Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Distributed Time Protocol”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 343 records · Page 19

Real‐time XFEL data analysis at SLAC and NERSC: A trial run of nascent exascale experimental data analysis

X‐ray scattering experiments using free electron lasers (XFELs) are a powerful tool to determine the molecular structure and function of unknown samples (such as COVID‐19 viral proteins). XFEL experiments are a challenge to computing in two ways: (i) due to the high cost of running XFELs, a fast turnaround time from data acquisition to data analysis is essential to make informed decisions on experimental protocols; (ii) data‐collection rates are growing exponentially, requiring new scalable algorithms. Here we report our experiences analyzing data from two experiments at the Linac Coherent Light Source (LCLS) during September 2020. Raw data were analyzed on NERSC's Cori XC40 system, using the Superfacility paradigm: our workflow automatically moves raw data between LCLS and NERSC, where it is analyzed using the software package CCTBX. We achieved real time data analysis with a turnaround time from data acquisition to full molecular reconstruction in as little as 10 min—sufficient time for the experiment's operators to make informed decisions. By hosting the data analysis on Cori, and by automating LCLS‐NERSC interoperability, we achieved a data analysis rate which matches the data acquisition rate. Completing data analysis within 10 min is a first for XFEL experiments and an important milestone if we are to keep up with data‐collection trends.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Porting Gravitational Wave Signal Extraction to Parallel Virtual Machine (PVM)

Laser Interferometer Space Antenna (LISA) is a planned NASA-ESA mission to be launched around 2012. The Gravitational Wave detection is fundamentally the determination of frequency, source parameters, and waveform amplitude derived in a specific order from the interferometric time-series of the rotating LISA spacecrafts. The LISA Science Team has developed a Mock LISA Data Challenge intended to promote the testing of complicated nested search algorithms to detect the 100-1 millihertz frequency signals at amplitudes of 10E-21. However, it has become clear that, sequential search of the parameters is very time consuming and ultra-sensitive; hence, a new strategy has been developed. Parallelization of existing sequential search algorithms of Gravitational Wave signal identification consists of decomposing sequential search loops, beginning with outermost loops and working inward. In this process, the main challenge is to detect interdependencies among loops and partitioning the loops so as to preserve concurrency. Existing parallel programs are based upon either shared memory or distributed memory paradigms. In PVM, master and node programs are used to execute parallelization and process spawning. The PVM can handle process management and process addressing schemes using a virtual machine configuration. The task scheduling and the messaging and signaling can be implemented efficiently for the LISA Gravitational Wave search process using a master and 6 nodes. This approach is accomplished using a server that is available at NASA Ames Research Center, and has been dedicated to the LISA Data Challenge Competition. Historically, gravitational wave and source identification parameters have taken around 7 days in this dedicated single thread Linux based server. Using PVM approach, the parameter extraction problem can be reduced to within a day. The low frequency computation and a proxy signal-to-noise ratio are calculated in separate nodes that are controlled by the master using message and vector of data passing. The message passing among nodes follows a pattern of synchronous and asynchronous send-and-receive protocols. The communication model and the message buffers are allocated dynamically to address rapid search of gravitational wave source information in the Mock LISA data sets.

Thirumalainambi, Rajkumar↗

Companion Assisted Software Based Remote Attestation in SCADA Networks

Critical infrastructure such as power generation and water distribution systems have become a priority target in cyber warfare because of their recent computerization and introduction to the internet. As a result, Supervisory Control and Data Acquisition (SCADA) system security has become a hot topic in academic and industrial research. Among these topics, Remote Attestation is a security method intended to detect the presence of fileless malware in remote devices as they continue to operate. This allows for the detection of malware in the absence of long-term storage artifacts before symptoms of compromise begin to appear. In general, a trusted device (the verifier) makes a request for evidence of innocence from the untrusted device (the prover). In software-based schemes, the verifier can then measure the delay between its request and the prover’s response. If this delay is greater than the known computational time of the evidence gathering algorithm performed by the prover, then evidence may have been forged. Multi-hop networks often introduce too much network jitter to allow accurate measurement of prover response time, which limits the effectiveness of software based Remote Attestation in a real-world setting. In this work, we introduce a companion device that the verifier can trust to perform a subset of attestation, thereby removing any network jitter. This device is a Field Programmable Gate Array (FPGA) that is physically connected to the prover. We provide a communication protocol between the verifier, prover, and companion. To evaluate our scheme, we simulate it in a common SCADA network environment under normal and heavy traffic loads. Our simulations are performed in the discrete event network simulator NS-3, and we perform statistical analysis over our results to show that our scheme allows for tight timing constraints to be placed on the prover such that the verifier can more easily determine the validity of the evidence that it receives.

