Search NASA⌕ Search

SEARCH · Search NASA

Results for “data security defense”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Data Security Defense: Modeling and Detection of Synchrophasor Data Spoofing Attack for Grid Edge

Data security and cyberattack have become critical issues in the distributed power system where adversaries can swap the source information of sensors or even spoof and alter measurements. However, the cyber security of the power system is challenged by the unpredictability and stealth of the spoofing attacks. Here, to protect the data security at the grid edge, this paper developed a synchrophasor data spoofing attack detection framework based on the time-frequency feature extraction techniques including the short-time Fourier transform (STFT) and object detection network for real-time synchrophasor data categorization and spoofing attack localization. The proposed approach outperforms earlier work in terms of spoofing attack detection and offers a vital localization function employing distributed synchrophasor sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗

AI-based Detection and Defense Against Cyberattacks in Distributed Energy Resources

This study will provide comprehensive artificial intelligence (AI)-based solution tools for network security, malware prevention, and sensor data anomaly detection for distributed energy resource (DER) research, development, and demonstration. DER technologies are energy systems (e.g., solar panels, wind turbines, and energy storage systems) that are often connected to the internet and thus vulnerable to cyberattacks. Cybersecurity should be of primary concern for DERs, which is why we propose an integrated multi-layer cyber-defense system for DERs. This system encompasses risk assessments, network security, malware prevention, and detection of anomalies in the sensor data. Implementation of a comprehensive risk assessment with an overview of the model architecture should be the primary step, and should include the potential impact of experiencing, at a given time, one or more cyberattacks on the system. The second step is to ensure that the network security includes firewalls, intrusion detection, and malware prevention. The third step is to provide solution tools that enable sensor data anomaly detection for DERs. By incorporating these considerations into DER research, development, and demonstration, organizations can help ensure the safety and security of their systems and protect against potential cyberattacks.

20 FOSSIL-FUELED POWER PLANTS↗

Multilevel Cybersecurity for Photovoltaic Systems

The motivation behind this project is to protect critical infrastructure in electric power generation pertaining to solar photovoltaic (PV) systems. This growing renewable energy resource is becoming a more vital part of the nation’s energy portfolio, particularly since it has achieved grid-parity to existing generation methods in terms of cost. It is thus vital that steps be taken to ensure the cybersecurity of these assets. The project goal was to devise a multilevel cybersecurity solution to address PV security gaps at the inverter and system levels, and field test the solution under the supervision and review of a US-based solar inverter manufacturer and PV installer/operator. A two-level cyberattack defense approach was formulated whereby the first level, the solar inverter level, hardens individual devices and achieves a deeply cyber-secure inverter. The inverter level security involves a multi-layer defense-in-depth approach for securing the inverter while also providing data for the system level algorithms. The second level, the system level, addresses intrusion detection and restoration involving an ensemble of inverters and relevant systems.

14 SOLAR ENERGY↗

Using Science Driven Technologies for the Defense and Security Applications

For the past three decades, Earth science remote sensing technologies have been providing enormous amounts of useful data and information in broadening our understanding of our home planet as a system. This research, as it has expanded our learning process, has also generated additional questions. This has further resulted in establishing new science requirements, which have culminated in defining and pushing the state-of-the-art technology needs. NASA s Earth science program has deployed 18 highly complex satellites, with a total of 80 sensors, so far and is in a process of defining and launching multiple observing systems in the next decade. Due to the heightened security alert of the nation, researchers and technologists are paying serious attention to the use of these science driven technologies for dual use. In other words, how such sophisticated observing and measuring systems can be used in detecting multiple types of security concerns with a substantial lead time so that the appropriate law enforcement agencies can take adequate steps to defuse any potential risky scenarios. This paper examines numerous NASA technologies such as laser/lidar systems, microwave and millimeter wave technologies, optical observing systems, high performance computational techniques for rapid analyses, and imaging products that can have a tremendous pay off for security applications.

