Search NASA⌕ Search

SEARCH · Search NASA

Results for “firmware analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Evaluating Methods of Software Bill of Materials Generation to Enhance Nuclear Power Plant Cybersecurity

Instrumentation and control (I&C) systems in nuclear power plants (NPPs) are potential targets of cyberattacks and can prove deleterious for the safety of the NPPs. A Software Bill of Materials (SBOM) provides a detailed list of the various components and their dependencies in software, which helps in vulnerability and risk assessment for cyber hygiene and situational awareness. For an NPP, the process of generating an accurate SBOM report can be complex due to the legacy systems and firmware binaries involved. While most current SBOM tools are focused more on modern internet technology software, this research provides insights and guidelines for an NPP to generate an accurate and efficient SBOM. Here, the paper proposes a new methodology to help NPPs categorize software and use appropriate tools to generate SBOMs for their digital I&C systems.

SBOM↗

Forensic Analysis of SOHO Router Binaries

Small Office/Home Office (SOHO) routers are used by millions of consumers across the United States, and are commensurately vulnerable. Forensic analysis of SOHO router firmware helps to understand and mitigate those vulnerabilities. This poster focused particularly on analysis of BusyBox executables, a software suite that provides several Unix utilities in a single file. Three main tools were used to analyze the binaries. BinWalk was used to extract the files, but also to build entropy graphs, extract Linux kernel images, and identify CPU architectures; WiiBin processed the binaries to find endianness, architecture, the percent compressed/encrypted, and compiler data; and @DisCo, a machine learning tool used to determine function similarity in disassembled binaries, analyzed similarities and determined versions of extracted BusyBox files from each router. These tools found that venders from all five routers utilized the same version of the BusyBox software across different firmware updates, demonstrating the importance of constant firmware scrutiny to protect against security vulnerabilities.

24 POWER TRANSMISSION AND DISTRIBUTION↗

SCA Tools - SCRM Value Add or Lossy Noise Machines

Software supply chain risk management (SCRM) depends upon accurate information regarding the software components that comprise any given software system. The collection of components included in a software package can be organized within a software bill of materials, or SBOM. SBOMs are ideally generated when the software components are put together, such as at compile time, but for many reasons that has not and is not always possible. For example, legacy or proprietary software packages often do not have SBOMs available to downstream consumers of that software. It’s not just end users that are affected, manufacturers themselves also must deal with this problem. To answer these questions, the market has seen the rise of several commercial software composition analysis (SCA) tools. These tools aim to peer into completed software systems, automatically identifying hidden software dependencies and looking up known vulnerabilities associated with those dependencies to enable end-users to enhance their cyber supply chain risk management processes. These tools are potentially a huge boon to end users of legacy and proprietary software – and a potential bane, depending on how accurate they are. This research asks that question – how accurate are currently available binary SCA tools – and provides answers to several other questions: What does it mean to be “accurate”? What limitations do the tools have in identifying common edge cases that take place in modern software development? Can they help you avoid a devastating supply chain attack, or is it all just noise? After researching SCA tools on the market, we identified three vendors that fit our use case and would provide analysis on compiled binaries. Using these tools, we submitted firmware for critical infrastructure devices for analysis and SBOM generation. The SBOM outputs were then cross referenced with SBOMs generated through manual analysis for comparison. In addition to the firmware samples, we also submitted edge case samples based off a popular open-source library that were specifically crafted to evaluate each tools’ ability to accurately identify components. These samples were customized to be consistent with modifications we have seen in modern software development as well as a couple that are representative of supply chain attacks.

97 MATHEMATICS AND COMPUTING↗

Automated Vulnerability Detection (AVUD) for Compiled Smart Grid Software

This project developed and implemented a system for conducting cybersecurity vulnerability detection of smart grid components and systems by performing static analysis of compiled software (“firmware”). The resulting system for automated vulnerability detection (AVUD) was implemented as part of Oak Ridge National Laboratory’s existing test bed for smart meters, the Sustainable Campus Initiative. The work consisted of two phases: the first phase implemented the necessary software and computational models to perform the analysis, and the second phase demonstrated the system on example firmware in partnership with smart meter manufacturer Sensus USA, Inc. The resulting system won an R&D 100 award and has been successfully commercialized, winning a National Laboratory Consortium Commercialization Award.

