Search NASA⌕ Search

SEARCH · Search NASA

Results for “firewall”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Firewalls at exponentially late times

We consider a version of the typical state firewall setup recently reintroduced by Stanford and Yang, who found that wormholes may create firewalls. We examine a late-time scaling limit in JT gravity in which one can resum the expansion in the number of wormholes, and we use this to study the exact distribution of interior slices at times exponential in the entropy. We consider a thermofield double with and without early perturbations on a boundary. These perturbations can appear on interior slices as dangerous high energy shockwaves. For exponentially late times, wormholes tend to teleport the particles created by perturbations and render the interior more dangerous. In states with many perturbations separated by large times, the probability of a safe interior is exponentially small, even though these would be safe without wormholes. With perturbation, even in the safest state we conceive, the odds of encountering a shock are fifty-fifty. One interpretation of the phenomenon is that wormholes can change time-ordered contours into effective out-of-time-ordered folds, making shockwaves appear in unexpected places.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

Protecting Websites from Cross-Site Scripting (XSS) Attacks: A Novel Configuration using Pulse Secure © Pulse Connect Secure © and Virtual Web Application Firewall (vWAF)

Cross-site scripting (XSS), one of the most prevalent forms of client-side attacks, is when bad actors attempt to access sensitive information from the backend web server and other systems on the backend network. Some XSS attacks attempt to access client-side sensitive information, such as cookies. Web application firewalls (WAFs) are a first line of defense where common Uniform Resource Locator (URL) patterns are analyzed to detect and block known attacks. This paper describes a novel configuration using the Pulse Secure © Pulse Connect Secure © (PCS © ) Secure Socket Layer Virtual Private Network software and Virtual Web Application Firewall (vWAF) that protects a website from XSS attacks. This paper also presents novel aspects of the configuration that control the redirection of traffic through the vWAF and provide fine-grained behavioral control at the application level while decoupling the PCS and vWAF configurations. The intended audience for this paper comprises system and site administrators who are familiar with standard web server environments. These configuration details might prove useful during the design of a more secure infrastructure.

97 MATHEMATICS AND COMPUTING↗

Entanglement island, miracle operators and the firewall

In this paper, we obtain some general results on information retrieval from the black hole interior, based on the recent progress on quantum extremal surface formula and entanglement island. We study an AdS black hole coupled to a bath with generic dynamics, and ask whether it is possible to retrieve information about a small perturbation in the interior from the bath system. We show that the one-norm distance between two reduced states in a bath region A is equal to the same quantity in the bulk quantum field theory for region AI where I is the entanglement island of A. This is a straightforward generalization of bulk-boundary correspondence in AdS/CFT. However, we show that a contradiction arises if we apply this result to a special situation when the bath dynamics includes a unitary operation that carries a particular measurement to a region A and send the result to another region W. Physically, the contradiction arises between transferability of classical information during the measurement, and non-transferability of quantum information which determines the entanglement island. We propose that the resolution of the contradiction is to realize that the state reconstruction formula does not apply to the special situation involving interior-information-retrieving measurements. This implies that the assumption of smooth replica AdS geometry with boundary condition set by the flat space bath has to break down when the particular measurement operator is applied to the bath. Using replica trick, we introduce an explicitly construction of such operator, which we name as “miracle operators”. From this construction we see that the smooth replica geometry assumption breaks down because we have to introduce extra replica wormholes connecting with the “simulated blackholes” introduced by the miracle operator. We study the implication of miracle operators in understanding the firewall paradox.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Firewalls from General Covariance

I define “horizon normalcy” as the approximate validity of semiclassical gravity and effective field theory for the description of observers that approach or cross a black hole horizon. If black holes return information, then horizon normalcy must fail substantially, at least in some global states. It has been proposed that horizon normalcy persists, so long as the Hawking radiation remains in a computationally simple state. Here I argue that state-dependent horizon normalcy—independent of the underlying mechanism and independent of the class of radiation states asserted to guarantee normalcy—requires a breakdown of general covariance far from the black hole, or else horizon normalcy will depend on the infinite future of the exterior. This is because the radiation can be in different states at different events, all spacelike to the horizon crossing event whose normalcy is at stake. I discuss a related effect in AdS/CFT, and I argue that its resolution by timefolds is of no help here.

