Search NASA⌕ Search

SEARCH · Search NASA

Results for “threat profile”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

FIC Threat Profile: Provided by Shamrock Cyber

The FIC team has engaged with PNNL’s Shamrock Cyber Team to produce this Threat Profile. The Threat Profile provides the foundation for a thorough understanding of threats for development teams and stakeholders, and users of the system. The Threat Profile can be used as is, or as content to inform other reports tailored to a specific audience. It is intended to enable decision makers at all levels to improve the security posture of the system.

97 MATHEMATICS AND COMPUTING↗

A Cybersecurity Threat Profile for a Connected Lighting System

In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement.

97 MATHEMATICS AND COMPUTING↗

A Cybersecurity Threat Profile for a Connected Lighting System

In anticipation of improved energy performance and cost savings, cities and building owners are increasingly considering “smart lighting initiatives” that aim to convert their collection of simple luminaires (i.e., lighting fixtures) into an intelligent connected lighting system (CLS) capable of remotely monitoring energy consumption and fault conditions, and possibly implementing adaptive lighting schemes. The U.S. Department of Energy (DOE) has set an national goal of tripling the energy efficiency and demand flexibility of the buildings sector by 2030, relative to 2020 levels 1. It is forecast that connected lighting systems can contribute to that goal by delivering 125 TWh of annual energy savings by 2035 2, equivalent to the annual output of 50 typical (500 MW) power plants. However, these energy savings and the DOE goal are put at significant risk if connected technologies are not adopted due to real or perceived cybersecurity concerns. Connected IoT devices such as these have historically been rife with vulnerabilities which sometimes put security considerations secondary to functionality and operability. What are the cybersecurity threats that will impact these systems, as formerly banal luminaires transition into intelligent connected devices that collect information about themselves, their surrounding environment, and possibly us? In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement. Fifty-seven threats were identified. Among our key findings: (1) 65% (37/57) of the threats did not involve the luminaires, but rather the other components needed to communicate with and manage them; (2) 63% (36/57) of the threats could have been mitigated through manufacturer-implemented defensive techniques or “controls”; and (3) 23% (13/57) of the threats were dependent on the network configuration. Recommendations based on the results of this work are made to key stakeholder groups. Notably, lighting technology developers are advised to address all threats that can be reasonably controlled with baked-in technology solutions (e.g., encryption or authentication controls), and employ some form of secure supply chain management and tracking where other parts (e.g., sensors, microprocessors) of a luminaire must also be built and manufactured with the proper security controls in place. Developers should also review threats involving assets not developed in-house to understand how connectivity with other devices will affect their product during system operation and determine if a compensating control for a defense-in-depth strategy will be needed. Finally, those interested in deploying CLS should compare the differences between cloud and on-premise models to determine which is more suitable for their needs and the abilities of their security team.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Oak Ridge National Laboratory Security by Design: A Plant Design and Component-Based Approach to Technical Solutions to Insider and Outsider Threat

Security costs for nuclear reactors have been shown to rise over the lifecycle of a nuclear facility as new threats, security weaknesses, and the generic threat profile of the plant location change over time. This paper conducts a review of the technological gaps that currently exist in Security by Design (SeBD) based on the literature available and attempts to close those gaps through proposing technological constructs and processes that can integrate safety and security in the design process of a plant, with a primary focus on SMR technology. Under the new modular and mass manufacturing regime, where plant designs attempt to reduce costs with potential economies of scale and modular construction, the current SeBD definitions focusing on state level regulators are not considered adequate since the licensing stage is often too late in the design process to integrate the true cost savings of SeBD. Thus, this paper attempts to remedy the current logic in order to allow for continuous implementation of security alongside the development of the safety concept for the plant. If adopted within the design process the establishment of this type of technology will allow for a technological ecosystem to evolve that will imbed security concepts into the physical design of the components of the plant.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Assessing the Threat: Weaving Cybersecurity into the Building Development Process

