Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “information security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

American cities in a time of global environmental change: the case of the Baltimore Social-Environmental Collaborative

The Baltimore Social-Environmental Collaborative (BSEC) Urban Integrated Field Laboratory seeks a new paradigm for urban climate research. Motivated by deep uncertainties in urban climate and the future of urban systems, BSEC works collaboratively across institutions and stakeholder groups to co-generate the science needed to advance energy security and resilience to extreme events across the city of Baltimore, Maryland, USA, and to do so in a manner that can inform similar efforts in other cities. BSEC begins with stakeholder priorities (health, affordable energy, etc) and designs observation networks and models to deliver climate science to address them. This takes the form of an iterative collaborative cycle, in which an initial research strategy is repeatedly updated in conversation with community partners, and researchers and stakeholders learn from each other. To date, this cycle has included multiple rounds of collaborative deliberation on urban heat mitigation, in which a multicriteria decision tool has been updated with more community-relevant spatial structure and modified optimization metrics. The guiding objective of this cycle is to inform potential ‘secure and resilient pathways’ for energy and infrastructure. In doing so, BSEC addresses fundamental urban science questions in natural and social sciences. It also tests our ability to integrate this science in a manner that advances participatory decision-making for urban resilience.

climate↗

Extreme Temperature Cryptography Based On Nitrogen-Incorporated Ultrananocrystalline Diamond

Physical entropy sources that remain stable under extreme temperatures are essential for cryptography in emerging technological frontiers in deep space exploration, geothermal energy harvesting, and nuclear energy. However, conventional semiconductor platforms fail to generate stable and reliable cryptographic keys above 200 degrees C due to performance degradation. Here, we report a diamond-based cryptographic primitive that exploits the defect-rich sp 2 -bonded grain boundary network in nitrogen-incorporated ultrananocrystalline diamond (n-UNCD) film as a robust entropy source to generate cryptographic keys that remain operationally stable even after enduring extreme temperatures of 700 degrees C for 54 h while also surviving thermal cycling between room temperature and 700 degrees C for 48 h. The strength of the generated keys is assessed through several cryptographic metrics such as bit uniformity, entropy, hamming distances, and correlation coefficients, all of which are found to be near their respective ideal values. Moreover, the generated keys pass the NIST SP 800 and SP 800-90B tests and are also resilient to supply bias variations and a regression-based machine learning attack model based on the Fourier series. The robustness of the keys is attributed to the better thermal stability and chemical inertness of the n-UNCD film. This is supported by high-resolution energy-dispersive X-ray spectroscopy (EDS), which shows no significant lateral diffusion of metal atoms into the n-UNCD layer, and by Raman spectroscopy, which reveals no significant changes in the bonding configuration of the n-UNCD structure. Our findings highlight the remarkable potential of n-UNCD film for extreme environment cryptography by expanding the operational limits of conventional hardware security platforms.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Regression Analysis with the Directed Infusion of Data

Integrating artificial intelligence and machine learning tools into industry necessitates large-scale collaborative efforts that ensure the robust and accurate execution of downstream analytics such as time series prediction, uncertainty quantification, grid optimization, and condition monitoring. However, concerns related to data privacy pervade the nuclear industry due to the proprietary nature of its data and the possibility of data leakage. Legacy techniques such as encryption often require the explicit transmission of data to trustworthy parties, thereby inviting data leakage concerns. The ideal collaboration scenario avoids the explicit dissemination of data/code while maintaining experimental fidelity, which is currently accomplished using various techniques such as trusted execution environments, homomorphic encryption, differential privacy, and multimatrix masking. These techniques, however, often necessitate a trade-off between trust, efficiency, and utility. This article extends a previously proposed technique called the directed infusion of data (DIOD) that ensures data privacy, allows for scalable obfuscation, and combats the risk of data leakage without compromising utility. The experiments discussed in this article examine a regression-type scenario using DIOD with the goal of preserving the inferential link between two variables. Using the point-kinetics equations, regression experiments compare the performance of a model trained using the original data to that of a model trained using the obfuscated data, which produced identical results. Our claim is further strengthened by an information theoretic proof and experiment, which showed that the inferential content between variables remains the same after obfuscation, thereby avoiding the required communication of the proprietary data.

