Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Computer security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 487 records · Page 27

Measurement and applications: Exploring the challenges and opportunities of hierarchical federated learning in sensor applications

Sensor applications have become ubiquitous in modern society as the digital age continues to advance. AI-based techniques (e.g., machine learning) are effective at extracting actionable information from large amounts of data. An example would be an automated water irrigation system that uses AI-based techniques on soil quality data to decide how to best distribute water. However, these AI-based techniques are costly in terms of hardware resources, and Internet-of-Things (IoT) sensors are resource-constrained with respect to processing power, energy, and storage capacity. These limitations can compromise the security, performance, and reliability of sensor-driven applications. To address these concerns, cloud computing services can be used by sensor applications for data storage and processing. Unfortunately, cloud-based sensor applications that require real-time processing, such as medical applications (e.g., fall detection and stroke prediction), are vulnerable to issues such as network latency due to the sparse and unreliable networks between the sensor nodes and the cloud server [1]. As users approach the edge of the communications network, latency issues become more severe and frequent. A promising alternative is edge computing, which provides cloud-like capabilities at the edge of the network by pushing storage and processing capabilities from centralized nodes to edge devices that are closer to where the data are gathered, resulting in reduced network delays [2], [3].

Po-Leen Ooi, Melanie↗

The GABLE Report: Garbled Autonomous Bots Leveraging Ethereum

Simple but mission-critical internet-based applications that require extremely high reliability and availability could potentially benefit from running on robust public programmable blockchain platforms such as Ethereum. Unfortunately, program code running on such blockchains is ordinarily publicly viewable, rendering these platforms unsuitable for applications requiring strict privacy of application code, data, and results. However, might it be possible to encode an application's business logic and data for these platforms in such a way that it becomes impossible for unauthorized parties to infer any meaningful information whatsoever about the semantics of the data, and the operations being performed on that data? In this report, we describe GABLE (Garbled Autonomous Bots Leveraging Ethereum), a system concept developed at Sandia that achieves this security goal in a limited, but still useful range of circumstances. GABLE, uses simple but effective algorithms to permit secure private execution of garbled state machines (and more efficient garbled circuits) on public computing resources. We give an example working implementation for garbled state machines, written using the Python and Solidity programming languages, and outline how our methods can be extended to support a more powerful garbled universal circuit model of computation. The capability embodied by the GABLE, system has significant potential applications, a few of which we discuss in this report.

97 MATHEMATICS AND COMPUTING↗

20 years of the CEA/DAM NNSA/DP Agreement

For the past twenty years, there has been a very active, productive International Agreement between France and the United States of America for Cooperation on Fundamental Science supporting Stockpile Stewardship. Under this Agreement the scientists at the nuclear weapons laboratories in both countries have collaborated on many unclassified research projects in areas such as Materials in Extreme Conditions, Nuclear Physics, and Atomic and Plasma Physics. The results of their efforts have not only been published in the open literature but have enhanced the physics base of the computer codes essential to the mission of ensuring that the nuclear stockpiles are safe, secure and effective. Work on these collaborations is extremely important. Not only does such joint work bring more brilliant minds to work on pressing research problems for both countries but also the collaborative effort sharpens the scientific skills of and presents scientific challenges to the scientific and technical staff of the laboratories. As we reach the 20th Anniversary of the formal signing of the Agreement, we feel it is important to thank all of the individuals who have contributed to its continuing success. Our expectations for brilliant, exciting, challenging joint research projects under this Agreement are at an all-time high. We toast the achievement of this milestone and look forward to the research results to come.

36 MATERIALS SCIENCE↗

End-to-end Analytics for Grid Arch Design & All-hazard Assessment

Resiliency, reliability, and security of the next-generation smart grid depend upon leveraging advanced communication and computing technologies, integrating them with physical power systems, and developing real-time, fast, data-based applications to help in wide-area monitoring and control of the grid. Using a high sampling data rate from phasor measurement units (PMUs) to develop applications has opened the door to achieving the next-generation grid requirements. The North American Synchrophasor Initiative Network (NASPlnet) was developed in 2007-09 to create a standard and guide for PMU data exchanges. With the advancement in both networking and grid requirements, it is necessary to evaluate the performance of different NASPInet versions and their impact on applications. Therefore, we need a cyber-power cosimulation framework that supports very large-scale co-simulation capable of running in parallel, high-performance computing platforms and capturing real-life network behavior. This work presents a cyber-physical co-simulation testbed using NS3 to model the communication network, GridPACK to model the power grid, and HELICS as a co-simulation engine. Comparative analysis of latency in synchrophasor networks and a performance evaluation of a power system stabilizer application based on PMU data in an Institute of Electrical and Electronics Engineers 39-bus test system is presented using this co-simulation testbed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Redefining Tactical Operations for MER Using Cloud Computing

