Search NASA⌕ Search

SEARCH · Search NASA

Results for “intrusion detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Passive intrusion detection system

An intrusion detection system is described in which crystal oscillators are used to provide a frequency which varies as a function of fluctuations of a particular environmental property of the atmosphere, e.g., humidity, in the protected volume. The system is based on the discovery that the frequency of an oscillator whose crystal is humidity sensitive, varies at a frequency or rate which is within a known frequency band, due to the entry of an intruder into the protected volume. The variable frequency is converted into a voltage which is then filtered by a filtering arrangement which permits only voltage variations at frequencies within the known frequency band to activate an alarm, while inhibiting the alarm activation when the voltage frequency is below or above the known frequency band.

Laue, E. G.↗

Intrusion detection: systems and models

This paper puts forward a review of state of the art and state of the applicability of intrusion detection systems, and models. The paper also presents a classfication of literature pertaining to intrusion detection.

intrusion detection risk security↗

Cyber Resiliency and the Implementation of a Host-Based Intrusion Detection System in an Urban Air Mobility Environment

With the growth in urban air mobility systems and the increasing reliance on interconnected technologies, ensuring the security of these complex infrastructures has become critical. As cities evolve into smart urban centers, the vulnerability to cyber threats escalates, possibly endangering citizens’ safety and the efficiency of transportation networks. In response to these challenges, this paper presents a study on implementing a Host-Based Intrusion Detection System (HIDS) tailored explicitly to urban mobility environments’ unique demands. This study explores the design, development, and deployment of the proposed HIDS, focusing on its adaptability to monitor the hybrid nature of the urban mobility environment. Leveraging machine learning algorithms and anomaly detection techniques, the HIDS is equipped to continuously monitor and analyze the behavior of individual host systems, vehicles, and devices, thereby providing a proactive approach to threat detection. Implementing a HIDS is a pivotal strategy for enhancing cyber resiliency, as it gives an organization granular visibility into internal system activities, enables rapid detection and response to anomalous behavior and cyber threats, and fortifies the organization’s overall cybersecurity posture. In conclusion, this paper highlights the significance of host-based intrusion detection in urban mobility environments and underscores the necessity of tailored security solutions to safeguard against emerging cyber threats.

UAM↗

Cyber Resiliency and the Implementation of a Host-Based Intrusion Detection System in an Urban Air Mobility Environment

With the growth in Urban Air Mobility systems and the increasing reliance on interconnected technologies, ensuring the security of these complex components has become critical. As cities evolve into smart urban centers, the vulnerability to cyber threats escalates, possibly endangering citizens safety and the efficiency of transportation networks.In response to these challenges, this paper presents a study on the need for cyber resilient techniques within future air traffic environments. It will pay specific attention to the implementation of a Host-Based Intrusion Detection System (HIDS) utilizing Atomic OSSEC software, tailored specifically to a NASA simulation of an UrbanAirMobility environments’ unique demands. Further, this study seeks to outline the rational for NASA’s recommendation for a HIDS in such environments. It explores the design, development, and deployment of the proposed HIDS, focusing on its adaptability to monitor the hybrid nature of the Urban Air Mobility environment. Leveraging machine learning algorithms and anomaly detection techniques, the HIDS is equipped to continuously monitor and analyze the behavior of individual host systems, vehicles, and devices, thereby providing a proactive approach to threat detection. Implementing a HIDS is a pivotal strategy for enhancing cyber resiliency, as it gives an organization granular visibility into internal system activities, enables rapid detection and response to anomalous behavior and cyber threats, and fortifies the organizations overall cybersecurity posture. Finally, this study aims to provide recommendations and include learned takeaways that the Urban Air Mobility industry should consider. In brief, this paper highlights the significance of host-based intrusion detection in UrbanAirMobility environments and underscores the necessity of tailored security solutions to safeguard against emerging cyber threats.

UAM↗

Adapting safety requirements analysis to intrusion detection

Several requirements analysis techniques widely used in safety-critical systems are being adapted to support the analysis of secure systems. Perhaps the most relevant system safety techique for Intrusion Detection Systems is hazard analysis.

requirements analysis safety intrusion detection↗

Scanning seismic intrusion detection method and apparatus

An intrusion monitoring system includes an array of seismic sensors, such as geophones, arranged along a perimeter to be monitored for unauthorized intrusion as by surface movement or tunneling. Two wires lead from each sensor to a central monitoring station. The central monitoring station has three modes of operation. In a first mode of operation, the output of all of the seismic sensors is summed into a receiver for amplification and detection. When the amplitude of the summed signals exceeds a certain predetermined threshold value an alarm is sounded. In a second mode of operation, the individual output signals from the sensors are multiplexed into the receiver for sequentially interrogating each of the sensors.

