Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Security monitoring”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

Operational Focused Data Analytics for Optimizing Radiation Portal Monitor-Based Nuclear Smuggling Detection Systems at Global Ports of Entry

The National Nuclear Security Administration’s Office of Nuclear Smuggling Detection and Deterrence has deployed a fleet of radiation portal monitors (RPMs) across the world at global ports of entry including seaports, airports, and land border crossings. These RPMs are integrated into radiation detection systems (RDS) that also include fixed cameras, optical character recognition (OCR) systems, primary scanning systems (e.g., X-ray or gamma-ray), and secondary scanning systems (e.g., spectroscopic radiation portal monitors, portable radiation detection systems). The data from these sensing technologies is collected at the Central Alarm Station (CAS) where servers and computers reside to control and operate the system. Operators utilize the data collected by the CAS and declared cargo information to make decisions on how to respond to an alarm.This work explores the use of CAS-located data, looking at both the sensor data streams and operator inputs, to perform analysis which supports customs and border protection agencies to improve training capability and operational effectiveness. We focus on analyzing site level effectiveness and behavior by rolling up CAS-located data collected from individual occurrences. To-date, more than 15 sites (e.g., seaports, airports, border crossings) have been analyzed in this manner with the goal of understanding system operations to verify effectiveness and recommend potential improvements. This work first aims to provide background information on relevant CAS-located data sources and our current operational system analytics process including example results. After summarizing our current analytic techniques, we discuss how the future data analytics systems can provide key benefits to improving operational performance while minimizing the burden these detection systems place on operators.

Kuhn, Michael↗

A Review of Behind-the-Meter Solar Generation Modeling and Forecasting

Solar photovoltaic systems largely integrated within the distribution grid are operated 'behind-the-meter' and power generation cannot be directly monitored by most utilities. The increasing penetration of behind-the-meter solar photovoltaic systems can deter efficient network and market operations due to variability and uncertainty in net load, which is exacerbated by limited visibility and the difficulty in analyzing the hosting capacity. Risk introduced by behind-the-meter solar contributions may hinder reliable and secure grid operations due to biased system monitoring and forecasts. Accurate behind-the-meter estimations, together with capacity and specification forecasts, thus play a key role in balancing supply and demand and this article reviews the pertinent literature, identifying key characteristics and predictive methods for efficient behind-the-meter solar photovoltaic generation. Forecasting is central to methods herein. The fundamental characteristics of behind-the-meter solar forecasting, including which methods are applicable for scenario-driven use cases, are driven by the metrics most useful for system-wide performance evaluation. To this aim, the literature is reviewed with a focus on forecasting applications for aggregate, regional behind-the-meter generation useful to bulk system and utility operations. As distinguished from net load forecasting, subtleties in these coincident tasks are explored before concluding with recommendations for current practice and future implementations.

behind-the-meter↗

Cyber–Physical System Security of Distribution Systems

The Information and Communications Technology (ICT) for control and monitoring of power systems is a layer on top of the physical power system infrastructure. The cyber system and physical power system components form a tightly coupled Cyber–Physical System (CPS). Sources of vulnerabilities arise from the computing and communication systems of the cyber–power grid. Cyber intrusions targeting the power grid are serious threats to the reliability of electricity supply that is critical to society and the economy. In a typical Information Technology environment, numerous attack scenarios have shown how unauthorized users can access and manipulate protected information from a network domain. The need for cyber security has led to industry standards that power grids must meet to ensure that the monitoring, operation, and control functions are not disrupted by cyber intrusions. Cyber security technologies such as encryption and authentication have been deployed on the CPS. Intrusion or anomaly detection and mitigation tools developed for power grids are emerging. Furthermore, this survey paper provides the basic concepts of cyber vulnerabilities of distribution systems and CPS security. The important ICT subjects for distribution systems covered in this paper include Supervisory Control And Data Acquisition, Distributed Energy Resources, including renewable energy and smart meters.

97 MATHEMATICS AND COMPUTING↗

Recent Advances in Machine Learning for Fiber Optic Sensor Applications

Over the last three decades, fiber optic sensors (FOS) have gained a lot of attention for their wide range of monitoring applications across many industries, including aerospace, defense, security, civil engineering, and energy. FOS technologies hold great promise to form the backbone for next‐generation intelligent sensing platforms that offer long‐distance, high‐accuracy, distributed measurement capabilities and multiparametric monitoring with resilience to harsh environmental conditions. The major limitations posed by FOS are 1) cross‐sensitivity, 2) enormous volume and large data generation, 3) low data processing speed, 4) degradation of signal‐to‐noise ratio over the fiber length, and 5) overall cost of sensor and interrogator systems. These challenges can be overcome by building advanced data analytics engines enabled by recent breakthroughs in machine learning (ML) and artificial intelligence (AI). This article presents a comprehensive review of recent studies that integrate ML and AI algorithms with FOS technologies. This review also highlights several FOS technology development directions that promise a significant impact on widespread use for several industrial applications, with an emphasis on energy systems monitoring. A perspective on future directions for further research development is also provided.

