Search NASA⌕ Search

SEARCH · Search NASA

Results for “hardware vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

FOD Prevention at NASA-Marshall Space Flight Center

NASA-MSFC directive MID 5340.1 requires FOD prevention for all flight hardware projects, and requires all support organizations to comply. MSFC-STD-3598 implements a standard approach for FOD prevention, tailored from NAS 412. Three levels of FOD Sensitive Area are identified, adopting existing practices at other NASA facilities. Additional emphasis is given to prevention of impact damage and mitigation of facility FOD sources, especially leaks and spills. Impact Damage Susceptible (IDS) items are identified as FOD-sensitive as well as hardware vulnerable to entrapment of small items.

Lowrey, Nikki M.↗

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere was heightened from Airports to the communication among the military branches legionnaires. With advanced persistent threats (APTs) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning and configuration of network devices i.e. routers and IDSsIPSs. In addition I will be completing security assessments on software and hardware, vulnerability assessments and reporting, conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, policies and procedures.

computer information security↗

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere has heightened from airports to the communication among the military branches legionnaires. With advanced persistent threats (APT's) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning, and configuration of network devices i.e. routers and IDS's/IPS's. In addition, I will be completing security assessments on software and hardware, vulnerability assessments and reporting, and conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out the tasks stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, as well as policies and procedures.

security↗

Experiences with Extra-Vehicular Activities in Response to Critical ISS Contingencies

The maturation of the International Space Station (ISS) design from the proposed Space Station Freedom to today's current implementation resulted in external hardware redundancy vulnerabilities in the final design. Failure to compensate for or respond to these vulnerabilities could put the ISS in a posture where it could no longer function as a habitable space station. In the first years of ISS assembly, these responses were to largely be addressed by the continued resupply and Extra-Vehicular Activity (EVA) capabilities of the Space Shuttle. Even prior to the decision to retire the Space Shuttle, it was realized that ISS needed to have its own capability to be able to rapidly repair or replace external hardware without needing to wait for the next cargo resupply mission. As documented in a previous publication, in 2006 development was started to baseline Extra-Vehicular Activity (EVA, or spacewalk) procedures to replace hardware components whose failure would expose some of the ISS vulnerabilities should a second failure occur. This development work laid the groundwork for the onboard crews and the ground operations and engineering teams to be ready to replace any of this failed hardware. In 2010, this development work was put to the test when one of these pieces of hardware failed. This paper will provide a brief summary of the planning and processes established in the original Contingency EVA development phase. It will then review how those plans and processes were implemented in 2010, highlighting what went well as well as where there were deficiencies between theory and reality. This paper will show that the original approach and analyses, though sound, were not as thorough as they should have been in the realm of planning for next worse failures, for documenting Programmatic approval of key assumptions, and not pursuing sufficient engineering analysis prior to the failure of the hardware. The paper will further highlight the changes made to the Contingency EVA preparation team structure, approach, goals, and the resources allocated to its work after the 2010 events. Finally, the authors will overview the implementation of these updates in addressing failures onboard the ISS in 2012, 2013, and 2014. The successful use of the updated approaches, and the application of the approaches to other spacewalks, will demonstrate the effectiveness of this additional work and make a case for putting significant time and resources into pre-failure planning and analysis for critical hardware items on human-tended spacecraft.

Van Cise, E. A.↗

Experiences with Extra-Vehicular Activities in Response to Critical ISS Contingencies

The maturation of the International Space Station (ISS) design from the proposed Space Station Freedom to today's current implementation resulted in external hardware redundancy vulnerabilities in the final design. Failure to compensate for or respond to these vulnerabilities could put the ISS in a posture to where it could no longer function as a habitable space station. In the first years of ISS assembly, these responses were to largely be addressed by the continued resupply and Extra-Vehicular Activity (EVA) capabilities of the Space Shuttle. Even prior to the decision to retire the Space Shuttle, it was realized that ISS needed to have its own capability to be able to rapidly repair or replace external hardware without needing to wait for the next cargo resupply mission. As documented in a previous publicatoin5, in 2006 development was started to baseline Extra- Vehicular Activity (EVA, or spacewalk) procedures to replace hardware components whose failure would expose some of the ISS vulnerabilities should a second failure occur. This development work laid the groundwork for the onboard crews and the ground operations and engineering teams to be ready to replace any of this failed hardware. In 2010, this development work was put to the test when one of these pieces of hardware failed. This paper will provide a brief summary of the planning and processes established in the original Contingency EVA development phase. It will then review how those plans and processes were implemented in 2010, highlighting what went well as well as where there were deficiencies between theory and reality. This paper will show that the original approach and analyses, though sound, were not as thorough as they should have been in the realm of planning for next worse failures, for documenting Programmatic approval of key assumptions, and not pursuing sufficient engineering analysis prior to the failure of the hardware. The paper will further highlight the changes made to the Contingency EVA preparation team structure, approach, goals, and the resources allocated to its work after the 2010 events. Finally, the authors will overview the implementation of these updates in addressing failures onboard the ISS in 2012, 2013, and 2014. The successful use of the updated approaches, and the application of the approaches to other spacewalks, will demonstrate the effectiveness of this additional work and make a case for putting significant time and resources into pre-failure planning and analysis for critical hardware items on human-tended spacecraft.