The Mars Exploration Rover Mission (MER) includes the twin rovers, Spirit and Opportunity, which have been performing geological research and surface exploration since early 2004. The rovers' durability well beyond their original prime mission (90 sols or Martian days) has allowed them to be a valuable platform for scientific research for well over 2000 sols, but as a by-product it has produced new challenges in providing efficient and cost-effective tactical operational planning. An early stage process adaptation was the move to distributed operations as mission scientists returned to their places of work in the summer of 2004, but they would still came together via teleconference and connected software to plan rover activities a few times a week. This distributed model has worked well since, but it requires the purchase, operation, and maintenance of a dedicated infrastructure at the Jet Propulsion Laboratory. This server infrastructure is costly to operate and the periodic nature of its usage (typically heavy usage for 8 hours every 2 days) has made moving to a cloud based tactical infrastructure an extremely tempting proposition. In this paper we will review both past and current implementations of the tactical planning application focusing on remote plan saving and discuss the unique challenges present with long-latency, distributed operations. We then detail the motivations behind our move to cloud based computing services and as well as our system design and implementation. We will discuss security and reliability concerns and how they were addressed

Mars↗

Use Case-Informed Framework for Utility Cloud Migration

This white paper presents a comprehensive methodology for assessing utilities’ cloud postures and frameworks. It aims to produce a roadmap and strategy for a cloud-enabled grid future, providing guidance for integrators, asset owners, and operators. Instead of offering a yes or no answer for cloud implementation, this framework offers strategic guidance on responsibly preparing for and deploying cloud solutions. This paper delves into cloud-service models pertinent to the electric sector, dissecting the shared responsibility model and elucidating what on-premise infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (SaaS) entail. A pivotal consideration within the context of the shared responsibility model is the allocation of responsibility for foundational security aspects—a decision that will be informed by a comprehensive risk assessment. The ensuing discussion will present a checklist of certifications necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and with a strategic roadmap. Furthermore, the paper outlines gaps in understanding the U.S. government’s role in shaping technology development and responsible use. Its purpose is to aid decision-making by offering support for risk-informed solutions that benefit those managing assets and operating in the cloud environment. The primary objective is to enhance the resilience and future readiness of a decarbonized electric grid, with cloud solutions as one viable option. The paper synthesizes information on current and future grid architectures and applications, considering both conservative and progressive energy transitions, along with scalable and distributed computing considerations.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Methodology and Application of Physical Security Effectiveness Based on Dynamic Force-on-Force Modeling

This report describes the research and development being performed at INL towards a dynamic modeling and simulation framework to enable physical security optimization at commercial nuclear power plants. The framework is based on the dynamic modeling tool EMRALD and is demonstrated for applications that can result in physical security optimization. Two main applications are presented: 1. Integrating FLEX portable equipment performance with FOF models of a plant’s physical security posture, and 2. Location optimization of bullet resistant enclosure. The generic framework for modeling FLEX portable equipment is described in detail, followed by a case study modeling an adversarial attack aimed at causing a radiological release by sabotaging the plant’s power supply and its ultimate heat sink capabilities at a hypothetical PWR. Two distinct FLEX deployment strategies, series and parallel, are modeled with distinct timelines. The results of the adversarial attack modeled in a commercial FOF tool, AVERT, are integrated with the FLEX deployment model in EMRALD. Monte Carlo simulation is used to model the distribution of the timeline in FLEX deployment strategies. Thermal-hydraulic analysis of FLEX performance is performed in RELAP5 and integrated with the EMRALD simulations to provide more realistic timelines in the models. The results demonstrate that, even in the extreme case of a successful adversarial attack, deployment of FLEX equipment can result in a significantly high likelihood of preventing radiological release. The modeling and simulation framework of integrating FLEX equipment with FOF models enables the NPPs to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security. The objective of location optimization of BRE is to determine the best location in the plant for a new BRE being planned by the plant to enhance their physical security effectiveness. The plant physical security FOF model is integrated with EMRALD that performs Monte Carlo simulation to run different attack scenarios and a discrete set of potential BRE locations. Sensitivity analysis is used to determine the most effective location for the BRE. The optimization approach can be extended to wide applications such as location optimization of remotely operated weapons and other strategic fixed assets.