Johnson, William A.↗

An Autonomous MCP Bridge to Rucio: Enhancing Data Management Accessibility for High Energy Physics

The Rucio Data Management System [1] is an important tool used by High Energy Physics experiments, including those at Fermi National Accelerator Laboratory, to store and manage exabyte-scale scientific datasets. Despite its central role in coordinating data across globally distributed storage sites, Rucio's command line interface (CLI) presents a steep learning curve, and makes it difficult for scientists to navigate through. To solve this issue, a containerized Model Context Protocol (MCP) [2] server was built that connects Large Language Models directly to Rucio, allowing AI agents to handle data tasks by using simple, natural language rather than memorized terminal commands. The core engineering focus of this project was moving the server away from slow terminal commands that require text parsing and replacing them with a native Python Client API toolset and a planned REST API framework. Moving to the Python API handles data operations directly in memory, which helps clear up formatting errors, provides the AI with clean, structured JSON data and speeds up tool execution. To prove that the system actually works, a benchmarking pipeline was also built with various questions to test the AI across four different model configurations. The questions included finding data scopes, tracking down specific datasets, and checking replication rules. Through benchmarking, early runs showed that with raw terminal text, the model would get confused and stuck, whereas switching to the Python API to feed the AI clean, structured data yielded massive improvement. By creating an intelligent and autonomous bridge to a storage network, this project shows how AI can be implemented in scientific data management, which ultimately helps scientists at Fermilab spend less time sorting through data and more time focusing on their experiments and analysis.

Akella, Kashyap [William Rainey Harper Coll.]↗

Recommendations for Data-in-Transit Requirements for Securing DER Communications

With the adoption of Distributed Energy Resource (DER) interoperability standards, common communication protocols are now being deployed between power system operators and DER devices. In 2018, a revision to the US interconnection and interoperability standard, Institute of Electrical and Electronics Engineers (IEEE) Std. 1547, required DER equipment to have an IEEE 2030.5, IEEE 1815, or SunSpec Modbus communication exchange interface. This change supports the future transition to secure connection and exchange of information between the DER equipment and implementing parties, such as grid operators. Adoption of standardized communication protocols and associated information models is a critical step toward interoperability between power system operators and DER, such as photovoltaic (PV) and energy storage systems. However, security requirements for these standardized communication protocols are not comprehensive, resulting in non-standard and vendor-specific implementation that may leave DER equipment susceptible to cyberattacks. This paper examines the data-in-flight security requirements for standardized DER communication protocols, per IEEE 1547-2018 revision, as it relates to device authentication, key management, and encryption. The state of the art for these security features is also explored, addressing their impact on communication and performance of low-cost single board computers, which are typical of DER devices. In conclusion, a recommendation is provided to adopt a common set of communication requirements, which are intended to achieve interoperability and implement data security over DER network pathways, while ensuring reliable, secure, and real-time information delivery.

