Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “time security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Dynamic IT Security Database and Analytics for Launch Control Systems Software

During the Summer 2020 session, I worked with intern Destani S. Van Arsdalen of EGS Software. Together, we co-created a tool to aid the dynamic investigation, updated over time,of the security compliance of LCS COTS and open source software. We originally planned touse spreadsheet software for management and analysis, but through this exploratoryproject, chose to use Python and JSON after receiving feedback on our project’s current anddesired capabilities at that time.At first, the project was solely designed to help on-board new COTS software, based on aquestionnaire that could be filled out for each software package. This, combined with usingthe spreadsheet application’s web-query capabilities to fetch information from the NVD,allowed presentation and analytics cells to automatically populate as elements of themanually-filled questionnaire changed. While this system was promising, we decided tochange technologies for a few reasons. In the spreadsheet, single cells could not hold complexdata like arrays and objects. The automatic population of cells and dynamic updates made itdifficult to manage and add new features. And finally, it had limited extensibility sinceadding new software required significant understanding of how both the spreadsheet wasconstructed, and the more obscure, proprietary scripting languages packaged with it.The pivot to a standard computer science database language of JSON, aided by thescripting capabilities of Python, greatly helped to improve the project’s functionality. First,and most importantly, the script’s import and analysis of database data is easilyreproducible. Additional data analysis can be modularly added without requiringmodification of the script and is capable of routine scheduling. The revised process can besplit into three parts. First, the conversion of LCS asset and software documentation into theJSON hierarchical database format. Second, the merging of this database with the NVD,forming a new data structure, using CPEs of the CVE object as a linking element betweenthem. And third, the automatically performed analytics and analysis of the combined data,in a modular and extensible format, to produce better informed business decisions. The outputted graphs, for example, are automatically generated by the Python script inconnection with the combined database. This allows updated graphs and any analytics to be re-rendered automatically following updates to the LCS’s initial asset documentation. Afinal report can then be programmatically and easily constructed from these sources to allow fully reproducible metrics for heavily evidenced risk management decisions.

it↗

A Domain-Decomposed Multi-Level Method for Adaptively Refined Cartesian Grids with Embedded Boundaries

The work presents a new method for on-the-fly domain decomposition technique for mapping grids and solution algorithms to parallel machines, and is applicable to both shared-memory and message-passing architectures. It will be demonstrated on the Cray T3E, HP Exemplar, and SGI Origin 2000. Computing time has been secured on all these platforms. The decomposition technique is an outgrowth of techniques used in computational physics for simulations of N-body problems and the event horizons of black holes, and has not been previously used by the CFD community. Since the technique offers on-the-fly partitioning, it offers a substantial increase in flexibility for computing in heterogeneous environments, where the number of available processors may not be known at the time of job submission. In addition, since it is dynamic it permits the job to be repartitioned without global communication in cases where additional processors become available after the simulation has begun, or in cases where dynamic mesh adaptation changes the mesh size during the course of a simulation. The platform for this partitioning strategy is a completely new Cartesian Euler solver tarcreted at parallel machines which may be used in conjunction with Ames' "Cart3D" arbitrary geometry simulation package.

Aftosmis, M. J.↗

Physical Processes Governing Atmospheric Trace Constituents Measured from an Aircraft on PEM-Tropics

Before the mission, the PI (principal investigator) was instrumental in securing real-time use of the new 51-level ECMWF (European Centre for Medium Range Weather Forecasts) meteorological data. During the mission, he provided flight planning and execution guidance as meteorologist for the P-3B. Mr. Yong Zhu computed and plotted meteorological forecast maps using the ECMWF data and transmitted them to the field from MIT (Massachusetts Institute of Technology). Dr. John Cho was in the field for the Christmas Island portion to extract data from the on-site NOAA (National Oceanic and Atmospheric Administration) radars for local wind profiles that were used at the flight planning meetings. When the power supply for the VHF radar failed, he assisted the NOAA engineer in its repair. After the mission, Mr. Zhu produced meteorological data memos, which were made available to the PEM (Pacific Exploratory Mission)-Tropics B science team on request. An undergraduate student, Ms. Danielle Morse, wrote memos annotating the cloud conditions seen on the aircraft external monitor video tapes. Dr. Cho and the PI circulated a memo regarding the status (and associated problems) of the meteorological measurement systems on the DC-8 and P-3B to the relevant people on the science team. Several papers by members of our project were completed and accepted by JGR (Journal of Geophysical Research) for the first special section on PEM-Tropics B. These papers included coverage of the following topics: 1) examination of boundary layer data; 2) water vapor transport; 3) tropospheric trace constituent layers; 4) summarizations of the meteorological background and events during PEM-Tropics B; 5) concomitant lidar measurements of ozone, water vapor, and aerosol.