97 MATHEMATICS AND COMPUTING↗

Baylor University Campus-Wide Deep Dive

In January 2020, staff members from the Engagement and Performance Operations Center (EPOC) and the Lonestar Education And Research Network (LEARN) met with researchers and staff at Baylor University for the purpose of a Campus-Wide Deep Dive into research drivers. The goal of this meeting was to help characterize the requirements for five campus research use cases and to enable cyberinfrastructure support staff to better understand the needs of the researchers they support. Profiled scientific use cases included: - Experimental High Energy Physics (HEP) - Proton Computed Tomography (pCT) - Nutrition and Relation to Digestive Microbiome - Baylor University Core Research Facilities - Molecular Quantum-dot Cellular Automata (QCA), and Material Science of Quantum Computing - Modeling and Simulation of Low-Dimensional and Nano-Structured Materials - Computational Fluid Dynamics Material for this event included the written documentation from each of the research areas at Baylor University, documentation about the current state of technology support, and a write-up of the discussion that took place in person. The Case Studies highlighted the ongoing challenges that Baylor University has in supporting a cross-section of established and emerging research use cases. Each Case Study mentioned unique challenges which were summarized into common needs. These included: - Tradeoffs for network/software security, and usability of the resulting infrastructure. Better communication to set expectations and understand realities is required. - Computation use on campus is widespread and healthy. While no major problems were uncovered, upgrades to maintain current usage patterns and encourage growth will be required. - Storage is a critical need for enterprise use cases and research. In particular, a campus wide ‘storage architecture’ to support research use cases (e.g. instruments, data sharing) is required in the 2-5 year time window. - Instrumentation on campus is healthy and expanding. Technology must scale with this in the form of computation and storage. - Working with LEARN to upgrade network capacity (in multiples of 10G, or upgrades to 100G) will be required in the 1-3 year time frame. - Network monitoring and visibility will help to establish external science use cases. - Data sharing via portal systems is not currently a critical need, but growing in scope. EPOC can assist Baylor with options.

99 GENERAL AND MISCELLANEOUS↗

Algorithms to Improve Training for Deep Learning with Diabetic Retinopathy Images

This is a minisymposium presentation I plan to give at the SIAM conference on Computational Science and Engineering on March 1st, 2021. The work is based on research from my SDRD this year and describes a new pooling method we've developed called variable stride. The goal of the minisymposium is to highlight some of the ground-breaking work being done across the National Nuclear Security Administration by graduate students and Postdocs.

97 MATHEMATICS AND COMPUTING↗

NREL Project CloudZero

The National Renewable Energy Laboratory's (NREL's) CloudZero project is evaluating the ability to reliably and securely manage complex energy systems from the cloud, identifying major technical and regulatory barriers to cloud adoption, suggesting new security controls and best practices for cloud applications, and empowering industry to embrace the cloud, where appropriate.

cloud↗

Cyber–physical vulnerability and resiliency analysis for DER integration: A review, challenges and research needs

High penetration of renewable and sustainable Distributed Energy Resources (DER) into the traditional distribution system requires a well-coordinated control strategy for the improvement of system-wide reliability and resiliency. Implementation of such a holistic control architecture requires a flexible, near real-time, and bi-directional communication framework for facilitating the participation of various agents in a multi-vendor heterogeneous smart grid. While the sustainability of energy generation is ensured, this exposes the smart grid to extrinsic cyber threats, and appropriate defense mechanism(s) must be deployed to guarantee continued reliability and resiliency of the power grid. Further, the comprehensive literature review presented in this paper discusses the latest trends in the DER control schemes with fast communication requirements and their accompanying cyber–physical vulnerabilities. These control schemes are compared and contrasted for various traits. A three-level DER system architecture has been depicted, facilitating the deployment of these control schemes. The current developments of standard communication protocols, key security mechanisms, and best practices along major standards and guidelines are explored. The impacts of different attack types with miscellaneous DER functions based on various control schemes and associated mitigation solutions are also provided. Finally, challenges and future research directions for limiting cyber-power susceptibility to enhance resiliency are summarized. The work presented here will help us enabling a cyber-resilient and sustainable smart electric grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Anatomy of a Security Operations Center

