Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “firewall”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Open Source Service Agent (OSSA) in the intelligence community's Open Source Architecture

The Community Open Source Program Office (COSPO) has developed an architecture for the intelligence community's new Open Source Information System (OSIS). The architecture is a multi-phased program featuring connectivity, interoperability, and functionality. OSIS is based on a distributed architecture concept. The system is designed to function as a virtual entity. OSIS will be a restricted (non-public), user configured network employing Internet communications. Privacy and authentication will be provided through firewall protection. Connection to OSIS can be made through any server on the Internet or through dial-up modems provided the appropriate firewall authentication system is installed on the client.

Fiene, Bruce F.↗

Command and Control of Space Assets Through Internet-Based Technologies Demonstrated

The NASA Glenn Research Center successfully demonstrated a transmission-control-protocol/ Internet-protocol- (TCP/IP) based approach to the command and control of onorbit assets over a secure network. This is a significant accomplishment because future NASA missions will benefit by using Internet-standards-based protocols. Benefits of this Internet-based space command and control system architecture include reduced mission costs and increased mission efficiency. The demonstration proved that this communications architecture is viable for future NASA missions. This demonstration was a significant feat involving multiple NASA organizations and industry. Phillip Paulsen, from Glenn's Project Development and Integration Office, served as the overall project lead, and David Foltz, from Glenn's Satellite Networks and Architectures Branch, provided the hybrid networking support for the required Internet connections. The goal was to build a network that would emulate a connection between a space experiment on the International Space Station and a researcher accessing the experiment from anywhere on the Internet, as shown. The experiment was interfaced to a wireless 802.11 network inside the demonstration area. The wireless link provided connectivity to the Tracking and Data Relay Satellite System (TDRSS) Internet Link Terminal (TILT) satellite uplink terminal located 300 ft away in a parking lot on top of a panel van. TILT provided a crucial link in this demonstration. Leslie Ambrose, NASA Goddard Space Flight Center, provided the TILT/TDRSS support. The TILT unit transmitted the signal to TDRS 6 and was received at the White Sands Second TDRSS Ground Station. This station provided the gateway to the Internet. Coordination also took place at the White Sands station to install a Veridian Firewall and automated security incident measurement (ASIM) system to the Second TDRSS Ground Station Internet gateway. The firewall provides a trusted network for the simulated space experiment. A second Internet connection at the demonstration area was implemented to provide Internet connectivity to a group of workstations to serve as platforms for controlling the simulated space experiment. Installation of this Internet connection was coordinated with an Internet service provider (ISP) and local NASA Johnson Space Center personnel. Not only did this TCP/IP-based architecture prove that a principal investigator on the Internet can securely command and control on-orbit assets, it also demonstrated that valuable virtual testing of planned on-orbit activities can be conducted over the Internet prior to actual deployment in space.

Foltz, David A.↗

[Network Design of the Spaceport Command and Control System]

I helped the Launch Control System (LCS) hardware team sustain the network design of the Spaceport Command and Control System. I wrote the procedure that will be used to satisfy an official hardware test for the hardware carrying data from the Launch Vehicle. I installed hardware and updated design documents in support of the ongoing development of the Spaceport Command and Control System and applied firewall experience I gained during my spring 2017 semester to inspect and create firewall security policies as requested. Finally, I completed several online courses concerning networking fundamentals and Unix operating systems.

Teijeiro, Antonio↗

Report on the deployment of the National Geothermal Data System 2.0

This reports includes a video description of recent upgrades and changes to the National Geothermal Data System (geothermaldata.org) and a text report of its relevant security upgrades. Improvements include a new operating system, implementation of HTTPS, implementation of a standard firewall, PostgreSQL upgrades, an ESRI ArcGIS server, new registration policies, and a non-public API.

15 GEOTHERMAL ENERGY↗

Kennedy Space Center Timing and Countdown Interface to Kennedy Ground Control Subsystem

Kennedy Ground Control System (KGCS) engineers at the National Aeronautics and Space Administration (NASA) Kennedy Space Center (KSC) are developing a time-tagging process to enable reconstruction of the events during a launch countdown. Such a process can be useful in the case of anomalies or other situations where it is necessary to know the exact time an event occurred. It is thus critical for the timing information to be accurate. KGCS will synchronize all items with Coordinated Universal Time (UTC) obtained from the Timing and Countdown (T&CD) organization. Network Time Protocol (NTP) is the protocol currently in place for synchronizing UTC. However, NTP has a peak error that is too high for today's standards. Precision Time Protocol (PTP) is a newer protocol with a much smaller peak error. The focus of this project has been to implement a PTP solution on the network to increase timing accuracy while introducing and configuring the implementation of a firewall between T&CD and the KGCS network.

