Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Using Gamification to Enhance Mastery of Network Security Concepts

Gamification has proven to be effective in engaging and encouraging people to work towards and achieve goals. Many students struggle to focus on schoolwork, due to a lack of interest, lack of understanding, or other factors unique to the student. Applying gamification elements to education can help engage these students in learning their course material and help them excel academically. This study examines the effectiveness of using gamification techniques to enhance the learning experience in college Computer Science courses. A video game application is utilized to review and reinforce cybersecurity concepts that students have already been taught in class. Previous work has been made on a prototype game build that teaches about ARP (Address Resolution Protocol) components. The focus of this study is to refine and develop the structure of the prototype into a more interactive and enjoyable format with non-competitive and captivating activities that allow students to study at their own pace. An updated version of the game was created that focused on reaching a balance between education and entertainment. The game was used by students enrolled in a cybersecurity class, where pre-survey, post-survey and a focus group interview were conducted to determine how effective the updated version is compared to the current build, in addition to how effective the gamification method is regarding student retention of taught material. The pre-survey and post-survey results revealed an increase in interest and mastery of cybersecurity concepts as a result of playing the game. Students found value in the game as both a method of reviewing material taught in class and an entertaining and engaging game. These results show potential in using gamification in cybersecurity and education.

Hilliard, Kevin↗

Distributed and Secure Spectrum Sharing for 5G and 6G Networks

Secure spectrum sharing or spectrum co-existence of multiple 5G networks and future 6G networks is a powerful enabler technology. The National Spectrum Strategy (NSS) published by the White House in November, 2023, and the subsequent NSS implementation plan led by the National Telecommunication and Information Administration (NTIA) is the driver of a national effort to enable co-existence of government incumbents and commercial networks in selected spectrum bands. Cellular networks such as 5G & 6G and non-cellular Wi-Fi 6E & 7 are the prominent wireless technologies considered for co-existence with incumbent wireless links. Security of the spectrum sharing solutions is a must to make this transformation of spectrum use possible, specially for mission critical communications. However, current spectrum sharing solutions rely on centralized data bases with inherent vulnerabilities. This paper focuses on secure spectrum sharing among multiple 5G networks using unlicensed and shared frequency bands. It presents an innovative AI/ML based distributed spectrum sharing approach that can be autonomously used by multiple networks. Each sharing network uses its own observation of the Radio Frequency (RF) environment, which consists of RF measurements reported from the 5G User Equipment (UE), to adjust the transmission power levels for secure co-existence. Data is presented to illustrate the superior performance of this solution compared to other spectrum sharing solutions where each network can utilize usage data of the other networks. Finally it discusses how this efficient spectrum sharing solution can evolve in the future for the 6G networks.

5G↗

Fusing Edge Computing with Transport Security by Leveraging the Controller Area Network Transport Security Tracking and Reporting (C-STAR) Unit

Rapid advances in embedded system complexity and capability provides exciting opportunities for transportation security deployment. Manufacturers and developers of these embedded systems continue to provide lower cost and more powerful solutions that can be leveraged by researchers and engineers. Furthermore, deploying these devices at the “edge” of the Internet-of-Things (IoT) infrastructure provides opportunities for highly capable applications in transport security. In an edge computation architecture, the device is co-located at the source of the data in the larger IoT structure – this provides computational capability at the location directly where the data is collected. For shipment transport security, this provides a direct compute node for digestion of data and mitigation actions in real-time. In our application, the vehicle provides a significant amount of this data that can be processed in real-time via the Controller Area Network Transport Security Tracking and Reporting (C-STAR) edge device. Utilization of a computational node located on the vehicle, such as the C-STAR, capitalizes on previously discussed opportunities of edge architectures. In this paper, we will discuss this security solution’s usability, current deployments, and scalability to further applications in transport security. First, we will cover the supported vehicle platforms that can leverage the C-STAR technology. This will be particularly relevant to medium- and heavy-duty vehicles transporting high-risk shipments. Second, we will speak to current deployments of the C-STAR that are ongoing. Finally, we will discuss additional areas for expansion such as maturing the onboard algorithms through continuing collaborations.

Cook, Adian [ORNL] (ORCID:0000000160825395)↗

Ensuring Flexibility and Security in SDN-Based Spacecraft Communication Networks Through Risk Assessment

Software-defined networking (SDN) has enabled elastic networking and resource distribution in cloud computing. The centralization and separation of the Control Plane also offers a high degree of network configurability and management, which can be used to mitigate and manage threats to the network. Space communication networks have historically been restricted and circuit switching in these networks has been a manual process. This study evaluates the potential role of SDN in space communication networks from a networking security standpoint. The evaluation covers the networking security needs of spacecraft missions and their associated assets. The results from the evaluation lead to a risk assessment that identifies vulnerabilities in an SDN-based communications architecture. Security challenges introduced into the network from integrating SDN are also considered. A risk register summarizes the severity of the attack outcomes, as well as occurrence likelihood. The study identifies Denial-of-Service (DoS) attacks as a new threat (presently unmitigated by existing security controls) that would be prevalent in an SDN-based space communication environment. A Mininet-based emulation testbed is built to demonstrate the susceptibility of spacecraft flight software to a flooding DoS attack when on an interconnected SDN-managed network. This type of attack would be highly consequential to mission assets, and therefore SDN-based space communications would need to be resilient to such attacks. Future work will need to be performed to fully characterize DoS attack methods that can apply to the space communication scenario, as well as to devise a comprehensive DoS-resilient solution.