Newell, Reginald E.↗

User and Task Analysis of the Flight Surgeon Console at the Mission Control Center of the NASA Johnson Space Center

Astronauts in a space station are to some extent like patients in an intensive care unit (ICU). Medical support of a mission crew will require acquisition, transmission, distribution, integration, and archiving of significant amounts of data. These data are acquired by disparate systems and will require timely, reliable, and secure distribution to different communities for the execution of various tasks of space missions. The goal of the Comprehensive Medical Information System (CMIS) Project at Johnson Space Center Flight Medical Clinic is to integrate data from all Medical Operations sources, including the reference information sources and the electronic medical records of astronauts. A first step toward the full CMIS implementation is to integrate and organize the reference information sources and the electronic medical record with the Flight Surgeons console. In order to investigate this integration, we need to understand the usability problems of the Flight Surgeon's console in particular and medical information systems in general. One way to achieve this understanding is through the use of user and task analyses whose general purpose is to ensure that only the necessary and sufficient task features that match users capacities will be included in system implementations. The goal of this summer project was to conduct user and task analyses employing cognitive engineering techniques to analyze the task of the Flight Surgeons and Biomedical Engineers (BMEs) while they worked on Console. The techniques employed were user interviews, observations and a questionnaire to collect data for which a hierarchical task analysis and an information resource assessment were performed. They are described in more detail below. Finally, based on our analyses, we make recommendations for improvements to the support structure.

Johnson, Kathy A.↗

Airport Information Sharing Concept Architecture

The National Airspace System (NAS) Air Traffic management, control and operation depends on a timely and efficient distribution of real time information generated by stakeholders and published from a variety of sources. The Federal Aviation Administration System Wide Information Management (SWIM) is a service oriented architecture design to provide stakeholders with timely NAS information. However, there are other sources of useful information generated by stakeholders that can be included in the management of NAS operations. Airport facilities are host to most stakeholders operating in the NAS (airspace user, airport authority, ground handling, controller tower) and thus large information is generated and consumed at these facilities. The NASA Glenn Research center has been investigating an information exchange architecture framework that would enable the timely, efficient and secure gathering and distribution information generated at airport facilities. This presentation describes the framework architecture concept for the efficient information exchange of airport information.

Airports↗

DSN Wide Area Network Architecture, Capacity and Performance

This paper discusses the architecture of the wide area network that connects key communications facilities within the National Aeronautic and Space Administration (NASA) Deep Space Network (DSN). Several considerations are given to the design of this wide area network to ensure a timely, reliable, and secure data delivery between the mission users and their spacecraft. The network star configuration simplifies data delivery to users and minimizes operational cost. The dual-path connections maximize the system reliability, with geographical diversity in data routing to avoid single point of failure. Data encryption enhances the protection of mission users’ data. The system bandwidth is determined by balancing the needs to minimize the operating bandwidth cost and to have sufficient bandwidth to be able to deliver data to all users within the required. The DSN uses a class base weighted fair queuing (CBWFQ) method in its data delivery. This scheme guarantees a minimum bandwidth to each class of users and allows users to also access any unused bandwidth by other groups. The paper will also show performance of system reliability and bandwidth margin.