42 ENGINEERING↗

Provenance in Data Interoperability for Multi-Sensor Intercomparison

As our inventory of Earth science data sets grows, the ability to compare, merge and fuse multiple datasets grows in importance. This requires a deeper data interoperability than we have now. Efforts such as Open Geospatial Consortium and OPeNDAP (Open-source Project for a Network Data Access Protocol) have broken down format barriers to interoperability; the next challenge is the semantic aspects of the data. Consider the issues when satellite data are merged, cross-calibrated, validated, inter-compared and fused. We must match up data sets that are related, yet different in significant ways: the phenomenon being measured, measurement technique, location in space-time or quality of the measurements. If subtle distinctions between similar measurements are not clear to the user, results can be meaningless or lead to an incorrect interpretation of the data. Most of these distinctions trace to how the data came to be: sensors, processing and quality assessment. For example, monthly averages of satellite-based aerosol measurements often show significant discrepancies, which might be due to differences in spatio- temporal aggregation, sampling issues, sensor biases, algorithm differences or calibration issues. Provenance information must be captured in a semantic framework that allows data inter-use tools to incorporate it and aid in the intervention of comparison or merged products. Semantic web technology allows us to encode our knowledge of measurement characteristics, phenomena measured, space-time representation, and data quality attributes in a well-structured, machine-readable ontology and rulesets. An analysis tool can use this knowledge to show users the provenance-related distrintions between two variables, advising on options for further data processing and analysis. An additional problem for workflows distributed across heterogeneous systems is retrieval and transport of provenance. Provenance may be either embedded within the data payload, or transmitted from server to client in an out-of-band mechanism. The out of band mechanism is more flexible in the richness of provenance information that can be accomodated, but it relies on a persistent framework and can be difficult for legacy clients to use. We are prototyping the embedded model, incorporating provenance within metadata objects in the data payload. Thus, it always remains with the data. The downside is a limit to the size of provenance metadata that we can include, an issue that will eventually need resolution to encompass the richness of provenance information required for daata intercomparison and merging.

Lynnes, Chris↗

Relationship of Exercise, Age, and Gender on Decompression Sickness and Venous Gas Emboli During 2-Hour Oxygen Prebreathe Prior to Hypobaric Exposure

We evaluated four 2-hour oxygen prebreathe protocols combining adynamia (non-walking) and 4 different amounts of exercise for potential use with extravehicular activity (EVA) on the International Space Station. Phase I: upper and lower body exercises using dual-cycle ergometry (75% VO2 max for 10 min). Phase 11: same ergometry plus 24 min of light exercise that simulated space suit preparations. Phase III: same 24 min of light exercise but no ergometry, and Phase IV: 56 min of light exercise without ergometry. After 80 min on 100% O2, the subjects breathed 26.5% O2 - 73.5% N2 for 30 min at 10.2 psi. All subjects performed a series of upper body exercises from a recumbent position for 4 hrs at 4.3 psi to simulate EVA work. Venous gas emboli (VGE) were monitored every 12 min using precordial Doppler ultrasound. The 39 female and 126 male exposures were analyzed for correlations between decompression sickness (DCS) or VGE, and risk variables. The duration and quantity of exercise during prebreathe inversely relates to DCS and VGE incidence. The type and distribution of the 19 cases of DCS were similar to historical cases. There was no correlation of age, gender, body mass index, or fitness level with greater incidence of DCS or all VGE. However there were more Grade IV VGE in males > 40 years (10 of 19) than in those =< 40 years (3 of 107), with p<0.01 from Fisher's Exact Chi square The latency time for VGE was longer (103 min +/- 56 SD, n = 15 versus 53 min +/- 31, n =13) when the ergometry occurred about 15 min into the prebreathe than when performed at the start of the prebreathe, but the order of the ergometry did not influence the overall DCS and VGE incidence. An increasing amount of exercise during prebreathes reduced the risk of DCS during subsequent exposures to 4.3 psi. Age, gender, or fitness level did not correlate with the incidence of DCS or VGE (combination of Grades I-IV). However males greater than 40 years had a higher incidence of Grade IV VGE.

Conkin, J.↗

Spin-Photon Entanglement of a Single Er 3 + Ion in the Telecom Band

Entanglement between photons and a quantum memory is a key component of quantum repeaters, which allow long-distance quantum entanglement distribution in the presence of fiber losses. Spin-photon entanglement has been implemented with a number of different atomic and solid-state qubits with long spin coherence times, but none directly emit photons into the 1.5 − μ m telecom band where losses in optical fibers are minimized. Here, we demonstrate spin-photon entanglement using a single rare earth ion in the solid-state Er 3 + coupled to a silicon nanophotonic cavity, which directly emits photons at 1532.6 nm. We infer an entanglement fidelity of 73(3)% after propagating through 15.6 km of optical fiber. This work opens the door to large-scale quantum networks based Er 3 + ions, leveraging scalable silicon device fabrication and spectral multiplexing. Published by the American Physical Society 2025