Many agencies and corporations are either contemplating or in the process of building a cyber Security Operations Center (SOC). Those Agencies that have established SOCs are most likely working on major revisions or enhancements to existing capabilities. As principle developers of the NASA SOC; this Presenters' goals are to provide the GFIRST community with examples of some of the key building blocks of an Agency scale cyber Security Operations Center. This presentation viII include the inputs and outputs, the facilities or shell, as well as the internal components and the processes necessary to maintain the SOC's subsistence - in other words, the anatomy of a SOC. Details to be presented include the SOC architecture and its key components: Tier 1 Call Center, data entry, and incident triage; Tier 2 monitoring, incident handling and tracking; Tier 3 computer forensics, malware analysis, and reverse engineering; Incident Management System; Threat Management System; SOC Portal; Log Aggregation and Security Incident Management (SIM) systems; flow monitoring; IDS; etc. Specific processes and methodologies discussed include Incident States and associated Work Elements; the Incident Management Workflow Process; Cyber Threat Risk Assessment methodology; and Incident Taxonomy. The Evolution of the Cyber Security Operations Center viII be discussed; starting from reactive, to proactive, and finally to proactive. Finally, the resources necessary to establish an Agency scale SOC as well as the lessons learned in the process of standing up a SOC viII be presented.

Wang, John↗

System for Secure Integration of Aviation Data

The Aviation Data Integration System (ADIS) of Ames Research Center has been established to promote analysis of aviation data by airlines and other interested users for purposes of enhancing the quality (especially safety) of flight operations. The ADIS is a system of computer hardware and software for collecting, integrating, and disseminating aviation data pertaining to flights and specified flight events that involve one or more airline(s). The ADIS is secure in the sense that care is taken to ensure the integrity of sources of collected data and to verify the authorizations of requesters to receive data. Most importantly, the ADIS removes a disincentive to collection and exchange of useful data by providing for automatic removal of information that could be used to identify specific flights and crewmembers. Such information, denoted sensitive information, includes flight data (here signifying data collected by sensors aboard an aircraft during flight), weather data for a specified route on a specified date, date and time, and any other information traceable to a specific flight. The removal of information that could be used to perform such tracing is called "deidentification." Airlines are often reluctant to keep flight data in identifiable form because of concerns about loss of anonymity. Hence, one of the things needed to promote retention and analysis of aviation data is an automated means of de-identification of archived flight data to enable integration of flight data with non-flight aviation data while preserving anonymity. Preferably, such an automated means would enable end users of the data to continue to use pre-existing data-analysis software to identify anomalies in flight data without identifying a specific anomalous flight. It would then also be possible to perform statistical analyses of integrated data. These needs are satisfied by the ADIS, which enables an end user to request aviation data associated with de-identified flight data. The ADIS includes client software integrated with other software running on flight-operations quality-assurance (FOQA) computers for purposes of analyzing data to study specified types of events or exceedences (departures of flight parameters from normal ranges). In addition to ADIS client software, ADIS includes server hardware and software that provide services to the ADIS clients via the Internet (see figure). The ADIS server receives and integrates flight and non-flight data pertaining to flights from multiple sources. The server accepts data updates from authorized sources only and responds to requests from authorized users only. In order to satisfy security requirements established by the airlines, (1) an ADIS client must not be accessible from the Internet by an unauthorized user and (2) non-flight data as airport terminal information system (ATIS) and weather data must be displayed without any identifying flight information. ADIS hardware and software architecture as well as encryption and data display scheme are designed to meet these requirements. When a user requests one or more selected aviation data characteristics associated with an event (e.g., a collision, near miss, equipment malfunction, or exceedence), the ADIS client augments the request with date and time information from encrypted files and submits the augmented request to the server. Once the user s authorization has been verified, the server returns the requested information in de-identified form.

Kulkarni, Deepak↗

Integration of the NCRC Database and Other INL Databases

The Nuclear Computational Resource Center provides a portal by which industry professionals, educational staff, students, national laboratory employees, and others may request access to certain engineering software tools. As the tools provided through the Nuclear Computational Resource Center portal are not open-source and freely available, a set of approvals are necessary before access is granted. All code recipients must be associated with an institution that has a license with Idaho National Laboratory for the code requested. Information about these licenses is controlled by Idaho National Laboratory’s Technology Deployment organization and housed in a Technology Deployment database. Those requesting code access who are not citizens of the United States must also have a security plan, mandated by Idaho National Laboratory policy. Security plans are managed by the International Access Program and are stored in an International Access Program database known as IFacts. Granting access to software thus depends on information stored in the Technology Deployment database and IFacts. In the past, no connection between the Nuclear Computational Resource Center portal and these databases existed, making checking the status of license agreements and security plans time consuming and error prone. This report demonstrates that the Nuclear Computational Resource Center portal now connects to both the Technology Deployment database and IFacts, greatly improving the ease of use of the Nuclear Computational Resource Center system for administrators, which leads to a better overall experience for those requesting code access.

