Award Nominations: Reverse Engineering a Winning Submission
Explore the source record for details and available documents.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
Medical cybersecurity research addresses the critical intersection of healthcare and digital security. As medical devices expand and become increasingly interconnected, the healthcare sector is poised to become a primary target for cyber warfare. This project aims to mitigate the risks associated with a field that often underestimates the importance of cybersecurity.
An emerging trend in advanced manufacturing is printed electronics and sensors. The ability to print customized electronics and sensors integrated into functional packages is a growing need within a variety of growing markets such as smart manufacturing, internet of things (IoT), and the small satellite industry. Both Oak Ridge National Laboratory (ORNL) and the MITRE Corporation have seedling research efforts evaluating the potential for future printed electronic systems. High frequency, wide-bandwidth phased array antennas (i.e. >45 GHz) open the door to new applications. However, such sensors require currently prohibitively small feature sizes for commercial 3D printing technologies along with increasing challenges with connecting the driving electronics to such features. An additional finding with related advanced manufacturing challenges is the rapid production of 3D additive connectors for integration with commercial printed circuit boards (PCBs), primarily for advanced in-circuit inspection techniques. This work is developing additive manufacturing processes for producing connected and conductive fine scale 3D features. The primary focus was on aerosol-jet printing (AJP), which has a small minimum resolution (<50 µm) but is traditionally printed flat with small height/width aspect ratios <<1, and developing controls to enable fully 3D, high aspect ratio, and unsupported features. In Phase 1 of this effort, baselines of process performance were characterized, and test coupons produced for both ultra-high frequency antennas and microstructures to support reverse engineering of PCBs. In Phase 2, these efforts will be extended for system demonstration of ultra-high frequency antenna arrays, as well as reverse engineering circuitry for dense PCBs.
Yarrowia lipolytica , an oleaginous yeast, shows promise for industrial fermentation due to its robust acetyl-CoA flux and well-developed genetic engineering tools. However, its lack of an active xylose metabolism restricts the conversion of cellulosic sugars to valuable products. To address this, metabolic engineering, and adaptive laboratory evolution (ALE) were applied to the Y. lipolytica PO1f strain, resulting in an efficient xylose-assimilating strain (XEV). Whole-genome sequencing (WGS) of the XEV followed by reverse engineering revealed that the amplification of the heterologous oxidoreductase pathway and a mutation in the GTPase-activating protein gene (YALI0B12100g) might be the primary reasons for improved xylose assimilation in the XEV strain. When a sorghum hydrolysate was used, the XEV strain showed superior xylose consumption and lipid production compared to its parental strain (X123). This study advances our understanding of xylose metabolism in Y. lipolytica and proposes effective metabolic engineering strategies for optimizing lignocellulosic hydrolysates.
In industrial control systems (ICS), programmable logic controllers (PLCs) are used to automate physical processes such as nuclear plants and power grid stations, and are often subject to cyber attacks. As in conventional IT domain, the memory analysis of the PLCs can help answer important forensic questions about the attack, such as the presence of malicious firmware, injection of modified control logic (the program running on the PLC), and manipulation of I/O devices (e.g., sensors and actuators). Unlike conventional IT domain, PLCs have heterogeneous hardware architecture, proprietary firmware and control software, making it challenging to employ a unified framework for their memory forensics. For merely extracting artifacts of forensic importance, reverse-engineering the firmware is a tedious task, and the effort needs to be repeated for every PLC model. As a community, a step-wise approach to tackle this challenge is to analyze the memory of specific PLCs, and subsequently find a generic framework applicable to all PLCs. Our work is a step forward in this direction. By following a methodology that focuses on the functional layer of PLCs instead of reverse engineering the firmware, we analyze the digital forensic artifacts available in a common PLC, Allen-Bradley ControlLogix 1756-L61. Before diving into the memory dump, we analyze the PLC control software to create a list of important artifacts that are sure to exist in the PLC memory dump. The approach employs a setup where PLC control software RSLogix-5000 is connected to the PLC, and the memory dump can be obtained as and when needed. We create test cases that sequentially highlight each category of artifacts, followed by an examination of the resultant impact on memory. After attaining the listed artifacts, we employ conventional string and known data searches to extract interesting information present in this PLC's memory. The memory analysis profile, presented as a Python library and shared with the community, can help a forensic investigator to readily extract forensic artifacts from the same model's controller. The adopted approach may help researchers in creating memory profile of other PLCs, and ultimately formulating a generic PLC memory analysis framework.