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

The VLBA correlator: Real-time in the distributed era

The correlator is the signal processing engine of the Very Long Baseline Array (VLBA). Radio signals are recorded on special wideband (128 Mb/s) digital recorders at the 10 telescopes, with sampling times controlled by hydrogen maser clocks. The magnetic tapes are shipped to the Array Operations Center in Socorro, New Mexico, where they are played back simultaneously into the correlator. Real-time software and firmware controls the playback drives to achieve synchronization, compute models of the wavefront delay, control the numerous modules of the correlator, and record FITS files of the fringe visibilities at the back-end of the correlator. In addition to the more than 3000 custom VLSI chips which handle the massive data flow of the signal processing, the correlator contains a total of more than 100 programmable computers, 8-, 16- and 32-bit CPUs. Code is downloaded into front-end CPU's dependent on operating mode. Low-level code is assembly language, high-level code is C running under a RT OS. We use VxWorks on Motorola MVME147 CPU's. Code development is on a complex of SPARC workstations connected to the RT CPU's by Ethernet. The overall management of the correlation process is dependent on a database management system. We use Ingres running on a Sparcstation-2. We transfer logging information from the database of the VLBA Monitor and Control System to our database using Ingres/NET. Job scripts are computed and are transferred to the real-time computers using NFS, and correlation job execution logs and status flow back by the route. Operator status and control displays use windows on workstations, interfaced to the real-time processes by network protocols. The extensive network protocol support provided by VxWorks is invaluable. The VLBA Correlator's dependence on network protocols is an example of the radical transformation of the real-time world over the past five years. Real-time is becoming more like conventional computing. Paradoxically, 'conventional' computing is also adopting practices from the real-time world: semaphores, shared memory, light-weight threads, and concurrency. This appears to be a convergence of thinking.

Wells, D. C.↗

Collaborative Supervised Learning for Sensor Networks

Collaboration methods for distributed machine-learning algorithms involve the specification of communication protocols for the learners, which can query other learners and/or broadcast their findings preemptively. Each learner incorporates information from its neighbors into its own training set, and they are thereby able to bootstrap each other to higher performance. Each learner resides at a different node in the sensor network and makes observations (collects data) independently of the other learners. After being seeded with an initial labeled training set, each learner proceeds to learn in an iterative fashion. New data is collected and classified. The learner can then either broadcast its most confident classifications for use by other learners, or can query neighbors for their classifications of its least confident items. As such, collaborative learning combines elements of both passive (broadcast) and active (query) learning. It also uses ideas from ensemble learning to combine the multiple responses to a given query into a single useful label. This approach has been evaluated against current non-collaborative alternatives, including training a single classifier and deploying it at all nodes with no further learning possible, and permitting learners to learn from their own most confident judgments, absent interaction with their neighbors. On several data sets, it has been consistently found that active collaboration is the best strategy for a distributed learner network. The main advantages include the ability for learning to take place autonomously by collaboration rather than by requiring intervention from an oracle (usually human), and also the ability to learn in a distributed environment, permitting decisions to be made in situ and to yield faster response time.

Wagstaff, Kiri L.↗

Studying impacts of communication system performance on dynamic stability of networked microgrid

The development of smart grid technologies has resulted in increased interdependence between power and communication systems. Many of the operations in the existing power system rely on a stable and secured communication system. For electrically weak systems and time‐critical applications, this reliance can be even greater, where a small degradation in communication performance can degrade system stability. However, despite inter‐dependencies between power and communication systems, only a few studies have investigated the impacts of communication system performance on power system dynamics. This study investigates the dependencies of power system dynamics operations on a communication system performance. First, a detailed, dynamic networked microgrid model is developed in the GridLAB‐D simulation environment, along with a representative multi‐traffic, multi‐channel, multi‐protocol communication system model, developed in the network simulator (ns‐3). Second, a hierarchical engine for large‐scale infrastructure co‐simulation framework is developed to co‐simulate microgrid dynamics, its communication system, and a microgrid control system. The impact of communication system delays on the dynamic stability of networked microgrids is evaluated for the loss of generation using three use‐cases. While the example use‐cases examine microgrid applications and the impact to resiliency, the framework can be applied to all levels of power system operations.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Marine Hydrogen Demonstration