97 MATHEMATICS AND COMPUTING↗

Firmware Tampering Detection in Heavy-Duty Vehicles through J1939 CAN Analysis

Modern heavy-duty vehicles rely on complex networks of Electronic Control Units (ECUs) that communicate using the J1939 protocol. While this system makes it easier to update and configure vehicle components, it also opens the door to serious cybersecurity risks if not properly secured. This work investigates the potential for firmware tampering through the J1939 communication protocol, which enables ECU configuration and reprogramming over the Controller Area Network (CAN) bus. By monitoring CAN traffic during legitimate maintenance operations and reverse-engineering OEM diagnostic software, we identified common and proprietary J1939 message identifiers, authentication patterns, and vulnerabilities within Unified Diagnostic Services (UDS). These findings demonstrate that inadequate authentication mechanisms can allow malicious actors to alter ECU firmware or disable safety functions, posing severe operational and safety risks. Our analysis contributes to the development of vehicle intrusion detection systems capable of recognizing abnormal reprogramming activity and future firmware fingerprinting methods to verify software integrity across ECUs. This work highlights the importance of standardizing secure firmware authentication across manufacturers to strengthen cyber resilience in heavy-duty vehicle systems.

33 ADVANCED PROPULSION SYSTEMS↗

Open Source Software Prevalence Ingest Tool

The OSSP Ingest Tool accepts user-input organizational information, ingests IT/OT asset lists in Excel format, and ingests the associated CycloneDX SBOM's. It then performs analytics demonstrating the ability to answer the follow research questions: o RQ1. Ability to identify all OSS services running on, and all OSS components present within, an OT device o RQ1a: Ability to differentiate multiple versions of the same OSS component within each OT device. o RQ1b: Ability to differentiate running from not-running OSS components. o RQ1c: Ability to differentiate based on the originator of the component, because a supplier may have modified it after retrieval from the upstream software source. o RQ2. Ability to correlate the identity of a single OSS component across multiple OT devices, mitigating common name variations such as differences in capitalization, '-' vs '_', and so on. o RQ3. Ability to perform subset analysis of OSS components across multiple OT devices o RQ3a: Ability to perform subset analysis across OSS libraries, generating density & distribution graphs to identify commonly-used libraries and outliers. o RQ3b: Ability to perform subset analysis of a single OSS library, generating density & distribution by CI sector, by device type, by device make/model, and/or by firmware version. o RQ3c: Ability to perform subset analysis by grouping OSS libraries according to programming language, then overlay with RQ4b. o RQ3d: Ability to perform subset analysis by OSS upstream source, providing insight into degree of modifications performed by suppliers. o RQ4. Ability to identify dependencies (transitive and direct) of each differentiated OSS library within each OT device, and enable RQ1,2,3 iteratively for dependencies. o RQ1. Ability to identify all OSS services running on, and all OSS components present within, an OT device o RQ1a: Ability to differentiate multiple versions of the same OSS component within each OT device. o RQ1b: Ability Page

