Search NASA⌕ Search

SEARCH · Search NASA

Results for “firewall”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Firewalls at exponentially late times

We consider a version of the typical state firewall setup recently reintroduced by Stanford and Yang, who found that wormholes may create firewalls. We examine a late-time scaling limit in JT gravity in which one can resum the expansion in the number of wormholes, and we use this to study the exact distribution of interior slices at times exponential in the entropy. We consider a thermofield double with and without early perturbations on a boundary. These perturbations can appear on interior slices as dangerous high energy shockwaves. For exponentially late times, wormholes tend to teleport the particles created by perturbations and render the interior more dangerous. In states with many perturbations separated by large times, the probability of a safe interior is exponentially small, even though these would be safe without wormholes. With perturbation, even in the safest state we conceive, the odds of encountering a shock are fifty-fifty. One interpretation of the phenomenon is that wormholes can change time-ordered contours into effective out-of-time-ordered folds, making shockwaves appear in unexpected places.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

Protecting Websites from Cross-Site Scripting (XSS) Attacks: A Novel Configuration using Pulse Secure © Pulse Connect Secure © and Virtual Web Application Firewall (vWAF)

Cross-site scripting (XSS), one of the most prevalent forms of client-side attacks, is when bad actors attempt to access sensitive information from the backend web server and other systems on the backend network. Some XSS attacks attempt to access client-side sensitive information, such as cookies. Web application firewalls (WAFs) are a first line of defense where common Uniform Resource Locator (URL) patterns are analyzed to detect and block known attacks. This paper describes a novel configuration using the Pulse Secure © Pulse Connect Secure © (PCS © ) Secure Socket Layer Virtual Private Network software and Virtual Web Application Firewall (vWAF) that protects a website from XSS attacks. This paper also presents novel aspects of the configuration that control the redirection of traffic through the vWAF and provide fine-grained behavioral control at the application level while decoupling the PCS and vWAF configurations. The intended audience for this paper comprises system and site administrators who are familiar with standard web server environments. These configuration details might prove useful during the design of a more secure infrastructure.

97 MATHEMATICS AND COMPUTING↗

Entanglement island, miracle operators and the firewall

In this paper, we obtain some general results on information retrieval from the black hole interior, based on the recent progress on quantum extremal surface formula and entanglement island. We study an AdS black hole coupled to a bath with generic dynamics, and ask whether it is possible to retrieve information about a small perturbation in the interior from the bath system. We show that the one-norm distance between two reduced states in a bath region A is equal to the same quantity in the bulk quantum field theory for region AI where I is the entanglement island of A. This is a straightforward generalization of bulk-boundary correspondence in AdS/CFT. However, we show that a contradiction arises if we apply this result to a special situation when the bath dynamics includes a unitary operation that carries a particular measurement to a region A and send the result to another region W. Physically, the contradiction arises between transferability of classical information during the measurement, and non-transferability of quantum information which determines the entanglement island. We propose that the resolution of the contradiction is to realize that the state reconstruction formula does not apply to the special situation involving interior-information-retrieving measurements. This implies that the assumption of smooth replica AdS geometry with boundary condition set by the flat space bath has to break down when the particular measurement operator is applied to the bath. Using replica trick, we introduce an explicitly construction of such operator, which we name as “miracle operators”. From this construction we see that the smooth replica geometry assumption breaks down because we have to introduce extra replica wormholes connecting with the “simulated blackholes” introduced by the miracle operator. We study the implication of miracle operators in understanding the firewall paradox.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Firewall Traversal for CORBA Applications Using an Implementation of Bidirectional IIOP in MICO

The Object Management Group (OMG) has added specifications to the General Inter-ORB Protocol (GIOP 1.2), specifically the Internet Inter-ORB Protocol (IIOP 1.2), that allow servers and clients on opposing sides of a firewall to reverse roles and still communicate freely. This addition to the GIOP specifications is referred to as Bidirectional GIOP. The implementation of these specifications as applied to communication over TCP/IP connections is referred to as 'Bidirectional Internet Inter-ORB Protocol' or BiDirIIOP. This paper details the implementation and testing of the BiDirIIOP Specification in an open source ORB, MICO, that did not previously support Bidirectional GIOP. It also provides simple contextual information and a description of the OMG GIOP/IIOP messaging protocols.

Griffin, Robert I.↗

Firewalls from General Covariance

I define “horizon normalcy” as the approximate validity of semiclassical gravity and effective field theory for the description of observers that approach or cross a black hole horizon. If black holes return information, then horizon normalcy must fail substantially, at least in some global states. It has been proposed that horizon normalcy persists, so long as the Hawking radiation remains in a computationally simple state. Here I argue that state-dependent horizon normalcy—independent of the underlying mechanism and independent of the class of radiation states asserted to guarantee normalcy—requires a breakdown of general covariance far from the black hole, or else horizon normalcy will depend on the infinite future of the exterior. This is because the radiation can be in different states at different events, all spacelike to the horizon crossing event whose normalcy is at stake. I discuss a related effect in AdS/CFT, and I argue that its resolution by timefolds is of no help here.