This report summarizes Phase 1 of a project involving the design of a Floating Hydrogen Production and Dispensing Barge destined for the Port of San Francisco (SF). The H 2 Barge is designed to produce renewable H 2 at the rate of ~ 530 kg/day, storing 512 kg of hydrogen at 517-bar, allowing fast refueling of hydrogen fuel cell vessels and land-side hydrogen delivery trailers for distribution into the nascent SF hydrogen ecosystem. The broader considerations that impacted the H2 Barge design are also described. An account is given of a new review process formulated by the United States Coast Guard (USCG) to review this first-of-its-kind maritime implementation of hydrogen technology. The immediate goals of the H 2 Barge Project are to 1) demonstrate the feasibility, viability and methods of hydrogen production, storage and fueling in a maritime context, 2) help shape (where needed) and navigate the required local, state and federal regulatory gauntlet and 3) catalyze a “green hydrogen ecosystem” (both marine and landside) with locally produced renewable hydrogen at the San Francisco waterfront. A summary is also given of the modeling and experimental activity of Phase 1 directed to the development of science-based refueling protocols for large marine Type IV 250-bar hydrogen tanks. Combined modeling and experimental studies are reported of the filling of large (28 kg) 250-bar Type IV hydrogen tanks of the type being deployed on early hydrogen ferries, such as the MV Sea Change. The primary question was to determine how such tanks can be successfully filled (state of charge greater than 97%) within 45 minutes without exceeding the 82 °C temperature limit historically set for such tanks. The studies show that a gas injector is needed avoid thermal stratification during filling which can result in potential hot spots. Pre-cooling of the hydrogen was found to be essential in most cases, as ambient conditions greatly affect the need for a pre-cooling to achieve the 45-minute fill time. Pre-cooling cannot be supplied by nearby water, such as that found in nature (bays, lakes, rivers, etc.) because pre-cooling cooling below 0 °C was found to be necessary to avoid excessive compression heating. The experimental results afforded a calibration of the engineering model (SOFIL) for these large 250-bar tanks, which now enables using SOFIL to predict volume-averaged hydrogen filling temperatures to an accuracy of +/- 2.7°C for these tanks. The model can therefore be used to evaluate potential scenarios for development of a standardized fueling methodology for ferries utilizing large Type-IV tanks of the type examined here.

08 HYDROGEN↗

Creating Accurate Methane Emission Inventories through Data-Driven Airborne Survey Strategies: Methods and Results from the Haynesville, Anadarko, and Permian Basins

Significantly reducing methane emissions from the oil and gas sector can decrease the rate of climate change over the next two decades, buying critical time for a global energy transition. However, emissions inventories that can be used by oil and gas operators and environmental regulators to identify optimal methane emission mitigation strategies are either based on conservative emission factor methods, or are inconsistent between studies due to differences in sampling strategies or survey technologies. We developed a new approach for methane emissions survey design that yields representative basinwide methane emissions inventories by surveying a subset of total assets in a given oil and gas basin. We identify several sampling and analysis principles, including large sample sizes, balanced sampling across oil and gas production, careful survey area definition, and a unified protocol for analysis, to be vital to producing an unbiased estimate of basin-scale emissions that can be reconciled with future studies. We further present results from deploying this strategy in two oil and gas producing regions in the United States: the Haynesville Basin in Texas and Louisiana, and the Woodford Shale in the Anadarko Basin in Oklahoma. Aerial surveys were performed in 2023 using the Insight M LeakSurveyor™ technology. Preliminary results from methane emissions detected by Insight M indicate that aerially detected emissions above roughly 30 kg(CH4)/hr by themselves contribute a fractional loss rate of 1.13% of gross gas production across oil and gas operations in the Haynesville Basin, with aerially detected emissions equivalent to 2.67% of gross gas production in the Woodford Shale. We supplement these aerial estimates with modeled emissions that are below the LeakSurveyor’s survey sensitivity using a recently published inventory-based model of methane emissions, which we update for our survey areas. We then combine our aerial detections with modeled emissions to yield methane emission distributions and inventories that incorporate the full range of potential methane emissions from the smallest to the largest. These results can be used to identify the most effective methane mitigation strategies for our study areas, and can be reconciled with future methane emissions surveys that use different technologies.

