Search NASA⌕ Search

SEARCH · Search NASA

Results for “hardware vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Investigating Formal Methods Tools and their Applicability for Hardware Vulnerability Remediation

Formal methods use mathematical logic and equations to prove that a system or code is secure. In this poster, I examine existing formal methods tools and their application for projects working to remediate vulnerabilities in hardware and hardware description language. This poster is focused on the tools ReWire and AutoGenILA and I hope to evaluate their benefits and weaknesses with the intention of creating an internal report on the application and weaknesses of existing formal methods tools and identifying gaps for future formal methods tool creation.

97 - MATHEMATICS AND COMPUTING↗

Hardware Fuzzing with An Emulator

Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.

42 ENGINEERING↗

Equipment Assessment Guide: A Technical Inspection and Hardening Guide for Devices in Power Grid Operations

This Equipment Assessment Guide, developed by Idaho National Laboratory (INL), provides a comprehensive framework designed to enhance the security of operational technology (OT) devices within power grid operations. The guide outlines essential steps for asset owners to conduct technical inspections and harden vulnerable hardware and firmware components commonly found in embedded systems. It focuses on components frequently targeted by cyber threats, offering valuable identification techniques for locating and recognizing critical components on devices. Additionally, the guide presents recommended secure configurations aimed at minimizing exposure and reinforcing defenses, along with impact analysis that highlights the potential consequences for grid operations if components are compromised. By implementing the recommendations outlined in this guide, asset owners can significantly enhance their cybersecurity posture, reduce the attack surface of field-deployed devices, and improve the resilience of grid services against emerging cyber threats.

42 - ENGINEERING↗

FOD Prevention at NASA-Marshall Space Flight Center

NASA-MSFC directive MID 5340.1 requires FOD prevention for all flight hardware projects, and requires all support organizations to comply. MSFC-STD-3598 implements a standard approach for FOD prevention, tailored from NAS 412. Three levels of FOD Sensitive Area are identified, adopting existing practices at other NASA facilities. Additional emphasis is given to prevention of impact damage and mitigation of facility FOD sources, especially leaks and spills. Impact Damage Susceptible (IDS) items are identified as FOD-sensitive as well as hardware vulnerable to entrapment of small items.

Lowrey, Nikki M.↗

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere was heightened from Airports to the communication among the military branches legionnaires. With advanced persistent threats (APTs) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning and configuration of network devices i.e. routers and IDSsIPSs. In addition I will be completing security assessments on software and hardware, vulnerability assessments and reporting, conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, policies and procedures.

computer information security↗

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere has heightened from airports to the communication among the military branches legionnaires. With advanced persistent threats (APT's) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning, and configuration of network devices i.e. routers and IDS's/IPS's. In addition, I will be completing security assessments on software and hardware, vulnerability assessments and reporting, and conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out the tasks stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, as well as policies and procedures.

security↗

Visualizing a Vulnerability: Its Connections to Hardware and Software

All Hazards Analysis (AHA) is a framework developed by Idaho National Laboratory that provides capabilities to collect, store, analyze, and visualize critical infrastructure information. A core function of AHA is its ability to simulate faults or outages in networks of infrastructure originating from a plethora of causes, ranging from natural disasters to cyberattacks. AHA utilizes Hardware and Software Bills of Material (HBOM and SBOM, respectively) along with Known Exploited Vulnerabilities (KEVs) to document the potential attack vectors for each piece of infrastructure. The objective of this contribution to AHA was to create a visualization tool that could capture the small details held in each individual artifact as well as preserve the large-scale connections that link them together to aid threat modeling.

58 GEOSCIENCES↗

Experiences with Extra-Vehicular Activities in Response to Critical ISS Contingencies

