Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure data analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Ground System Architectures Workshop GMSEC SERVICES SUITE (GSS): an Agile Development Story

The GMSEC (Goddard Mission Services Evolution Center) Services Suite (GSS) is a collection of tools and software services along with a robust customizable web-based portal that enables the user to capture, monitor, report, and analyze system-wide GMSEC data. Given our plug-and-play architecture and the needs for rapid system development, we opted to follow the Scrum Agile Methodology for software development. Being one of the first few projects to implement the Agile methodology at NASA GSFC, in this presentation we will present our approaches, tools, successes, and challenges in implementing this methodology. The GMSEC architecture provides a scalable, extensible ground and flight system for existing and future missions. GMSEC comes with a robust Application Programming Interface (GMSEC API) and a core set of Java-based GMSEC components that facilitate the development of a GMSEC-based ground system. Over the past few years, we have seen an upbeat in the number of customers who are moving from a native desktop application environment to a web based environment particularly for data monitoring and analysis. We also see a need to provide separation of the business logic from the GUI display for our Java-based components and also to consolidate all the GUI displays into one interface. This combination of separation and consolidation brings immediate value to a GMSEC-based ground system through increased ease of data access via a uniform interface, built-in security measures, centralized configuration management, and ease of feature extensibility.

Software Development/Agile↗

NASA's Unsteady Pressure-Sensitive Paint Research and Operational Capability Developments

In the last three years, several advancements have been made to produce a new state-of-the-art capability in the field of Aerosciences. NASA’s Aerosciences Evaluations and Test Capabilities (AETC) Portfolio Office has funded a multi-year project to produce the unsteady Pressure-Sensitive Paint (uPSP) technology as an operational capability in key ground test facilities at NASA. The research and development has primarily been conducted at NASA Ames Research Center’s (ARC) Unitary Plan Wind Tunnel (UPWT) 11-by 11-ft Transonic Wind Tunnel (TWT). The NASA ARC UPWT is one of the ground test facilities under NASA AETC’s Portfolio Office. AETC’s goals are to provide the tools to deliver the technology innovations and breakthroughs necessary to address increasingly complex research and development challenges. AETC’s integrated approach will consider the complimentary high-end compute capabilities necessary to advance analysis in conjunction with ground experimental capabilities. The uPSP Capability Challenge Project is a demonstration of several different technologies: 1) the unsteady Pressure-Sensitive Paint (uPSP) technology, and 2) Project: Red Rover, establishing a secure, reliable, fast connection between experimental and computation facilities, leveraging NASA’s computational resources within the High-End Compute Capability (HECC) Project for processing, storing, and sharing data efficiently. This project demonstrates the technical diversity and technical inclusion need to advance the field of Aerosciences. The approach to combine subject matter experts in experimental methods, optical methods, production wind tunnel testing, network engineering, high-end computing, signal processing, grid generation, and visualization while establishing the required infrastructure for subject matter experts to have access to the data while the wind tunnel test is being conducted. The most recent advancements for the uPSP technology have focused on three key areas: development of data products, robust processing pipeline, operational efficiencies and uncertainty quantification.

buffet↗

AI-based Cyber Event OSINT via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes.

Dale, Dakota↗

Open Source Intelligence for Cybersecurity Events via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes. We also examine the potential of OSINT for identifying the network protocols associated with specific events, which can aid in the mitigation procedures by informing operators if the vulnerability is exploitable given their system’s network configurations.