Habib, Shahid↗

Rapid Monitoring and Defense Approach for Resilience Improvement of Grid Cyber Security

Cyber-physical systems and electric utilities significantly depend on the reliability and efficiency of information and operational technology. However, false data injection attacks based on synchrophasor measurement data pose a serious threat to the safe and reliable operation of modern power systems. Here, to mitigate this problem, a rapid monitoring and defense approach is proposed to defend against cyber attacks. Initially, the Time and Frequency based Convolutional neural Network (TFCN) is proposed to detect different types of attacks. Within the TFCN, the advances are that both time and frequency domain information can be fused without extra spectrum analysis methods, and can save detection time to speed the calculation efficiency using the developed time-frequency block. Next, a comprehensive defense strategy is developed for multiple cyber attacks to ensure the stability and resilience of the power system according to the feedback detection results. The advances of this strategy are that different control strategies can be automatically selected to recover the stability to the greatest extent according to the detected attacks. To verify the effectiveness of the proposed approach, the high-speed frequency measurements collected from the wide-area monitoring system are used. The results demonstrate that the cyber attack detection performance can reach 95.57% accuracy, outperforming both traditional and some advanced neural networks. Importantly, the defense strategy is conducted and verified in a modified IEEE 39 bus system as well, which illustrates profound performance in faster stability restoration.

Comprehensive defense strategy↗

Payload Performance of Third Generation TDRS and Future Services

NASA has accepted two of the 3rd generation Tracking and Data Relay Satellites, TDRS K, L, and M, designed and built by Boeing Defense, Space & Security (DSS). TDRS K, L, and M provide S-band Multiple Access (MA) service and S-band, Ku-band and Ka-band Single Access (SA) services to near Earth orbiting satellites. The TDRS KLM satellites offer improved services relative to the 1st generation TDRS spacecraft, such as: an enhanced MA service featuring increased EIRPs and G/T; and Ka-band SA capability which provides a 225 and 650 MHz return service (customer-to-TDRS direction) bandwidth and a 50 MHz forward service (TDRS-to-customer direction) bandwidth. MA services are provided through a 15 element forward phased array that forms up to two beams with onboard active beamforming and a 32 element return phased array supported by ground-based beamforming. SA services are provided through two 4.6m tri-band reflector antennas which support program track pointing and autotrack pointing. Prior to NASAs acceptance of the satellites, payload on-orbit testing was performed on each satellite to determine on-orbit compliance with design requirements. Performance parameters evaluated include: EIRP, G/T, antenna gain patterns, SA antenna autotrack performance, and radiometric tracking performance. On-orbit antenna calibration and pointing optimization was also performed on the MA and SA antennas including 24 hour duration tests to characterize and calibrate out diurnal effects. Bit-Error-Rate (BER) tests were performed to evaluate the end-to-end link BER performance of service through a TDRS K and L spacecraft. The TDRS M is planned to be launched in August 2017. This paper summarizes the results of the TDRS KL communications payload on-orbit performance verification and end-to-end service characterization and compares the results with the performance of the 2nd generation TDRS J. The paper also provides a high-level overview of an optical communications application that will augment the data rates supported by the Space Network.

RF↗

Payload Performance of TDRS KL and Future Services

NASA has accepted two of the 3nd generation Tracking and Data Relay Satellites, TDRS K, L, and M, designed and built by Boeing Defense, Space Security (DSS). TDRS K, L, and M provide S-band Multiple Access (MA) service and S-band, Ku-band and Ka-band Single Access (SA) services to near Earth orbiting satellites. The TDRS KLM satellites offer improved services relative to the 1st generation TDRS spacecraft, such as: an enhanced MA service featuring increased EIRPs and GT; and Ka-band SA capability which provides a 225 and 650 MHz return service (customer-to-TDRS direction) bandwidth and a 50 MHz forward service (TDRS-to-customer direction) bandwidth. MA services are provided through a 15 element forward phased array that forms up to two beams with onboard active beamforming and a 32 element return phased array supported by ground-based beamforming. SA services are provided through two 4.6m tri-band reflector antennas which support program track pointing and autotrack pointing. Prior to NASAs acceptance of the satellites, payload on-orbit testing was performed on each satellite to determine on-orbit compliance with design requirements. Performance parameters evaluated include: EIRP, GT, antenna gain patterns, SA antenna autotrack performance, and radiometric tracking performance. On-orbit antenna calibration and pointing optimization was also performed on the MA and SA antennas including 24 hour duration tests to characterize and calibrate out diurnal effects. Bit-Error-Rate (BER) tests were performed to evaluate the end-to-end link BER performance of service through a TDRS K and L spacecraft. The TDRS M is planned to be launched in August 2017. This paper summarizes the results of the TDRS KL communications payload on-orbit performance verification and end-to-end service characterization and compares the results with the performance of the 2nd generation TDRS J. The paper also provides a high-level overview of an optical communications application that will augment the data rates supported by the Space Network.