97 MATHEMATICS AND COMPUTING↗

Biodiversity and Global Health: Intersection of Health, Security, and the Environment

One of the biggest consequences of large-scale environmental change is the loss of biodiversity. Recent studies predict a loss of 1 million species in the near future. Biodiversity loss and land use change through anthropogenic disturbance are known to affect disease exposure, disease severity, and disease impacts. It is becoming increasingly clear that biodiversity loss will lead to an increase in infectious diseases in certain regions. Changes in biodiversity may contain important signatures for prediction of infectious diseases and outbreaks. Here, we argue that areas of high or rapid biodiversity loss will be critical to monitor under the umbrella of global health security. Global Health Security consists of the actions and activities required to reduce the impact of public health events in populations living in different geographic regions and across international borders. Like infectious diseases, climate change and other causes of environmental changes do not respect international borders and are becoming more widespread in all parts of the world. Here, the relationships among biodiversity, climate and environmental changes, and pathogen prevalence are dynamic, context dependent, and complex. Accounting for this complexity requires the inclusion of the environment sector, presently missing, when evaluating the potential of global health security actions for mitigating disease risks.

59 BASIC BIOLOGICAL SCIENCES↗

A process activity monitor for AOS/VS

With the ever increasing concern for computer security, users of computer systems are becoming more sensitive to unauthorized access. One of the initial security concerns for the Shuttle Management Information System was the problem of users leaving their workstations unattended while still connected to the system. This common habit was a concern for two reasons: it ties up resources unnecessarily and it opens the way for unauthorized access to the system. The Data General MV/10000 does not come equipped with an automatic time-out option on interactive peripherals. The purpose of this memorandum is to describe a system which monitors process activity on the system and disconnects those users who show no activity for some time quantum.

Mckosky, R. A.↗

Flexible visualization of a 3rd party Intrusion Prevention (Security) tool: A use case with the ELK stack

A difficult aspect of cyber security is the ability to achieve automated real time intrusion prevention across various sets of systems. To this extent, several companies are offering comprehensive solutions that leverage an "accuracy of scale" and moving much of the intelligence and detection on the Cloud, relying on an ever-growing set of data and analytics to increase decision accuracy. Often, they provide tools to visualize the decision workflows in attack prevention (as well as tune the algorithm) but those solutions are not always practical as companies see the problem as "global" that is, from a unified Cyber-security standpoint. However, a key to a successful Cyber-security program is transparency and trust: from an experimental team viewpoint, this specifically means having the ability to immediately see what and from where, who has been blocked and being able to inform the community in case of a revoked access without the need for filing a "ticket" (that may eventually be answered) – in other words, rapid response to their user-base is essential but solutions targeting "sub-groups" in an organization are not often available. We have come up with a versatile solution leveraging the ELK stack (Elasticsearch, Logstash, & Kibana) and an IPS (Intrusion Prevention System) based WAF (Web Application Firewall) from Signal Sciences. Signal Science allows the streaming of detailed logs in a Logstash format suitable for custom solutions for visualization. By combining these two tools, we have strengthened our security posture and enabled individual experiments to monitor their own traffic. Specifically, the IPS WAF provides unique data such as country of origin, protocol, response code, source IP, and paths accessed. In this contribution, we will show how we engineered a visualization solution so experiment groups could access a dashboard with predefined graphs but also, where they can create individual customizable dashboards used to display blocked traffic and troubleshoot latency issues. We will discuss the details and procedures for developing and configuring these tools and how it benefits cyber security postures across our scientific based environment.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Acoustic Measurements of Solvent Extraction Processes in Support of Safeguards