Sherwin, Evan (ORCID:0000000321804297)↗

Simple, Secure, Internet Delivery of MOOSE-based Applications

Application packaging and distribution are the final steps for delivering software to end-users; both are frequently neglected when creating scientific software. Commercial businesses rely on electronic distribution systems that have rendered disk drives obsolete. Still, national laboratories continue to rely heavily on removable media to distribute and limit access to controlled applications. With increasing concerns of unauthorized copying of sensitive applications, a modern distribution system that utilizes cryptographically secure communication and authentication protocols has been developed. This new distribution system will secure the chain of custody for nuclear software while simultaneously simplifying access to these tools. This report summarizes four primary advancements made toward the secure distribution of Nuclear Energy Advanced Modeling and Simulation (NEAMS)-developed, Multiphysics Object Oriented Simulation Environment (MOOSE)-based applications: application installation, package distribution, automated package building, and distribution of documentation. NEAMS is currently developing more than ten separate applications based on the open-source MOOSE Framework. Distribution of these applications has primarily been accomplished by distributing source code, with end-users compiling the applications themselves. This work created a mechanism where MOOSE applications can be installed in a similar way to any other software. This allows both administrators and end-users simplified access to runnable executables. With this new installation capability, it was then possible to rethink distribution. A new, secure capability for delivering MOOSE-based applications over the internet has been created. This system requires unique cryptographic tokens for authentication, greatly securing the custody chain for software. Once granted access, installation of any NEAMS code can be accomplished with these terminal commands: "conda install ncrc" "ncrc install ncrc-bison." After these two commands (and authenticating) the BISON application will be securely down- loaded from Idaho National Laboratory (INL)’s servers, installed, and ready to use. To enable this new distribution capability to be successful, the open-source Continuous Integration, Verification, Enhancement, and Testing (CIVET) Continuous Integration (CI) capability was augmented to add Continuous Delivery (CD). CD enables the automated building and packaging of MOOSE-based applications as they are modified by development teams, ensuring that our customers can obtain up-to-date versions of the software at any time. The need for instruction on how to use these applications was addressed through modifications to the MOOSE documentation system. The MooseDocs capability, which enables robust documentation of MOOSE-based applications, has been extended to allow both for the installation of documentation and the packaging of documentation with installed applications. Together, these enhancements form the core of a new, secure distribution mechanism for nuclear simulation tools. In concert with the Nuclear Computational Resource Center (NCRC), NEAMS- developed applications will now be straightforward to obtain securely.

97 MATHEMATICS AND COMPUTING↗

Precursor Analysis Report: Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016

The Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016 Precursor Analysis Report leverages publicly available information about the December 2016 cyber attack against the Ukrainian Ukrenergo electric transmission utility and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. Industroyer is a modular malware framework designed to deploy several Industrial Control System (ICS) protocol-specific attack payloads to disrupt electricity distribution. Adversaries deployed Industroyer within the target network on a Microsoft Windows endpoint capable of directly manipulating or communicating with ICS. Industroyer abuses the functionality of a targeted ICS’s legitimate control system to achieve its intended impact. Adversaries likely first gained access to Ukrenergo enterprise networks in early 2016 after a successful spearphishing campaign against organizations in the electric power sector. Adversaries then began capturing credentials beginning on 1 December 2016. This allowed access to the ICS environment at the Pivnichna electric transmission substation outside Kyiv through a device dual-homed on the Information Technology (IT) and ICS networks. Adversaries conducted discovery, targeting, and access to this device using information and previously captured credentials from compromised enterprise IT machines. Finally, the adversaries deployed and launched the Industroyer malware just before midnight on 17 December. By midnight, Ukrenergo had lost control of a targeted substation, resulting in electric power outages for over an hour in the city of Kyiv and the Kyiv region. Researchers and analysts identified 31 unique techniques (used in a sequence of 33 steps) utilized during the attack with a total of 846 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-nine of the identified techniques used during the Industroyer cyber attack were precursors to the triggering event. Analysis identified 548 observables associated with these precursor techniques, 353 of which were assessed to have an increased likelihood of being perceived in the 300 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Novel Advancements in Internet-Based Real Time Data Technologies