Van Cise, E. A.↗

Flammability Test Method for Materials Intended for Use as Fire Barriers in Crewed Habitats

In some crewed-spacecraft applications, onboard materials are intentionally selected to function as hazard control barriers to prevent powered hardware and/or ignited flammable items from igniting nearby flammable materials by acting as non-breaching, non-flammable containment (e.g., cargo transfer bags, zero gravity stowage racks, and jettison stowage bags on the International Space Station). Historically, flammability self-extinguishment testing of broad acreage or outermost layer materials alone was believed to be sufficient to verify overall flammability compliance. Though required, testing on design features such as threaded seams and zippers was not performed due to the incorrect assumption that flammability performance would not be impacted. However, recent coupon level testing of layups and configurations consisting of multiple materials have revealed that these features may be more susceptible to ignition and fire propagation than the bulk material. Additionally, configurational coupon ignition and propagation testing does not explicitly determine a material’s ability to provide protection to vulnerable flammable hardware. The need to evaluate this gap in assessing material or layup effectiveness as fire barriers between ignition sources and flammable materials led to the development of a new configuration-based fire barrier test. Test setup, relevant configurations, and test validation are discussed. The new barrier test method establishes a configuration for the test apparatus, identifies a conservative ignitor configuration, and defines pass/fail criteria. Test setup, relevant configurations, and test validation are discussed.

Susana Harper↗

"Glitch Logic" and Applications to Computing and Information Security

This paper introduces a new method of information processing in digital systems, and discusses its potential benefits to computing and information security. The new method exploits glitches caused by delays in logic circuits for carrying and processing information. Glitch processing is hidden to conventional logic analyses and undetectable by traditional reverse engineering techniques. It enables the creation of new logic design methods that allow for an additional controllable "glitch logic" processing layer embedded into a conventional synchronous digital circuits as a hidden/covert information flow channel. The combination of synchronous logic with specific glitch logic design acting as an additional computing channel reduces the number of equivalent logic designs resulting from synthesis, thus implicitly reducing the possibility of modification and/or tampering with the design. The hidden information channel produced by the glitch logic can be used: 1) for covert computing/communication, 2) to prevent reverse engineering, tampering, and alteration of design, and 3) to act as a channel for information infiltration/exfiltration and propagation of viruses/spyware/Trojan horses.