Dale, Dakota↗

Modelling and Analysis of a Regenerative Fuel Cell Propulsion System for a High Altitude Long Endurance UAV

In the search to bridge current gaps in surveillance and communication technologies, a new type of, aircraft is currently undergoing design. The idea of a High Altitude Long Endurance (HALE) aircraft is already a few decades old, but has only recently become realizable. A relay and collector of information at altitudes of 65,000 feet and higher could greatly improve standards of data exchange, homeland security, and research of the air, land and sea. NASA, as a major force in propulsion research, is exploring methods of powering an autonomous aircraft for days, weeks, or even months without refueling. Such a task requires not only high energy density, but also the ability to make use of renewable energy sources to regenerate power. Hydrogen is one of the most energy dense fuels available. Fuel cells make use of hydrogen by harnessing the energy released as it combines with oxygen to produce electricity and water. Fuel cells are envisioned to occupy future propulsion systems in cooperation with solar cells where the photovoltaic arrays harness sunlight into power which can electrolize the water byproduct into reusable hydrogen and oxygen. Modeling this type of system requires adequate assumptions of support hardware and daily transients in operation. The performance of a regenerative fuel cell propulsion system lies in the flight characteristics (altitude, density, temperature, latitude, etc.). Each subsystem is defined by many parameters which can be varied across wide ranges. Statistical and probabilistic analyses bring forward a wealth of information that can be utilized in the design process. This is necessary since the required technologies are relatively young and barely, if yet, capable. Once the modeling is complete, a design space exploration of this highly constrained scenario can be utilized to find the optimal design. The model will become an interactive environment with which experiments and tests can be run. When linked

Simpson, Mike B.↗

mvBayesR

SAND2025-11559O The mvBayesR tool performs multivariate Bayesian analysis on generic data. It includes tools for regression modeling, diagnosis, basis decomposition, sensitivity analysis, and visualization. The tool compiles state-of-the-art methodology into one easy-to-use package. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Tucker, James [Sandia National Lab. (SNL-CA), Live↗

Countermeasure Evaluation and Validation Project (CEVP) Database Requirement Documentation

The initial focus of the project by the JSC laboratories will be to develop, test and implement a standardized complement of integrated physiological test (Integrated Testing Regimen, ITR) that will examine both system and intersystem function, and will be used to validate and certify candidate countermeasures. The ITR will consist of medical requirements (MRs) and non-MR core ITR tests, and countermeasure-specific testing. Non-MR and countermeasure-specific test data will be archived in a database specific to the CEVP. Development of a CEVP Database will be critical to documenting the progress of candidate countermeasures. The goal of this work is a fully functional software system that will integrate computer-based data collection and storage with secure, efficient, and practical distribution of that data over the Internet. This system will provide the foundation of a new level of interagency and international cooperation for scientific experimentation and research, providing intramural, international, and extramural collaboration through management and distribution of the CEVP data. The research performed this summer includes the first phase of the project. The first phase of the project is a requirements analysis. This analysis will identify the expected behavior of the system under normal conditions and abnormal conditions; that could affect the system's ability to produce this behavior; and the internal features in the system needed to reduce the risk of unexpected or unwanted behaviors. The second phase of this project have also performed in this summer. The second phase of project is the design of data entry screen and data retrieval screen for a working model of the Ground Data Database. The final report provided the requirements for the CEVP system in a variety of ways, so that both the development team and JSC technical management have a thorough understanding of how the system is expected to behave.