The proposed poster focuses on using acoustic monitoring to advance detection techniques for reprocessing equipment in support of nuclear safeguards. The usage of free air acoustic monitoring has been previously demonstrated at Idaho National Laboratory (INL) at facilities such as the Advanced Test Reactor and the National Security Test Range. However, this work focuses on a deployment environment dedicated to monitoring separation processes, using solvent extraction equipment such as centrifugal contactors. This environment offers an opportunity for signal discovery and in characterizing acoustic signatures of the equipment in operation. This data can support the development of safeguards by design and security by design measures for aqueous reprocessing facilities. Furthermore, this type of monitoring can aid in early detection and identification of removed materials indicating diversion, which is essential for initiating material recovery and actor identification. The results of this work include data from nine low-frequency acoustic sensors used to investigate potential acoustic characteristics of centrifugal contactors used in multi-stage processes. The results also discuss the correlation between the signatures and the operation of the contactor banks.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Famine Early Warning Systems Network (FEWS NET) Land Data Assimilation System (LDAS) and Other Assimilated Hydrological Data at NASA GES DISC

The NASA Goddard Earth Sciences Data and Information Services Center (GES DISC) provides science support for several data sets relevant to agriculture and food security, including the Famine Early Warning Systems Network (FEWS NET) Land Data Assimilation System (LDAS), or FLDAS data set. The GES DISC is one of twelve NASA Earth Observing System (EOS) data centers that process, archive, document, and distribute data from Earth science missions and related projects. The GES DISC hosts a wide range of remote sensing and model data, and provides reliable and robust data access and other services to users worldwide. Beyond data archive and access, the GES DISC offers many services to visualize and analyze the data. This presentation provides a summary of the hydrological data available at the GES DISC, along with an overview of related data services. Specifically, the FLDAS data set has been adapted to work with domains, data streams, and monitoring and forecast requirements associated with food security assessment in data-sparse, developing country settings. The FLDAS global monthly data have a 0.1 x 0.1 degree spatial resolution covering the period from January 1982 to present. Global FLDAS monthly anomaly and monthly climatology data are also available at the GES DISC to evaluate how current conditions compare to averages over the FLDAS 35-year period. Several case studies using the FLDAS soil moisture, evapotranspiration, rainfall, runoff, and surface temperature data will be presented.

Loeser, Carlee↗

Field Programmable Gate Array-Based Reactor Protection Systems and Potential for Inclusion of Secure Elements to Improve Cybersecurity

For acceptable implementations of technologies like wireless communications, remote monitoring, etc., strong mitigations must be developed and evaluated to ensure that new attack pathways do not increase risk for Advanced Reactors. Secure Elements can be adopted and adapted for this purpose based on tamper resistance and cryptographic abilities, but research must be done to properly integrate into critical components such as FPGA-based Important to Safety systems in conjunction with current and future regulations on cyber security features in Advanced Reactors. Typically, the integration of a Secure Element happens during the POST and UEFI boot of a computing platform, performed by the Operating System, which is not possible with FPGAs because they do not include these firmware components. Work must be done to identify a reliable and secure method for integration in FPGA-based systems which lack Operating Systems and therefore complex boot procedures, system calls, etc.

97 MATHEMATICS AND COMPUTING↗

Field Programmable Gate Array-Based Reactor Protection Systems and Potential for Inclusion of Secure Elements to Improve Cybersecurity

For acceptable implementations of technologies like wireless communications, remote monitoring, etc., strong mitigations must be developed and evaluated to ensure that new attack pathways do not increase risk for Advanced Reactors. Secure Elements can be adopted and adapted for this purpose based on tamper resistance and cryptographic abilities, but research must be done to properly integrate into critical components such as FPGA-based Important to Safety systems in conjunction with current and future regulations on cyber security features in Advanced Reactors. Typically, the integration of a Secure Element happens during the POST and UEFI boot of a computing platform, performed by the Operating System, which is not possible with FPGAs because they do not include these firmware components. Work must be done to identify a reliable and secure method for integration in FPGA-based systems which lack Operating Systems and therefore complex boot procedures, system calls, etc.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Quantum Key Distribution for Critical Infrastructures: Towards Cyber-Physical Security for Hydropower and Dams

Hydropower facilities are often remotely monitored or controlled from a centralized remote control room. Additionally, major component manufacturers monitor the performance of installed components, increasingly via public communication infrastructures. While these communications enable efficiencies and increased reliability, they also expand the cyber-attack surface. Communications may use the internet to remote control a facility’s control systems, or it may involve sending control commands over a network from a control room to a machine. The content could be encrypted and decrypted using a public key to protect the communicated information. These cryptographic encoding and decoding schemes become vulnerable as more advances are made in computer technologies, such as quantum computing. In contrast, quantum key distribution (QKD) and other quantum cryptographic protocols are not based upon a computational problem, and offer an alternative to symmetric cryptography in some scenarios. Although the underlying mechanism of quantum cryptogrpahic protocols such as QKD ensure that any attempt by an adversary to observe the quantum part of the protocol will result in a detectable signature as an increased error rate, potentially even preventing key generation, it serves as a warning for further investigation. In QKD, when the error rate is low enough and enough photons have been detected, a shared private key can be generated known only to the sender and receiver. We describe how this novel technology and its several modalities could benefit the critical infrastructures of dams or hydropower facilities. The presented discussions may be viewed as a precursor to a quantum cybersecurity roadmap for the identification of relevant threats and mitigation.