Laser↗

Mission Assurance Modeling and Simulation: A Cyber Security Roadmap

This paper proposes a cyber security modeling and simulation roadmap to enhance mission assurance governance and establish risk reduction processes within constrained budgets. The term mission assurance stems from risk management work by Carnegie Mellon's Software Engineering Institute in the late 19905. By 2010, the Defense Information Systems Agency revised its cyber strategy and established the Program Executive Officer-Mission Assurance. This highlights a shift from simply protecting data to balancing risk and begins a necessary dialogue to establish a cyber security roadmap. The Military Operations Research Society has recommended a cyber community of practice, recognizing there are too few professionals having both cyber and analytic experience. The authors characterize the limited body of knowledge in this symbiotic relationship. This paper identifies operational and research requirements for mission assurance M&S supporting defense and homeland security. M&S techniques are needed for enterprise oversight of cyber investments, test and evaluation, policy, training, and analysis.

Gendron, Gerald↗

Secure State Estimation with Asynchronous Measurements for Coordinated Cyber Attack Detection in Active Distribution Systems

Coordinated cyber attacks tamper with measurement data to disrupt the situational awareness of active distribution systems. Various sensors report measurements asynchronously at different rates, which introduces challenges during state estimation. In addition, this forces cyber intruders to exert greater effort to compromise multiple communication channels and launch coordinated attacks. Therefore, multi-channel and asynchronous measurements could be harnessed to develop more secure cyber defense strategies. In this paper, a prediction-correction-based multi-rate observer is designed to exploit the value of asynchronous measurements for the detection of coordinated false data injection (FDI) attacks. First, a time-function-dependent prediction-correction strategy is proposed to adjust the sampling interval for each sensor’s measurement. Then, an observer is designed based on the trade-off between estimation error and the optimal period of the most recent sampling instant, with the convergence of estimation error with the maximum permitted sampling interval. Moreover, the conditions for exponential stability are developed using the Lyapunov–Krasovskii functional technique. Next, a coordinated FDI attack detection strategy is developed based on the dual nonlinear minimization problem. The proposed attack detection and secure state estimation strategies are tested on the IEEE 13-node system. Simulation results show that these schemes are effective in enhancing attack detection based on asynchronous measurements or compromised data.

asynchronous measurements↗

Transboundary Water: Improving Methodologies and Developing Integrated Tools to Support Water Security

River basins for which transboundary coordination and governance is a factor are of concern to US national security, yet there is often a lack of sufficient data-driven information available at the needed time horizons to inform transboundary water decision-making for the intelligence, defense, and foreign policy communities. To address this need, a two-day workshop entitled Transboundary Water: Improving Methodologies and Developing Integrated Tools to Support Global Water Security was held in August 2017 in Maryland. The committee that organized and convened the workshop (the Organizing Committee) included representatives from the National Aeronautics and Space Administration (NASA), the US Army Corps of Engineers Engineer Research and Development Center (ERDC), and the US Air Force. The primary goal of the workshop was to advance knowledge on the current US Government and partners' technical information needs and gaps to support national security interests in relation to transboundary water. The workshop also aimed to identify avenues for greater communication and collaboration among the scientific, intelligence, defense, and foreign policy communities. The discussion around transboundary water was considered in the context of the greater global water challenges facing US national security.

