Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “traffic monitoring”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

31 records · Page 2

Analyzing Risks of Virtual Private Network Connections

The use of Splunk for analyzing VPN logs is an effective approach for identifying vulnerabilities in network endpoints. Splunk, a powerful platform for searching, monitoring, and analyzing machine-generated data, enables organizations to aggregate VPN logs in real-time, providing insights into network activity, user behavior, and potential security risks. By indexing VPN traffic and authentication logs, security teams can track abnormal patterns such as multiple failed login attempts, unusual IP addresses, or unexpected changes in bandwidth usage, all of which could indicate potential vulnerabilities or breaches. With Splunk’s advanced search and reporting capabilities, users can create custom dashboards and alerts to detect suspicious activities. Automated searches can flag endpoints exhibiting unusual behavior, while correlation analysis can identify links between compromised devices and broader network vulnerabilities. In particular, Splunk's machine learning capabilities can be leveraged to predict and prevent threats by identifying trends that might otherwise be missed in traditional log analysis. This proactive approach to monitoring VPN logs allows for the early detection of security weaknesses, enabling rapid response and minimizing potential damage to network integrity. By enhancing endpoint visibility, Splunk plays a crucial role in securing remote connections and safeguarding sensitive information. Additionally, Splunk’s automation and alerting features allow teams to create custom workflows that notify them of vulnerable or misconfigured endpoints identified through Shodan. This synergy between Splunk’s log analysis and Shodan’s device intelligence enhances an organization’s ability to proactively identify and mitigate security risks, improving the overall resilience of their VPN infrastructure.

97 MATHEMATICS AND COMPUTING↗

Heavy metal imprints in Antarctic snow from research and tourism

Antarctica, long regarded as one of the last pristine environments on Earth, is increasingly affected by human activity. As tourism surges and scientific operations expand, air pollution from local emissions is raising new environmental concerns. Here, in this study, we analyze surface snow samples collected along a ~2,000 km transect, from the South Shetland Islands (62°S) to the Ellsworth Mountains (79°S), to map the geochemical fingerprints of aerosol deposition. We identify distinct spatial patterns shaped by crustal, marine, biogenic, and anthropogenic sources. Notably, we detect heavy metal imprints in the snow chemistry of the northern Antarctic Peninsula, where major research stations are concentrated and marine tourism traffic is most intense. Our findings shed light on the extent of the impacts from energy-intensive local activities in Antarctica, underscoring the need for enhanced environmental monitoring and sustainable management strategies in this fragile region.

Cordero, Raúl R. [Univ. of Groningen, Leeuwarden (↗

Vedizar Fingerprinter

SAND2025-03289O Vedizar Fingerprinter simplifies the process of identifying devices on a network by analyzing traffic data. It uses a unique library to recognize different devices, making it easier for users to understand what is happening on their networks. This software is ideal for IT and operational technology environments, helping organizations monitor their networks effectively. By saving results in a database, it allows for easy access and review of device information. Users can enhance their network security and optimize performance without needing specialized hardware or technical expertise. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Jacobellis, John [Sandia National Lab. (SNL-CA), L↗

Network performance analysis for HPC datacenters (net_perf) v1.0

The software has two main features: (1) identify data movement trends in HPC data centers that use network flow monitoring (2) analyze the performance of individual data flows under the existing data movement management strategy and identify performance bottlenecks that impede timely data availability for science workflows. Its main advantage is that it is tailored for HPC network traffic by considering HPC data movement management intricacies.

Giannakou, Anna↗

Short-Term Energy and Meteorological Impacts on Thanksgiving CO2 in Salt Lake City

Abstract Long-term, high-frequency atmospheric CO2 measurements at multiple sites in the Salt Lake City (SLC), Utah, reveal that annual and monthly CO2 variability aligns with a priori estimates of emissions from anthropogenic and biological sources. In this study, we investigate whether short-term fluctuations in anthropogenic emissions, as captured in the Vulcan3 dataset for the United States, can be detected in atmospheric CO2 observations. Specifically, we focus on Thanksgiving holidays, when traffic and energy usage patterns differ from the rest of November. Onroad CO2 emissions exhibit a double peak during weekday morning and evening rush hours but remain relatively low on weekends and Thanksgiving. Interestingly, CO2 mole fractions during Thanksgiving were higher than the rest of November at all SLC monitoring sites, particularly from 2008 to 2013. This increase is partially attributed to elevated energy-related emissions — especially residential sources — and meteorological factors such as weak wind speeds, cold temperature, and a low planetary boundary layer height (PBLH).