hardware vulnerabilities↗

Terrestrial Sources of X-Ray Radiation and Their Effects on NASA Flight Hardware

X-rays are an energetic and penetrating form of ionizing electromagnetic radiation, which can degrade NASA flight hardware. The main concern posed by such radiation is degradation of active electronic devices and, in some cases, diodes. Non-electronic components are only damaged at doses that far exceed the point where any electronic device would be destroyed. For the purposes of this document, flight hardware can be taken to mean an entire instrument, the flight electronics within the instrument or the individual microelectronic devices in the flight electronics. This document will discuss and describe the ways in which NASA flight hardware might be exposed to x-rays, what is and isn't a concern, and how to tell the difference. First, we must understand what components in flight hardware may be vulnerable to degradation or failure as a result of being exposed to ionizing radiation, such as x-rays. As stated above, bulk materials (structural metals, plastics, etc.) are generally only affected by ionizing radiation at very high dose levels. Likewise, passive electronic components (e.g. resistors, capacitors, most diodes) are strongly resistant to exposure to x-rays, except at very high doses. The main concerns arise when active components, that is, components like discrete transistors and microelectronic devices, are exposed to ionizing radiation. Active components are designed to respond to minute changes in currents and voltages in the circuit. As such, it is not surprising that exposure to ionizing radiation, which creates ionized and therefore electrically active particles, may degrade the way the hardware performs. For the most part, the mechanism for this degradation is trapping of the charges generated by ionizing radiation by defects in dielectric materials in the hardware. As such, the degree of damage is a function of both the quantity of ionizing radiation exposure and the physical characteristics of the hardware itself. The metric that describes the level of exposure to ionizing radiation is total ionizing dose (TID). The unit of TID is the rad, which is defined as 100 ergs absorbed per gram of material. Dose can be expressed in other units, for example grays (gy), where 1 gy = 100 rads. The actual fluence of radiation needed to deliver a rad depends on the absorbing material, so units of dose are usually stated in reference to the material of interest. That is, for microelectronic devices, the unit of dose is generally rad (Si) or rad (SiO2). However, the definition of absorbed dose in this fashion has the advantage that the type of radiation causing the ionization can be normalized so that a realistic and adequate comparison can be made. The sensitivity of microelectronic parts to TID varies over many orders of magnitude. (Note: Doses to humans are typically expressed in rems-or roentgen-equivalent-man-which measures tissue damage, and depends on the type of radiation, as well as the dose in rads.) Thus far, the "softest" parts tested at NASA showed damage at 500 rads (Si), while parts that are radiation-hardened by design can remain functional to doses on the order of 107 rads (Si). This broad range of sensitivity highlights one of the most important considerations when considering the effects of radiation on electronic parts: In order to determine whether a radiation exposure is a concern for a particular part, one must understand the technologies used in the part and their vulnerabilities to TID damage. A NASA radiation expert should be consulted to obtain such information.

X-ray↗

IADC Vulnerability Report, IT32-21

Numerous mission support hardware systems and their spares are maintained outside of the habitable volume of the International Space Station (ISS), and are arranged covered by a multi-layer insulation (MLI) thermal blanket which provides both thermal control and a measure of protection from micrometeoroids and orbital debris (MMOD). The NASA Hypervelocity Impact Technology (HVIT) group at the Johnson Space Center in Houston Texas has assessed the protection provided by MLI in a series of hypervelocity impact tests using a 1 mm thick aluminum 6061-T6 rear wall to simulate the actual hardware behind the MLI. HVIT has also evaluated methods to enhance the protection provided by MLI thermal blankets. The impact study used both aluminum and steel spherical projectiles accelerated to speeds of 7 km/s using a 4.3 mm, two-stage, light-gas gun at the NASA White Sands Test Facility (WSTF).

Christiansen, E. L.↗

Automated Addressing Failure Detection for Multiplexer Systems

Multiplexers are electronic devices which select between several input signals and deliver an output signal. Also known as data selectors or mux, multiplexers are commonly used in circuit design to provide signal switching, simplify hardware and manufacturing, and decrease cost. Systems which use a digital mux as a switch or selector are vulnerable to events called addressing failures, arising in hardware or software. An addressing failure results in the system requesting, or the mux delivering, a data signal other than the one intended. The unintended use of this erroneous signal may lead to system-level failures. This paper discusses a novel method of automatic detection for addressing failures, utilizing multiplexer channelization and a monitoring algorithm.

multiplexer↗

Distributed Ada: Methodology, notation and tools

The task of creating software to run on a distributed system brings with it many problems not encountered in a uni-processor environment. The designer, in addition to creating a solution to meet the functional requirements of the applicaiton, must determine how to distribute that functionality in order to meet the nonfunctional requirements such as performance and fault tolerance. In the traditional approach to building distributed software systems, decisions of how to partition the software must be made early in the design process so that a separate program can be written for each of the processors in the system. This design paradigm is extremely vulnerable to changes in the target hardware environment, as well as being sensitive to poor initial guesses about what distribution of functionality will satisfy the nonfunctional requirements. The paradigm is also weak in that no compiler has a complete view of the system. Many of the advantages of using a powerful language system are lost in a one-program-per-processor environment. Another approach to the development of distributed software systems, Honeywell's Distributed Ada program, is presented.

Eisenhauer, Greg↗

Planetary Protection Technologies for Planetary Science Instruments, Spacecraft, and Missions: Report of the NASA Planetary Protection Technology Definition Team (PPTDT)