Over the past few decades, software has become ubiquitous as it has been integrated into nearly every aspect of society, including household appliances, consumer electronics, industrial control systems, public utilities, government operations, and military systems. Consequently, many critical national security questions can no longer be answered convincingly without understanding software, including its purpose, its capabilities, its flaws, its communication, or how it processes and stores data. As software continues to become larger, more complex, and more widespread, our ability to answer important mission questions and reason about software in a timely way is falling behind. Today, to achieve such understanding of third-party software, we rely predominantly on the ability of reverse engineering experts to manually answer each particular mission question for every software system of interest. This approach often requires heroic human effort that nevertheless fails to meet current mission needs and will never scale to meet future needs. The result is an emerging crisis: a massive and expanding gap between the national security need to answer mission questions about software and our ability to do so. Sandia National Laboratories has established the Rapid Analysis of Mission Software Systems (RAMSeS) effort, a collaborative long-term effort aimed at dramatically improving our nation’s ability to answer mission questions about third-party software by growing an ecosystem of tools that augment the human reverse engineer through automation, interoperability, and reuse. Focusing on static analysis of binary programs, we are attempting to identify reusable software analysis components that advance our ability to reason about software, to automate useful aspects of the software analysis process, and to integrate new methodologies and capabilities into a working ecosystem of tools and experts. We aim to integrate existing tools where possible, adapt tools when modest modifications will enable them to interoperate, and implement missing capability when necessary. Although we do hope to automate a growing set of analysis tasks, we will approach this goal incrementally by assisting the human in an ever-widening range of tasks.
Triggering the anionic redox reaction is an effective approach to boost the capacity of layered transition metal (TM) oxides. However, the irreversible oxygen release and structural deterioration at high voltage remain conundrums. Herein, a strategy for Mg ion and vacancy dual doping with partial TM ions pinned in the Na layers is developed to improve both the reversibility of anionic redox reaction and structural stability of layered oxides. Both the Mg ions and vacancies (□) are contained in the TM layers, while partial Mn ions (~1.1%) occupy the Na-sites. The introduced Mg ions combined with vacancies not only create abundant nonbonding O 2p orbitals in favor of high oxygen redox capacity, but also suppress the voltage decay originated from Na–O–□ configuration. The Mn ions pinned in the Na layers act as “rivets” to restrain the slab gliding at extreme de-sodiated state and thereby inhibit the generation of cracks. The positive electrode, Na 0.67 Mn 0.011 [Mg 0.1 □ 0.07 Mn 0.83 ]O 2 , delivers an enhanced discharge capacity and decent cyclability. This study provides insights into the construction of stable layered oxide positive electrode with highly reversible anionic redox reaction for sodium storage.
Abstract Software product line engineering is a best practice for managing reuse in families of software systems that is increasingly being applied to novel and emerging domains. In this work we investigate the use of software product line engineering in one of these new domains, synthetic biology. In synthetic biology living organisms are programmed to perform new functions or improve existing functions. These programs are designed and constructed using small building blocks made out of DNA. We conjecture that there are families of products that consist of common and variable DNA parts, and we can leverage product line engineering to help synthetic biologists build, evolve, and reuse DNA parts. In this paper we perform an investigation of domain engineering that leverages an open-source repository of more than 45,000 reusable DNA parts. We show the feasibility of these new types of product line models by identifying features and related artifacts in up to 93.5% of products, and that there is indeed both commonality and variability. We then construct feature models for four commonly engineered functions leading to product lines ranging from 10 to 7.5 × 10 20 products. In a case study we demonstrate how we can use the feature models to help guide new experimentation in aspects of application engineering. Finally, in an empirical study we demonstrate the effectiveness and efficiency of automated reverse engineering on both complete and incomplete sets of products. In the process of these studies, we highlight key challenges and uncovered limitations of existing SPL techniques and tools which provide a roadmap for making SPL engineering applicable to new and emerging domains.