Shin, Sung Y.↗

The Glory Program: Global Science from a Unique Spacecraft Integration

The Glory program is an Earth and Solar science mission designed to broaden science community knowledge of the environment. The causes and effects of global warming have become a concern in recent years and Glory aims to contribute to the knowledge base of the science community. Glory is designed for two functions: one is solar viewing to monitor the total solar irradiance and the other is observing the Earth s atmosphere for aerosol composition. The former is done with an active cavity radiometer, while the latter is accomplished with an aerosol polarimeter sensor to discern atmospheric particles. The Glory program is managed by NASA Goddard Space Flight Center (GSFC) with Orbital Sciences in Dulles, VA as the prime contractor for the spacecraft bus, mission operations, and ground system. This paper will describe some of the more unique features of the Glory program including the integration and testing of the satellite and instruments as well as the science data processing. The spacecraft integration and test approach requires extensive analysis and additional planning to ensure existing components are successfully functioning with the new Glory components. The science mission data analysis requires development of mission unique processing systems and algorithms. Science data analysis and distribution will utilize our national assets at the Goddard Institute for Space Studies (GISS) and the University of Colorado's Laboratory for Atmospheric and Space Physics (LASP). The Satellite was originally designed and built for the Vegetation Canopy Lidar (VCL) mission, which was terminated in the middle of integration and testing due to payload development issues. The bus was then placed in secure storage in 2001 and removed from an environmentally controlled container in late 2003 to be refurbished to meet the Glory program requirements. Functional testing of all the components was done as a system at the start of the program, very different from a traditional program. The plan for Glory is to minimize any changes to the spacecraft in order to meet the Glory requirements. This means that the instrument designs must adhere to the existing interfaces and capabilities as much as possible. Given Glory's unique history and the potential science return, the program is one of significant value to both the science community and the world. The findings Glory promises will improve our understanding of the drivers for global climate change for a minimal investment. The program hopes to show that reuse of existing government assets can result in a lower cost, and fully successful mission.

Bajpayee Jaya↗

Information Power Grid: Distributed High-Performance Computing and Large-Scale Data Management for Science and Engineering

We use the term "Grid" to refer to distributed, high performance computing and data handling infrastructure that incorporates geographically and organizationally dispersed, heterogeneous resources that are persistent and supported. This infrastructure includes: (1) Tools for constructing collaborative, application oriented Problem Solving Environments / Frameworks (the primary user interfaces for Grids); (2) Programming environments, tools, and services providing various approaches for building applications that use aggregated computing and storage resources, and federated data sources; (3) Comprehensive and consistent set of location independent tools and services for accessing and managing dynamic collections of widely distributed resources: heterogeneous computing systems, storage systems, real-time data sources and instruments, human collaborators, and communications systems; (4) Operational infrastructure including management tools for distributed systems and distributed resources, user services, accounting and auditing, strong and location independent user authentication and authorization, and overall system security services The vision for NASA's Information Power Grid - a computing and data Grid - is that it will provide significant new capabilities to scientists and engineers by facilitating routine construction of information based problem solving environments / frameworks. Such Grids will knit together widely distributed computing, data, instrument, and human resources into just-in-time systems that can address complex and large-scale computing and data analysis problems. Examples of these problems include: (1) Coupled, multidisciplinary simulations too large for single systems (e.g., multi-component NPSS turbomachine simulation); (2) Use of widely distributed, federated data archives (e.g., simultaneous access to metrological, topological, aircraft performance, and flight path scheduling databases supporting a National Air Space Simulation systems}; (3) Coupling large-scale computing and data systems to scientific and engineering instruments (e.g., realtime interaction with experiments through real-time data analysis and interpretation presented to the experimentalist in ways that allow direct interaction with the experiment (instead of just with instrument control); (5) Highly interactive, augmented reality and virtual reality remote collaborations (e.g., Ames / Boeing Remote Help Desk providing field maintenance use of coupled video and NDI to a remote, on-line airframe structures expert who uses this data to index into detailed design databases, and returns 3D internal aircraft geometry to the field); (5) Single computational problems too large for any single system (e.g. the rotocraft reference calculation). Grids also have the potential to provide pools of resources that could be called on in extraordinary / rapid response situations (such as disaster response) because they can provide common interfaces and access mechanisms, standardized management, and uniform user authentication and authorization, for large collections of distributed resources (whether or not they normally function in concert). IPG development and deployment is addressing requirements obtained by analyzing a number of different application areas, in particular from the NASA Aero-Space Technology Enterprise. This analysis has focussed primarily on two types of users: the scientist / design engineer whose primary interest is problem solving (e.g. determining wing aerodynamic characteristics in many different operating environments), and whose primary interface to IPG will be through various sorts of problem solving frameworks. The second type of user is the tool designer: the computational scientists who convert physics and mathematics into code that can simulate the physical world. These are the two primary users of IPG, and they have rather different requirements. The results of the analysis of the needs of these two types of users provides a broad set of requirements that gives rise to a general set of required capabilities. The IPG project is intended to address all of these requirements. In some cases the required computing technology exists, and in some cases it must be researched and developed. The project is using available technology to provide a prototype set of capabilities in a persistent distributed computing testbed. Beyond this, there are required capabilities that are not immediately available, and whose development spans the range from near-term engineering development (one to two years) to much longer term R&D (three to six years). Additional information is contained in the original.