47 - OTHER INSTRUMENTATION↗

Sovereign Credit Rating Processes Adapted to Critical Infrastructure Cyber Risk Assessment

United States critical infrastructure entities are increasingly targeted by motivated and capable threat actors and must be prepared to assess and treat a diverse range of cyber risks. Consequently, this necessitates some form of analytical process to evaluate risks and inform cyber security investment decisions. A potential solution for structuring cyber risk evaluation exists within the field of sovereign credit ratings – where agencies employ mature approaches that integrate quantitative and qualitative data to produce a singular value of assessment. Adapting such approaches, we present a novel criterion and methodology for measuring and communicating the likelihood element of cyber risk. The methodology is composed of three sequential phases: a quantitative baseline organized by distinct capability frames, a bounded qualitative adjustment per frame, and a greater-bounded qualitative adjustment spanning the entire process. The process culminates in publication of a cyber capability rating that communicates a critical infrastructure entity’s ability and willingness to mitigate discontinuous function due to cyberattack.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Regulatory Considerations for Domestic Reprocessing Facility Physical Security

U.S. advanced non-light-water reactor vendors may pursue collocated on-site reprocessing activities. Therefore, these facilities are likely to possess formula quantities, or Category I quantities, of special nuclear material (SNM) during normal operations. The U.S. Nuclear Regulatory Commission (U.S. NRC) has yet to formally establish a regulatory framework for commercial reprocessing. While Category I requirements would explicitly not apply in this circumstance under current regulatory requirements, regulatory certainty does not exist. A novel framework should be developed to ensure public health and safety while also risk-informing the physical security requirements. This report reviews the relevant background of related rulemaking activities and proposes risk-informed physical protection requirements to satisfy these objectives. Insights from NRC security-related rulemaking activities provide a substantial technical basis to approach potential establishment of physical security requirements for reprocessing facilities. If a licensee can provide justification that the material satisfies a sufficient self-protecting radiation dose threshold, the material may not be subject to theft or diversion requirements and only potential sabotage requirements would apply. Furthermore, if the material can be justified to be moderately dilute, a set of risk-informed requirements could provide adequate protection of public health and safety. A revised performance objective for prevention of theft of moderately dilute Category I SNM may be detection to allow prompt recovery by a local law enforcement agency. However, a significant caveat to the proposed categorization scheme is the unknown integration of radiological sabotage with requirements for the protection against theft. Future licensees should consult with the NRC regarding treatment of this regulatory topic. Additionally, the self-protecting radiation dose threshold (either the existing or a proposed future threshold) would need to be considered. An integrated approach may apply graded potential requirements for protection against the design basis threat of radiological sabotage currently applicable to commercial nuclear power plants and Category I SNM facilities defined within 10 CFR 73.1(a).

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Raw_data_Batch_I: Argonne to Shorewood via I-55

Date of collection: May 12, 2023 Location: Interstate 55, DuPage County, IL This data set contains lidar and vision data collected along a round trip between I-55 Exit 273A and Exit 253. The data contains the following Robot Operating System (ROS) topics: - /Central_Camera_blurred – Image flow from coaxial camera heading, vehicle front. - /Left_Camera_blurred – Image flow from left camera, 60° from central camera on the left side. - /Right_Camera_blurred – Image flow from right camera, 60° from central camera on the right side. - /camera0/camera_info – Intrinsic and distortion information of left camera. - /camera0/projection_matrix – Extrinsic matrix of left camera from lidar. - /camera2/camera_info – Intrinsic and distortion information of central camera. - /camera2/projection_matrix – Extrinsic matrix of central camera from lidar. - /camera5/camera_info – Intrinsic and distortion information of right camera. - /camera5/projection_matrix – Extrinsic matrix of right camera from lidar. - /novatel/oem7/bestpos – Latitude, longitude, and elevation information from NovAtel GNSS-INS system. - /points_raw – VLP-32 lidar point cloud. - /tf – Vehicle base frame. The data are organized into a data description file and one or more ROS .bag files, dependent on original file size. The data description file provides information about the data collection date, location, and detailed mapping, while the .bag file(s) contain the actual data. Please note that for the purpose of securing personally identifiable information, all license plates and faces included in this publication have been intentionally blurred during real-time processing. ![argonne shorewood image](argone-shorewood.png)

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Raw_data_Batch_I: Ashland Avenue