Controller area networks (CANs) are a broadcast protocol for real-time communication of critical vehicle subsystems. Original equipment manufacturers of passenger vehicles hold secret their mappings of CAN data to vehicle signals, and these definitions vary according to make, model, and year. Without these mappings, the wealth of real-time vehicle information hidden in the CAN packets is uninterpretable, severely impeding vehicle-related research, including CAN cybersecurity and privacy studies, aftermarket tuning, efficiency and performance monitoring, and fault diagnosis to name a few. Guided by the four-part CAN signal definition, we present CAN-D (CAN-Decoder), a modular, four-step pipeline for identifying each signal's boundaries (start bit and length), endianness (byte ordering), signedness (bit-to-integer encoding), and by leveraging diagnostic standards, augmenting a subset of the extracted signals with meaningful, physical interpretation. En route to CAN-D, we provide a comprehensive review of the CAN signal reverse engineering research. All previous methods ignore endianness and signedness, rendering them incapable of decoding many standard CAN signal definitions. Incorporating endianness grows the search space from 128 to 4.72E21 signal tokenizations and introduces a web of changing dependencies. In response, we formulate, formally analyze, and provide an efficient solution to an optimization problem, allowing identification of the optimal set of signal boundaries and byte orderings. In addition, we provide two novel, state-of-the-art signal boundary classifiers—both of which are superior to previous approaches in precision and recall in three different test scenarios—and the first signedness classification algorithm, which exhibits a $>$ 97% F-score. Altogether, CAN-D is the only solution with the potential to extract any CAN signal that is also the state of the art. In evaluation on 10 vehicles of different makes, CAN-D's average $\ell ^1$ error is five times better (81% less) than all previous methods and exhibits lower average error, even when considering only signals that meet prior methods’ assumptions. Finally, CAN-D is implemented in lightweight hardware, allowing for an on-board diagnostic (OBD-II) plugin for real-time in-vehicle CAN decoding.
Engineered reverse hairpin constructs containing a partial C-heptad repeat (CHR) sequence followed by a short loop and full-length N-heptad repeat (NHR) were previously shown to form trimers in solution and to be nanomolar inhibitors of HIV-1 Env mediated fusion. Their target is the in situ gp41 fusion intermediate, and they have similar potency to other previously reported NHR trimers. However, their design implies that the NHR is partially covered by CHR, which would be expected to limit potency. An exposed hydrophobic pocket in the folded structure may be sufficient to confer the observed potency, or they may exist in a partially unfolded state exposing full length NHR. Here, in this study, we examined their structure by crystallography, CD and fluorescence, establishing that the proteins are folded hairpins both in crystal form and in solution. We examined unfolding in the milieu of the fusion reaction by conducting experiments in the presence of a membrane mimetic solvent and by engineering a disulfide bond into the structure to prevent partial unfolding. We further examined the role of the hydrophobic pocket, using a hairpin-small molecule adduct that occluded the pocket, as confirmed by X-ray footprinting. The results demonstrated that the NHR region nominally covered by CHR in the engineered constructs and the hydrophobic pocket region that is exposed by design were both essential for nanomolar potency and that interaction with membrane is likely to play a role in promoting the required inhibitor structure. The design concepts can be applied to other Class 1 viral fusion proteins.
Yarrowia lipolytica, an oleaginous yeast, shows promise for industrial fermentation due to its robust acetyl-CoA flux and well-developed genetic engineering tools. However, its lack of an active xylose metabolism restricts the conversion of cellulosic sugars to valuable products. To address this, metabolic engineering, and adaptive laboratory evolution (ALE) were applied to the Y. lipolytica PO1f strain, resulting in an efficient xylose-assimilating strain (XEV). Whole-genome sequencing (WGS) of the XEV followed by reverse engineering revealed that the amplification of the heterologous oxidoreductase pathway and a mutation in the GTPase-activating protein gene (YALI0B12100g) might be the primary reasons for improved xylose assimilation in the XEV strain. When a sorghum hydrolysate was used, the XEV strain showed superior xylose consumption and lipid production compared to its parental strain (X123). This study advances our understanding of xylose metabolism in Y. lipolytica and proposes effective metabolic engineering strategies for optimizing lignocellulosic hydrolysates.