Kapadia, Shayna [Lawrence Livermore National Labor↗

FY25 Mid-Year Report: FNCL Enhancements Implementation

During the first half of FY25 the FNCL team has made consistent progress toward the completion of our project goals. The FNCL prototype panel design has been successfully applied to a fully instrumented 3-panel system which is actively under construction. The FNCL Demonstrator System contains solid scintillators instrumented with SiPMs, which operate on an updated CAEN digitizer, requires no high-voltage, and has a smaller overall footprint. The onboard software will include the LLNL-developed GMM-PSD signal processing. Later this year the system will be experimentally tested alongside the baseline FNCL instrument at LLNLs ISSA facility. In addition to a full systems test, the performance of a DD generator for active interrogation measurements compared to the standard AmLi source will be established for both systems. The data collected at the ISSA facility will be used to experimentally validate the FNCL-Fast Isotopic Fuel Assay’s (FIFA) capability to measure U-235 loading and to predict gadolinium poison content with passive interrogation. The FNCL-FIFA modal was benchmarked with simulation-based data and a user-friendly GUI was added earlier this year. Three separate codes have been submitted to the LLNL ESW system for review prior to their transfers. These include the Predictive Modeling Response toolkit, GMM-PSD firmware beta version, and the FNCL-FIFA analysis package with GUI and user documentation.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

New machine protection system at the Spallation Neutron Source – design process and performance analysis

A New Machine Protection System (MPS) at the Spallation Neutron Source (SNS) was developed and implemented on µTCA-based hardware platforms. The system monitors more than 2500 field inputs and shuts off the beam within 10 µs if adverse events occur. We will present system level design process of various firmware and software components as well as the system integration into EPICS environment. The performance analysis of the MPS after two SNS run cycles will also be presented.

Bobrek, Miljko [ORNL] (ORCID:0000000332763451)↗

A prototype scintillator real‐time beam monitor for ultra‐high dose rate radiotherapy

Background: FLASH Radiotherapy (RT) is an emergent cancer RT modality where an entire therapeutic dose is delivered at more than 1000 times higher dose rate than conventional RT. For clinical trials to be conducted safely, a precise and fast beam monitor that can generate out-of-tolerance beam interrupts is required. This paper describes the overall concept and provides results from a prototype ultra-fast, scintillator-based beam monitor for both proton and electron beam FLASH applications. Purpose: A FLASH Beam Scintillator Monitor (FBSM) is being developed that employs a novel proprietary scintillator material. The FBSM has capabilities that conventional RT detector technologies are unable to simultaneously provide: (1) large area coverage; (2) a low mass profile; (3) a linear response over a broad dynamic range; (4) radiation hardness; (5) real-time analysis to provide an IEC-compliant fast beam-interrupt signal based on true two-dimensional beam imaging, radiation dosimetry and excellent spatial resolution. Methods: The FBSM uses a proprietary low mass, less than 0.5 mm water equivalent, non-hygroscopic, radiation tolerant scintillator material (designated HM: hybrid material) that is viewed by high frame rate CMOS cameras. Folded optics using mirrors enable a thin monitor profile of ∼10 cm. A field programmable gate array (FPGA) data acquisition system generates real-time analysis on a time scale appropriate to the FLASH RT beam modality: 100–1000 Hz for pulsed electrons and 10–20 kHz for quasi-continuous scanning proton pencil beams. An ion beam monitor served as the initial development platform for this work and was tested in low energy heavy-ion beams ( 86 Kr +26 and protons). A prototype FBSM was fabricated and then tested in various radiation beams that included FLASH level dose per pulse electron beams, and a hospital RT clinic with electron beams. Results: Results presented in this report include image quality, response linearity, radiation hardness, spatial resolution, and real-time data processing. Furthermore, the HM scintillator was found to be highly radiation damage resistant. It exhibited a small 0.025%/kGy signal decrease from a 216 kGy cumulative dose resulting from continuous exposure for 15 min at a FLASH compatible dose rate of 237 Gy/s. Measurements of the signal amplitude versus beam fluence demonstrate linear response of the FBSM at FLASH compatible dose rates of >40 Gy/s. Comparison with commercial Gafchromic film indicates that the FBSM produces a high resolution 2D beam image and can reproduce a nearly identical beam profile, including primary beam tails. The spatial resolution was measured at 35–40 µm. Tests of the firmware beta version show successful operation at 20 000 Hz frame rate or 50 µs/frame, where the real-time analysis of the beam parameters is achieved in less than 1 µs. Conclusions: The FBSM is designed to provide real-time beam profile monitoring over a large active area without significantly degrading the beam quality. A prototype device has been staged in particle beams at currents of single particles up to FLASH level dose rates, using both continuous ion beams and pulsed electron beams. Using a novel scintillator, beam profiling has been demonstrated for currents extending from single particles to 10 nA currents. Radiation damage is minimal and even under FLASH conditions would require ≥50 kGy of accumulated exposure in a single spot to result in a 1% decrease in signal output. Beam imaging is comparable to radiochromic films, and provides immediate images without hours of processing. Real-time data processing, taking less than 50 µs (combined data transfer and analysis times), has been implemented in firmware for 20 kHz frame rates for continuous proton beams.