Planetary bodies like Mars, Europa, and Enceladus pose the question, "How to study them without contaminating them and destroying future prospects to detect life, if it is there?" The natural trade-off, of course, is that the cleaner your spacecraft, the more you can explore such a body without risk of contaminating it. As chartered by NASA Headquarters, the Planetary Protection Technology Definition Team (PPTDT) was asked to provide a report covering six different areas related to the engineering and technology challenges of implementing planetary protection requirements on solar system exploration missions, including: Assessment of technical and engineering challenges to applying available microbial-reduction methods, including recontamination prevention, to spacecraft hardware and instruments, to meet current NASA requirements on preventing the forward contamination of potentially habitable worlds by future spacecraft missions (orbiters, atmospheric missions, landers, penetrators, and drills); Identification of spacecraft and instrument materials known to be compatible with existing planetary protection protocols; Planetary protection protocols/processes available or which appear promising, and areas ripe for technological development; The technical and engineering challenges in ensuring that spacecraft hardware and instruments can meet organic cleanliness requirements needed to ensure high confidence in differentiating Earth contamination from extraterrestrial signals to avoid false negative as well as false positive results; Approaches for mitigating the identified challenges that would allow instruments to be flown successfully at the required levels of cleanliness and microbial reduction, beginning with identification of commonly used materials and spacecraft hardware that are compatible (or particularly vulnerable) to planetary protection protocols; Engineering, technology, and scientific research and development that could be funded by NASA to provide future capabilities to field scientific instruments and spacecraft on missions that require either subsystem or system-level microbial reduction and recontamination prevention.

John D. Rummel↗

Ground Software Technologies – Embracing Change: Mission Drivers and Technology Opportunities to Enable Long Lived Missions

Mission lifecycles have proven to extend well beyond their original design. The benefits to this are countless but introduce challenges in today’s rapidly changing ground infrastructure and software technologies used to enable mission success. What remains constant is the risk posture missions maintain when accepting change and the use of new technologies. Larger missions are ready for change in early lifecycle development but near launch and especially in operations, few continue to evolve beyond what is set in place in phase C. This paper will discuss how the Advance Multi-Mission Operations System (AMMOS) intends to address, three driving missions concerns: Maintaining functionality (hardware/software) for decades, rapidly responding to security vulnerabilities in software, and finally the ability to quickly evolve infrastructure and software changes. These driving concerns are briefly described below: 1. Maintaining functionality (hardware/software) for decades. Hardware updates considerably faster than 10 years ago. Expectations that a system can remain in place for more than 10 years is no longer valid. Expecting to find hardware replacements for a system older than 5 years will increasingly become more and more challenging. How than do missions plan for hardware changes for long lived missions? Principle Objective: Provide abstraction by virtualizing and containerizing software abstract away any hardware dependencies and package up the application lightweight units. 2. Rapidly responding to security vulnerabilities in software. Cost is often the main impediment and largely driven by the revalidation and testing of system that undergo change. In todays, environment security updates are a major diver demanding systems remain up to date. How then do missions accept these changes and avoid large testing efforts? Principle Objective: Help reduce the cost of re-testing by automation of testing, deployment, and compartmentalizing change. 3. Ability to quickly evolve infrastructure and software changes. Responding quickly to change is similar to the second concern in this paper regarding security vulnerabilities. In this case, it address broader concerns of updating software and infrastructure on a more realistic timeline. How do missions stay up to date with the most recent versions of software and allowing for improved functionality? Principle Objective: Use continuous integration techniques at the system level to ensure rapid turnaround. This paper explores each of these concerns in more detail. It focuses the AMMOS’s current plans, challenges and current roadmap.

Giovannoni, Brian J.↗

Management of human error by design

Design-induced errors and error prevention as well as the concept of lines of defense against human error are discussed. The concept of human error prevention, whose main focus has been on hardware, is extended to other features of the human-machine interface vulnerable to design-induced errors. In particular, it is pointed out that human factors and human error prevention should be part of the process of transport certification. Also, the concept of error tolerant systems is considered as a last line of defense against error.

Wiener, Earl↗

Development and Testing of Molecular Adsorber Coatings

The effect of on-orbit molecular contamination has the potential to degrade the performance of spaceflight hardware and diminish the lifetime of the spacecraft. For example, sensitive surfaces, such as optical surfaces, electronics, detectors, and thermal control surfaces, are vulnerable to the damaging effects of contamination from outgassed materials. The current solution to protect these surfaces is through the use of zeolite coated ceramic adsorber pucks. However, these pucks and its additional complex mounting hardware requirements result in several disadvantages, such as size, weight, and cost related concerns, that impact the spacecraft design and the integration and test schedule. As a result, a new innovative molecular adsorber coating was developed as a sprayable alternative to mitigate the risk of on-orbit molecular contamination. In this study, the formulation for molecular adsorber coatings was optimized using various binders, pigment treatment methods, binder to pigment ratios, thicknesses, and spray application techniques. The formulations that passed coating adhesion and vacuum thermal cycling tests were further tested for its adsorptive capacity. Accelerated molecular capacitance tests were performed in an innovatively designed multi-unit system containing idealized contaminant sources. This novel system significantly increased the productivity of the testing phase for the various formulations that were developed. Work performed during the development and testing phases has demonstrated successful application of molecular adsorber coatings onto metallic substrates, as well as, very promising results for the adhesion performance and the molecular capacitance of the coating. Continued testing will assist in the qualification of molecular adsorber coatings for use on future contamination sensitive spaceflight missions.

