy.

79 ASTRONOMY AND ASTROPHYSICS↗

Device-Centric Firmware Malware Detection for Smart Inverters using Deep Transfer Learning

Since future power grids are inverter-dominant grids and inverters are getting smarter by incorporating remote access and seamless firmware update, it is anticipated that malware attackers will directly target smart inverters. However, malware threats targeting smart inverters have been less studied yet. This paper explores potential malware attacks targeting smart inverters and proposes a deep transfer-learning (DTL)-based malware detection framework for smart inverters. The proposed DTL method can significantly reduce development time and efforts for an artificial intelligence-based malware detection algorithm while improving detection accuracy. The experimental result shows that the proposed method achieves 98% of firmware malware detection accuracy. Furthermore, this approach will be transformative to other smart grid devices enabling seamless firmware update.

artificial intelligence↗

LatticeAnalytics: Strut-Level Visualization and Inspection of Additively Manufactured Lattice Structures

Additive manufacturing (AM) is revolutionizing the production of custom components with complex internal geometries, essential for high-performance applications in diverse fields such as medicine and defense. These AM parts optimize strength while minimizing weight by utilizing internal lattice structures consisting of large quantities of small interconnected struts. However, the complexity of these structures, combined with the challenges of using X-ray Computed Tomography (XCT) data, makes validation of part reliability difficult. This ultimately inhibits the development of novel parts for our collaborating material scientists. Here, we introduce LatticeAnalytics, a novel framework specifically designed for visual inspection of defects in these lattice structures. Our framework offers an end-to-end solution that includes the data management of XCT scans, enables remote access for geographically dispersed teams through a web-based dashboard, and incorporates novel visualizations. Our analysis is facilitated by a coarse alignment between the lattice’s nominal model, a spatial graph, and the XCT data. We employ a simple VR-based approach for fast and rough alignment, followed by an offline registration and identification of the struts. With the nodes and struts aligned and identified in the volume, our framework allows querying of subvolumes containing a single strut at multiple resolutions. This avoids computation over the entire lattice and also allow for easy parallelization of down-stream computations, such as strut-specific metrics. To depict a fast overview of the strut quality, we introduce two innovative visual encodings, crucial for our collaborators’ research in creating novel AM parts: the Contour View and the Roughness Map, which depict critical geometrical and surface features of individual struts in standardized two 2D views. We evaluated the integrated system through expert interviews. The feedback confirms the framework’s practicality and its effectiveness in enhancing current inspection workflows. It solves major bottlenecks for our collaborators, ultimately helping them create novel parts with advanced properties.

Miao, Haichao [Lawrence Livermore National Laborat↗

Timing Distribution Test for Mu2e Experiment

Various tests and reconfigurations have been made to improve the timing distribution for the TDAQ subsystem of the Mu2e experiment. Additionally, efforts have been made to allow remote access to various teams involved in the development and testing of the DIRAC board.

Dewey, Brianna↗

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY↗