The maturation of the International Space Station (ISS) design from the proposed Space Station Freedom to today's current implementation resulted in external hardware redundancy vulnerabilities in the final design. Failure to compensate for or respond to these vulnerabilities could put the ISS in a posture where it could no longer function as a habitable space station. In the first years of ISS assembly, these responses were to largely be addressed by the continued resupply and Extra-Vehicular Activity (EVA) capabilities of the Space Shuttle. Even prior to the decision to retire the Space Shuttle, it was realized that ISS needed to have its own capability to be able to rapidly repair or replace external hardware without needing to wait for the next cargo resupply mission. As documented in a previous publication, in 2006 development was started to baseline Extra-Vehicular Activity (EVA, or spacewalk) procedures to replace hardware components whose failure would expose some of the ISS vulnerabilities should a second failure occur. This development work laid the groundwork for the onboard crews and the ground operations and engineering teams to be ready to replace any of this failed hardware. In 2010, this development work was put to the test when one of these pieces of hardware failed. This paper will provide a brief summary of the planning and processes established in the original Contingency EVA development phase. It will then review how those plans and processes were implemented in 2010, highlighting what went well as well as where there were deficiencies between theory and reality. This paper will show that the original approach and analyses, though sound, were not as thorough as they should have been in the realm of planning for next worse failures, for documenting Programmatic approval of key assumptions, and not pursuing sufficient engineering analysis prior to the failure of the hardware. The paper will further highlight the changes made to the Contingency EVA preparation team structure, approach, goals, and the resources allocated to its work after the 2010 events. Finally, the authors will overview the implementation of these updates in addressing failures onboard the ISS in 2012, 2013, and 2014. The successful use of the updated approaches, and the application of the approaches to other spacewalks, will demonstrate the effectiveness of this additional work and make a case for putting significant time and resources into pre-failure planning and analysis for critical hardware items on human-tended spacecraft.

Van Cise, E. A.↗

Experiences with Extra-Vehicular Activities in Response to Critical ISS Contingencies

The maturation of the International Space Station (ISS) design from the proposed Space Station Freedom to today's current implementation resulted in external hardware redundancy vulnerabilities in the final design. Failure to compensate for or respond to these vulnerabilities could put the ISS in a posture to where it could no longer function as a habitable space station. In the first years of ISS assembly, these responses were to largely be addressed by the continued resupply and Extra-Vehicular Activity (EVA) capabilities of the Space Shuttle. Even prior to the decision to retire the Space Shuttle, it was realized that ISS needed to have its own capability to be able to rapidly repair or replace external hardware without needing to wait for the next cargo resupply mission. As documented in a previous publicatoin5, in 2006 development was started to baseline Extra- Vehicular Activity (EVA, or spacewalk) procedures to replace hardware components whose failure would expose some of the ISS vulnerabilities should a second failure occur. This development work laid the groundwork for the onboard crews and the ground operations and engineering teams to be ready to replace any of this failed hardware. In 2010, this development work was put to the test when one of these pieces of hardware failed. This paper will provide a brief summary of the planning and processes established in the original Contingency EVA development phase. It will then review how those plans and processes were implemented in 2010, highlighting what went well as well as where there were deficiencies between theory and reality. This paper will show that the original approach and analyses, though sound, were not as thorough as they should have been in the realm of planning for next worse failures, for documenting Programmatic approval of key assumptions, and not pursuing sufficient engineering analysis prior to the failure of the hardware. The paper will further highlight the changes made to the Contingency EVA preparation team structure, approach, goals, and the resources allocated to its work after the 2010 events. Finally, the authors will overview the implementation of these updates in addressing failures onboard the ISS in 2012, 2013, and 2014. The successful use of the updated approaches, and the application of the approaches to other spacewalks, will demonstrate the effectiveness of this additional work and make a case for putting significant time and resources into pre-failure planning and analysis for critical hardware items on human-tended spacecraft.

Van Cise, E. A.↗

Flammability Test Method for Materials Intended for Use as Fire Barriers in Crewed Habitats

In some crewed-spacecraft applications, onboard materials are intentionally selected to function as hazard control barriers to prevent powered hardware and/or ignited flammable items from igniting nearby flammable materials by acting as non-breaching, non-flammable containment (e.g., cargo transfer bags, zero gravity stowage racks, and jettison stowage bags on the International Space Station). Historically, flammability self-extinguishment testing of broad acreage or outermost layer materials alone was believed to be sufficient to verify overall flammability compliance. Though required, testing on design features such as threaded seams and zippers was not performed due to the incorrect assumption that flammability performance would not be impacted. However, recent coupon level testing of layups and configurations consisting of multiple materials have revealed that these features may be more susceptible to ignition and fire propagation than the bulk material. Additionally, configurational coupon ignition and propagation testing does not explicitly determine a material’s ability to provide protection to vulnerable flammable hardware. The need to evaluate this gap in assessing material or layup effectiveness as fire barriers between ignition sources and flammable materials led to the development of a new configuration-based fire barrier test. Test setup, relevant configurations, and test validation are discussed. The new barrier test method establishes a configuration for the test apparatus, identifies a conservative ignitor configuration, and defines pass/fail criteria. Test setup, relevant configurations, and test validation are discussed.