General relativity↗

A swapped genetic code prevents viral infections and gene transfer

Engineering the genetic code of an organism has been proposed to provide a firewall from natural ecosystems by preventing viral infections and gene transfer. However, numerous viruses and mobile genetic elements encode parts of the translational apparatus, potentially rendering a genetic-code-based firewall ineffective. Here we show that such mobile transfer RNAs (tRNAs) enable gene transfer and allow viral replication in Escherichia coli despite the genome-wide removal of 3 of the 64 codons and the previously essential cognate tRNA and release factor genes. We then establish a genetic firewall by discovering viral tRNAs that provide exceptionally efficient codon reassignment allowing us to develop cells bearing an amino acid-swapped genetic code that reassigns two of the six serine codons to leucine during translation. This amino acid-swapped genetic code renders cells resistant to viral infections by mistranslating viral proteomes and prevents the escape of synthetic genetic information by engineered reliance on serine codons to produce leucine-requiring proteins. As these cells may have a selective advantage over wild organisms due to virus resistance, we also repurpose a third codon to biocontain this virus-resistant host through dependence on an amino acid not found in nature. Furthermore, our results may provide the basis for a general strategy to make any organism safely resistant to all natural viruses and prevent genetic information flow into and out of genetically modified organisms.

59 BASIC BIOLOGICAL SCIENCES↗

The Integration of The Cloudflare WAF

HTTP Strict Transport Security (HSTS) is a standard that ensures website visitor’s traffic is always sent using HTTPS ensuring that all traffic is protected during transit. This initiative was adopted in 2012 by the IETF and has grown in popularity all around the world. Because the traffic is encrypted with TLS/SSL, it can be used by attackers to bypass various cybersecurity capabilities such as a site firewall. To address this lack of visibility into encrypted traffic in motion, the CST at Fermilab acquired the Cloudflare Web Application Firewall (WAF). To help in the implementation and integration of the Cloudflare WAF, I was directed to learn about and aid in this process. This has been a profound learning experience into the on-goings of project management, web application firewalls, collaboration, and networking.

Blum, Ethan T.↗

V-INT: Automated Vulnerability Intelligence and Risk Assessment

The project team, including the University of Arkansas (UA) as the lead, the University of Arkansas at Little Rock (UALR), Network Perception (NP), and Bastazo, has successfully researched, developed, and demonstrated the V-INT toolset, and also integrated it into the commercial products of NP (i.e., NP-View) and Bastazo (i.e., Spartan). The end product is a cybersecurity software tool for energy utilities that can automatically assess the risks of software vulnerabilities in an organization’s assets considering the organization’s firewall policies. It allows security operators to identify the small portion of vulnerabilities that poses true threats to their system (i.e., those that are not protected by firewall policies) and prioritize the mitigation of these vulnerabilities to minimize risks. It also allows security operators to identify the vulnerability-induced attack paths under their organization’s firewall policy, providing effective decision supports for mitigating potential attacks.

97 MATHEMATICS AND COMPUTING↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

Diffeomorphism invariance and quantum mechanical paradoxes

Paradoxes in gravitational physics, such as grandfather paradoxes with closed timelike curves or the AMPS paradox, are often constructed in a weak gravity regime but upon further examination engender strong gravitational responses such as unstable Cauchy horizons or firewalls. In contrast, some proposed paradoxes in nonrelativistic quantum mechanics ignore gravity completely. Such nonrelativistic proposed paradoxes are often not gauge invariant — they use local operators which should be forbidden by diffeomorphism-invariant quantum gravity. Ignoring this complication is reasonable if there is a consistent weak gravity regime where the paradox can be formulated with gauge invariant observables up to some order in Newton’s constant. Here, we show that this approach remains inconsistent due to a lack of analyticity of the necessary solutions. As a consequence, there is no consistent weak gravity, diffeomorphism invariant embedding of such paradoxes—just as in other gravitational paradoxes they generate a strong gravitational response and are in principle sensitive to quantum gravity.

quantum gravity↗

Report on the deployment of the National Geothermal Data System 2.0

This reports includes a video description of recent upgrades and changes to the National Geothermal Data System (geothermaldata.org) and a text report of its relevant security upgrades. Improvements include a new operating system, implementation of HTTPS, implementation of a standard firewall, PostgreSQL upgrades, an ESRI ArcGIS server, new registration policies, and a non-public API.