97 MATHEMATICS AND COMPUTING↗

Modeling Data Flows with Network Calculus in Cyber-Physical Systems: Enabling Feature Analysis for Anomaly Detection Applications

The electric grid is becoming increasingly cyber-physical with the addition of smart technologies, new communication interfaces, and automated grid-support functions. Because of this, it is no longer sufficient to only study the physical system dynamics, but the cyber system must also be monitored as well to examine cyber-physical interactions and effects on the overall system. To address this gap for both operational and security needs, cyber-physical situational awareness is needed to monitor the system to detect any faults or malicious activity. Techniques and models to understand the physical system (the power system operation) exist, but methods to study the cyber system are needed, which can assist in understanding how the network traffic and changes to network conditions affect applications such as data analysis, intrusion detection systems (IDS), and anomaly detection. In this paper, we examine and develop models of data flows in communication networks of cyber-physical systems (CPSs) and explore how network calculus can be utilized to develop those models for CPSs, with a focus on anomaly and intrusion detection. This provides a foundation for methods to examine how changes to behavior in the CPS can be modeled and for investigating cyber effects in CPSs in anomaly detection applications.

97 MATHEMATICS AND COMPUTING↗

IoT Devices and Applications for Wire-Based Hybrid Manufacturing Machine Tools

Hybrid manufacturing machine tools have the potential to be a disruptive technology as they can leverage the benefits of both additive and subtractive manufacturing by incorporating both processes on the same machine while limiting the downsides of the individual processes. Since these machines use two very disparate manufacturing processes and hybrid manufacturing is an emerging technology, it will be useful to monitor data coming from the machine and apply it to improve the manufacturing process, the operation of the machine, and to integrate the machine into the larger digital framework of Industrial Internet of Things (IoT). The present work discusses IoT devices that would be beneficial to add to a hybrid machine tool as well as applications for those devices. The proposed methods discussed in this work have not been experimentally implemented on a hybrid machine tool and so there are no performance data available yet. The hybrid machine tool used as a basis to generate these IoT applications is the Mazak VC-500A/5x AM Hot Wire Deposition, which is a 5-axis machine tool incorporated with a wire feedstock 4kW laser deposition system. Methodologies and applications will be outlined for machine health and process monitoring. Other areas covered include process benchmarking, secure networking options for the proposed IoT framework, and hybrid process improvement. Limitations of these methods and future work for new sensor devices and application areas is also discussed.

Thien, Austen↗

Puck and Puck/SAW Loop Seals (Final Report)

Tamper-indicating devices (TIDs), also known as seals, play a crucial role in various sectors including international nuclear safeguards, arms control, domestic security, and commercial products, by ensuring that monitored or high-value items are not accessed undetected. These devices do not block access but alert to unauthorized tampering. With adversaries' capabilities evolving, there's a pressing need for seals to advance in terms of effectiveness (e.g., better tamper indication and unique identification), and new technology can improve the efficiency of installation and verification. Passive loop seals, widely used in international nuclear safeguards to ensure that continuity of knowledge is maintained on declared items, face stringent International Atomic Energy Agency (IAEA) requirements that surpass those met by commercial products. The metal cup seal (Figure 1, left), a staple IAEA seal, is robust but requires significant resources for post-use verification – specifically, the seal’s unique identity can only be verified at IAEA headquarters after removal from facilities. Further, the seal has been in use for decades and seal types should periodically be replaced to counter adversarial efforts for defeating seals. In 2020, the IAEA outlined about 40 requirements for a new passive loop seal, aiming for in-situ verification, minimal external tool use, unique identification (UID), and clear tamper indication. In response, research and development efforts focused on creating a new passive loop seal that meets these criteria and in 2022 the IAEA announced the completion of the Field Verifiable Passive Loop Seal (FVPS) (Figure 1, right). Concurrently to the IAEA’s efforts, Sandia National Laboratories (SNL) and Oak Ridge National Laboratory (ORNL) designed, developed, and tested two seal versions – Puck and Puck/SAW, with Puck based on the IAEA’s requirements and including a novel visually-obvious tamper response, and Puck/SAW adding additional beneficial capabilities like the ability to receive a unique identifier from a standoff distance and monitoring the wire integrity. Puck/SAW was specifically designed and developed to address sealing applications in dry spent fuel storage facilities, where the number of sealed spent fuel containers results in heavy verification burden and inspector safety issues related to radiation exposure. These efforts are described in this Executive Summary.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Video Event Trigger