General relativity↗

Atmospheric Profile Imprint in Firewall Ablation Coefficient

A general formula which expresses the distance along the meteoric fireball trajectory 1 as a function of t is discussed. Differential equations which include the motion and ablation of a single nonfragmenting meteor body are presented. The importance of the atmospheric density profile in the meteor formula is emphasized.

Ceplecha, Z.↗

Modular Firewalls for Storage Areas

Giant honeycomb structures assembled in modular units. Flammable materials stored in cells. Walls insulated with firebrick to prevent spread of fire among cells. Portable, modular barrier withstands heat of combustion for limited time and confines combustion products horizontally to prevent fire from spreading. Barrier absorbs heat energy by ablation and not meant to be reused. Designed to keep fires from spreading among segments of solid rocket propellant in storage, barrier erected between storage units of other flammable or explosive materials; tanks of petroleum or liquid natural gas. Barrier adequate for most industrial purposes.

Fedor, O. H.↗

Safe Grid

The biggest users of GRID technologies came from the science and technology communities. These consist of government, industry and academia (national and international). The NASA GRID is moving into a higher technology readiness level (TRL) today; and as a joint effort among these leaders within government, academia, and industry, the NASA GRID plans to extend availability to enable scientists and engineers across these geographical boundaries collaborate to solve important problems facing the world in the 21 st century. In order to enable NASA programs and missions to use IPG resources for program and mission design, the IPG capabilities needs to be accessible from inside the NASA center networks. However, because different NASA centers maintain different security domains, the GRID penetration across different firewalls is a concern for center security people. This is the reason why some IPG resources are been separated from the NASA center network. Also, because of the center network security and ITAR concerns, the NASA IPG resource owner may not have full control over who can access remotely from outside the NASA center. In order to obtain organizational approval for secured remote access, the IPG infrastructure needs to be adapted to work with the NASA business process. Improvements need to be made before the IPG can be used for NASA program and mission development. The Secured Advanced Federated Environment (SAFE) technology is designed to provide federated security across NASA center and NASA partner's security domains. Instead of one giant center firewall which can be difficult to modify for different GRID applications, the SAFE "micro security domain" provide large number of professionally managed "micro firewalls" that can allow NASA centers to accept remote IPG access without the worry of damaging other center resources. The SAFE policy-driven capability-based federated security mechanism can enable joint organizational and resource owner approved remote access from outside of NASA centers. A SAFE enabled IPG can enable IPG capabilities to be available to NASA mission design teams across different NASA center and partner company firewalls. This paper will first discuss some of the potential security issues for IPG to work across NASA center firewalls. We will then present the SAFE federated security model. Finally we will present the concept of the architecture of a SAFE enabled IPG and how it can benefit NASA mission development.

Chow, Edward T.↗

Methods for designing treatments to reduce interior noise of predominant sources and paths in a single engine light aircraft

The sources and paths by which noise enters the cabin of a small single engine aircraft were determined through a combination of flight and laboratory tests. The primary sources of noise were found to be airborne noise from the propeller and engine casing, airborne noise from the engine exhaust, structureborne noise from the engine/propeller combination and noise associated with air flow over the fuselage. For the propeller, the primary airborne paths were through the firewall, windshield and roof. For the engine, the most important airborne path was through the firewall. Exhaust noise was found to enter the cabin primarily through the panels in the vicinity of the exhaust outlet although exhaust noise entering the cabin through the firewall is a distinct possibility. A number of noise control techniques were tried, including firewall stiffening to reduce engine and propeller airborne noise, to stage isolators and engine mounting spider stiffening to reduce structure-borne noise, and wheel well covers to reduce air flow noise.

Hayden, Richard E.↗

A swapped genetic code prevents viral infections and gene transfer

Engineering the genetic code of an organism has been proposed to provide a firewall from natural ecosystems by preventing viral infections and gene transfer. However, numerous viruses and mobile genetic elements encode parts of the translational apparatus, potentially rendering a genetic-code-based firewall ineffective. Here we show that such mobile transfer RNAs (tRNAs) enable gene transfer and allow viral replication in Escherichia coli despite the genome-wide removal of 3 of the 64 codons and the previously essential cognate tRNA and release factor genes. We then establish a genetic firewall by discovering viral tRNAs that provide exceptionally efficient codon reassignment allowing us to develop cells bearing an amino acid-swapped genetic code that reassigns two of the six serine codons to leucine during translation. This amino acid-swapped genetic code renders cells resistant to viral infections by mistranslating viral proteomes and prevents the escape of synthetic genetic information by engineered reliance on serine codons to produce leucine-requiring proteins. As these cells may have a selective advantage over wild organisms due to virus resistance, we also repurpose a third codon to biocontain this virus-resistant host through dependence on an amino acid not found in nature. Furthermore, our results may provide the basis for a general strategy to make any organism safely resistant to all natural viruses and prevent genetic information flow into and out of genetically modified organisms.