 While CO₂ emissions and mole fraction patterns align over time, notable spatial differences exist. For instance, the near-highway site in Murray shows the highest CO₂ mole fractions despite low local emissions, suggesting pollution transport via highways and wind advection. Random Forest model-based SHapley Additive exPlanations (SHAP) analysis reveals that onroad emissions dominate CO2 contributions on weekdays and weekends, while energy-related emissions play a larger role during Thanksgiving, alongside meteorological drivers such as wind speed and PBLH. Across six urban cities, CO2 emissions display a consistent pattern: residential and commercial (onroad) emissions peak during Thanksgiving (weekday) with substantial (minimal) year-to-year variability. These findings highlight that urban CO₂ variability is driven by the combined influence of emissions and meteorology, underscoring the need for integrated mitigation strategies. Additionally, multi-site measurements are essential for accurate source attribution and the development of effective policy interventions. 

Ryoo, Ju-Mee (ORCID:0000000234256296)↗

Infrastructure-Based Cooperative Perception at a Traffic Intersection: Overview and Challenges: Preprint

Recent advancement in autonomous driving vehicles and V2X communication has attracted increasing attention towards Intelligent Transportation Systems to build a safe and reliable traffic intersection. However, most of the systems are still at the initial stages and require significant progress to become a reality. This paper presents an overview of NREL Infrastructure Perception and Control (IPC) framework which is an open-source track-data fusion engine which takes input from infrastructure-based perception sensors and cooperatively shared messages from Connected Autonomous Vehicles (CAVs) and Connected Vehicle (CVs) and the challenges associated with deploying such cooperative perception framework at a four-way traffic intersection in the city of Colorado Springs, CO, USA. The sensor data is collected by deploying two radars and two LiDAR sensors on the IPC mobile lab and two radars on diagonally opposite traffic poles at the proposed intersection. The sensor output results imply the need for rapid sensor calibration to bring the collective perception to a common coordinate frame, the importance of time synchronization between the sensors in order to capture accurate spatial and temporal alignment of the objects, and the need for a health monitoring system with fail safe closed-loop detection model for real-time deployment.

camera↗

Spatiotemporal Automatic Calibration of Infrastructure Lidar, Radar, and Camera with a Global Navigation Satellite System

Robust and accurate perception is important for modern intelligent transportation systems (ITS), which use sensors of various modalities for data fusion to create a digital twin of an intersection. Sensor calibration is an important process that creates a unified coordinate frame for the sensor output data so that it can be used for data fusion. Classical approaches for sensor calibration are time-consuming, require an overlapping field of view for feature matching, and are not feasible for ITS application as they cause disruptions in the flow of traffic. In this paper, we present a spatiotemporal automatic calibration approach to calibrate multiple infrastructure lidar, radar, and cameras installed at a traffic intersection. The approach uses global navigation satellite system (GNSS) positioning information shared by connected vehicles, and when the vehicle is detected by the sensor, we match the sensor detections with the GNSS coordinates. The proposed algorithm is evaluated with a real-world dataset utilizing detections from two radars, cameras, and lidars with a test vehicle instrumented with a post-processing kinematic (PPK)-corrected GNSS driving past the sensors installed at a four-way traffic intersection. The experimental results show that the proposed automatic calibration approach can achieve the transformation with a root mean squared error of less than 0.5 for radar and lidar and less than 2 for camera detections. The ability to rapidly calibrate sensors not only benefits initial installations, but can also be used for system health monitoring, while utilizing available connected vehicle data to test the real-time sensor fidelity and operational status.