Today’s connected lighting systems have the potential to reduce energy consumption and operational costs via the use of the data they collect and share with other building systems (e.g., HVAC, building automation, security). However, many market available products are new to being networked, and when networked components in lighting and other building systems are not sufficiently secured, they present opportunities for criminals to exploit. Further, security vulnerabilities in one system can be used as lateral steppingstones that allow access to other prized assets on the same network. These cybersecurity concerns could deter the adoption and use of connected systems, which then could jeopardize long-term national objectives for reduced energy usage. The workflows described here and presented in more detail in the referenced reports are examples of how these frameworks and tools can be put to practical use during system design and specification.

attack surface, Building development, threat analy↗

Recommendations for Secure Transport: Material Conveyance Physical Protection Technology

Nuclear material is at higher risk of theft and sabotage during transport than during any other phase of the nuclear fuel lifecycle. Nuclear materials are transported in the public domain where adversaries have an upper hand by taking advantage of the time and location of the theft or sabotage attempt. As such, even modest threat profiles for transport of nuclear and radioactive material can require substantial detection and delay measures to support timely response. Conveyance tracking augmented with technology that improves on-the-scene situational awareness at a remote monitoring center has been adopted as a de-facto standard approach for transportation security. At present, the extended tracking and situational awareness capabilities needed for a nuclear material shipment, as is provided by the purpose designed, Transportation – Security, Tracking and Reporting (T-STAR) System, do not exist in a single commercial off-the-shelf (COTS) solution. Typically, the COTS systems that excel in one area are deficient in other areas, presenting challenges to designing well-rounded, robust systems. Still, COTS solutions can offer the basic set of tracking and situational awareness capabilities by indicating last update time, current location, and route taken. By incorporating vehicle and driver performance measures via the vehicle’s controller area network (CAN bus) and video alongside other data streams allows telemetry and other shipment information to be assessed in novel ways.This paper describes the operation, capabilities and features of various conveyance protection systems and approaches, assesses emerging technologies and how they could be used through a unified interface, and enumerates additional ways to provide early detection using vehicle, onboard technologies, effective delay technologies and approaches and simple equipment to improve protection during transport.

Shannon, Michael↗

Disease resistance in coral is mediated by distinct adaptive and plastic gene expression profiles

Infectious diseases are an increasing threat to coral reefs, resulting in altered community structure and hindering the functional contributions of disease-susceptible species. We exposed seven reef-building coral species from the Caribbean to white plague disease and determined processes involved in (i) lesion progression, (ii) within-species gene expression plasticity, and (iii) expression-level adaptation among species that lead to differences in disease risk. Gene expression networks enriched in immune genes and cytoskeletal arrangement processes were correlated to lesion progression rates. Whether or not a coral developed a lesion was mediated by plasticity in genes involved in extracellular matrix maintenance, autophagy, and apoptosis, while resistant coral species had constitutively higher expression of intracellular protein trafficking. This study offers insight into the process involved in lesion progression and within- and between-species dynamics that lead to differences in disease risk that is evident on current Caribbean reefs.

59 BASIC BIOLOGICAL SCIENCES↗

Countering Weapons of Mass Destruction (CWMD) Device Cybersecurity Characterization Process and Profile