Lee, R. D.↗

Towards Reliable Evaluation of Anomaly-Based Intrusion Detection Performance

This report describes the results of research into the effects of environment-induced noise on the evaluation process for anomaly detectors in the cyber security domain. This research was conducted during a 10-week summer internship program from the 19th of August, 2012 to the 23rd of August, 2012 at the Jet Propulsion Laboratory in Pasadena, California. The research performed lies within the larger context of the Los Angeles Department of Water and Power (LADWP) Smart Grid cyber security project, a Department of Energy (DoE) funded effort involving the Jet Propulsion Laboratory, California Institute of Technology and the University of Southern California/ Information Sciences Institute. The results of the present effort constitute an important contribution towards building more rigorous evaluation paradigms for anomaly-based intrusion detectors in complex cyber physical systems such as the Smart Grid. Anomaly detection is a key strategy for cyber intrusion detection and operates by identifying deviations from profiles of nominal behavior and are thus conceptually appealing for detecting "novel" attacks. Evaluating the performance of such a detector requires assessing: (a) how well it captures the model of nominal behavior, and (b) how well it detects attacks (deviations from normality). Current evaluation methods produce results that give insufficient insight into the operation of a detector, inevitably resulting in a significantly poor characterization of a detectors performance. In this work, we first describe a preliminary taxonomy of key evaluation constructs that are necessary for establishing rigor in the evaluation regime of an anomaly detector. We then focus on clarifying the impact of the operational environment on the manifestation of attacks in monitored data. We show how dynamic and evolving environments can introduce high variability into the data stream perturbing detector performance. Prior research has focused on understanding the impact of this variability in training data for anomaly detectors, but has ignored variability in the attack signal that will necessarily affect the evaluation results for such detectors. We posit that current evaluation strategies implicitly assume that attacks always manifest in a stable manner; we show that this assumption is wrong. We describe a simple experiment to demonstrate the effects of environmental noise on the manifestation of attacks in data and introduce the notion of attack manifestation stability. Finally, we argue that conclusions about detector performance will be unreliable and incomplete if the stability of attack manifestation is not accounted for in the evaluation strategy.

cyber defense↗

Real-Time, Non-Intrusive Detection of Liquid Nitrogen in Liquid Oxygen at High Pressure and High Flow

An integrated fiber-optic Raman sensor has been designed for real-time, nonintrusive detection of liquid nitrogen in liquid oxygen (LOX) at high pressures and high flow rates in order to monitor the quality of LOX used during rocket engine ground testing. The integrated sensor employs a high-power (3-W) Melles Griot diode-pumped, solid-state (DPSS), frequency-doubled Nd:YAG 532- nm laser; a modified Raman probe that has built-in Raman signal filter optics; two high-resolution spectrometers; and photomultiplier tubes (PMTs) with selected bandpass filters to collect both N2 and O2 Raman signals. The PMT detection units are interfaced with National Instruments Lab- VIEW for fast data acquisition. Studies of sensor performance with different detection systems (i.e., spectrometer and PMT) were carried out. The concentration ratio of N2 and O2 can be inferred by comparing the intensities of the N2 and O2 Raman signals. The final system was fabricated to measure N2 and O2 gas mixtures as well as mixtures of liquid N2 and LOX

Singh, Jagdish P.↗

Cybersecurity - Host-based Intrusion Detection Systems (HIDS)

Given a set of flight trajectories, can we classify the trajectories that do not follow a normal path? By identifying abnormal trajectories, further analysis can be done to determine the reasoning for these actions. Addressing these scenarios can bring possible solutions for holding and rerouting problems when its time to incorporate UAM in the airspace.

DFR↗

Cyber Security: Big Data Think II Working Group Meeting

This presentation focuses on approaches that could be used by a data computation center to identify attacks and ensure malicious code and backdoors are identified if planted in system. The goal is to identify actionable security information from the mountain of data that flows into and out of an organization. The approaches are applicable to big data computational center and some must also use big data techniques to extract the actionable security information from the mountain of data that flows into and out of a data computational center. The briefing covers the detection of malicious delivery sites and techniques for reducing the mountain of data so that intrusion detection information can be useful, and not hidden in a plethora of false alerts. It also looks at the identification of possible unauthorized data exfiltration.