2D beam imaging↗

Highly Segmented Silicon Strip Detectors for Radiation Detection (LDRD Final Report)

Large area highly segmented silicon strip detectors were investigated for use in applied radiation detection applications. Two ASIC-based readout electronics solutions were tested for compatibility. During the analysis, it was determined that significant computational resources and highly specialized firmware are required to reconstruct the data into a meaningful data stream for generalized spectroscopic performance. Future investment in the technology and careful choice of readout ASIC is expected to demonstrate relevance in measuring high activity samples.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

A High Dynamic-Range Photon-Counting Receiver for Deep Space Optical Communication

The Deep Space Optical Communication (DSOC) project will demonstrate free-space optical communication at almost 3 AU, or 3 orders of magnitude further than any previous attempt. DSOC will utilize the 5m Palomar Hale Telescope to receive the downlink signal, which will couple the downlink light onto an optical table and into a superconducting nanowire single photon detector (SNSPD). The output of the SNSPD is digitized by the Ground Laser Receiver Signal Processing Assembly (GSPA) using a high throughput streaming time to digital converter (TDC). The GSPA is a scalable FPGA-based receiver which demodulates and decodes the DSOC downlink signal through novel signal processing algorithms implemented on Xilinx UltraScale+ FPGAs, as well as Python-based software monitor and control routines. Exploiting the unique TDC-based architecture, the GSPA supports over four orders of magnitude of downlink data rates across multiple orders of magnitude of signal and background powers. In this paper we present an overview of the hardware, firmware and software architectures to implement this system, as well as performance analysis for links ranging from near-Earth to 2.8 AU.

Srinivasan, Meera↗

JTAG-based PLC memory acquisition framework for industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLC) are the embedded devices that directly control and monitor critical industrial infrastructure processes such as nuclear plants and power grid stations. Cyberattacks often target PLCs to sabotage a physical process. A memory forensic analysis of a suspect PLC can answer questions about an attack, including compromised firmware and manipulation of PLC control logic code and I/O devices. Given physical access to a PLC, collecting forensic information from the PLC memory at the hardware-level is risky and challenging. It may cause the PLC to crash or hang since PLCs have proprietary, legacy hardware with heterogeneous architecture. This paper addresses this research problem and proposes a novel JTAG (Joint Test Action Group)-based framework, Kyros, for reliable PLC memory acquisition. Kyros systematically creates a JTAG profile of a PLC through hardware assessment, JTAG pins identification, memory map creation, and optimizing acquisition parameters. It also facilitates the community of interest (such as ICS owners, operators, and vendors) to develop the JTAG profiles of PLCs. Further, we present a case study of Kyros implementation over Allen-Bradley 1756-A10/B to help understand the framework's application on a real-world PLC used in industry settings. The sample PLC memory dumps are shared with the research community to facilitate further research.