Liao, Jason↗

LMI Automated Air Cargo Operations Market Research and Forecast

Air cargo companies and aircraft manufacturers are making significant investments to enable the movement of cargo via various levels of automated aircraft, such as aircraft with simplified operations requiring a pilot, remotely monitored or piloted aircraft, and fully autonomous aircraft. These investments will enable greater utilization of aircraft while unlocking new air markets traditionally served by ground transportation only. Many cargo companies and aerospace experts envision an operating environment where a single pilot can remotely pilot numerous aircraft for significant increases in aircraft utilization. The future operating environment is also expected to include air cargo companies flying smaller aircraft from airports and distribution centers outside of major U.S. cities directly to city centers, avoiding congested roads and increasing the velocity of cargo shipments, particularly those that are high-value, time-sensitive, and security sensitive (e.g., pharmaceuticals). These are just a few benefits and use cases cargo companies and aerospace experts see with the advancement of automated aircraft. To better understand industry’s direction, NASA asked the LMI team to research the forecasted market, timeline, risks, and opportunities for integrating unmanned air cargo vehicles into the National Airspace System (NAS) for the development and prioritization of the NASA Air Traffic Management Exploration’s research portfolio. To begin the market assessment, we gathered data via numerous interviews with key stakeholders and subject matter experts and literature reviews. We then incorporated the data into a custom-developed systems dynamics model and visualization dashboard. The systems dynamics model classifies the size of the market (e.g., overall fleet size of automated aircraft) for four distinct use cases over the next 20 years. The model projects the year in which various types of automated aircraft will enter the commercial cargo market based on our team’s collective research on when the aircraft will become viable due to manufacturing and certification timelines and the lifespan of current, traditional aircraft in service, to name a few factors. While this report defines our team’s estimated timeline of entry and growth, the model is dynamic—it enables NASA users to change variables based on future-year events. If the necessary technology does not mature in accordance with our assumptions, then NASA can change the entry of service point to a future year to evaluate the changes in market size in the out years. This flexibility will be key to deciding when and how NASA should invest in various areas.

air traffic management↗

A Deep Optical Survey of the Ecliptic

This was an observing-intensive investigation into the newly discovered regions of the solar system beyond Neptune. The research was focussed on the use of unique imaging facilities on telescopes atop Mauna Kea, Hawaii, although other observatories (in Arizona and Chile) were also occasionally used. We secured about 20 nights of telescope time per year for our 'Medium Depth Wide Area' survey (JLC96). In this, we covered 5 sq. deg. of sky to apparent red magnitude 24.2. We used a high quantum efficiency Tektronix 2048x2048 CCD for all observations in this program. We secured observing time at the UH 2.2 meter for testing the suitability of a much larger array CCD camera for survey work (an 8192x8192 pixel device). We obtained observing runs at the twin Schmidt telescopes of Kitt Peak National Observatory and Cerro-Tololo InterAmerican Observatory in order to assess the number of bright Kuiper Belt objects, Centaurs and gas giant Trojans.

Jewitt, David↗

Expert system development methodology and the transition from prototyping to operations: FIESTA, a case study

A major barrier in taking expert systems from prototype to operational status involves instilling end user confidence in the operational system. The software of different life cycle models is examined and the advantages and disadvantages of each when applied to expert system development are explored. The Fault Isolation Expert System for Tracking and data relay satellite system Applications (FIESTA) is presented as a case study of development of an expert system. The end user confidence necessary for operational use of this system is accentuated by the fact that it will handle real-time data in a secure environment, allowing little tolerance for errors. How FIESTA is dealing with transition problems as it moves from an off-line standalone prototype to an on-line real-time system is discussed.

Happell, Nadine↗

Expert system development methodology and the transition from prototyping to operations - Fiesta, a case study

A major barrier in taking expert systems from prototype to operational status involves instilling end user confidence in the operational system. The software of different life cycle models is examined and the advantages and disadvantages of each when applied to expert system development are explored. The Fault Isolation Expert System for Tracking and data relay satellite system Applications (FIESTA) is presented as a case study of development of an expert system. The end user confidence necessary for operational use of this system is accentuated by the fact that it will handle real-time data in a secure environment, allowing little tolerance for errors. How FIESTA is dealing with transition problems as it moves from an off-line standalone prototype to an on-line real-time system is discussed.

