Search NASA⌕ Search

SEARCH · Search NASA

Results for “security operations”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

The Impact of Cultural Values and Organizational Processes on Nuclear Security Operations

Human performance is a pivotal factor in the design, testing, maintenance, and operation of security systems. The effectiveness of these systems relies not only on the capabilities, limitations, motives, and attitudes of the individuals involved, but also on the quality of training, instructional content, and evaluation methods provided. To uphold security standards, seamless integration between technologies and operators necessitates reliable human input. In security operations, human errors, often attributed to blame, sanctions, low motivation, individual accountability, or complacency, are primary causes of system failures. Complacency, characterized by a false sense of security, reflects a lack of awareness of potential threats and is a significant contributing factor to lapses in security. Security incidents arise from various factors, many extend beyond individual control, highlighting the need for a holistic approach to human performance that integrates organizational processes and team collaboration. Historically, errors have been attributed to individual moral or cognitive failures. However, insights from Operational Experiences (OEs) suggest that organizational processes weakness and deficiencies in nuclear cultural values contribute more significantly to security failures than individual mistakes. This paper consolidates lessons learned from diverse international nuclear security cultures and aims to highlight the importance of security culture in shaping global perspectives on nuclear security. It underscores the role of cultural values in shaping nuclear security practices and enhancing the resilience of security systems in the nuclear sector.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

Anatomy of a Security Operations Center

Many agencies and corporations are either contemplating or in the process of building a cyber Security Operations Center (SOC). Those Agencies that have established SOCs are most likely working on major revisions or enhancements to existing capabilities. As principle developers of the NASA SOC; this Presenters' goals are to provide the GFIRST community with examples of some of the key building blocks of an Agency scale cyber Security Operations Center. This presentation viII include the inputs and outputs, the facilities or shell, as well as the internal components and the processes necessary to maintain the SOC's subsistence - in other words, the anatomy of a SOC. Details to be presented include the SOC architecture and its key components: Tier 1 Call Center, data entry, and incident triage; Tier 2 monitoring, incident handling and tracking; Tier 3 computer forensics, malware analysis, and reverse engineering; Incident Management System; Threat Management System; SOC Portal; Log Aggregation and Security Incident Management (SIM) systems; flow monitoring; IDS; etc. Specific processes and methodologies discussed include Incident States and associated Work Elements; the Incident Management Workflow Process; Cyber Threat Risk Assessment methodology; and Incident Taxonomy. The Evolution of the Cyber Security Operations Center viII be discussed; starting from reactive, to proactive, and finally to proactive. Finally, the resources necessary to establish an Agency scale SOC as well as the lessons learned in the process of standing up a SOC viII be presented.

Wang, John↗

LDRD23-0184: Resilience and Hazard Risk Assessment to Prioritize Security Operations for Decisions and Impacts (RHAPSODI)

Recent examples provide a significant concern for the resilience of the U.S. electric grid and represent a need for enhanced decision-making to address an increasingly wide range of complex system interactions and potential consequences. In response, this LDRD project produced a proof-of-concept evaluation called the Resilience and Hazard Assessment to Prioritize Security Operations for Decisions and Impacts (RHAPSODI) methodology as an agile and flexible analytic framework capable of addressing multiple, diverse threats to desired electric grid performance. After empirically grounding needs for the future of U.S. electric grid resilience, this project employed the systems-theoretic process analysis (STPA) to develop a systems engineering risk model. The results of a completed feasibility study of a notional high voltage transmission system demonstrate an improved ability to incorporate both spatial (e.g., geographically distributed) and temporal (e.g., dynamic and time-dependent) elements of security risk to the gird. The success of this LDRD project provides the foundation for further evolution of the systems engineering risk model for the grid; derivation of quantitative approaches to evaluate risk and resilience performance; facilitation of agile experimenting and grid sensitivity to a range of vulnerabilities; and development of tools to assist decision-makers in enhancing U.S. electrical grid resilience.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

NASA Blue Team: Determining Operational Security Posture of Critical Systems and Networks

Emergence of Cybersecurity has increased the focus on security risks to Information Technology (IT) assets going beyond traditional Information Assurance (IA) concerns: More sophisticated threats have emerged from increasing sources as advanced hacker tools and techniques have emerged and proliferated to broaden the attack surface available across globally interconnected networks.