computer security↗

Detecting Distributed SQL Injection Attacks in a Eucalyptus Cloud Environment

The cloud computing environment offers malicious users the ability to spawn multiple instances of cloud nodes that are similar to virtual machines, except that they can have separate external IP addresses. In this paper we demonstrate how this ability can be exploited by an attacker to distribute his/her attack, in particular SQL injection attacks, in such a way that an intrusion detection system (IDS) could fail to identify this attack. To demonstrate this, we set up a small private cloud, established a vulnerable website in one instance, and placed an IDS within the cloud to monitor the network traffic. We found that an attacker could quite easily defeat the IDS by periodically altering its IP address. To detect such an attacker, we propose to use multi-agent plan recognition, where the multiple source IPs are considered as different agents who are mounting a collaborative attack. We show that such a formulation of this problem yields a more sophisticated approach to detecting SQL injection attacks within a cloud computing environment.

Kebert, Alan↗

One-Dimensional Scanning Approach to Shock Sensing

Measurement tools for high speed air flow are sought both in industry and academia. Particular interest is shown in air flows that exhibit aerodynamic shocks. Shocks are accompanied by sudden changes in density, pressure, and temperature. Optical detection and characterization of such shocks can be difficult because the medium is normally transparent air. A variety of techniques to analyze these flows are available, but they often require large windows and optical components as in the case of Schlieren measurements and/or large operating powers which precludes their use for in-flight monitoring and applications. The one-dimensional scanning approach in this work is a compact low power technique that can be used to non-intrusively detect shocks. The shock is detected by analyzing the optical pattern generated by a small diameter laser beam as it passes through the shock. The optical properties of a shock result in diffraction and spreading of the beam as well as interference fringes. To investigate the feasibility of this technique a shock is simulated by a 426 m diameter optical fiber. Analysis of results revealed a direct correlation between the optical fiber or shock location and the beam s diffraction pattern. A plot of the width of the diffraction pattern vs. optical fiber location reveals that the width of the diffraction pattern was maximized when the laser beam is directed at the center of the optical fiber. This work indicates that the one-dimensional scanning approach may be able to determine the location of an actual shock. Near and far field effects associated with a small diameter laser beam striking an optical fiber used as a simulated shock are investigated allowing a proper one-dimensional scanning beam technique.

Tokars, Roger↗

NASA Tech Briefs, May 2012

Topics covered include: An "Inefficient Fin" Non-Dimensional Parameter to Measure Gas Temperatures Efficiently; On-Wafer Measurement of a Multi-Stage MMIC Amplifier with 10 dB of Gain at 475 GHz; Software to Control and Monitor Gas Streams; Miniaturized Laser Heterodyne Radiometer (LHR) for Measurements of Greenhouse Gases in the Atmospheric Column; Anomaly Detection in Test Equipment via Sliding Mode Observers; Absolute Position of Targets Measured Through a Chamber Window Using Lidar Metrology Systems; Goldstone Solar System Radar Waveform Generator; Fast and Adaptive Lossless Onboard Hyperspectral Data Compression System; Iridium Interfacial Stack - IrIS; Downsampling Photodetector Array with Windowing; Optical Phase Recovery and Locking in a PPM Laser Communication Link; High-Speed Edge-Detecting Line Scan Smart Camera; Optical Communications Channel Combiner; Development of Thermal Infrared Sensor to Supplement Operational Land Imager; Amplitude-Stabilized Oscillator for a Capacitance-Probe Electrometer; Automated Performance Characterization of DSN System Frequency Stability Using Spacecraft Tracking Data; Histogrammatic Method for Determining Relative Abundance of Input Gas Pulse; Predictive Sea State Estimation for Automated Ride Control and Handling - PSSEARCH; LEGION: Lightweight Expandable Group of Independently Operating Nodes; Real-Time Projection to Verify Plan Success During Execution; Automated Performance Characterization of DSN System Frequency Stability Using Spacecraft Tracking Data; Web-Based Customizable Viewer for Mars Network Overflight Opportunities; Fabrication of a Cryogenic Terahertz Emitter for Bolometer Focal Plane Calibrations; Fabrication of an Absorber-Coupled MKID Detector; Graphene Transparent Conductive Electrodes for Next- Generation Microshutter Arrays; Method of Bonding Optical Elements with Near-Zero Displacement; Free-Mass and Interface Configurations of Hammering Mechanisms; Wavefront Compensation Segmented Mirror Sensing and Control; Long-Life, Lightweight, Multi-Roller Traction Drives for Planetary Vehicle Surface Exploration; Reliable Optical Pump Architecture for Highly Coherent Lasers Used in Space Metrology Applications; Electrochemical Ultracapacitors Using Graphitic Nanostacks; Improved Whole-Blood-Staining Device; Monitoring Location and Angular Orientation of a Pill; Molecular Technique to Reduce PCR Bias for Deeper Understanding of Microbial Diversity; Laser Ablation Electrodynamic Ion Funnel for In Situ Mass Spectrometry on Mars; High-Altitude MMIC Sounding Radiometer for the Global Hawk Unmanned Aerial Vehicle; PRTs and Their Bonding for Long-Duration, Extreme-Temperature Environments; Mid- and Long-IR Broadband Quantum Well Photodetector; 3D Display Using Conjugated Multiband Bandpass Filters; Real-Time, Non-Intrusive Detection of Liquid Nitrogen in Liquid Oxygen at High Pressure and High Flow; Method to Enhance the Operation of an Optical Inspection Instrument Using Spatial Light Modulators; Dual-Compartment Inflatable Suitlock; Large-Strain Transparent Magnetoactive Polymer Nanocomposites; Thermodynamic Vent System for an On-Orbit Cryogenic Reaction Control Engine; Time Distribution Using SpaceWire in the SCaN Testbed on ISS; and Techniques for Solution- Assisted Optical Contacting.