Date of collection: May 26, 2023 Location: Ashland Avenue, Chicago, IL This data set contains lidar and vision data collected along Ashland Avenue. A south-to-north run starts from the intersection of Irving Park and Ashland and ends at Andersonville Garden. A north-to-south run starts from Andersonville Garden and ends around the intersection of Irving Park and Ashland. The data contains the following Robot Operating System (ROS) topics: - /Central_Camera_blurred – Image flow from coaxial camera heading, vehicle front. - /Left_Camera_blurred – Image flow from left camera, 60° from central camera on the left side. - /Right_Camera_blurred – Image flow from right camera, 60° from central camera on the right side. - /camera0/camera_info – Intrinsic and distortion information of left camera. - /camera0/projection_matrix – Extrinsic matrix of left camera from lidar. - /camera2/camera_info – Intrinsic and distortion information of central camera. - /camera2/projection_matrix – Extrinsic matrix of central camera from lidar. - /camera5/camera_info – Intrinsic and distortion information of right camera. - /camera5/projection_matrix – Extrinsic matrix of right camera from lidar. - /novatel/oem7/bestpos – Latitude, longitude, and elevation information from NovAtel GNSS-INS system. - /points_raw – VLP-32 lidar point cloud. - /tf – Vehicle base frame. The data are organized into a data description file and one or more ROS .bag files, dependent on original file size. The data description file provides information about the data collection date, location, and detailed mapping, while the .bag file(s) contain the actual data. Please note that for the purpose of securing personally identifiable information, all license plates and faces included in this publication have been intentionally blurred during real-time processing. ![ashland avenue image](ashland-avenue.png)

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Raw_data_Batch_I: Downers Grove to Darien

Date of collection: May 11, 2023 Location: Downers Grove to Darien, IL This dataset contains lidar and vision data collected in Downers Grove and Darien, IL. The vehicle started in Downers Grove at the intersection of Main and Ogden, headed east. At the intersection of Odgen and IL 83, it then headed south until IL 33 and then west along IL 33 until the intersection of IL 33 and Lemont Road. It then headed north along Lemont Road/Main Street until the intersection of Main and Ogden. The data contains the following Robot Operating System (ROS) topics: - /Central_Camera_blurred – Image flow from coaxial camera heading, vehicle front. - /Left_Camera_blurred – Image flow from left camera, 60° from central camera on the left side. - /Right_Camera_blurred – Image flow from right camera, 60° from central camera on the right side. - /camera0/camera_info – Intrinsic and distortion information of left camera. - /camera0/projection_matrix – Extrinsic matrix of left camera from lidar. - /camera2/camera_info – Intrinsic and distortion information of central camera. - /camera2/projection_matrix – Extrinsic matrix of central camera from lidar. - /camera5/camera_info – Intrinsic and distortion information of right camera. - /camera5/projection_matrix – Extrinsic matrix of right camera from lidar. - /novatel/oem7/bestpos – Latitude, longitude, and elevation information from NovAtel GNSS-INS system. - /points_raw – VLP-32 lidar point cloud. - /tf – Vehicle base frame. The data are organized into a data description file and one or more ROS .bag files, dependent on original file size. The data description file provides information about the data collection date, location, and detailed mapping, while the .bag file(s) contain the actual data. Please note that for the purpose of securing personally identifiable information, all license plates and faces included in this publication have been intentionally blurred during real-time processing. ![downers grove image](downers-grove-darien.png)

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Raw_data_Batch_I: Garfield Ridge

Date of collection: May 4, 2023 Location: Garfield Ridge, Chicago, IL This data set contains lidar and vision data collected in Garfield Ridge, Chicago. The vehicle started from the intersection of Garfield Ridge and S. Harlem, headed east until S. Central Ave. The vehicle headed south along S. Central Ave. until West 60th Street, headed west, and turned north along S. Austin Ave. until it turned west onto W. 59th Street. The vehicle then headed north along S. Harlem Ave. and returned to the intersection of Garfield Ridge and S. Harlem. The data contains the following Robot Operating System (ROS) topics: - /Central_Camera_blurred – Image flow from coaxial camera heading, vehicle front. - /Left_Camera_blurred – Image flow from left camera, 60° from central camera on the left side. - /Right_Camera_blurred – Image flow from right camera, 60° from central camera on the right side. - /camera0/camera_info – Intrinsic and distortion information of left camera. - /camera0/projection_matrix – Extrinsic matrix of left camera from lidar. - /camera2/camera_info – Intrinsic and distortion information of central camera. - /camera2/projection_matrix – Extrinsic matrix of central camera from lidar. - /camera5/camera_info – Intrinsic and distortion information of right camera. - /camera5/projection_matrix – Extrinsic matrix of right camera from lidar. - /novatel/oem7/bestpos – Latitude, longitude, and elevation information from NovAtel GNSS-INS system. - /points_raw – VLP-32 lidar point cloud. - /tf – Vehicle base frame. The data are organized into a data description file and one or more ROS .bag files, dependent on original file size. The data description file provides information about the data collection date, location, and detailed mapping, while the .bag file(s) contain the actual data. Please note that for the purpose of securing personally identifiable information, all license plates and faces included in this publication have been intentionally blurred during real-time processing. ![garfield ridge image](garfield-ridge.png)