Countering Weapons of Mass Destruction (CWMD) recognizes that threats in the cyberspace domain continue to grow, which requires CWMD devices and supporting systems to be both cybersecure (ability to protect or defend from cyber-attacks) and resilient (ability to maintain required capability in the face of adversity) to cyber threats. The CWMD cybersecurity characterization approach in this document supports existing cyber resilience activities within the Acquisition Lifecycle Framework. Similarly, this process supports existing Department of Homeland Security Cyber Resilience Test and Evaluation activities, which consist of iterative processes, starting at the initiation of system acquisition and continuing throughout the entire device and system life cycle. Cyber resilience is the ability of an information system to continue to operate while under attack, even if in a degraded or debilitated state, and to rapidly recover operational capabilities for essential functions after a successful attack. The goal of the security characterization task for CWMD is to support the development of a CBRN device-dependent profile that aligns with device network capabilities and maps to recommended security controls to create a characterization security profile impact levels. The impact levels for CWMD devices should be characterized as Low (L), Moderate (M), High (H) to align with the low, moderate, high control baselines. To estimate the impact levels, the device’s security-related attributes are translated into the security objectives: Confidentiality (C), Integrity (I), and Availability (A), known as the CIA triad. The potential impact for each device can be L, M, H, for devices that connect and transmit different types of data and may have different impact levels. National Institute of Standards and Technology Federal Information Processing Standards Publication 199 states, “the potential impact values assigned to the respective security objectives shall be the highest value from among those security categories that have been determined for each type of information resident on the information system.” As CWMD is determining the cybersecurity impact levels of CBRN devices based on network connections and data transfers, the impact levels are aligned with the associated attributes of network connections and communications. For example, if the device system is connected to a wireless network and transmits different data types based on the confidentiality of the data, the highest impact value for each security objective should represent the device’s CIA impact level. This document is intended to be used by test managers, test team, and program managers.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Countering Weapons of Mass Destruction (CWMD) Device Cybersecurity Characterization Process and Profile

Countering Weapons of Mass Destruction (CWMD) recognizes that threats in the cyberspace domain continue to grow, which requires CWMD devices and supporting systems to be both cybersecure (ability to protect or defend from cyber-attacks) and resilient (ability to maintain required capability in the face of adversity) to cyber threats. The CWMD cybersecurity characterization approach in this document supports existing cyber resilience activities within the Acquisition Lifecycle Framework. Similarly, this process supports existing Department of Homeland Security Cyber Resilience Test and Evaluation activities, which consist of iterative processes, starting at the initiation of system acquisition and continuing throughout the entire device and system life cycle. Cyber resilience is the ability of an information system to continue to operate while under attack, even if in a degraded or debilitated state,1 and to rapidly recover operational capabilities for essential functions after a successful attack.2 The goal of the security characterization task for CWMD is to support the development of a CBRN device-dependent profile that aligns with device network capabilities and maps to recommended security controls to create a characterization security profile impact levels. The impact levels for CWMD devices should be characterized as Low (L), Moderate (M), High (H) to align with the low, moderate, high control baselines. To estimate the impact levels, the device’s security-related attributes are translated into the security objectives: Confidentiality (C), Integrity (I), and Availability (A), known as the CIA triad. The potential impact for each device can be L, M, H, for devices that connect and transmit different types of data and may have different impact levels. National Institute of Standards and Technology Federal Information Processing Standards Publication 199 states, “the potential impact values assigned to the respective security objectives shall be the highest value from among those security categories that have been determined for each type of information resident on the information system.”3 As CWMD is determining the cybersecurity impact levels of CBRN devices based on network connections and data transfers, the impact levels are aligned with the associated attributes of network connections and communications. For example, if the device system is connected to a wireless network and transmits different data types based on the confidentiality of the data, the highest impact value for each security objective should represent the device’s CIA impact level. This document is intended to be used by test managers, test team, and program managers.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

FIC Consequence Profile - Hypothetical Cybercrime Syndicate Adversary Dossier

The FIC team has engaged PNNL’s Shamrock Cyber team to produce this Consequence Profile. This Consequence Profile is an Adversary Dossier, which provides the foundation for a thorough understanding of unacceptable mission outcomes, and the threats and vulnerabilities that make these outcomes plausible. The dossier helps stakeholders and development teams understand each other’s viewpoints. It also provides a means for reducing overall risk by prioritizing threats and vulnerabilities based on unacceptable outcomes. The Consequence Profile can be used as is, or as content to inform other reports tailored to a specific audience. It is intended to enable decision makers at all levels to improve the security posture of the system.