Video event trigger (VET) processes video image data to generate trigger signal when image shows significant change like motion or appearance, disappearance, change in color, change in brightness, or dilation of object. System aids in efficient utilization of image-data-storage and image-data-processing equipment in applications in which many video frames show no changes and are wasteful to record and analyze all frames when only relatively few frames show changes of interest. Applications include video recording of automobile crash tests, automated video monitoring of entrances, exits, parking lots, and secure areas.

Williams, Glenn L.↗

Utilization of Ancillary Data Sets for Conceptual SMAP Mission Algorithm Development and Product Generation

The planned Soil Moisture Active Passive (SMAP) mission is one of the first Earth observation satellites being developed by NASA in response to the National Research Council's Decadal Survey, Earth Science and Applications from Space: National Imperatives for the Next Decade and Beyond [1]. Scheduled to launch late in 2014, the proposed SMAP mission would provide high resolution and frequent revisit global mapping of soil moisture and freeze/thaw state, utilizing enhanced Radio Frequency Interference (RFI) mitigation approaches to collect new measurements of the hydrological condition of the Earth's surface. The SMAP instrument design incorporates an L-band radar (3 km) and an L band radiometer (40 km) sharing a single 6-meter rotating mesh antenna to provide measurements of soil moisture and landscape freeze/thaw state [2]. These observations would (1) improve our understanding of linkages between the Earth's water, energy, and carbon cycles, (2) benefit many application areas including numerical weather and climate prediction, flood and drought monitoring, agricultural productivity, human health, and national security, (3) help to address priority questions on climate change, and (4) potentially provide continuity with brightness temperature and soil moisture measurements from ESA's SMOS (Soil Moisture Ocean Salinity) and NASA's Aquarius missions. In the planned SMAP mission prelaunch time frame, baseline algorithms are being developed for generating (1) soil moisture products both from radiometer measurements on a 36 km grid and from combined radar/radiometer measurements on a 9 km grid, and (2) freeze/thaw products from radar measurements on a 3 km grid. These retrieval algorithms need a variety of global ancillary data, both static and dynamic, to run the retrieval models, constrain the retrievals, and provide flags for indicating retrieval quality. The choice of which ancillary dataset to use for a particular SMAP product would be based on a number of factors, including its availability and ease of use, its inherent error and resulting impact on the overall soil moisture or freeze/thaw retrieval accuracy, and its compatibility with similar choices made by the SMOS mission. All decisions regarding SMAP ancillary data sources would be fully documented by the SMAP Project and made available to the user community.

freeze/thaw↗

Signal Decomposition for Intrusion Detection in Reliability Assessment in Cyber Resilience (Summary Report)

The complexity of assuring cyber resilience for physical process interactions in connected systems such as energy grids increases dramatically as the coupling between processes becomes more direct and responsive. An example of this growing complexity is provided by Integrated Energy Systems (IES), in which various processes such as nuclear heat generation and commodity production are being directly coupled for increased responsiveness to highly variable signals such as market pricing or electricity demand. As such, the potential attack surface of the coupled processes is larger than the two processes independently. Securing these complex systems requires two-fold monitoring: cybersecure monitoring for potential malicious incursion, and physics monitoring for system tampering. Physics monitoring includes analyzing the behavior of the signals within the system for anomalous behavior. This analysis has been shown to be insufficient if approached by only data-driven machine learning and artificial intelligence (MLAI) techniques or only low-level model comparison. Previous efforts at Purdue University suggested combining high-fidelity models with MLAI algorithms as a basis for a software tool for detecting anomalies in physical processes. This work built on that suggestion, developing an advanced library for signal decomposition and analysis using both MLAI and high-fidelity physics algorithms for greatly improved anomaly detection, especially false data injection. This software can be used as part of a secure imbedded intelligence (SEI) system designed under Consequence-driven Cyber-informed Engineering (CCE) for complex coupled systems. This library established a foundation for online and posteriori analysis of digital signals for the purpose of detecting potential malicious tampering in digital signals representing physical processes. Demonstrations carried out throughout the development highlight the effective use of characterization algorithms to detect signal perturbations, particularly triangle attack-style perturbations, in three wide-ranging applications: seismic monitoring, nuclear thermal hydraulics system simulation, and custom manufacturing.

97 MATHEMATICS AND COMPUTING↗