Happell, Nadine↗

L-Band Digital Aeronautical Communications System Engineering - Initial Safety and Security Risk Assessment and Mitigation

This document is being provided as part of ITT's NASA Glenn Research Center Aerospace Communication Systems Technical Support (ACSTS) contract NNC05CA85C, Task 7: "New ATM Requirements--Future Communications, C-Band and L-Band Communications Standard Development." ITT has completed a safety hazard analysis providing a preliminary safety assessment for the proposed L-band (960 to 1164 MHz) terrestrial en route communications system. The assessment was performed following the guidelines outlined in the Federal Aviation Administration Safety Risk Management Guidance for System Acquisitions document. The safety analysis did not identify any hazards with an unacceptable risk, though a number of hazards with a medium risk were documented. This effort represents a preliminary safety hazard analysis and notes the triggers for risk reassessment. A detailed safety hazards analysis is recommended as a follow-on activity to assess particular components of the L-band communication system after the technology is chosen and system rollout timing is determined. The security risk analysis resulted in identifying main security threats to the proposed system as well as noting additional threats recommended for a future security analysis conducted at a later stage in the system development process. The document discusses various security controls, including those suggested in the COCR Version 2.0.

Zelkin, Natalie↗

Easily Accessible Camera Mount

Modified mount enables fast alinement of movie cameras in explosionproof housings. Screw on side and readily reached through side door of housing. Mount includes right-angle drive mechanism containing two miter gears that turn threaded shaft. Shaft drives movable dovetail clamping jaw that engages fixed dovetail plate on camera. Mechanism alines camera in housing and secures it. Reduces installation time by 80 percent.

Chalson, H. E.↗

Communications and control for electric power systems: Power flow classification for static security assessment

This report investigates the classification of power system states using an artificial neural network model, Kohonen's self-organizing feature map. The ultimate goal of this classification is to assess power system static security in real-time. Kohonen's self-organizing feature map is an unsupervised neural network which maps N-dimensional input vectors to an array of M neurons. After learning, the synaptic weight vectors exhibit a topological organization which represents the relationship between the vectors of the training set. This learning is unsupervised, which means that the number and size of the classes are not specified beforehand. In the application developed in this report, the input vectors used as the training set are generated by off-line load-flow simulations. The learning algorithm and the results of the organization are discussed.

Niebur, D.↗

C-Band Airport Surface Communications System Engineering-Initial High-Level Safety Risk Assessment and Mitigation

This document is being provided as part of ITT's NASA Glenn Research Center Aerospace Communication Systems Technical Support (ACSTS) contract: "New ATM Requirements--Future Communications, C-Band and L-Band Communications Standard Development." ITT has completed a safety hazard analysis providing a preliminary safety assessment for the proposed C-band (5091- to 5150-MHz) airport surface communication system. The assessment was performed following the guidelines outlined in the Federal Aviation Administration Safety Risk Management Guidance for System Acquisitions document. The safety analysis did not identify any hazards with an unacceptable risk, though a number of hazards with a medium risk were documented. This effort represents an initial high-level safety hazard analysis and notes the triggers for risk reassessment. A detailed safety hazards analysis is recommended as a follow-on activity to assess particular components of the C-band communication system after the profile is finalized and system rollout timing is determined. A security risk assessment has been performed by NASA as a parallel activity. While safety analysis is concerned with a prevention of accidental errors and failures, the security threat analysis focuses on deliberate attacks. Both processes identify the events that affect operation of the system; and from a safety perspective the security threats may present safety risks.

Zelkin, Natalie↗

Cloud Computing for Mission Design and Operations

The space mission design and operations community already recognizes the value of cloud computing and virtualization. However, natural and valid concerns, like security, privacy, up-time, and vendor lock-in, have prevented a more widespread and expedited adoption into official workflows. In the interest of alleviating these concerns, we propose a series of guidelines for internally deploying a resource-oriented hub of data and algorithms. These guidelines provide a roadmap for implementing an architecture inspired in the cloud computing model: associative, elastic, semantical, interconnected, and adaptive. The architecture can be summarized as exposing data and algorithms as resource-oriented Web services, coordinated via messaging, and running on virtual machines; it is simple, and based on widely adopted standards, protocols, and tools. The architecture may help reduce common sources of complexity intrinsic to data-driven, collaborative interactions and, most importantly, it may provide the means for teams and agencies to evaluate the cloud computing model in their specific context, with minimal infrastructure changes, and before committing to a specific cloud services provider.