Rais, Muhammad Haris↗

Soft Decision Analyzer

The Soft Decision Analyzer (SDA) is an instrument that combines hardware, firmware, and software to perform realtime closed-loop end-to-end statistical analysis of single- or dual- channel serial digital RF communications systems operating in very low signal-to-noise conditions. As an innovation, the unique SDA capabilities allow it to perform analysis of situations where the receiving communication system slips bits due to low signal-to-noise conditions or experiences constellation rotations resulting in channel polarity in versions or channel assignment swaps. SDA s closed-loop detection allows it to instrument a live system and correlate observations with frame, codeword, and packet losses, as well as Quality of Service (QoS) and Quality of Experience (QoE) events. The SDA s abilities are not confined to performing analysis in low signal-to-noise conditions. Its analysis provides in-depth insight of a communication system s receiver performance in a variety of operating conditions. The SDA incorporates two techniques for identifying slips. The first is an examination of content of the received data stream s relation to the transmitted data content and the second is a direct examination of the receiver s recovered clock signals relative to a reference. Both techniques provide benefits in different ways and allow the communication engineer evaluating test results increased confidence and understanding of receiver performance. Direct examination of data contents is performed by two different data techniques, power correlation or a modified Massey correlation, and can be applied to soft decision data widths 1 to 12 bits wide over a correlation depth ranging from 16 to 512 samples. The SDA detects receiver bit slips within a 4 bits window and can handle systems with up to four quadrants (QPSK, SQPSK, and BPSK systems). The SDA continuously monitors correlation results to characterize slips and quadrant change and is capable of performing analysis even when the receiver under test is subjected to conditions where its performance degrades to high error rates (30 percent or beyond). The design incorporates a number of features, such as watchdog triggers that permit the SDA system to recover from large receiver upsets automatically and continue accumulating performance analysis unaided by operator intervention. This accommodates tests that can last in the order of days in order to gain statistical confidence in results and is also useful for capturing snapshots of rare events.

Steele, Glen↗

Memory forensic analysis of a programmable logic controller in industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLCs) are used to automate physical processes such as nuclear plants and power grid stations, and are often subject to cyber attacks. As in conventional IT domain, the memory analysis of the PLCs can help answer important forensic questions about the attack, such as the presence of malicious firmware, injection of modified control logic (the program running on the PLC), and manipulation of I/O devices (e.g., sensors and actuators). Unlike conventional IT domain, PLCs have heterogeneous hardware architecture, proprietary firmware and control software, making it challenging to employ a unified framework for their memory forensics. For merely extracting artifacts of forensic importance, reverse-engineering the firmware is a tedious task, and the effort needs to be repeated for every PLC model. As a community, a step-wise approach to tackle this challenge is to analyze the memory of specific PLCs, and subsequently find a generic framework applicable to all PLCs. Our work is a step forward in this direction. By following a methodology that focuses on the functional layer of PLCs instead of reverse engineering the firmware, we analyze the digital forensic artifacts available in a common PLC, Allen-Bradley ControlLogix 1756-L61. Before diving into the memory dump, we analyze the PLC control software to create a list of important artifacts that are sure to exist in the PLC memory dump. The approach employs a setup where PLC control software RSLogix-5000 is connected to the PLC, and the memory dump can be obtained as and when needed. We create test cases that sequentially highlight each category of artifacts, followed by an examination of the resultant impact on memory. After attaining the listed artifacts, we employ conventional string and known data searches to extract interesting information present in this PLC's memory. The memory analysis profile, presented as a Python library and shared with the community, can help a forensic investigator to readily extract forensic artifacts from the same model's controller. The adopted approach may help researchers in creating memory profile of other PLCs, and ultimately formulating a generic PLC memory analysis framework.

Rais, Muhammad Haris↗

ARCADE (Advanced Reactor Cyber Analysis and Development Environment)

SAND2025-11780O ARCADE (Advanced Reactor Cyber Analysis and Development Environment) software performs cybersecurity experiments on Defensive Cyber Security Architectures (DCSA) for Distributed Control Systems (DCSs). The application is integrated into a cohesive environment that performs cyber risk analyses and reduces costs. ARCADE can investigate the entire cyber-attack surface of a DCS from the physics of control, down to the firmware of individual components with automated efficiency. ARCADE has five major functional components: the Data Broker system, the virtualization environment, the cyber-attack simulator, the cyber-physical analysis system, and the physics simulator. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Valme, Romuald↗