15 GEOTHERMAL ENERGY↗

Entanglement wedge reconstruction and the information paradox

When absorbing boundary conditions are used to evaporate a black hole in AdS/CFT, we show that there is a phase transition in the location of the quantum Ryu-Takayanagi surface, at precisely the Page time. The new RT surface lies slightly inside the event horizon, at an infalling time approximately the scrambling time β/2 π logS BH into the past. We can immediately derive the Page curve, using the Ryu-Takayanagi formula, and the Hayden-Preskill decoding criterion, using entanglement wedge reconstruction. Because part of the interior is now encoded in the early Hawking radiation, the decreasing entanglement entropy of the black hole is exactly consistent with the semiclassical bulk entanglement of the late-time Hawking modes, despite the absence of a firewall.By studying the entanglement wedge of highly mixed states, we can understand the state dependence of the interior reconstructions. A crucial role is played by the existence of tiny, non-perturbative errors in entanglement wedge reconstruction. Directly after the Page time, interior operators can only be reconstructed from the Hawking radiation if the initial state of the black hole is known. As the black hole continues to evaporate, reconstructions become possible that simultaneously work for a large class of initial states. Using similar techniques, we generalise Hayden-Preskill to show how the amount of Hawking radiation required to reconstruct a large diary, thrown into the black hole, depends on both the energy and the entropy of the diary. Finally we argue that, before the evaporation begins, a single, state-independent interior reconstruction exists for any code space of microstates with entropy strictly less than the Bekenstein-Hawking entropy, and show that this is sufficient state dependence to avoid the AMPSS typical-state firewall paradox.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Islands far outside the horizon

Information located in an entanglement island in semiclassical gravity can be nonperturbatively reconstructed from distant radiation, implying a radical breakdown of effective field theory. We show that this occurs well outside of the black hole stretched horizon. We compute the island associated to large-angular momentum Hawking modes of a four-dimensional Schwarzschild black hole. These modes typically fall back into the black hole but can be extracted to infinity by relativistic strings or, more abstractly, by asymptotic boundary operators constructed using the timelike tube theorem. Remarkably, we find that their island can protrude a distance of order $\sqrt{\ell_p{r}_{\textrm{hor}}}$ outside the horizon. This is parametrically larger than the Planck scale ℓ p and is comparable to the Bohr radius for supermassive black holes. Therefore, in principle, a distant observer can determine experimentally whether the black hole information paradox is resolved by complementarity, or by a firewall.

AdS-CFT correspondence↗

Reinforcement Learning for feedback-enabled cyber resilience

The rapid growth in the number of devices and their connectivity has enlarged the attack surface and made cyber systems more vulnerable. As attackers become increasingly sophisticated and resourceful, mere reliance on traditional cyber protection, such as intrusion detection, firewalls, and encryption, is insufficient to secure the cyber systems. Cyber resilience provides a new security paradigm that complements inadequate protection with resilience mechanisms. A Cyber-Resilient Mechanism (CRM) adapts to the known or zero-day threats and uncertainties in real-time and strategically responds to them to maintain the critical functions of the cyber systems in the event of successful attacks. Feedback architectures play a pivotal role in enabling the online sensing, reasoning, and actuation process of the CRM. Reinforcement Learning (RL) is an important gathering of algorithms that epitomize the feedback architectures for cyber resilience. It allows the CRM to provide dynamic and sequential responses to attacks with limited or without prior knowledge of the environment and the attacker. In this work, we review the literature on RL for cyber resilience and discuss the cyber-resilient defenses against three major types of vulnerabilities, i.e., posture-related, information-related, and human-related vulnerabilities. Here we introduce moving target defense, defensive cyber deception, and assistive human security technologies as three application domains of CRMs to elaborate on their designs. The RL algorithms also have vulnerabilities themselves. We explain the major vulnerabilities of RL and present develop several attack models where the attacker target the information exchanged between the environment and the agent: the rewards, the state observations, and the action commands. We show that the attacker can trick the RL agent into learning a nefarious policy with minimum attacking effort. The paper introduces several defense methods to secure the RL-enabled systems from these attacks. However, there is still a lack of works that focuses on the defensive mechanisms for RL-enabled systems. Last but not least, we discuss the future challenges of RL for cyber security and resilience and emerging applications of RL-based CRMs.