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Raw_data_Batch_I: Lakeshore Drive

Date of collection: May 18, 2023 Location: Lakeshore Drive, Chicago, IL Content: “North to South” “South to North” This data set contains lidar and vision data collected along Lakeshore Drive. The “South to North” folder starts from the intersection of Lakeshore Drive and 31st Street and ends at Hollywood Towers Chicago. The “North to South” folder starts from the intersection of Lakeshore Drive and Sheridan Avenue and ends at the 31st Street intersection. The data contains the following Robot Operating System (ROS) topics: - /Central_Camera_blurred – Image flow from coaxial camera heading, vehicle front. - /Left_Camera_blurred – Image flow from left camera, 60° from central camera on the left side. - /Right_Camera_blurred – Image flow from right camera, 60° from central camera on the right side. - /camera0/camera_info – Intrinsic and distortion information of left camera. - /camera0/projection_matrix – Extrinsic matrix of left camera from lidar. - /camera2/camera_info – Intrinsic and distortion information of central camera. - /camera2/projection_matrix – Extrinsic matrix of central camera from lidar. - /camera5/camera_info – Intrinsic and distortion information of right camera. - /camera5/projection_matrix – Extrinsic matrix of right camera from lidar. - /novatel/oem7/bestpos – Latitude, longitude, and elevation information from NovAtel GNSS-INS system. - /points_raw – VLP-32 lidar point cloud. - /tf – Vehicle base frame. The data are organized into a data description file and one or more ROS .bag files, dependent on original file size. The data description file provides information about the data collection date, location, and detailed mapping, while the .bag file(s) contain the actual data. Please note that for the purpose of securing personally identifiable information, all license plates and faces included in this publication have been intentionally blurred during real-time processing. ![lakeshore drive image](lakeshore-drive.png)

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Raw_data_Batch_I: Lisle to Waterfall Glen

Date of collection: May 11, 2023 Location: DuPage County, IL This dataset contains lidar and vision data collected between Lisle, IL, and the Waterfall Glen parking lot. The vehicle started near Cass School District 63, headed east along IL 34. The vehicle then turned south along IL 83 until Interstate 55. Finally, the vehicle turned southwest along I 55 until Exit 273A and headed toward the Waterfall Glen parking lot. The data contains the following Robot Operating System (ROS) topics: - /Central_Camera_blurred – Image flow from coaxial camera heading, vehicle front. - /Left_Camera_blurred – Image flow from left camera, 60° from central camera on the left side. - /Right_Camera_blurred – Image flow from right camera, 60° from central camera on the right side. - /camera0/camera_info – Intrinsic and distortion information of left camera. - /camera0/projection_matrix – Extrinsic matrix of left camera from lidar. - /camera2/camera_info – Intrinsic and distortion information of central camera. - /camera2/projection_matrix – Extrinsic matrix of central camera from lidar. - /camera5/camera_info – Intrinsic and distortion information of right camera. - /camera5/projection_matrix – Extrinsic matrix of right camera from lidar. - /novatel/oem7/bestpos – Latitude, longitude, and elevation information from NovAtel GNSS-INS system. - /points_raw – VLP-32 lidar point cloud. - /tf – Vehicle base frame. The data are organized into a data description file and one or more ROS .bag files, dependent on original file size. The data description file provides information about the data collection date, location, and detailed mapping, while the .bag file(s) contain the actual data. Please note that for the purpose of securing personally identifiable information, all license plates and faces included in this publication have been intentionally blurred during real-time processing. ![lisle waterfall image](lisle-waterfall.png)

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Raw_data_Batch_I: Randall Road