AZ Technology has been working with MSFC Ground Systems Department to find ways to make it easier for remote experimenters (RPI's) to monitor their International Space Station (ISS) payloads in real-time from anywhere using standard/familiar devices. AZ Technology was awarded an SBIR Phase I grant to research the technologies behind and advancements of distributing live ISS data across the Internet. That research resulted in a product called "EZStream" which is in use on several ISS-related projects. Although the initial implementation is geared toward ISS, the architecture and lessons learned are applicable to other space-related programs. This paper presents the high-level architecture and components that make up EZStream. A combination of commercial-off-the-shelf (COTS) and custom components were used and their interaction will be discussed. The server is powered by Apache's Jakarta-Tomcat web server/servlet engine. User accounts are maintained in a My SQL database. Both Tomcat and MySQL are Open Source products. When used for ISS, EZStream pulls the live data directly from NASA's Telescience Resource Kit (TReK) API. TReK parses the ISS data stream into individual measurement parameters and performs on-the- fly engineering unit conversion and range checking before passing the data to EZStream for distribution. TReK is provided by NASA at no charge to ISS experimenters. By using a combination of well established Open Source, NASA-supplied. and AZ Technology-developed components, operations using EZStream are robust and economical. Security over the Internet is a major concern on most space programs. This paper describes how EZStream provides for secure connection to and transmission of space- related data over the public Internet. Display pages that show sensitive data can be placed under access control by EZStream. Users are required to login before being allowed to pull up those web pages. To enhance security, the EZStream client/server data transmissions can be encrypted to preclude interception. EZStream was developed to make use of a host of standard platforms and protocols. Each are discussed in detail in this paper. The I3ZStream server is written as Java Servlets. This allows different platforms (i.e. Windows, Unix, Linux . Mac) to host the server portion. The EZStream client component is written in two different flavors: JavaBean and ActiveX. The JavaBean component is used to develop Java Applet displays. The ActiveX component is used for developing ActiveX-based displays. Remote user devices will be covered including web browsers on PC#s and scaled-down displays for PDA's and smart cell phones. As mentioned. the interaction between EZStream (web/data server) and TReK (data source) will be covered as related to ISS. EZStream is being enhanced to receive and parse binary data stream directly. This makes EZStream beneficial to both the ISS International Partners and non-NASA applications (i.e. factory floor monitoring). The options for developing client-side display web pages will be addressed along with the development of tools to allow creation of display web pages by non-programmers.

Myers, Gerry↗

Refinement of Protocols for Measuring the Apparent Optical Properties of Seawater

Ocean color satellite missions, like the Sea-viewing Wide Field-of-view Sensor (SeaWiFS) or the Moderate Resolution Imaging Spectroradiometer (MODIS) projects, are tasked with acquiring a global ocean color data set, validating and monitoring the accuracy and quality of the data, processing the radiometric data into geophysical units using a set of atmospheric and bio-optical algorithms, and distributing the final products to the scientific community. The long-standing requirement of the SeaWiFS Project, for example, is to produce spectral water-leaving radiances, LW(lambda), to within 5% absolute (lambda denotes wavelength) and chlorophyll a concentrations to within 35% (Hooker and Esaias 1993), and most ocean color sensors have the same or similar requirements. Although a diverse set of activities are required to ensure the accuracy requirements are met (Hooker and McClain 2000), the perspective here is with field observations. The accurate determination of upper ocean apparent optical properties (AOPs) is essential for the vicarious calibration of ocean color data and the validation of the derived data products, because the sea-truth measurements are used to evaluate the satellite observations (Hooker and McClain 2000). The uncertainties with in situ AOP measurements have various sources: a) the sampling procedures used in the field, including the environmental conditions encountered; b) the absolute characterization of the radiometers in the laboratory; c) the conversion of the light signals to geophysical units in a processing scheme, and d) the stability of the radiometers in the harsh environment they are subjected to during transport and use. Assuming ideal environmental conditions, so this aspect can be neglected, the SeaWiFS ground-truth uncertainty budget can only be satisfied if each uncertainty is on the order of 1-2%, or what is generally referred to as 1% radiometry. In recent years, progress has been made in estimating the magnitude of some of these uncertainties and in defining procedures for minimizing them. For the SeaWiFS Project, the first step was to convene a workshop to draft the SeaWiFS Ocean Optics Protocols (hereafter referred to as the Protocols). The Protocols initially adhered to the Joint Global Ocean Flux Study (JGOFS) sampling procedures (JGOFS 1991) and defined the standards for optical measurements to be used in SeaWiFS calibration and validation activities (Mueller and Austin 1992). Over time, the Protocols were revised (Mueller and Austin 1995), and then recurringly updated on essentially an annual basis (Mueller 2000, 2002, and 2003) as part of the Sensor Inter-comparison and Merger for Biological and Interdisciplinary Oceanic Studies (SIMBIOS) project. 98