Protocol↗

Entanglement wedge reconstruction and the information paradox

When absorbing boundary conditions are used to evaporate a black hole in AdS/CFT, we show that there is a phase transition in the location of the quantum Ryu-Takayanagi surface, at precisely the Page time. The new RT surface lies slightly inside the event horizon, at an infalling time approximately the scrambling time β/2 π logS BH into the past. We can immediately derive the Page curve, using the Ryu-Takayanagi formula, and the Hayden-Preskill decoding criterion, using entanglement wedge reconstruction. Because part of the interior is now encoded in the early Hawking radiation, the decreasing entanglement entropy of the black hole is exactly consistent with the semiclassical bulk entanglement of the late-time Hawking modes, despite the absence of a firewall.By studying the entanglement wedge of highly mixed states, we can understand the state dependence of the interior reconstructions. A crucial role is played by the existence of tiny, non-perturbative errors in entanglement wedge reconstruction. Directly after the Page time, interior operators can only be reconstructed from the Hawking radiation if the initial state of the black hole is known. As the black hole continues to evaporate, reconstructions become possible that simultaneously work for a large class of initial states. Using similar techniques, we generalise Hayden-Preskill to show how the amount of Hawking radiation required to reconstruct a large diary, thrown into the black hole, depends on both the energy and the entropy of the diary. Finally we argue that, before the evaporation begins, a single, state-independent interior reconstruction exists for any code space of microstates with entropy strictly less than the Bekenstein-Hawking entropy, and show that this is sufficient state dependence to avoid the AMPSS typical-state firewall paradox.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Islands far outside the horizon

Information located in an entanglement island in semiclassical gravity can be nonperturbatively reconstructed from distant radiation, implying a radical breakdown of effective field theory. We show that this occurs well outside of the black hole stretched horizon. We compute the island associated to large-angular momentum Hawking modes of a four-dimensional Schwarzschild black hole. These modes typically fall back into the black hole but can be extracted to infinity by relativistic strings or, more abstractly, by asymptotic boundary operators constructed using the timelike tube theorem. Remarkably, we find that their island can protrude a distance of order $\sqrt{\ell_p{r}_{\textrm{hor}}}$ outside the horizon. This is parametrically larger than the Planck scale ℓ p and is comparable to the Bohr radius for supermassive black holes. Therefore, in principle, a distant observer can determine experimentally whether the black hole information paradox is resolved by complementarity, or by a firewall.

AdS-CFT correspondence↗

Reinforcement Learning for feedback-enabled cyber resilience

The rapid growth in the number of devices and their connectivity has enlarged the attack surface and made cyber systems more vulnerable. As attackers become increasingly sophisticated and resourceful, mere reliance on traditional cyber protection, such as intrusion detection, firewalls, and encryption, is insufficient to secure the cyber systems. Cyber resilience provides a new security paradigm that complements inadequate protection with resilience mechanisms. A Cyber-Resilient Mechanism (CRM) adapts to the known or zero-day threats and uncertainties in real-time and strategically responds to them to maintain the critical functions of the cyber systems in the event of successful attacks. Feedback architectures play a pivotal role in enabling the online sensing, reasoning, and actuation process of the CRM. Reinforcement Learning (RL) is an important gathering of algorithms that epitomize the feedback architectures for cyber resilience. It allows the CRM to provide dynamic and sequential responses to attacks with limited or without prior knowledge of the environment and the attacker. In this work, we review the literature on RL for cyber resilience and discuss the cyber-resilient defenses against three major types of vulnerabilities, i.e., posture-related, information-related, and human-related vulnerabilities. Here we introduce moving target defense, defensive cyber deception, and assistive human security technologies as three application domains of CRMs to elaborate on their designs. The RL algorithms also have vulnerabilities themselves. We explain the major vulnerabilities of RL and present develop several attack models where the attacker target the information exchanged between the environment and the agent: the rewards, the state observations, and the action commands. We show that the attacker can trick the RL agent into learning a nefarious policy with minimum attacking effort. The paper introduces several defense methods to secure the RL-enabled systems from these attacks. However, there is still a lack of works that focuses on the defensive mechanisms for RL-enabled systems. Last but not least, we discuss the future challenges of RL for cyber security and resilience and emerging applications of RL-based CRMs.