Susana Harper↗

"Glitch Logic" and Applications to Computing and Information Security

This paper introduces a new method of information processing in digital systems, and discusses its potential benefits to computing and information security. The new method exploits glitches caused by delays in logic circuits for carrying and processing information. Glitch processing is hidden to conventional logic analyses and undetectable by traditional reverse engineering techniques. It enables the creation of new logic design methods that allow for an additional controllable "glitch logic" processing layer embedded into a conventional synchronous digital circuits as a hidden/covert information flow channel. The combination of synchronous logic with specific glitch logic design acting as an additional computing channel reduces the number of equivalent logic designs resulting from synthesis, thus implicitly reducing the possibility of modification and/or tampering with the design. The hidden information channel produced by the glitch logic can be used: 1) for covert computing/communication, 2) to prevent reverse engineering, tampering, and alteration of design, and 3) to act as a channel for information infiltration/exfiltration and propagation of viruses/spyware/Trojan horses.

hardware vulnerabilities↗

Terrestrial Sources of X-Ray Radiation and Their Effects on NASA Flight Hardware

X-rays are an energetic and penetrating form of ionizing electromagnetic radiation, which can degrade NASA flight hardware. The main concern posed by such radiation is degradation of active electronic devices and, in some cases, diodes. Non-electronic components are only damaged at doses that far exceed the point where any electronic device would be destroyed. For the purposes of this document, flight hardware can be taken to mean an entire instrument, the flight electronics within the instrument or the individual microelectronic devices in the flight electronics. This document will discuss and describe the ways in which NASA flight hardware might be exposed to x-rays, what is and isn't a concern, and how to tell the difference. First, we must understand what components in flight hardware may be vulnerable to degradation or failure as a result of being exposed to ionizing radiation, such as x-rays. As stated above, bulk materials (structural metals, plastics, etc.) are generally only affected by ionizing radiation at very high dose levels. Likewise, passive electronic components (e.g. resistors, capacitors, most diodes) are strongly resistant to exposure to x-rays, except at very high doses. The main concerns arise when active components, that is, components like discrete transistors and microelectronic devices, are exposed to ionizing radiation. Active components are designed to respond to minute changes in currents and voltages in the circuit. As such, it is not surprising that exposure to ionizing radiation, which creates ionized and therefore electrically active particles, may degrade the way the hardware performs. For the most part, the mechanism for this degradation is trapping of the charges generated by ionizing radiation by defects in dielectric materials in the hardware. As such, the degree of damage is a function of both the quantity of ionizing radiation exposure and the physical characteristics of the hardware itself. The metric that describes the level of exposure to ionizing radiation is total ionizing dose (TID). The unit of TID is the rad, which is defined as 100 ergs absorbed per gram of material. Dose can be expressed in other units, for example grays (gy), where 1 gy = 100 rads. The actual fluence of radiation needed to deliver a rad depends on the absorbing material, so units of dose are usually stated in reference to the material of interest. That is, for microelectronic devices, the unit of dose is generally rad (Si) or rad (SiO2). However, the definition of absorbed dose in this fashion has the advantage that the type of radiation causing the ionization can be normalized so that a realistic and adequate comparison can be made. The sensitivity of microelectronic parts to TID varies over many orders of magnitude. (Note: Doses to humans are typically expressed in rems-or roentgen-equivalent-man-which measures tissue damage, and depends on the type of radiation, as well as the dose in rads.) Thus far, the "softest" parts tested at NASA showed damage at 500 rads (Si), while parts that are radiation-hardened by design can remain functional to doses on the order of 107 rads (Si). This broad range of sensitivity highlights one of the most important considerations when considering the effects of radiation on electronic parts: In order to determine whether a radiation exposure is a concern for a particular part, one must understand the technologies used in the part and their vulnerabilities to TID damage. A NASA radiation expert should be consulted to obtain such information.