Hooker, Stanford B.↗

Ground Based, Millimeter Wave Measurement of Ozone in the Middle Atmosphere

There is a need for highly reliable measurements of stratospheric ozone. Policy makers worldwide concerned with public health rely oil a clear consensus from the scientific community as a basis for ozone-related environmental policy that has a significant impact oil national economies. Tile latest Such consensus was presented in WMO, and used in a 1999 meeting of the parties considering amendments to the Montreal Protocol oil Substances that Deplete the Ozone Layer. Tile scientific community, in turn, needs highly precise and accurate measurements of ozone levels, and small time derivatives of these levels, both in continued - development of its understanding of the physical and chemical processes involved and as clear evidence that these processes are occurring as stated. Over most of the world, changes in ozone levels are small. For example, over the heavily populated northern midlatitudes, the linearized rate of ozone decline is between 0.2% per year and 0.7% per year, depending on altitude. These values are small enough to make measurement requirements technically challenging. Data quality may suffer from imperfections in individual instruments. In one instance, early results from a satellite-borne ozone sensor were later found to be invalid because of calibration drift. Even in the absence of drift, tile absolute calibration of a new sensor may differ slightly from that of its predecessor in service. Most ozone remote sensing instruments operate at ultraviolet or infrared wavelengths where scattering from dust and aerosols must be taken into account; results from these systems may be or are affected following a major volcanic eruption, such as tile one at Mt. Pinatubo in 1991. Given these difficulties, a consensus of measurements from several independent systems is required to insure a reliable understanding of stratospheric ozone levels. Because of the above-described need for highly precise and accurate ozone measurements using several independent techniques, there was interest in developing several techniques which were known but not highly developed in the 1980's into systems capable of being used in ail operational manner to make measurements with the level of quality needed to-detect small trends in ozone levels. A ground-based microwave instrument capable of remotely sensing stratospheric ozone had been designed by tile Principal Investigator of the present project. This instrument was built at tile Millitech Corporation in South Deerfield, Massachusetts before tile present work began. (Funding for design and construction of the instrument came from sources other than the present grant.) Tile instrument measured the spectrum of one of the many emission lines produced by purely rotational transitions of ozone, one at a frequency of 110.8 GHz. The altitude distribution of ozone can. in principle, be retrieved from the details of the pressure-broadened spectrum of the ozone transition. However, the level of contamination of the spectral measurement by instrumentally induced artifacts must be very low in order to retrieve a ozone profile of useful quality from it. The Millitech instrument demonstrated spectral purity at ail adequate level, and there were promising ideas for instrumental improvements and for further development of the technique. The initial objectives of the present project, then, were to develop techniques for calibrating the Millitech instrument, to minimize artifacts in tile spectra it produces, to optimally retrieve ozone profiles from tile spectra, to test tile quality of the microwave profiles by comparing them with profiles obtained using several other, independent techniques over both short and periods of time, and to perform research using the ozone data gathered with the instrument.

Parrish, Alan↗