Date of collection: June 3, 2022 Location: Randall Road, DuPage County, IL Content: “North to South” “South to North” This data set contains lidar and vision data collected along Randall Road in DuPage County, Illinois. The “South to North” folder starts at 1480 N. Orchard Road, Aurora, IL 60506, headed north along Randall Road until 238 N. Randall Road, St. Charles, IL 60174. The “North to South” folder starts from 238 N. Randall Road, St. Charles, IL 60174, headed south along Randall Road until 1480 N. Orchard Road, Aurora, IL. The data contains the following Robot Operating System (ROS) topics: - /Central_Camera_blurred – Image flow from coaxial camera heading, vehicle front. - /Left_Camera_blurred – Image flow from left camera, 60° from central camera on the left side. - /Right_Camera_blurred – Image flow from right camera, 60° from central camera on the right side. - /camera0/camera_info – Intrinsic and distortion information of left camera. - /camera0/projection_matrix – Extrinsic matrix of left camera from lidar. - /camera2/camera_info – Intrinsic and distortion information of central camera. - /camera2/projection_matrix – Extrinsic matrix of central camera from lidar. - /camera5/camera_info – Intrinsic and distortion information of right camera. - /camera5/projection_matrix – Extrinsic matrix of right camera from lidar. - /novatel/oem7/bestpos – Latitude, longitude, and elevation information from NovAtel GNSS-INS system. - /points_raw – VLP-32 lidar point cloud. - /tf – Vehicle base frame. The data are organized into a data description file and one or more ROS .bag files, dependent on original file size. The data description file provides information about the data collection date, location, and detailed mapping, while the .bag file(s) contain the actual data. Please note that for the purpose of securing personally identifiable information, all license plates and faces included in this publication have been intentionally blurred during real-time processing. ![randall road image](randall-road.png)

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Raw_data_Batch_I: State Street

Date of collection: May 18, 2023 Location: State Street, Chicago, IL This data set contains lidar and vision data collected along State Street. The vehicle started from outside of the McCormick Tribune Campus Center at the Illinois Institute of Technology’s Mies Campus and headed north along State Street, until the north end of State Street in the Gold Coast. The data contains the following Robot Operating System (ROS) topics: - /Central_Camera_blurred – Image flow from coaxial camera heading, vehicle front. - /Left_Camera_blurred – Image flow from left camera, 60° from central camera on the left side. - /Right_Camera_blurred – Image flow from right camera, 60° from central camera on the right side. - /camera0/camera_info – Intrinsic and distortion information of left camera. - /camera0/projection_matrix – Extrinsic matrix of left camera from lidar. - /camera2/camera_info – Intrinsic and distortion information of central camera. - /camera2/projection_matrix – Extrinsic matrix of central camera from lidar. - /camera5/camera_info – Intrinsic and distortion information of right camera. - /camera5/projection_matrix – Extrinsic matrix of right camera from lidar. - /novatel/oem7/bestpos – Latitude, longitude, and elevation information from NovAtel GNSS-INS system. - /points_raw – VLP-32 lidar point cloud. - /tf – Vehicle base frame. The data are organized into a data description file and one or more ROS .bag files, dependent on original file size. The data description file provides information about the data collection date, location, and detailed mapping, while the .bag file(s) contain the actual data. Please note that for the purpose of securing personally identifiable information, all license plates and faces included in this publication have been intentionally blurred during real-time processing. ![state street image](state-street.png)

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Characterization of Infrasonic Signatures of Earth-Grazing Fireballs as Analogues to Hypersonic Vehicles (Final Report)

Accurate detection, discrimination, and characterization of high-altitude hypersonic events using infrasonic monitoring are critical to planetary defense and global strategic surveillance. This report synthesizes recent advances achieved through rigorous analysis of infrasonic signatures from natural meteoroids, emphasizing shallow entry-angle meteoroids as essentially proxies for artificial hypersonic systems. Meteoroids naturally encompass diverse velocities, trajectories, altitudes, and fragmentation behaviors, enabling systematic validation of empirical period–yield relationships, waveform morphology classifiers, and trajectory-induced back-azimuth deviation models. Integration of adaptive array-processing enhancements within Cardinal software further extends infrasonic detection sensitivity and signal classification reliability. Collectively these advances, based solely on infrasonic signatures or limited optical data, offer robust methodologies for distinguishing natural from artificial hypersonic sources, significantly reducing event geolocation uncertainties and refining source-function determination. The outcomes detailed herein lay foundational groundwork for improved global hypersonic event-surveillance frameworks, supporting improved security preparedness and informing strategic monitoring and defense policies.

54 ENVIRONMENTAL SCIENCES↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