X-ray↗

Hardware Aware Mitigation of Timing Side-Channel Vulnerabilities in Critical Infrastructure Software

Program runtime/timing attacks exploit variations in a program’s execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime sidechannel attacks attempt to balance the execution time of the sensitive code for different control flow paths to eliminate the timing leakage. However, during the mitigation process, most techniques do not consider the underlying hardware/device on which the target program is supposed to run on. This can lead to over-fixing (unnecessary extra operations), under-fixing (not solving the imbalance properly), and even failures. We propose DISARM, a joint hardware-software methodology (unlike any existing solution) for mitigating runtime side-channel vulnerabilities that utilizes timing values from real embedded devices to generate targeted software fixes. We implement DISARM to support C/C++/Java source codes and validate it across 22 standard benchmarks. DISARM outperforms state-of-the-art solutions such as PENDULUM and DifFuzzAR in terms of execution time overhead (up to −46%), code size overhead (up to −10%), and correctness (no failures) on five different embedded/edge devices.

Suha, Tasneem [University of Maine]↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

IADC Vulnerability Report, IT32-21

Numerous mission support hardware systems and their spares are maintained outside of the habitable volume of the International Space Station (ISS), and are arranged covered by a multi-layer insulation (MLI) thermal blanket which provides both thermal control and a measure of protection from micrometeoroids and orbital debris (MMOD). The NASA Hypervelocity Impact Technology (HVIT) group at the Johnson Space Center in Houston Texas has assessed the protection provided by MLI in a series of hypervelocity impact tests using a 1 mm thick aluminum 6061-T6 rear wall to simulate the actual hardware behind the MLI. HVIT has also evaluated methods to enhance the protection provided by MLI thermal blankets. The impact study used both aluminum and steel spherical projectiles accelerated to speeds of 7 km/s using a 4.3 mm, two-stage, light-gas gun at the NASA White Sands Test Facility (WSTF).

Christiansen, E. L.↗

Seismic Resilience of Large Power Transformer Bushings & Non-SF6 Industrial Base Scan Review

Large (high voltage) power transformers (LPT), and more specifically, their bushings, are known to be susceptible to seismic failure. With bushing failure, a transformer will have to be replaced, which has a considerable lead time, adding to the power outage duration. Cost-efficient, proven solutions are not currently available to mitigate this risk, which can persist for the more than 30-year life of a particular transformer. This work will focus on developing and demonstrating a hardware solution to address seismic vulnerabilities and reduce outage risks from LPT failure. Sulfur Hexafluoride (SF6) is a specialty gas with excellent electrical insulation properties which has been used extensively in the power industry. This gas is unfortunately also one of the most potent greenhouse gases known to humanity. A 2014 report by the Intergovernmental Panel on Climate Change found that SF6 has a global warming potential (GWP) 23,000 times higher than Carbon Dioxide, and has the highest GWP of all gases assessed (Myhre 2013). SF6 is almost exclusively man-made and is produced for use as an insulator in high voltage electrical equipment. This makes the production and use of SF6 one of the leading sources of anthropogenic climate change. To fully eliminate the environmental impacts of SF6, alternative technology is needed. The ideal replacement would be a technology that can fulfil the same role as SF6, at the same cost or cheaper, but without adverse environmental effects. Currently, no technology fits this description, however several promising technologies have begun to enter the market. An industry scan was performed to assess the state of industry adoption and manufacturing capability for SF6-free alternative technologies for use at the high-voltage level, and the primary barriers to broader adoption.

10 SYNTHETIC FUELS↗

Automated Addressing Failure Detection for Multiplexer Systems

Multiplexers are electronic devices which select between several input signals and deliver an output signal. Also known as data selectors or mux, multiplexers are commonly used in circuit design to provide signal switching, simplify hardware and manufacturing, and decrease cost. Systems which use a digital mux as a switch or selector are vulnerable to events called addressing failures, arising in hardware or software. An addressing failure results in the system requesting, or the mux delivering, a data signal other than the one intended. The unintended use of this erroneous signal may lead to system-level failures. This paper discusses a novel method of automatic detection for addressing failures, utilizing multiplexer channelization and a monitoring algorithm.

multiplexer↗