Abraham, Nithin↗

Fallible humans and vulnerable systems - Lessons learned from aviation

It is suggested that the problems being experienced in complex automatic systems are essentially due to the failure of information management and communication. The failure covers the entire spectrum: display devices and techniques, coding information so as to reduce human error, and information economy, i.e., resisting the temptation to bombard the operator with unlimited information simply because the system possesses the capability to do so. Since there has been great progress in hardware engineering, it is suggested that further attention is needed in the 'soft' side of systems. The approach should focus on (1) preventing human cognitive slips and (2) making the systems less vulnerable to such slips when they do occur. Most of the examples are taken from studies of cockpit automation.

Wiener, Earl L.↗

Unsupervised Anomaly Detection in High-Dimensional Flight Data Using Convolutional Variational Auto-Encoder

The modern National Airspace System (NAS) is an extremely safe system and the aviation industry has experienced a steady decrease in fatalities over the years. This can be attributed to both improved flight critical systems with redundant hardware and software protections, as well as an increased focus on active monitoring and response to real time and historically identified vulnerabilities by implementing more resilient procedures and protocols. The main approach for identifying vulnerabilities in operations leverages domain expertise using knowledge about how the system should behave within the expected tolerances to known safety margins. This approach works well when the system has a well-defined operating condition. However, the operations in the NAS can be highly complex with various nuances that render it difficult to clearly pre-define all known safety vulnerabilities. With the advancement of data science and machine learning techniques, the potential to automatically identify emerging vulnerabilities in the observed operations has become more practical in recent years. The state-of-the-art anomaly detection approaches in aerospace data usually rely on supervised or semi-supervised learning. However, in many real-world problems such as flight safety, creating labels for the data requires huge amount of effort and is largely impractical. To address this challenge, we developed a Convolutional Variational Auto-Encoder (CVAE), which is an unsupervised learning approach for anomaly detection in high-dimensional heterogeneous time-series data. We validate performance of CVAE compared to the state-of-the-art supervised learning approach as well as unsupervised clustering-based approach using KMeans++ and kernel-based approach using One-Class Support Vector Machine (OC-SVM) on Yahoo!'s benchmark time series anomaly detection data. Finally, we showcase performance of CVAE on a case study of identifying anomalies in the first 60 seconds of commercial flights' take-offs using Flight Operational Quality Assurance (FOQA) data.

Memarzadeh, Milad↗

Unsupervised Anomaly Detection in High-Dimensional Flight Data Using Convolutional Variational Auto-Encoder

The modern National Airspace System (NAS) is an extremely safe system. The industry has experienced a steady decrease in fatalities over the years. This can be contributed to both improved flight critical systems with redundant hardware and software protections as well as an increased focus on active monitoring and response to real time and historically identified vulnerabilities by implementing more resilient procedures and protocols. The main practice for identifying vulnerabilities in operations leverages domain expertise using knowledge about how the system should behave with the expected tolerances to known safety margins. This approach works well when the system has a well-defined operating condition. However, the operations in the NAS can be highly complex with various nuances that render it difficult to clearly pre-define all known safety vulnerabilities. With the advancement of data science and machine learning techniques, the potential to automatically identify emerging vulnerabilities in the observed operations has become more practical in recent years. The state-of-the-art anomaly detection approaches in aerospace data usually rely on supervised or semi-supervised learning. However, in many real-world problems such as flight safety creating labels for the data requires huge amount of efforts and is largely expensive. As a result, in this article, we develop a Convolutional Variational Auto-Encoder (CVAE), an unsupervised learning approach for anomaly detection in high-dimensional heterogeneous time-series data. We validate performance of CVAE compared to the state-of-the-art supervised learning approach (as an upper bound) as well as an supervised clustering based on K-Means (as a lower bound) on Yahoo!'s benchmark time series anomaly detection data. Finally, we showcase performance of CVAE on a case study of identifying anomalies in the first 60 seconds of commercial flights' take-offs using Flight Operational Quality Assurance (FOQA) data.

Milad Memarzadeh↗