Johnston, William E.↗

Securing Sensitive Flight and Engine Simulation Data Using Smart Card Technology

NASA Glenn Research Center has developed a smart card prototype capable of encrypting and decrypting disk files required to run a distributed aerospace propulsion simulation. Triple Data Encryption Standard (3DES) encryption is used to secure the sensitive intellectual property on disk pre, during, and post simulation execution. The prototype operates as a secure system and maintains its authorized state by safely storing and permanently retaining the encryption keys only on the smart card. The prototype is capable of authenticating a single smart card user and includes pre simulation and post simulation tools for analysis and training purposes. The prototype's design is highly generic and can be used to protect any sensitive disk files with growth capability to urn multiple simulations. The NASA computer engineer developed the prototype on an interoperable programming environment to enable porting to other Numerical Propulsion System Simulation (NPSS) capable operating system environments.

Blaser, Tammy M.↗

HEASARC - The High Energy Astrophysics Science Archive Research Center

The High Energy Astrophysics Science Archive Research Center (HEASARC) is NASA's archive for high-energy astrophysics and cosmic microwave background (CMB) data, supporting the broad science goals of NASA's Physics of the Cosmos theme. It provides vital scientific infrastructure to the community by standardizing science data formats and analysis programs, providing open access to NASA resources, and implementing powerful archive interfaces. Over the next five years the HEASARC will ingest observations from up to 12 operating missions, while serving data from these and over 30 archival missions to the community. The HEASARC archive presently contains over 37 TB of data, and will contain over 60 TB by the end of 2014. The HEASARC continues to secure major cost savings for NASA missions, providing a reusable mission-independent framework for reducing, analyzing, and archiving data. This approach was recognized in the NRC Portals to the Universe report (2007) as one of the HEASARC's great strengths. This poster describes the past and current activities of the HEASARC and our anticipated developments in coming years. These include preparations to support upcoming high energy missions (NuSTAR, Astro-H, GEMS) and ground-based and sub-orbital CMB experiments, as well as continued support of missions currently operating (Chandra, Fermi, RXTE, Suzaku, Swift, XMM-Newton and INTEGRAL). In 2012 the HEASARC (which now includes LAMBDA) will support the final nine-year WMAP data release. The HEASARC is also upgrading its archive querying and retrieval software with the new Xamin system in early release - and building on opportunities afforded by the growth of the Virtual Observatory and recent developments in virtual environments and cloud computing.

Smale, Alan P.↗

Mapping Support for Targeted Critical Minerals Exploration and Extraction

The United States’ dependency on imported minerals poses significant risks to economic stability and national security due to potential supply disruptions. Recognizing the strategic importance of critical minerals, the Department of Energy (DOE) emphasizes the need for a secure and resilient supply chain to support emissions reduction, technology development, and capitalization on clean energy opportunities. The DOE’s Office of Manufacturing and Energy Supply Chains (MESC), in collaboration with the Office of Policy (OP), addresses these vulnerabilities by focusing on upstream domestic critical minerals production, balancing extraction with social and environmental goals, including conservation, environmental justice, and respect for Tribal sovereignty. This report showcases a collaborative effort involving Idaho National Laboratory (INL), Argonne National Laboratory (Argonne), National Renewable Energy Laboratory (NREL), and the U.S. Geological Survey (USGS) to map mineral development potential along with key social and environmental datasets. A geographical information system (GIS)-based web map application was developed as a preliminary tool for environmental analysis, integrating 158 geospatial data layers such as critical habitat, land ownership, economic indicators, and environmental concerns. Data were sourced from agencies like the Bureau of Land Management (BLM) and USGS and processed using GIS technology to enhance visualization and analysis. The proposed analysis framework categorizes areas into high, mid, and low concern based on withdrawn lands, special status species, the Economic Development Capacity Index (EDCI) Mining Composite Index, and the Climate and Economic Justice Screening Tool (CEJST). While the application provides broad visualizations, it is not a substitute for detailed environmental reviews required under the National Environmental Policy Act (NEPA). Users must conduct further analyses and engage with tribal entities and other stakeholders for comprehensive planning. A case study of the Idaho Cobalt Belt (ICB) in Lemhi County, Idaho, has been provided in the report to illustrate the tool's practical use. This report introduces a GIS application and framework to support stakeholders in identifying and prioritizing areas for critical mineral exploration, promoting secure supply chains, and advancing the nation's energy independence through responsible resource stewardship.