Hakimdavar, Raha↗

Modular Software Interfaces for Revolutionary Flexibility in Space Operations

To make revolutionary improvements in exploration, space systems need to be flexible, realtime reconfigurable, and able to trade data transparently among themselves and mission operations. Onboard operations systems, space assembly coordination and EVA systems in exploration and construction all require real-time modular reconfigurability and data sharing. But NASA's current exploration systems are still largely legacies from hastily-developed, one-off Apollo-era practices. Today's rovers, vehicles, spacesuits, space stations, and instruments are not able to plug-and-play, Lego-like: into different combinations. Point-to-point dominates - individual suit to individual vehicle, individual instrument to rover. All are locally optimized, all unique, each of the data interfaces has been recoded for each possible combination. This will be an operations and maintenance nightmare in the much larger Project Constellation system of systems. This legacy approach does not scale to the hundreds of networked space components needed for space construction and for new, space-based approaches to Earth-Moon operations. By comparison, battlefield information management systems, which are considered critical to military force projection, have long since abandoned a point-to-point approach to systems integration. From a system-of-systems viewpoint, a clean-sheet redesign of the interfaces of all exploration systems is a necessary prerequisite before designing the interfaces of the individual exploration systems. Existing communications and Global Information Grid and middleware technologies are probably sufficient for command and control and information interfaces, with some hardware and time-delay modifications for space environments. NASA's future advanced space operations must also be information and data compatible with aerospace operations and surveillance systems being developed by other US Government agencies such as the Department of Homeland Security, Federal Aviation Administration and Department of Defense. This paper discusses fundamental system-of-systems infrastructure: approaches and architectures for modular plug-and-play software interfaces for revolutionary improvements in flexibility, modularity, robustness, ease of maintenance, reconfigurability, safety and productivity. Starting with middleware, databases, and mobile communications technologies, our technical challenges will be to apply these ideas to the requirements of constellations of space systems and to implement them initially on prototype space hardware. This is necessary to demonstrate an integrated information sharing architecture and services. It is a bottom-up approach, one that solves the problem of space operations data integration. Exploration demands uniform software mechanisms for application information interchange, and the corresponding uniformly available software services to enhance these mechanisms. We will examine the issues in plug-and-play, real-time-configurable systems, including common definition and management and tracking of data and information among many different space systems. Different field test approaches are discussed, including the use of the International Space Station and terrestrial analog mission operations at field sites.

Glass, Brian↗

WRS Capabilities Booklet [Slides]

WRS is the digital backbone of the Weapons Program—delivering trusted data assets, cyber-assured software and systems, and AI-enabling software—that transform insights into decisive action. We empower physicists, engineers, researchers, and scientists to think faster, act strategically, and stay ahead in an ever-evolving threat landscape. Our efforts ensure critical nuclear weapons data remains secure, accessible, and usable—supporting mission-critical work, informed decision making, and scientific advancement at LANL and across the Nuclear Security Enterprise (NSE).

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

A Cybersecurity Testbed for Smart Buildings

Smart buildings are equipped with a plethora of cyber-physical systems, such as Internet of Things (IoT) devices and building automation systems. These devices, especially in commercial buildings, use legacy communications and hardware that were not designed with cybersecurity in mind. With increasing cyber threats in recent years, smart buildings have become an increasing target for attacks, but not enough published data are available from these incidents to study or replicate the scenarios to defend buildings. As part of the U.S. Department of Energy-funded project focusing on developing the Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS) platform, we developed a cybersecurity test bed for smart buildings. This test bed includes a building simulation tool, virtual devices, emulated operational technology networks, and remote hardware-in-the-loop. Using this test bed, we performed different cyberattacks on the smart building model and collected both physical building data, to understand the impacts on the building, and network data, to aid in separating mechanical faults from cyberattacks during the detection. This test bed is a significant tool in protecting smart buildings from cyberattacks because they can aid in both cybersecurity analysis and the evaluation of cyberattack detection tools by testing the tools in a secure environment without impacting the building operations.

alfalfa↗

Achieving Cyber-Resilience for Power Systems using a Learning, Model-Assisted Blockchain Framework