cybersecurity↗

Autonomous Satellite Operations Via Secure Virtual Mission Operations Center

The science community is interested in improving their ability to respond to rapidly evolving, transient phenomena via autonomous rapid reconfiguration, which derives from the ability to assemble separate but collaborating sensors and data forecasting systems to meet a broad range of research and application needs. Current satellite systems typically require human intervention to respond to triggers from dissimilar sensor systems. Additionally, satellite ground services often need to be coordinated days or weeks in advance. Finally, the boundaries between the various sensor systems that make up such a Sensor Web are defined by such things as link delay and connectivity, data and error rate asymmetry, data reliability, quality of service provisions, and trust, complicating autonomous operations. Over the past ten years, researchers from the NASA Glenn Research Center (GRC), General Dynamics, Surrey Satellite Technology Limited (SSTL), Cisco, Universal Space Networks (USN), the U.S. Geological Survey (USGS), the Naval Research Laboratory, the DoD Operationally Responsive Space (ORS) Office, and others have worked collaboratively to develop a virtual mission operations capability. Called VMOC (Virtual Mission Operations Center), this new capability allows cross-system queuing of dissimilar mission unique systems through the use of a common security scheme and published application programming interfaces (APIs). Collaborative VMOC demonstrations over the last several years have supported the standardization of spacecraft to ground interfaces needed to reduce costs, maximize space effects to the user, and allow the generation of new tactics, techniques and procedures that lead to responsive space employment.

Miller, Eric↗

Simulation and Modeling Concepts for Secure Airspace Operations

This paper examines cyber security vulnerabilities of Urban Air Mobility operations. With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, and the cyber resiliency of the current and future air traffic management system.

Urban Air Mobility↗

Simulation and Modeling Concepts for Secure Airspace Operations

This paper examines cyber security vulnerabilities of Urban Air Mobility operations. With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, and the cyber resiliency of the current and future air traffic management system.

Urban Air Mobility↗

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere was heightened from Airports to the communication among the military branches legionnaires. With advanced persistent threats (APTs) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning and configuration of network devices i.e. routers and IDSsIPSs. In addition I will be completing security assessments on software and hardware, vulnerability assessments and reporting, conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, policies and procedures.

computer information security↗

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere has heightened from airports to the communication among the military branches legionnaires. With advanced persistent threats (APT's) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning, and configuration of network devices i.e. routers and IDS's/IPS's. In addition, I will be completing security assessments on software and hardware, vulnerability assessments and reporting, and conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out the tasks stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, as well as policies and procedures.

security↗

Simulation and Modeling Concepts for Secure Airspace Operations

With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. This paper examines cyber security vulnerabilities of Urban Air Mobility operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, thus, improving the cyber resiliency of the current and future air traffic management system.

Cybersecurity↗

Operation and Security Considerations for Heat Pipe Cooled Microreactors

Microreactors and small modular reactors (SMRs) are anticipated to be key elements in the United States' carbon-free energy portfolio, serving as reliable power sources for remote communities, disaster relief zones, extraterrestrial deployments, and backup power needs. Microreactors employ technologies that are substantially more advanced and recent compared to conventional reactors. Furthermore, they are of a drastically smaller scale and are designed to be operated in a diverse set of locations, offering operational flexibility and mobility. In addition, the autonomous or semi-autonomous operation of microreactors with minimal or no on-site staff is anticipated. These factors give rise to specific challenges with regards to their safety and security. The present work investigates considerations related to heat pipe operation, reactor transport, and cyber/cyberphysical security to ensure the indirect and direct consequences of nefarious actors’ actions are understood and can be mitigated by design or through physical security measures. In addition, future directions are proposed for consideration by both HPMR designers and for regulators.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Smashing the Stovepipe: Leveraging the GMSEC Open Architecture and Advanced IT Automation to Rapidly Prototype, Develop and Deploy Next-Generation Multi-Mission Ground Systems