Beaman, Jacob E.↗

UAS Activity Profile Survey

Commercial vendors, trying to tap into the physical protection of critical infrastructure, are offering nuclear facilities the opportunity to borrow detection counter-unmanned aircraft systems (CUAS) equipment to survey the airspace over and around the facility. However, using one vendor or method of detection (e.g., radio frequency [RF], radar, acoustic, visual) will not necessarily provide a complete airspace profile since no single method can detect all UAS threats. Using several detection technologies, the unmanned aircraft systems (UAS) Team, who supports the U.S. National Nuclear Security Administration (NNSA) Office of International Nuclear Security (INS), would like to offer partners a comprehensive airspace profile of the types and frequency of UAS that fly within and around critical infrastructure. Improved UAS awareness will aid in the risk assessment process.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Pathway-based analyses of gene expression profiles at low doses of ionizing radiation

Radiation exposure poses a significant threat to human health. Emerging research indicates that even low-dose radiation once believed to be safe, may have harmful effects. This perception has spurred a growing interest in investigating the potential risks associated with low-dose radiation exposure across various scenarios. To comprehensively explore the health consequences of low-dose radiation, our study employs a robust statistical framework that examines whether specific groups of genes, belonging to known pathways, exhibit coordinated expression patterns that align with the radiation levels. Notably, our findings reveal the existence of intricate yet consistent signatures that reflect the molecular response to radiation exposure, distinguishing between low-dose and high-dose radiation. Moreover, we leverage a pathway-constrained variational autoencoder to capture the nonlinear interactions within gene expression data. By comparing these two analytical approaches, our study aims to gain valuable insights into the impact of low-dose radiation on gene expression patterns, identify pathways that are differentially affected, and harness the potential of machine learning to uncover hidden activity within biological networks. This comparative analysis contributes to a deeper understanding of the molecular consequences of low-dose radiation exposure.

63 RADIATION, THERMAL, AND OTHER ENVIRON. POLLUTAN↗

Ransomware Security Threat Modeling for Photovoltaic Systems

Ransomware attacks are one of the most dangerous cyber-attacks which can disrupt the operation of photovoltaic (PV) systems and incur an enormous economic loss. This paper introduces a ransomware security threat modeling method that identifies potential vulnerabilities, threats, and impacts of ransomware attacks targeting a PV system. Here, the security threat modeling consists of three steps: 1) system identification, 2) threat modeling that finds existing vulnerabilities, 3) attack modeling that designs attack profiles to succeed ransomware attacks, and 4) penetration testing that performs authorized cyber-attacks and analyzes impacts of the ransomware attack profiles using a real-time hardware-in-the-loop (HIL) PV system security testbed.

attack modeling↗

Satellite Enveloped with STITCHED Engineering Sensors for Detection of Approaching Objects

Today as well as tomorrows spaceborne assets impact almost all areas of national and nuclear security. Spaceborne assets can not only collect and disseminate valuable data, well beyond just the visual, but also track terrestrial-based mobile assets in real-time, and active spaceborne platforms potentially pose serious risk to vulnerable earth-based systems and infrastructures. The capability to defend national spaceborne assets from attack/interference is critical for security interests. This effort supports this mission through the cost-effective preeminent detection of approaching threats to our nation’s vital resources, in order to help secure and trust these high-value assets against the threats of tomorrow. This project develops novel fabrication techniques for conformal, low-profile and lightweight leakywave antenna (LWA) detection/imaging systems, which fuses technical embroidery (TE) and laser ablation (LA) processes with LWA design. Technical embroidery is an emerging field in additive textile manufacturing where flexible materials and functionalized fabrics are created for a wide variety of uses and purposes, while laser ablation is the process of removing material from a solid surface by irradiating it with a laser beam. Here, thin, conformal antenna designs are designed, modeled and fabricated using both TE and LA, to create lightweight, flexible and conformal object detection and imaging radars. This novel development ensures our nation’s ability to field advanced lightweight and conformal technologies to protect spaceborne assets.