An embedded device in an insecure environment is subject to additional security risk through capture and reverse-engineering by a capable adversary. If this device contains a microchip performing sensitive computations, capture of the chip may leak functionality to an adversary. In this paper we propose a novel method in which we randomly encode the input operands and the outputs of a computation, thus not revealing the arithmetic operations being performed. The operations are sequenced in a graph representing the overall application. Once the initialization values are overwritten and lost, the results of these computations are indecipherable by the device performing the calculations as well as by any adversary. The result is transmitted back to a secure server which has stored the initialization values and so can decode the results which appear random to the adversary.
Additive manufacturing (AM) was developed in the 1980s to create three-dimensional prototypes through layer-wise approaches to fabrication. Since then, these approaches have seen improvements in both materials and processing technologies. To date, there are now 7 types of additive manufacturing processes and hundreds of materials, which can be directly printed – going directly from digital design to fabricated components. In this project, Oak Ridge National Laboratory (ORNL), Vestas Wind Systems, and The National Renewable Energy Laboratory (NREL) collaborated to evaluate the effectiveness of state-of-the-art large-scale AM processes in the production of a structural component for use in a wind turbine nacelle, through both direct and indirect manufacturing approaches. Here, experienced AM design engineers detail techniques for AM design, including topology optimization (TO), support minimization, reverse engineering, and techniques for mitigating poor interlaminar performance. Fabrication of the components is presented, including printing parameters and postprocessing, and followed with full-scale component testing by a 3rd party testing laboratory. To evaluate the potential of the developed approaches, a complete techno-economic analysis is provided which evaluates the cost of these techniques given current and near to long-term projections of AM system capabilities.
NGS analysis for mutation analysis in Yarrowia lipolytica evolved strains. Yarrowia lipolytica, an oleaginous yeast, shows promise for industrial fermentation due to its robust acetyl-CoA flux and well-developed genetic engineering tools. However, its lack of an active xylose metabolism restricts the conversion of cellulosic sugars to valuable products. To address this, metabolic engineering, and adaptive laboratory evolution (ALE) were applied to the Y. lipolytica PO1f strain, resulting in an efficient xylose-assimilating strain (XEV). Whole-genome sequencing (WGS) of the XEV followed by reverse engineering revealed that the amplification of the heterologous oxidoreductase pathway and a mutation in the GTPase-activating protein gene (YALI0B12100g) might be the primary reasons for improved xylose assimilation in the XEV strain. When a sorghum hydrolysate was used, the XEV strain showed superior xylose consumption and lipid production compared to its parental strain (X123). This study advances our understanding of xylose metabolism in Y. lipolytica and proposes effective metabolic engineering strategies for optimizing lignocellulosic hydrolysates.
ABSTRACT In Saccharomyces cerevisiae, the complete set of proteins involved in transport of lactic acid across the cell membrane has not been determined. In this study, we aimed to identify transport proteins not previously described to be involved in lactic acid transport via a combination of directed evolution, whole-genome resequencing and reverse engineering. Evolution of a strain lacking all known lactic acid transporters on lactate led to the discovery of mutated Ato2 and Ato3 as two novel lactic acid transport proteins. When compared to previously identified S. cerevisiae genes involved in lactic acid transport, expression of ATO3T284C was able to facilitate the highest growth rate (0.15 ± 0.01 h-1) on this carbon source. A comparison between (evolved) sequences and 3D models of the transport proteins showed that most of the identified mutations resulted in a widening of the narrowest hydrophobic constriction of the anion channel. We hypothesize that this observation, sometimes in combination with an increased binding affinity of lactic acid to the sites adjacent to this constriction, are responsible for the improved lactic acid transport in the evolved proteins.