The secure integration and management of distributed energy resources (DER) and power aggregators in the electric grid requires secure communications and a physics-aware Command and Control (C2) strategy. A Blockchain (BC)-based overlay network was developed to provide a security layer for the existing power grid network that mitigates risks in current and legacy network and C2 protocols. By integrating a Model-Assisted Machine Learning (MAML) framework with a Secure Blockchain Overlay Network (SBON) a defense-in-depth strategy was achieved. In our approach, the MAML framework leveraged a smart contract framework to gather network data and learn the dynamics of DER to develop detection strategies for attacks targeting sensors and actuators used by DER. The MAML framework learned dynamical systems models for individual DERs to detect sensor attacks. For DER we utilized a Digital Twin (DT) to accelerate the learning process for a model resistant to stealthy attacks. The project created DT for PV inverters and BESS. The DTs were coupled with a model-assisted, data-driven learning of DER behavior. Specifically, we evaluated architectures for model-based learning with model-free fine-tuning. Additionally, differential privacy techniques were used to obfuscate data, while still allowing the computation of attack detection results based on obfuscated data. The SBON developed leverages a private permissioned blockchain network orchestrated with the Hyperledger Fabric framework. To connect the cyber world, which orchestrates the blockchain fabric, and the physical world where the power network resides, we developed a system implementation to enable the secure interaction of the physical world and the abstracted blockchain.

97 MATHEMATICS AND COMPUTING↗

Quantum adversarial learning for kernel methods

We show that hybrid quantum classifiers based on quantum kernel methods and support vector machines are vulnerable against adversarial attacks, namely small engineered perturbations of the input data can deceive the classifier into predicting the wrong result. Nonetheless, we also show that simple defense strategies based on data augmentation with a few crafted perturbations can make the classifier robust against new attacks. Our results find applications in security-critical learning problems and in mitigating the effect of some forms of quantum noise, since the attacker can also be understood as part of the surrounding environment.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

CyberGAN: Generating High-fidelity Cybersecurity Data With Generative Adversarial Networks

Machine learning for cyber defense offers the promise of detecting adversarial activity against the ground data systems managing critical space assets. A fundamental challenge facing machine learning research in cybersecurity is the lack of high-fidelity, shareable datasets for robust evaluation and testing of machine learning-based solutions. High-fidelity, real-world datasets are necessary for reliable benchmarking of nominal system behavior and malicious activity. Unfortunately, such realistic datasets of both nominal and adversarial activity are rarely shared publicly by data owners due to security and privacy concerns. Besides, the available adversarial data is sparse, which makes training models on malicious activity much harder. This situation has impeded and continues to impede the research and successful adoption of machine learning methods for cyber defense. Researchers have dealt with this problem by generating data within a low-fidelity lab environment, using classified and thus unshareable datasets, or downloading low-fidelity public datasets made available by others. We propose an innovative solution to the problem by employing machine learning methods to generate high-fidelity data. Specifically, we propose the use of Generative Adversarial Networks (GANs) to generate high-fidelity data for cybersecurity purposes. GANs have found successful image processing and natural language applications, but have not yet been investigated for cyber data generation. Our proposed approach first involves training the `discriminator' network of the GAN with a sample of real-world data consisting of malicious and nominal samples. We then use the `generator' network to generate new high-fidelity data samples consisting of an appropriate mix of malicious and nominal activity. We demonstrate applications of our architecture by generating high-fidelity cybersecurity data containing both malicious and nominal samples. We thoroughly evaluate the fidelity of our generated data using heuristics and evaluate its usefulness for machine learning applications using three different datasets. Overall, our approach results in high-fidelity, shareable datasets.