Satellite/Payload Ground Systems - Typically highly-customized to a specific mission's use cases - Utilize hundreds (or thousands!) of specialized point-to-point interfaces for data flows / file transfers Documentation and tracking of these complex interfaces requires extensive time to develop and extremely high staffing costs Implementation and testing of these interfaces are even more cost-prohibitive, and documentation often lags behind implementation resulting in inconsistencies down the road With expanding threat vectors, IT Security, Information Assurance and Operational Security have become key Ground System architecture drivers New Federal security-related directives are generated on a daily basis, imposing new requirements on current / existing ground systems - These mandated activities and data calls typically carry little or no additional funding for implementation As a result, Ground System Sustaining Engineering groups and Information Technology staff continually struggle to keep up with the rolling tide of security Advancing security concerns and shrinking budgets are pushing these large stove-piped ground systems to begin sharing resources - I.e. Operational / SysAdmin staff, IT security baselines, architecture decisions or even networks / hosting infrastructure Refactoring these existing ground systems into multi-mission assets proves extremely challenging due to what is typically very tight coupling between legacy components As a result, many "Multi-Mission" ops. environments end up simply sharing compute resources and networks due to the difficulty of refactoring into true multi-mission systems Utilizing continuous integration / rapid system deployment technologies in conjunction with an open architecture messaging approach allows System Engineers and Architects to worry less about the low-level details of interfaces between components and configuration of systems GMSEC messaging is inherently designed to support multi-mission requirements, and allows components to aggregate data across multiple homogeneous or heterogeneous satellites or payloads - The highly-successful Goddard Science and Planetary Operations Control Center (SPOCC) utilizes GMSEC as the hub for it's automation and situational awareness capability Shifts focus towards getting GS to a final configuration-managed baseline, as well as multi-mission / big-picture capabilities that help increase situational awareness, promote cross-mission sharing and establish enhanced fleet management capabilities across all levels of the enterprise.

GMSEC↗

V-INT: Automated Vulnerability Intelligence and Risk Assessment

The project team, including the University of Arkansas (UA) as the lead, the University of Arkansas at Little Rock (UALR), Network Perception (NP), and Bastazo, has successfully researched, developed, and demonstrated the V-INT toolset, and also integrated it into the commercial products of NP (i.e., NP-View) and Bastazo (i.e., Spartan). The end product is a cybersecurity software tool for energy utilities that can automatically assess the risks of software vulnerabilities in an organization’s assets considering the organization’s firewall policies. It allows security operators to identify the small portion of vulnerabilities that poses true threats to their system (i.e., those that are not protected by firewall policies) and prioritize the mitigation of these vulnerabilities to minimize risks. It also allows security operators to identify the vulnerability-induced attack paths under their organization’s firewall policy, providing effective decision supports for mitigating potential attacks.

97 MATHEMATICS AND COMPUTING↗

Employing a Hardware-in-the-Loop Approach to Realize a Fully Homomorphic Controller for a Small Modular Advanced High Temperature Reactor

This paper addresses the cybersecurity challenges of advanced nuclear reactors by integrating fully homomorphic encryption (FHE) into their control systems, enabling encrypted processing of control signals without compromising functionality. Advanced nuclear reactors, including Small Modular Reactors (SMRs) and microreactors, aim to achieve autonomous and remote operations, reducing costs and enhancing competitiveness. However, these advancements expand the attack surface for cyberattacks, particularly in autonomous and remote operation scenarios. Cyberattacks can exploit vulnerabilities to manipulate physical processes, causing shutdowns, asset damage, or public harm. Such attacks begin with passive reconnaissance, where adversaries intercept communications or observe behaviors to gather information, which is then leveraged to execute cyber-physical attacks by injecting malicious commands. Nuclear power must adopt cybersecurity protection measures to secure the integrity and availability of their digital control systems. This paper demonstrates the application of FHE to secure operations by enabling encrypted processing of sensitive signals and parameters -- ensuring privacy without exposing data. FHE supports secure mathematical operations on encrypted data without requiring decryption. Using a hardware-in-the-loop (HIL) approach, this paper implements an FHE-integrated controller on a BeagleBone Black (BBB) controlling a simulation of the Small Modular Advanced High Temperature Reactor (SmAHTR). By doing so, the encrypted controller protects the integrity of critical set points and control signals during transmission and processing. Thus, FHE-integrated controllers enhance secure operations of advanced nuclear reactors while maintaining functionality.

control systems↗