ADVANCED PROPULSION SYSTEMS,ENERGY CONSERVATION, C↗

Spatiotemporal Automatic Calibration of Infrastructure Lidar, Radar, and Camera with a Global Navigation Satellite System: Preprint

Robust and accurate perception is important for modern intelligent transportation systems (ITS), which use sensors of various modalities for data fusion to create a digital twin of an intersection. Sensor calibration is an important process that creates a unified coordinate frame for the sensor output data so that it can be used for data fusion. Classical approaches for sensor calibration are time-consuming, require an overlapping field of view for feature matching, and are not feasible for ITS application as they cause disruptions in the flow of traffic. In this paper, we present a spatiotemporal automatic calibration approach to calibrate multiple infrastructure lidar, radar, and cameras installed at a traffic intersection. The approach uses global navigation satellite system (GNSS) positioning information shared by connected vehicles, and when the vehicle is detected by the sensor, we match the sensor detections with the GNSS coordinates. The proposed algorithm is evaluated with a real-world dataset utilizing detections from two radars, cameras, and lidars with a test vehicle instrumented with a post-processing kinematic (PPK)-corrected GNSS driving past the sensors installed at a four-way traffic intersection. The experimental results show that the proposed automatic calibration approach can achieve the transformation with a root mean squared error of less than 0.5 for radar and lidar and less than 2 for camera detections. The ability to rapidly calibrate sensors not only benefits initial installations, but can also be used for system health monitoring, while utilizing available connected vehicle data to test the real-time sensor fidelity and operational status.

ADVANCED PROPULSION SYSTEMS↗

Air quality impacts from the development of unconventional oil and gas well pads: Air toxics and other volatile organic compounds

Unconventional oil and natural gas development (UOGD) has expanded rapidly across the United States in recent decades and raised concerns about associated air quality impacts. While significant effort has been made to quantify methane emissions, relatively few observations have been made of Volatile Organic Compounds (VOCs), especially during drilling and completion of new wells. Extensive air monitoring during development of several large, multi-well pads in Broomfield, Colorado, in the Denver-Julesburg Basin, provides a novel opportunity to examine changes in local air toxics and other VOC concentrations during well drilling and completions and production. These operations offer an especially useful case to study as several management practices were implemented to reduce emissions (e.g., electrified, grid-powered drill rigs and closed loop fluid handling systems to reduce truck traffic and limit fluid handling on the pad). With simultaneous measurements of methane and 50 VOCs from October 2018 to December 2022 at as many as 19 sites near well pads, in adjacent neighborhoods, and at a more distant reference location, we identify impacts from each phase of well development and production. Use of weekly, time-integrated canisters, a Proton Transfer Reaction Mass Spectrometer (PTR-MS), continuous photoionization detectors (PID) to trigger canister collection upon detection of VOC-rich plumes, and an instrumented vehicle, provided a powerful suite of measurements to characterize both transient plumes and longer-term changes in air quality. Prior to the start of well development, VOC gradients were small across Broomfield. Once drilling commenced, concentrations of oil and gas (O&G) related VOCs, including alkanes and aromatics, increased around active well pads. Concentration increases were clearly apparent during certain operations, including drilling, coil tubing/millout operations, and production tubing installation. Emissions of C 8 –C 10 n-alkanes during drilling operations highlighted the importance of VOC emissions from synthetic drilling mud chosen to reduce odor impacts. More than 90 samples were collected of transient plumes. Using composition measurements, meteorological data, and information about well pad activities, these plumes were connected with specific UOGD operations including drilling, flowback, and production equipment maintenance. The chemical signatures of these plumes differed by operation type (e.g., C 8 –C 10 n-alkanes constituted a larger fraction of measured VOCs in drilling-related plumes). Concentrations of individual, oil and gas-related VOCs in these plumes were often several orders of magnitude higher than in background air, with maximum ethane and benzene concentrations of 79,600 and 819 ppbv, respectively. Because these plumes typically impact a monitoring site for just several minutes, they are easily missed by slower-responding instruments. Study measurements highlight future emission mitigation opportunities during UOGD operations, including better control of emissions from shakers that separate drill cuttings from drilling mud, production separator maintenance operations, and periodic emptying of sand cans during flowback operations.