42 ENGINEERING↗

FIC Vulnerability Profile

The FIC team is engaged with Pacific Northwest National Laboratory’s (PNNL’s) Shamrock Cyber Team to provide cybersecurity analyses of the FIC software. Shamrock offers both Threat-Based Analysis services and Secure Software Development services. These services are ultimately used to understand and mitigate threats against software and to reduce vulnerabilities in software, thus improving overall cybersecurity and informing decision makers. Shamrock’s Secure Software Development services, specifically Static Analysis Security Testing (SAST) and Open-Source Analysis (OSA), produced this Vulnerability Profile.

97 MATHEMATICS AND COMPUTING↗

Pharmacological Profiling of a Brugia malayi Muscarinic Acetylcholine Receptor as a Putative Antiparasitic Target

The diversification of anthelmintic targets and mechanisms of action will help ensure the sustainable control of nematode infections in response to the growing threat of drug resistance. G protein-coupled receptors (GPCRs) are established drug targets in human medicine but remain unexploited as anthelmintic substrates despite their important roles in nematode neuromuscular and physiological processes. Bottlenecks in exploring the druggability of parasitic nematode GPCRs include a limited helminth genetic toolkit and difficulties establishing functional heterologous expression. In an effort to address some of these challenges, we profile the function and pharmacology of muscarinic acetylcholine receptors in the human parasite Brugia malayi, an etiological agent of human lymphatic filariasis. While acetylcholine-gated ion channels are intensely studied as targets of existing anthelmintics, comparatively little is known about metabotropic receptor contributions to parasite cholinergic signaling. Using multivariate phenotypic assays in microfilariae and adults, we show that nicotinic and muscarinic compounds disparately affect parasite fitness traits. We identify a putative G protein-linked acetylcholine receptor of B. malayi (Bma-GAR-3) that is highly expressed across intramammalian life stages and adapt spatial RNA in situ hybridization to map receptor transcripts to critical parasite tissues. Tissue-specific expression of Bma-gar-3 in Caenorhabditis elegans (body wall muscle, sensory neurons, and pharynx) enabled receptor deorphanization and pharmacological profiling in a nematode physiological context. Finally, we developed an image-based feeding assay as a reporter of pharyngeal activity to facilitate GPCR screening in parasitized strains. We expect that these receptor characterization approaches and improved knowledge of GARs as putative drug targets will further advance the study of GPCR biology across medically important nematodes.

60 APPLIED LIFE SCIENCES↗

Transitions of foliar mycobiota community and transcriptome in response to pathogenic conifer needle interactions

Profiling the host–mycobiota interactions in healthy vs. diseased forest ecosystems helps understand the dynamics of understudied yet increasingly important threats to forest health that are emerging due to climate change. We analyzed the structural and functional changes of the mycobiota and the responses of Pinus contorta in the Lophodermella needle cast pathosystem through metabarcoding and metatranscriptomics. When needles transitioned from asymptomatic to symptomatic, dysbiosis of the mycobiota occurred, but with an enrichment of Lophodermella pathogens. Many pathogenicity-related genes were highly expressed by the mycobiota at the necrotrophic phase, showing an active pathogen response that are absent in asymptomatic needles. This study also revealed that Lophodermella spp. are members of a healthy needle mycobiota that have latent lifestyles suggesting that other pine needle pathogens may have similar biology. Interestingly, Pinus contorta upregulated defense genes in healthy needles, indicating response to fungal recognition, while a variety of biotic and abiotic stresses genes were activated in diseased needles. Further investigation to elucidate the possible antagonistic interplay of other biotic members leading to disease progression and/or suppression is warranted. This study provides insights into microbial interactions in non-model pathosystems and contributes to the development of new forest management strategies against emerging latent pathogens.

59 BASIC BIOLOGICAL SCIENCES↗

Driver Identification Midyear Report

First, we create a profile for each authorized driver based on their existing driving data. We then train a machine learning model on the driving data from this profile, yielding an individualized model for each driver. Finally during a drive, we pass the Controller Area Network (CAN) data to the model and authen ticate the driver’s identity in real-time. This verification or lack thereof could be used to alert supervisors of threats to their drivers or transported materials. Deviations from their normal driving behavior could indicate high-risk situations, medical events, or even insider threats.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