54 ENVIRONMENTAL SCIENCES↗

Imagery Integration Team

The Human Exploration Science Office (KX) provides leadership for NASA's Imagery Integration (Integration 2) Team, an affiliation of experts in the use of engineering-class imagery intended to monitor the performance of launch vehicles and crewed spacecraft in flight. Typical engineering imagery assessments include studying and characterizing the liftoff and ascent debris environments; launch vehicle and propulsion element performance; in-flight activities; and entry, landing, and recovery operations. Integration 2 support has been provided not only for U.S. Government spaceflight (e.g., Space Shuttle, Ares I-X) but also for commercial launch providers, such as Space Exploration Technologies Corporation (SpaceX) and Orbital Sciences Corporation, servicing the International Space Station. The NASA Integration 2 Team is composed of imagery integration specialists from JSC, the Marshall Space Flight Center (MSFC), and the Kennedy Space Center (KSC), who have access to a vast pool of experience and capabilities related to program integration, deployment and management of imagery assets, imagery data management, and photogrammetric analysis. The Integration 2 team is currently providing integration services to commercial demonstration flights, Exploration Flight Test-1 (EFT-1), and the Space Launch System (SLS)-based Exploration Missions (EM)-1 and EM-2. EM-2 will be the first attempt to fly a piloted mission with the Orion spacecraft. The Integration 2 Team provides the customer (both commercial and Government) with access to a wide array of imagery options - ground-based, airborne, seaborne, or vehicle-based - that are available through the Government and commercial vendors. The team guides the customer in assembling the appropriate complement of imagery acquisition assets at the customer's facilities, minimizing costs associated with market research and the risk of purchasing inadequate assets. The NASA Integration 2 capability simplifies the process of securing one-of-a-kind imagery assets and skill sets, such as ground-based fixed and tracking cameras, crew-in the-loop imaging applications, and the integration of custom or commercial-off-the-shelf sensors onboard spacecraft. For spaceflight applications, the Integration 2 Team leverages modeling, analytical, and scientific resources along with decades of experience and lessons learned to assist the customer in optimizing engineering imagery acquisition and management schemes for any phase of flight - launch, ascent, on-orbit, descent, and landing. The Integration 2 Team guides the customer in using NASA's world-class imagery analysis teams, which specialize in overcoming inherent challenges associated with spaceflight imagery sets. Precision motion tracking, two-dimensional (2D) and three-dimensional (3D) photogrammetry, image stabilization, 3D modeling of imagery data, lighting assessment, and vehicle fiducial marking assessments are available. During a mission or test, the Integration 2 Team provides oversight of imagery operations to verify fulfillment of imagery requirements. The team oversees the collection, screening, and analysis of imagery to build a set of imagery findings. It integrates and corroborates the imagery findings with other mission data sets, generating executive summaries to support time-critical mission decisions.