97 MATHEMATICS AND COMPUTING↗

Finding pythons in unexpected places

In this work, we argue that novel (highly nonclassical) quantum extremal surfaces (QESs) play a crucial role in reconstructing the black hole interior even for isolated, single-sided, non-evaporating black holes (i.e. with no auxiliary reservoir). Specifically, any code subspace where interior outgoing modes can be excited will have a QES in its maximally mixed state. We argue that as a result, reconstruction of interior outgoing modes is always exponentially complex. Our construction provides evidence in favor of a strong python’s lunch proposal: that nonminimal QESs are the exclusive source of exponential complexity in the holographic dictionary. We also comment on the relevance of these QESs to the geometrization of state dependence in the typicality arguments for firewalls.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Flexible visualization of a 3rd party Intrusion Prevention (Security) tool: A use case with the ELK stack

A difficult aspect of cyber security is the ability to achieve automated real time intrusion prevention across various sets of systems. To this extent, several companies are offering comprehensive solutions that leverage an "accuracy of scale" and moving much of the intelligence and detection on the Cloud, relying on an ever-growing set of data and analytics to increase decision accuracy. Often, they provide tools to visualize the decision workflows in attack prevention (as well as tune the algorithm) but those solutions are not always practical as companies see the problem as "global" that is, from a unified Cyber-security standpoint. However, a key to a successful Cyber-security program is transparency and trust: from an experimental team viewpoint, this specifically means having the ability to immediately see what and from where, who has been blocked and being able to inform the community in case of a revoked access without the need for filing a "ticket" (that may eventually be answered) – in other words, rapid response to their user-base is essential but solutions targeting "sub-groups" in an organization are not often available. We have come up with a versatile solution leveraging the ELK stack (Elasticsearch, Logstash, & Kibana) and an IPS (Intrusion Prevention System) based WAF (Web Application Firewall) from Signal Sciences. Signal Science allows the streaming of detailed logs in a Logstash format suitable for custom solutions for visualization. By combining these two tools, we have strengthened our security posture and enabled individual experiments to monitor their own traffic. Specifically, the IPS WAF provides unique data such as country of origin, protocol, response code, source IP, and paths accessed. In this contribution, we will show how we engineered a visualization solution so experiment groups could access a dashboard with predefined graphs but also, where they can create individual customizable dashboards used to display blocked traffic and troubleshoot latency issues. We will discuss the details and procedures for developing and configuring these tools and how it benefits cyber security postures across our scientific based environment.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Black hole echoes

In this work, we consider a very simple model for gravitational wave echoes from black hole merger ringdowns which may arise from local Lorentz symmetry violations that modify graviton dispersion relations. If the corrections are sufficiently soft so they do not remove the horizon, the reflection of the infalling waves which trigger the echoes is very weak. As an example, we look at the dispersion relation of a test scalar field corrected by rotonlike operators depending only on spatial momenta, in Gullstrand-Painlevé coordinates. The near-horizon regions of a black hole do become reflective, but only very weakly. The resulting “bounces” of infalling waves can yield repetitive gravity wave emissions but their power is very small. This implies that to see any echoes from black holes we really need an egregious departure from either standard GR or effective field theory, or both. One possibility to realize such strong echoes is the recently proposed classical firewalls which replace black hole horizons with material shells surrounding timelike singularities.

79 ASTRONOMY AND ASTROPHYSICS↗

Blockchain-Based Man-in-the-Middle (MITM) Attack Detection for Photovoltaic Systems

Cybersecurity of photovoltaic (PV) systems entails a much larger scope than just encryption and firewall of communications. For instance, integrity of data in transit between inverters and a cloud server can be compromised by authorized third-party, devices, and internal network within security perimeter (i.e., man-in-the-middle (MITM) attack). To address this challenge, this paper proposes a blockchain-based MITM attack detection method for a PV system. A breakthrough method includes screening network data, network intrusion detection, and hash comparison of in-transit data using distributed ledgers. Furthermore, the proposed method is implemented in Internet-of-Thing (IoT) security modules as clients of a blockchain network and validated by experiments.

blockchain↗