54 ENVIRONMENTAL SCIENCES↗

eCounter: Inline Per-IP Network Monitoring at Millisecond Resolution via eBPF

Scientific data acquisition (SciDAQ) systems are shifting from archive-based workflows to streaming paradigms, where real-time, fine-grained network monitoring becomes essential. While P4-enabled devices offer per-packet in-band observability, they require specialized switches and routers. Host-side tools like Prometheus exporters lack sufficient temporal granularity. To bridge this gap, we present eCounter, a lightweight, hardware-agnostic, inline telemetry agent built on extended Berkeley Packet Filter (eBPF). eCounter captures per-interface ingress and egress traffic, categorized by IP address and protocol, at millisecond to sub-millisecond resolution. In a 100 Gbps environment, it continuously exports up to 3,257 time-series bins per second with only 4% CPU utilization at a 35¿KiB/s data rate. We evaluate eCounter across diverse NIC MTU settings, hook types, CPU architectures and operating systems, and observed negligible impact on concurrent high-throughput streaming applications. Complexity analysis confirms that it can be readily scaled to distributed SciDAQ deployments.

Mei, Xinxin [Computational Sciences and Technology↗

Center for Alternate Synchronization and Timing (CAST) PTP Network Monitoring Report

The Oak Ridge National Laboratory Center for Alternative Synchronization and Timing (CAST) performs research, development, testing, and evaluation of alternative terrestrial-based timing and synchronization infrastructure for the US power grid and other critical infrastructures. Alternative timing options reduce reliance on GPS and enhance the overall resilience of critical infrastructures. CAST infrastructure uses Precision Time Protocol (PTP) as the primary conduit for delivery of synchronization packets. CAST deploys PTP over long terrestrial links to synchronize a multitude of remote boundary clocks and downstream power grid components with the authoritative grand master clocks. Network traffic issues can severely degrade PTP accuracy. This report focuses on examining network traffic anomalies and their effects on PTP operation as well as the potential implications to CAST’s high-precision remote synchronization operations.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Human Supervision of Autonomous Vehicle Fleet Operations and Associated Passenger Communications: Preprint

Advances in automated vehicle (AV) technology and expanded operations are rapidly emerging with Automated Mobility District (AMD) deployments in global cities. NLR's AMD research addresses critical elements of human supervision of AV fleet operations and associated passenger communications for vehicles in which no driver or safety attendant is present. Although sufficiently advanced AVs no longer have direct oversight by a driver, fleet management remains staffed with operations personnel at the operations command and control (OCC) facility. This paper examines the functionality of the OCC, drawing comparisons of how automated train control and automated people mover OCCs operate. Within an AMD, the OCC manages various vehicle types, sizes, and operational modes, including on-demand and fixed route service, to facilitate a 'network of networks' for transport within a metropolitan area. The OCC serves as oversight for multiple AV fleets assisting AVs via remote operation of vehicles, communication, and dispatching personnel to resolve problems. The OCC also coordinates system operation, geographically staging vehicles, and managing weather, police, and emergency events. Informed by traffic management center (TMC) strategies using highly integrated software and communications, OCCs facilitate seamless information flows. OCC personnel remotely assist passengers and oversee multi-party operation to ensure safety and security. Although social norms mitigate large-capacity unattended vehicle operations, social interaction in multi-party automated small vehicles has little precedent. This poses a new frontier for society and requires research to effectively understand and manage. Future research will monitor OCC implementations, passenger interfaces, and deployment scaling of initial AMD systems.

33 ADVANCED PROPULSION SYSTEMS↗

Advanced Data Science Model for Detecting Intelligent Malware

This study focused on developing a robust artificial intelligence (AI) model capable of detecting and characterizing advanced malware in Internet of Things (IoT) devices using network data. By analyzing network traffic with various machine learning (ML) models, our AI model can identify and characterize malicious activities to significantly improve malware detection accuracy and reliability as compared to traditional methods. The developed AI/ML model was trained using network data from IoT devices, leveraging classifiers such as Random Forest, Gradient Boosting, AdaBoost, and others to optimize detection performance. This project demonstrates a scalable framework for real-time malware detection and characterization in IoT networks, capable of identifying infected devices and facilitating the necessary steps to remove or isolate them, thereby preventing further infections. Although digital twin (DT) integration is not yet implemented in the current model, it represents a promising future enhancement. By creating a virtual replica of physical IoT devices, DT technology would allow for real-time monitoring and analysis without directly accessing operational technology, thus reducing the risk of compromising or reducing the performance of actual devices. This integration would further enhance the security of IoT ecosystems, combining AI technology to better flag and detect indications of malware-infected devices within a nuclear system environment.

42 ENGINEERING↗