Calhoun, Tracy↗

Pando

SAND2025-02006O Pando is a distributed data analysis software tool. It is designed to handle large-scale graph analysis problems, often with a specific focus on blockchain/cryptocurrency data. Pando handles scalability by running on a distributed cluster of servers. Users can customize the output using the program’s plugin/extension design methodology. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Gabert, Kasimir↗

Model Assessment Wizard (MAW)

SAND2026-18710O The Model Assessment Wizard (MAW) is a tool for evaluating ontologies and provides users with a comprehensive workbench for analysis. MAW features sub-modules for visualization, alignment, Shapes Constraint Language (SHACL) and Web Ontology Language (OWL) constraints, and simplification. Users can upload data, identify missing information, visualize ontologies, and update constraints. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy's National Nuclear Security Administration under contract DE-NA0003525.

Murdock, Jaimie [Sandia National Lab. (SNL-CA), Li↗

Curation of Federally Owned Archeological Collections at NASA Langley Research Center

As a Federal agency, NASA has a moral and legal obligation to the public to manage the archeological heritage resources under its control. Archeological sites are unique, nonrenewable resources that must be preserved so that future generations may experience and interpret the material remains of the past. These sites are protected by a wide array of federal regulations. These regulations are intended to ensure that our nation's cultural heritage is preserved for the study and enjoyment of future generations. Once a site has been excavated, all that remains of it are the artifacts and associated records which, taken together, allow researchers to reconstruct the past. With the contextual information provided by associated records such as field notes, maps and photographs, archeological collections can provide important information about life in the past. An integral component of the federal archeology program is the curation of these databases so that qualified scholars will have access to them in years to come. Standards for the maintenance of archeological collections have been codified by various professional organizations and by the federal government. These guidelines focus on providing secure, climate-controlled archival storage conditions for the collections and an adequate study area in which researchers can examine the artifacts and documents. In the 1970's and early 1980's, a group of NASA employees formed the LRC Historical and Archeological Society (LRCHAS) in order to pursue studies of the colonial plantations that ha been displaced by Langley Research Center (LaRC). They collected data on family histories and land ownership as well as conducting archeological surveys and excavations at two important 17th-20th century plantation sites in LaRC, Cloverdale and Chesterville. The excavations produced a wealth of information in the form of artifacts, photographs, maps and other documents. Unfortunately, interest on the part of the LRCHAS membership waned before a report was written, and since 1982 the artifacts have moldered in a flimsy trailer with no climate controls, which had once served as a field laboratory but which threatened to become a tomb for the collection. A recent analysis of Langley's cultural resources by Gray & Pape, Inc. recommended that the collection be organized, cataloged, and placed in a proper curation facility in accordance with Federal regulations. The project for the LARSS program was to research curation standards, organize the collection, catalog it, and prepare it for transfer to a facility which could provide adequate long-term curation conditions for the artifacts and documents. The first phase was to organize the artifacts, which were lying about the lab in various stages of cleaning, analysis, and conservation. Once all of the artifacts from the various excavation units and levels had been regrouped, they were cleaned and/or repackaged in archivally-stable materials. A basic catalog was prepared which will provide interested parties with a rough idea of what we have and where it can be found. Another aspect of the project was to organize the records left by the LRCHAS. Bundles of papers, photographs, and field data found in every corner and drawer of the laboratory trailer were put into order and, where appropriate, copies were made on acid-free Permabond paper for long term storage. Finally, the entire collection and most of the lab equipment was transferred into a secure, climate controlled room which will serve as an archive and study space for qualified scholars interested in exploring LaRC's rich historical heritage.

Eastman, John Arnold↗

Tight Practical Bounds for Subgraph Densities in Ego-centric Networks

SAND2025-11782O Tight Practical Bounds for Subgraph Densities in Ego-centric Networks is a software tool for calculating the “subgraph spread ratio” for social network analysis. This value is useful in network analysis for determining the amount of exogenous and endogenous pressure on a graph. It can distinguish between networks coming from different sources, e.g. distinguishing a graph of Facebook data versus a graph of Wikipedia data. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Mattes, Connor↗

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie↗