Source record↗

Information Security and Integrity Systems

Viewgraphs from the Information Security and Integrity Systems seminar held at the University of Houston-Clear Lake on May 15-16, 1990 are presented. A tutorial on computer security is presented. The goals of this tutorial are the following: to review security requirements imposed by government and by common sense; to examine risk analysis methods to help keep sight of forest while in trees; to discuss the current hot topic of viruses (which will stay hot); to examine network security, now and in the next year to 30 years; to give a brief overview of encryption; to review protection methods in operating systems; to review database security problems; to review the Trusted Computer System Evaluation Criteria (Orange Book); to comment on formal verification methods; to consider new approaches (like intrusion detection and biometrics); to review the old, low tech, and still good solutions; and to give pointers to the literature and to where to get help. Other topics covered include security in software applications and development; risk management; trust: formal methods and associated techniques; secure distributed operating system and verification; trusted Ada; a conceptual model for supporting a B3+ dynamic multilevel security and integrity in the Ada runtime environment; and information intelligence sciences.

Source record↗

The impact of the eruptions of Mount Pinatubo and Cerro Hudson on antarctic aerosol levels during the 1991 austral spring

At the beginning of the 1991 Austral spring, volcanic aerosols from Mt. Pinatubo and Cerro Hudson were present in the polar stratosphere of the Southern Hemisphere. Satellite observations of aerosol extinction were used to identify and track the movement of these aerosols in the vicinity of the Antarctic vortex during August through November 1991. A layer of mature Mt. Pinatubo aerosols was identified near 21 km and a layer of fresh Cerro Hudson aerosols was identified near 12 km. This altitude separation of the Mt. Pinatubo and Cerro Hudson aerosols was observed throughout the period. Below 15 km, the polar stratosphere was subject to episodes of strong wave activity which transported the Cerro Hudson aerosols poleward and, after the middle of September, they became a persistent feature beneath the vortex. Above 15 km, signatures of Mt. Pinatubo aerosols were observed near the vortex boundary, but significant portions of the vortex interior remained free of any detectable intrusions of Mt. Pinatubo aerosols until the final warming in mid-November.

Pitts, M. C.↗

RTO Technical Report: A Quarterly Listing

This is a listing of recent unclassified RTO technical publications processed by the NASA Center for AeroSpace Information from April 1,2002 through June 30, 2002. Topics covered include: intrusion detection and design loads for aircraft.

Source record↗

Security in Full-Force

When fully developed for NASA, Vanguard Enforcer(TM) software-which emulates the activities of highly technical security system programmers, auditors, and administrators-was among the first intrusion detection programs to restrict human errors from affecting security, and to ensure the integrity of a computer's operating systems, as well as the protection of mission critical resources. Vanguard Enforcer was delivered in 1991 to Johnson Space Center and has been protecting systems and critical data there ever since. In August of 1999, NASA granted Vanguard exclusive rights to commercialize the Enforcer system for the private sector. In return, Vanguard continues to supply NASA with ongoing research, development, and support of Enforcer. The Vanguard Enforcer 4.2 is one of several surveillance technologies that make up the Vanguard Security Solutions line of products. Using a mainframe environment, Enforcer 4.2 achieves previously unattainable levels of automated security management.

Source record↗