Baker, Dylan Z.↗

Deny-by-Default Network Port Security: SPaRC Technical Bulletin #002

Operational Technology (OT) networks [e.g., industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems] have unique cyber security challenges due to their decades long service life, high availability requirements, and limited visibility. OT networks often take credit for being “air gapped” (i.e. disconnected from the Internet) and all devices within the OT network can “talk” to each other—even if they should not. This SPaRC Technical Bulletin describes how the unique limitations of OT networks can become strengths when it comes to cybersecurity.

Cybersecurity↗

Securing Mobile Networks in an Operational Setting

This paper describes a network demonstration and three month field trial of mobile networking using mobile-IPv4. The network was implemented as part of the US Coast Guard operational network which is a ".mil" network and requires stringent levels of security. The initial demonstrations took place in November 2002 and a three month field trial took place from July through September of 2003. The mobile network utilized encryptors capable of NSA-approved Type 1 algorithms, mobile router from Cisco Systems and 802.11 and satellite wireless links. This paper also describes a conceptual architecture for wide-scale deployment of secure mobile networking in operational environments where both private and public infrastructure is used. Additional issues presented include link costs, placement of encryptors and running routing protocols over layer-3 encryption devices.

Ivancic, William D.↗

Sentinel

Network intrusion detection systems (NIDS) are commonplace in network security but they frequently employ algorithms that are computational demanding requiring hardware and software with significant power requirements. Two examples of such resource-intensive algorithms used for network security are regular expression matching and broader signature pattern matching which are commonly used in deep packet inspection (DPI). Network security algorithms that have large power requirements may be a challenge for low-power internet-of-things (IoT) environments, which generally lack the power resources to implement complex security measures like computationally expensive DPI at the edge. Furthermore, IoT environments incorporating 5G standalone networks have network latency constraints beyond just power that make DPI at the edge even more difficult. Programmable logic is ideally suited for machine learning inference for DPI because of its deep instruction level parallelism and single-cycle memory access. Machine learning approaches for DPI have been explored before using the programmable logic of field programmable gate arrays (FPGA) as a potential solution for NIDS approaches that would be power-suitable for IoT. However, those previous programmable logic NIDS approaches utilize either a supervised or unsupervised learning model. Sentinel utilizes the ensemble of these two machine learning approaches known as a semi-supervised approach which has shown promise in NIDS implementations. Sentinel provides a programmable logic implementation of a semi-supervised approach for DPI which operates at much lower power and latency than a GPU implementation with negligible loss of accuracy due to quantization through a logistic regressor.

Anderson, MatthewW [Idaho National Laboratory (INL↗

Machine Learning 5G Attack Detection in Programmable Logic

Machine learning-assisted network security may significantly contribute to securing 5G components. However, machine learning network security inference speeds generally require tens to hundreds of milliseconds thereby introducing significant latency in 5G operations. The inference latency can be reduced by deploying the machine learning model to programmable logic in a field programmable gate array (FPGA) at the cost of a small loss in accuracy. In order to quantify this loss, as well as to establish baseline performance inference speeds for programmable logic implementations, this work explores an autoencoder and a ß-variational autoencoder deployed on two different FPGA evaluation boards and compares accuracy and performance against an NVIDIA A100 GPU implementation. A publicly available 5G dataset containing 10 types of attacks along with normal traffic is introduced as part of the evaluation.

97 MATHEMATICS AND COMPUTING↗

Secure Network-Centric Aviation Communication (SNAC)

The existing National Airspace System (NAS) communications capabilities are largely unsecured, are not designed for efficient use of spectrum and collectively are not capable of servicing the future needs of the NAS with the inclusion of new operators in Unmanned Aviation Systems (UAS) or On Demand Mobility (ODM). SNAC will provide a ubiquitous secure, network-based communications architecture that will provide new service capabilities and allow for the migration of current communications to SNAC over time. The necessary change in communication technologies to digital domains will allow for the adoption of security mechanisms, sharing of link technologies, large increase in spectrum utilization, new forms of resilience and redundancy and the possibly of spectrum reuse. SNAC consists of a long term open architectural approach with increasingly capable designs used to steer research and development and enable operating capabilities that run in parallel with current NAS systems.

Communications↗

Secure, Network-Centric Operations of a Space-Based Asset: Cisco Router in Low Earth Orbit (CLEO) and Virtual Mission Operations Center (VMOC)

This report documents the design of network infrastructure to support operations demonstrating the concept of network-centric operations and command and control of space-based assets. These demonstrations showcase major elements of the Transformal Communication Architecture (TCA), using Internet Protocol (IP) technology. These demonstrations also rely on IP technology to perform the functions outlined in the Consultative Committee for Space Data Systems (CCSDS) Space Link Extension (SLE) document. A key element of these demonstrations was the ability to securely use networks and infrastructure owned and/or controlled by various parties. This is a sanitized technical report for public release. There is a companion report available to a limited audience. The companion report contains detailed networking addresses and other sensitive material and is available directly from William Ivancic at Glenn Research Center.