Zhang, Yuening↗

DOE CESER 6 GHz Interference Study

DOE CESER has sponsored Idaho National Laboratory (INL) to conduct an objective and independent study of potential 6 GHz interference from outdoor operation of unlicensed devices in the 6 GHz band on fixed service (FS) microwave communication links operated by electrical sector incumbents in that band. INL is collaborating with University of Notre Dame (UND), Electric Power Research Institute (EPRI), Lockard & White, Southern Company, and AT&T, to gather data with real-world 6 GHz interference experiments and identify (1) the potential for interference from unlicensed devices and (2) the interference necessary to cause harm to the incumbents. In addition to the functional assessment, a security assessment of the FCC mandated Automatic Frequency Coordination (AFC) System to regulate use of unlicensed 6 GHz standard power devices is also being conducted. A major objective is to create a science-based and defensible methodology used to produce the necessary data and to derive objective conclusions. This proven methodology can then be used to produce objective data and conclusions for other spectrum bands with similar incumbent uses including 4.4 – 4.9 GHz and 7.125 – 7.4 GHz, identified in the reconciliation bill that was adopted on July 4, 2025, as well as the National Spectrum Strategy discussions that are ongoing. This report contains 6 GHz field experiments and findings in the following real-world scenarios with commercial unlicensed standard power (SP) 6 GHz devices regulated by Automated Frequency Coordination (AFC): • University of Notre Dame (UND) Stadium with a capacity of 80,000 spectators, where Wi-Fi operating in 6 GHz has been deployed recently • Southern Company 6 GHz FS microwave link between Columbus and Fortson, Georgia Following are the following key findings from this study. 1. The AFC is under-protective of FS when line-of-sight exists along the path centerline. Data collected at Southern’s 6 GHz fixed link site shows significant erosion of as much as 21.4-24.4 dB of under-protection that can lead to potential service degradation under typical operating conditions. This first key finding is most likely the result of erroneous use of the RF propagation model. INL will collaborate with EPRI and the AFC Functional Requirements Working Group to submit a change request to the WinnForum TS-1014 standard towards correct use of the propagation model by the AFC. 2. There is additive interference effect of about 3 dB from nearly equal power interferers measured from simultaneous operation of two SP AP's operating co-channel with the FS receive from different locations along the path. This second key finding should be used to add the impact of additive interference of operation of multiple APs in the same geographical area, to the next generation of AFCs. INL will collaborate with FCC on the need for the AFC to consider additive interference. We also recommend that additional experiments are conducted on 6 GHz spectrum interference to further improve the AFC operation as the number of outdoor Wi-Fi devices continues to increase. These proposed steps and recommendations will make the co-existence of the incumbents and the 6 GHz outdoor Wi-Fi providers possible without any impact on the incumbents with a win-win outcome for all.

6 GHz↗

Multi-phenomenology Yield Characterization

This report serves as the first delivery of a four-year applied science effort to transform and advance the error bounds for the yield estimate of an explosion. Each year’s delivery will be in this form, culminating in the submission of this work for peer review to a scientific journal. Importantly, the yearly progress reports can then also be viewed as expanding drafts working towards a formal journal article submission. For the first tranche of funding, we collaborated with Air Force Technical Applications Center (AFTAC) scientists to identify unclassified real-world data that demonstrate and validate our advanced error propagation methods. Collaboration includes visits to AFTAC and telecons. For this development, we illustrate the fusion of seismic, acoustic, optical, and surface effect signatures from an explosion. The mathematics and code being adapted to this specific application (Williams et al., 2021) involves physics models of multiple sensor signatures. We have also identified related physics models and have integrated them into code. Current methods of underground explosion yield estimation for the Threshold Test Ban Treaty (TTBT) have served the US treaty monitoring mission well for decades. A research objective of the Defense Nuclear Nonproliferation Research and Development (DNN R&D) office of the National Nuclear Security Administration (NNSA) has always been to provide new technical capabilities for monitoring lower thresholds. The general model and error propagation code to be developed in this project is based on significant advances in error modeling and propagation needed to analyze data at lower detection thresholds. The second tranche of funding for this project began on May 1, 2022, and planned work for the second tranche includes: i) completing the integration of physical model code into the general error model framework; this code accommodates a wide range of linear/nonlinear source models, fixed/ random effects, and frequentist/Bayesian analyses (the purpose of which is not to dictate to users how to analyze data, but instead to allow users the maximum flexibility in their work); ii) illustrative application of code to identified data, and; iii) initial planning with AFTAC researchers on delivery of code to the Common Development Environment at AFTAC, and continued writing of the planned final journal article submission (year two of this progress report), with particular emphasis on descriptions of data identified for this effort.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