59 BASIC BIOLOGICAL SCIENCES↗

The Integration of The Cloudflare WAF

HTTP Strict Transport Security (HSTS) is a standard that ensures website visitor’s traffic is always sent using HTTPS ensuring that all traffic is protected during transit. This initiative was adopted in 2012 by the IETF and has grown in popularity all around the world. Because the traffic is encrypted with TLS/SSL, it can be used by attackers to bypass various cybersecurity capabilities such as a site firewall. To address this lack of visibility into encrypted traffic in motion, the CST at Fermilab acquired the Cloudflare Web Application Firewall (WAF). To help in the implementation and integration of the Cloudflare WAF, I was directed to learn about and aid in this process. This has been a profound learning experience into the on-goings of project management, web application firewalls, collaboration, and networking.

Blum, Ethan T.↗

V-INT: Automated Vulnerability Intelligence and Risk Assessment

The project team, including the University of Arkansas (UA) as the lead, the University of Arkansas at Little Rock (UALR), Network Perception (NP), and Bastazo, has successfully researched, developed, and demonstrated the V-INT toolset, and also integrated it into the commercial products of NP (i.e., NP-View) and Bastazo (i.e., Spartan). The end product is a cybersecurity software tool for energy utilities that can automatically assess the risks of software vulnerabilities in an organization’s assets considering the organization’s firewall policies. It allows security operators to identify the small portion of vulnerabilities that poses true threats to their system (i.e., those that are not protected by firewall policies) and prioritize the mitigation of these vulnerabilities to minimize risks. It also allows security operators to identify the vulnerability-induced attack paths under their organization’s firewall policy, providing effective decision supports for mitigating potential attacks.

97 MATHEMATICS AND COMPUTING↗

Accessible Telemetry Streams using a Zero Trust Architecture for the Flight Operations Directorate

As a result of information technology based work becoming increasingly distributed, unique challenges have been presented within the realm of defined network perimeters, namely with respect to secure access to resources. Historically, and from a simplistic abstract perspective, the common approach has been to adopt the, so-called, moat model whereby a physical network perimeter (or interconnected perimeters) is defined to encapsulate resources behind a boundary protected by a firewall. Users are provisioned access through a virtual private network (VPN) and may be further constrained to resources through specific firewall allow and disallow rulesets. Virtual Private Networks and firewall rulesets lead to common problems, particularly at scale and, as a result, perimeter-less architectures provided over the public internet are increasingly becoming prevalent, particularly with its more popular implementation, the Zero Trust Architecture. We present a proposed implementation of the Zero Trust Architecture with a particular concrete example utilizing a de-perimeterized network that requires authentication and authorization for each action between nodes and does not operate within an implicit trust boundary. It should be noted that this paper is not an attempt at providing comprehensive resolutions for the specific problem space with respect to perimeter based security and is more directed at providing information with regard to our proposed implementation of a Zero Trust Architecture for the Flight Operations Directorate. We direct the reader to our Introduction and Background section for more details on specific documentation and where it can be located as it relates to de-perimeterization and Zero Trust.

Paul Shoemaker↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

Diffeomorphism invariance and quantum mechanical paradoxes

Paradoxes in gravitational physics, such as grandfather paradoxes with closed timelike curves or the AMPS paradox, are often constructed in a weak gravity regime but upon further examination engender strong gravitational responses such as unstable Cauchy horizons or firewalls. In contrast, some proposed paradoxes in nonrelativistic quantum mechanics ignore gravity completely. Such nonrelativistic proposed paradoxes are often not gauge invariant — they use local operators which should be forbidden by diffeomorphism-invariant quantum gravity. Ignoring this complication is reasonable if there is a consistent weak gravity regime where the paradox can be formulated with gauge invariant observables up to some order in Newton’s constant. Here, we show that this approach remains inconsistent due to a lack of analyticity of the necessary solutions. As a consequence, there is no consistent weak gravity, diffeomorphism invariant embedding of such paradoxes—just as in other gravitational paradoxes they generate a strong gravitational response and are in principle sensitive to quantum gravity.

quantum gravity↗

Open Source Service Agent (OSSA) in the intelligence community's Open Source Architecture

The Community Open Source Program Office (COSPO) has developed an architecture for the intelligence community's new Open Source Information System (OSIS). The architecture is a multi-phased program featuring connectivity, interoperability, and functionality. OSIS is based on a distributed architecture concept. The system is designed to function as a virtual entity. OSIS will be a restricted (non-public), user configured network employing Internet communications. Privacy and authentication will be provided through firewall protection. Connection to OSIS can be made through any server on the Internet or through dial-up modems provided the appropriate firewall authentication system is installed on the client.

Fiene, Bruce F.↗