Ivancic, William↗

AI-based Detection and Defense Against Cyberattacks in Distributed Energy Resources

This study will provide comprehensive artificial intelligence (AI)-based solution tools for network security, malware prevention, and sensor data anomaly detection for distributed energy resource (DER) research, development, and demonstration. DER technologies are energy systems (e.g., solar panels, wind turbines, and energy storage systems) that are often connected to the internet and thus vulnerable to cyberattacks. Cybersecurity should be of primary concern for DERs, which is why we propose an integrated multi-layer cyber-defense system for DERs. This system encompasses risk assessments, network security, malware prevention, and detection of anomalies in the sensor data. Implementation of a comprehensive risk assessment with an overview of the model architecture should be the primary step, and should include the potential impact of experiencing, at a given time, one or more cyberattacks on the system. The second step is to ensure that the network security includes firewalls, intrusion detection, and malware prevention. The third step is to provide solution tools that enable sensor data anomaly detection for DERs. By incorporating these considerations into DER research, development, and demonstration, organizations can help ensure the safety and security of their systems and protect against potential cyberattacks.

20 FOSSIL-FUELED POWER PLANTS↗

Single Photon Emitters Coupled to Photonic Wire bonds

This project will test the coupling of light emitted from silicon vacancy and nitrogen vacancy defects in diamond into additively manufactured photonic wire bonds toward integration into an "on-chip quantum photonics platform". These defects offer a room-temperature solid state solution for quantum information technologies but suffer from issues such as low activation rate and variable local environments. Photonic wire bonding will allow entanglement of pre-selected solid-state defects alleviating some of these issues and enable simplified integration with other photonic devices. These developments could prove to be key technologies to realize quantum secured networks for national security applications.

42 ENGINEERING↗

Machine Learning Models for Network Traffic Classification in Programmable Logic

Network traffic classification via machine learning on network packet payloads has emerged as an active area of research for network security due to the high accuracy machine learning models have achieved in classifying payloads. For effective deployment as part of network security, these machine learning models must not only classify malicious packet payloads accurately, they must also identify anomalous payloads and perform inference at speeds generally faster than 10,000 packets per second to be effective. This work explores the in- ference speeds and accuracy of several neural network models implemented in programmable logic on various field programmable gate arrays (FPGA) including the Xilinx VC1902 and Xilinx Zynq Ultrascale+. This work also presents the design and performance of both an autoencoder and variational autoencoder programmed on the FPGA for identifying anomalous packet payloads. The performance benefits of the FPGA implementation for this type of packet payload inspection driven by machine learning are compared against graphics processing unit (GPU) inference implementations run on two state-of-the-art datacenter GPU devices, the NVIDIA V100 and A100. The model accuracy difference between the FPGA and GPU implementations was found to be 4% or less while the Xilinx VC1902 outperformed both the NVIDIA V100 and A100 for inference speeds on all the models explored except the variational autoencoder.

97 MATHEMATICS AND COMPUTING↗

Advances in Secure 5G Network for a Nationwide Drone Corridor

Recent research has validated the proposal to add a separate set of antennas for 5G coverage in the air, while the conventional set of antennas continues to provide coverage on the ground, for a nationwide drone corridor for 5G cellular drones. More importantly, this drone corridor can be made secure and reliable by adapting the drone trajectories to avoid interference and security attacks, and with advanced precoding and physical layer security. Energy efficiency can also be improved with low-resolution massive multiple-input multiple-output (MIMO) systems that utilize low resolution digital to analog converters. This paper describes additional research findings to further support the creation of this nationwide drone corridor. We design optimal drone trajectory within the drone corridor to improve safety for pedestrians and vehicles on the ground. We derive the optimum antenna uptilt angle to minimize outage probability for a given drone corridor. We also study the placement of intelligent reflector surfaces in an urban drone corridor in order to improve the multi-path scattering and hence the spatial multiplexing gains for serving drones. We calculate trajectories to maximize data rate in the presence of smart interference when drones are used as relays and each drone may be deployed in the paths of data flows from multiple BSs to multiple UEs. Next we demonstrate how the use of the additional set of antennas along with the 3GPP standard based subframe blanking method can minimize the interference from ground reflection of the radio frequency (RF) radiation from the downtilted antennas. The paper concludes with plans to continue with experimental studies to advance this work further.

99 GENERAL AND MISCELLANEOUS↗

Monitor and Control of the Deep-Space network via Secure Web

(view graph) NASA lead center for robotic space exploration. Operating division of Caltech/Jet Propulsion Laboratory. Current missions, Voyagers, Galileo, Pathfinder, Global Surveyor. Upcoming missions, Cassini, Mars and New Millennium.

Deep-Space Network communications NCP Data Managem↗

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William↗