97 MATHEMATICS AND COMPUTING↗

Finding pythons in unexpected places

In this work, we argue that novel (highly nonclassical) quantum extremal surfaces (QESs) play a crucial role in reconstructing the black hole interior even for isolated, single-sided, non-evaporating black holes (i.e. with no auxiliary reservoir). Specifically, any code subspace where interior outgoing modes can be excited will have a QES in its maximally mixed state. We argue that as a result, reconstruction of interior outgoing modes is always exponentially complex. Our construction provides evidence in favor of a strong python’s lunch proposal: that nonminimal QESs are the exclusive source of exponential complexity in the holographic dictionary. We also comment on the relevance of these QESs to the geometrization of state dependence in the typicality arguments for firewalls.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Flexible visualization of a 3rd party Intrusion Prevention (Security) tool: A use case with the ELK stack

A difficult aspect of cyber security is the ability to achieve automated real time intrusion prevention across various sets of systems. To this extent, several companies are offering comprehensive solutions that leverage an "accuracy of scale" and moving much of the intelligence and detection on the Cloud, relying on an ever-growing set of data and analytics to increase decision accuracy. Often, they provide tools to visualize the decision workflows in attack prevention (as well as tune the algorithm) but those solutions are not always practical as companies see the problem as "global" that is, from a unified Cyber-security standpoint. However, a key to a successful Cyber-security program is transparency and trust: from an experimental team viewpoint, this specifically means having the ability to immediately see what and from where, who has been blocked and being able to inform the community in case of a revoked access without the need for filing a "ticket" (that may eventually be answered) – in other words, rapid response to their user-base is essential but solutions targeting "sub-groups" in an organization are not often available. We have come up with a versatile solution leveraging the ELK stack (Elasticsearch, Logstash, & Kibana) and an IPS (Intrusion Prevention System) based WAF (Web Application Firewall) from Signal Sciences. Signal Science allows the streaming of detailed logs in a Logstash format suitable for custom solutions for visualization. By combining these two tools, we have strengthened our security posture and enabled individual experiments to monitor their own traffic. Specifically, the IPS WAF provides unique data such as country of origin, protocol, response code, source IP, and paths accessed. In this contribution, we will show how we engineered a visualization solution so experiment groups could access a dashboard with predefined graphs but also, where they can create individual customizable dashboards used to display blocked traffic and troubleshoot latency issues. We will discuss the details and procedures for developing and configuring these tools and how it benefits cyber security postures across our scientific based environment.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Black hole echoes

In this work, we consider a very simple model for gravitational wave echoes from black hole merger ringdowns which may arise from local Lorentz symmetry violations that modify graviton dispersion relations. If the corrections are sufficiently soft so they do not remove the horizon, the reflection of the infalling waves which trigger the echoes is very weak. As an example, we look at the dispersion relation of a test scalar field corrected by rotonlike operators depending only on spatial momenta, in Gullstrand-Painlevé coordinates. The near-horizon regions of a black hole do become reflective, but only very weakly. The resulting “bounces” of infalling waves can yield repetitive gravity wave emissions but their power is very small. This implies that to see any echoes from black holes we really need an egregious departure from either standard GR or effective field theory, or both. One possibility to realize such strong echoes is the recently proposed classical firewalls which replace black hole horizons with material shells surrounding timelike singularities.

79 ASTRONOMY AND ASTROPHYSICS↗

Blockchain-Based Man-in-the-Middle (MITM) Attack Detection for Photovoltaic Systems

Cybersecurity of photovoltaic (PV) systems entails a much larger scope than just encryption and firewall of communications. For instance, integrity of data in transit between inverters and a cloud server can be compromised by authorized third-party, devices, and internal network within security perimeter (i.e., man-in-the-middle (MITM) attack). To address this challenge, this paper proposes a blockchain-based MITM attack detection method for a PV system. A breakthrough method includes screening network data, network intrusion detection, and hash comparison of in-transit data using distributed ledgers. Furthermore, the proposed method is implemented in Internet-of-Thing (IoT) security modules as clients of a blockchain network and validated by experiments.