Sn is a promising metal anode for aqueous batteries, with up to four-electron redox available per atom (903 mAh g −1 Sn ). However, practically harnessing the four-electron Sn(OH) 6 2− /Sn reversibility remains challenging due to limited mechanistic understanding. Here, in this study, we reveal a kinetically asymmetric redox pathway involving a successive four-electron plating and a stepwise 2 + 2 electron stripping through a Sn(OH) 3 − intermediate. The crossover of Sn(OH) 3 − induces a reversible self-discharge that reduces Coulombic efficiency but does not impact cyclability, demonstrated by four-electron Sn-Ni full cells that sustain >800 h of stable cycling. By tuning the ion selectivity of the separator to suppress Sn(OH) 3 − crossover while allowing OH − transport, we further demonstrate high Sn utilization (67%) and high energy density (143.1 Wh L −1 cell). The results provide key understandings of the tradeoffs in engineering reversible multi-electron metal anodes and define a new benchmark for practical energy density that exceeds any Sn-based aqueous batteries to date.
Networks are vital tools for understanding and modeling interactions in complex systems in science and engineering, and direct and indirect interactions are pervasive in all types of networks. However, quantitatively disentangling direct and indirect relationships in networks remains a formidable task. Here, we present a framework, called iDIRECT (Inference of Direct and Indirect Relationships with Effective Copula-based Transitivity), for quantitatively inferring direct dependencies in association networks. Using copula-based transitivity, iDIRECT eliminates/ameliorates several challenging mathematical problems, including ill-conditioning, self-looping, and interaction strength overflow. With simulation data as benchmark examples, iDIRECT showed high prediction accuracies. Application of iDIRECT to reconstruct gene regulatory networks in Escherichia coli also revealed considerably higher prediction power than the best-performing approaches in the DREAM5 (Dialogue on Reverse Engineering Assessment and Methods project, #5) Network Inference Challenge. In addition, applying iDIRECT to highly diverse grassland soil microbial communities in response to climate warming showed that the iDIRECT-processed networks were significantly different from the original networks, with considerably fewer nodes, links, and connectivity, but higher relative modularity. Further analysis revealed that the iDIRECT-processed network was more complex under warming than the control and more robust to both random and target species removal ( P < 0.001). As a general approach, iDIRECT has great advantages for network inference, and it should be widely applicable to infer direct relationships in association networks across diverse disciplines in science and engineering.
Poly(ethylene terephthalate) (PET) is one of the most ubiquitous plastics and can be depolymerized through biological and chemo-catalytic routes to its constituent monomers, terephthalic acid (TPA) and ethylene glycol (EG). TPA and EG can be re-synthesized into PET for closed-loop recycling or microbially converted into higher-value products for open-loop recycling. Here, in this study, we expand on our previous efforts engineering and applying Pseudomonas putida KT2440 for PET conversion by employing adaptive laboratory evolution (ALE) to improve TPA catabolism. Three P. putida strains with varying degrees of metabolic engineering for EG catabolism underwent an automation-enabled ALE campaign on TPA, a TPA and EG mixture, and glucose as a control. ALE increased the growth rate on TPA and TPA-EG mixtures by 4.1- and 3.5-fold, respectively, in approximately 350 generations. Evolved isolates were collected at the midpoints and endpoints of 39 independent ALE experiments, and growth rates were increased by 0.15 and 0.20 h -1 on TPA and a TPA-EG, respectively, in the best performing isolates. Whole-genome re-sequencing identified multiple converged mutations, including loss-of-function mutations to global regulators gacS, gacA, and turA along with large duplication and intergenic deletion events that impacted the heterologously-expressed tphAB II catabolic genes. Reverse engineering of these targets confirmed causality, and a strain with all three regulators deleted and second copies of tphAB II and tpaK displayed improved TPA utilization compared to the base strain. Taken together, an iterative strain engineering process involving heterologous pathway engineering, ALE, whole genome sequencing, and genome editing identified five genetic interventions that improve P. putida growth on TPA, aimed at developing enhanced whole-cell biocatalysts for PET upcycling.