cloud computing↗

Freddie Software Security Patching

Software applications become more complicated over time as they depend on many third-party, open-source libraries. The Freddie Platform Services team actively improves software security by addressing software bugs and vulnerabilities that negatively impact software applications, especially those providing real-time operations and services for the federal partners and industries. In order to detect bugs and patch vulnerabilities in software development and maintenance cycles, an automated and systematic approach is needed. This document describes what bugs and vulnerabilities are, and how they can be detected by using static code analyzers and software composition analysis tools. Once vulnerabilities are detected, the patching approaches, such as upgrading direct and transitive dependencies and loading custom classes first, are presented together with their strengths and weaknesses. In addition, patching walkthrough, example code, lessons learned throughout the vulnerability patching process and the recommended practices are discussed.

Chok Fung Lai↗

Security warning system monitors up to fifteen remote areas simultaneously

Security warning system consisting of 15 television cameras is capable of monitoring several remote or unoccupied areas simultaneously. The system uses a commutator and decommutator, allowing time-multiplexed video transmission. This security system could be used in industrial and retail establishments.

Fusco, R. C.↗

Toward Synthesis, Analysis, and Certification of Security Protocols

Implemented security protocols are basically pieces of software which are used to (a) authenticate the other communication partners, (b) establish a secure communication channel between them (using insecure communication media), and (c) transfer data between the communication partners in such a way that these data only available to the desired receiver, but not to anyone else. Such an implementation usually consists of the following components: the protocol-engine, which controls in which sequence the messages of the protocol are sent over the network, and which controls the assembly/disassembly and processing (e.g., decryption) of the data. the cryptographic routines to actually encrypt or decrypt the data (using given keys), and t,he interface to the operating system and to the application. For a correct working of such a security protocol, all of these components must work flawlessly. Many formal-methods based techniques for the analysis of a security protocols have been developed. They range from using specific logics (e.g.: BAN-logic [4], or higher order logics [12] to model checking [2] approaches. In each approach, the analysis tries to prove that no (or at least not a modeled intruder) can get access to secret data. Otherwise, a scenario illustrating the &tack may be produced. Despite the seeming simplicity of security protocols ("only" a few messages are sent between the protocol partners in order to ensure a secure communication), many flaws have been detected. Unfortunately, even a perfect protocol engine does not guarantee flawless working of a security protocol, as incidents show. Many break-ins and security vulnerabilities are caused by exploiting errors in the implementation of the protocol engine or the underlying operating system. Attacks using buffer-overflows are a very common class of such attacks. Errors in the implementation of exception or error handling can open up additional vulnerabilities. For example, on a website with a log-in screen: multiple tries with invalid passwords caused the expected error message (too many retries). but let the user nevertheless pass. Finally, security can be compromised by silly implementation bugs or design decisions. In a commercial VPN software, all calls to the encryption routines were incidentally replaced by stubs, probably during factory testing. The product worked nicely. and the error (an open VPN) would have gone undetected, if a team member had not inspected the low-level traffic out of curiosity. Also, the use secret proprietary encryption routines can backfire, because such algorithms often exhibit weaknesses which can be exploited easily (see e.g., DVD encoding). Summarizing, there is large number of possibilities to make errors which can compromise the security of a protocol. In today s world with short time-to-market and the use of security protocols in open and hostile networks for safety-critical applications (e.g., power or air-traffic control), such slips could lead to catastrophic situations. Thus, formal methods and automatic reasoning techniques should not be used just for the formal proof of absence of an attack, but they ought to be used to provide an end-to-end tool-supported framework for security software. With such an approach all required artifacts (code, documentation, test cases) , formal analyses, and reliable certification will be generated automatically, given a single, high level specification. By a combination of program synthesis, formal protocol analysis, certification; and proof-carrying code, this goal is within practical reach, since all the important technologies for such an approach actually exist and only need to be assembled in the right way.

Schumann, Johann↗