blockchain↗

Network Anomaly Detection Using Federated Learning

The internet is turning out to be an integral part of every-one's lives as more and more devices are being connected to serve societal needs. Our work is motivated by two ma-jor observations. Firstly, one drawback of connecting to the network is the threat of network attacks that can compromise users' private information, leading to data loss and adversely affecting productivity. There are several traditional security mechanisms to defend against these attacks, such as firewalls, virtual private networks (VPNs), demilitarized zones (DMZs), and vulnerability scanners. One way to prevent these attacks is early detection and prevention. However, these kinds of architecture do not scale very well because of their centralized nature. Secondly, we observe from heuristics and data set distributions that the majority of the requests made to a server are innocuous. Therefore, almost all server request data sets are highly imbalanced, weighted highly towards the harmless requests.

Marfo, William↗

Testbed and Experiments for Quantum-Conventional Networking

The realization of quantum networks requires the development of devices and methods unprecedented in conventional networks, and yet they critically depend on the latter for implementing foundational blocks and essential operations. We describe a testbed to support the development and testing of their functionality and performance by providing quantum and conventional data planes and devices, together with a secure conventional control plane. It incorporates a variety of entangled photon sources, qubit technologies, detector technologies, photonic components, and supporting conventional switches and workstations. It implements a novel fiber telescoping scheme that provides suites of connections using fiber spools and inground-aerial fiber loops. We briefly summarize a variety of experiments conducted over this testbed including: (i) flex-grid quantum connection experiments, (ii) quantum state and channel tomography, (iii) utilization of quantum key distribution keys to secure conventional encryption and firewall devices, (iv) comparative study of analytical capacity estimates and entanglement throughput, (v) deployed squeezing coexisting with conventional communications, and (iv) measurement of polarization time variation.

Rao, Nageswara [ORNL] (ORCID:0000000234085941)↗

ModuleOT

ModuleOT is an open hardware security platform which provides all features necessary for securing remote energy resources. The platform consists of a physical bump in-the wire device which runs a custom-built application built with Go and Python and leverages AES-NI Instruction set available on modern hardware for cryptographic acceleration. By combining these features, ModuleOT acts as an all-in-one low-cost solution to enable cryptographically secured communications to any critical remote servers or devices. Because the software application has been built using Golang, this source can be easily compiled for different hardware platforms. The module is designed to provide the following core features: (1) encrypted communications across an untrusted network, (2) certificate-based authentication with secure storage, (3) hardware cryptographic acceleration, (4) IP-based whitelisting, (5) local firewall management, and (6) legacy (RS485) device support.

Hasandka, Adarsh↗

Converting from NIS to Redhat Identity Management

The Jefferson Lab (Jlab) accelerator controls network has transitioned to a new authentication and network service interface. The new system uses the Redhat Identity Manager (IdM) as a single integrating front end to the Lightweight Directory Access Protocol (LDAP) and a replacement for NIS and the Kerberos authentication service. This system allows for integration of access and authentication across Unix and Windows environments and across different Jlab computing environments, including across firewalls. The decision making process, conversion steps, issues and solutions will be discussed.

McGuckin, T. S.↗

A technique to make an enterprise network a Darknet on the Internet, while providing required services to authorized users

In a well-designed and secure enterprise network, the hosts inside the network are not directly accessible from the Internet. The enterprise firewall blocks direct access to hosts inside the enterprise network and also blocks any attempts to probe or discover information about those hosts from the Internet. However, access to the enterprise network from the Internet is a must in today’s day and age. Hence, specialized mechanisms to allow secure access are implemented.

97 MATHEMATICS AND COMPUTING↗

Implementation and Demonstration of P4 Software for Improving ICS Protocol Visibility and Control [Slides]

No prior enabling funded work applicable to this proposal. Programming Protocol-independent Packet Processors (P4) is an open source, domain-specific programming language for network switching devices. P4 complements traditional Software Defined Networking (SDN) which is primarily concerned with the management of packets (e.g. routing/dropping decisions) rather than how each packet is processed. The introduction of P4 provided new capabilities (e.g. firewall, load balancing, enhanced security) but has primarily been deployed in data centers. This effort investigates ways to expand P4 into other niches such as ICS networks.

97 MATHEMATICS AND COMPUTING↗