99 GENERAL AND MISCELLANEOUS↗

Summer 2024 INL Intern Poster Session Submission - Brian Schumitz

This LRS submission is my poster for the INL Intern Poster Session, Summer 2024. Abstract: The Software Engineering and Cybersecurity Lab (SECL) at Montana State University has developed PIQUE, a system for evaluating software quality. PIQUE's adaptability allows for language-specific static-analysis operations, including a model for assessing cloud microservice ecosystems. These ecosystems often rely on Docker for efficient deployment and management of containerized services. Our research focuses on evaluating the network quality within these microservice ecosystems. To automate this process, we're utilizing Snort, an open-source intrusion detection system renowned for its ability to detect and log network traffic. By leveraging Snort's customizable rules, we aim to construct comprehensive testing methods for measuring and quantifying the network quality based on traffic between Docker containers. This research aims to enhance the overall security and reliability of cloud microservice ecosystems by providing automated and robust quality evaluation mechanisms, ultimately contributing to the advancement of software engineering practices in these environments

97 MATHEMATICS AND COMPUTING↗

The Namibia Early Flood Warning System, A CEOS Pilot Project

Over the past year few years, an international collaboration has developed a pilot project under the auspices of Committee on Earth Observation Satellite (CEOS) Disasters team. The overall team consists of civilian satellite agencies. For this pilot effort, the development team consists of NASA, Canadian Space Agency, Univ. of Maryland, Univ. of Colorado, Univ. of Oklahoma, Ukraine Space Research Institute and Joint Research Center(JRC) for European Commission. This development team collaborates with regional , national and international agencies to deliver end-to-end disaster coverage. In particular, the team in collaborating on this effort with the Namibia Department of Hydrology to begin in Namibia . However, the ultimate goal is to expand the functionality to provide early warning over the South Africa region. The initial collaboration was initiated by United Nations Office of Outer Space Affairs and CEOS Working Group for Information Systems and Services (WGISS). The initial driver was to demonstrate international interoperability using various space agency sensors and models along with regional in-situ ground sensors. In 2010, the team created a preliminary semi-manual system to demonstrate moving and combining key data streams and delivering the data to the Namibia Department of Hydrology during their flood season which typically is January through April. In this pilot, a variety of moderate resolution and high resolution satellite flood imagery was rapidly delivered and used in conjunction with flood predictive models in Namibia. This was collected in conjunction with ground measurements and was used to examine how to create a customized flood early warning system. During the first year, the team made use of SensorWeb technology to gather various sensor data which was used to monitor flood waves traveling down basins originating in Angola, but eventually flooding villages in Namibia. The team made use of standardized interfaces such as those articulated under the Open Cloud Consortium (OGC) Sensor Web Enablement (SWE) set of web services was good [1][2]. However, it was discovered that in order to make a system like this functional, there were many performance issues. Data sets were large and located in a variety of location behind firewalls and had to be accessed across open networks, so security was an issue. Furthermore, the network access acted as bottleneck to transfer map products to where they are needed. Finally, during disasters, many users and computer processes act in parallel and thus it was very easy to overload the single string of computers stitched together in a virtual system that was initially developed. To address some of these performance issues, the team partnered with the Open Cloud Consortium (OCC) who supplied a Computation Cloud located at the University of Illinois at Chicago and some manpower to administer this Cloud. The Flood SensorWeb [3] system was interfaced to the Cloud to provide a high performance user interface and product development engine. Figure 1 shows the functional diagram of the Flood SensorWeb. Figure 2 shows some of the functionality of the Computation Cloud that was integrated. A significant portion of the original system was ported to the Cloud and during the past year, technical issues were resolved which included web access to the Cloud, security over the open Internet, beginning experiments on how to handle surge capacity by using the virtual machines in the cloud in parallel, using tiling techniques to render large data sets as layers on map, interfaces to allow user to customize the data processing/product chain and other performance enhancing techniques. The conclusion reached from the effort and this presentation is that defining the interoperability standards in a small fraction of the work. For example, once open web service standards were defined, many users could not make use of the standards due to security restrictions. Furthermore, once an interoperable sysm is functional, then a surge of users can render a system unusable, especially in the disaster domain.

Mandl, Daniel↗

DGaaS: GPU as a Service on Distributed Computing System

In the rapidly evolving landscape of scientific computing, Graphics Processing Units (GPUs) have become indispensable for their unparalleled ability to handle parallel tasks in complex calculations, simulations, and data analysis. Their utility is further magnified in machine learning and AI applications, where they significantly accelerate model training and predictive analytics. Within this context, the Triton Inference Server emerges as a pivotal open-source tool, specializing in AI inferencing and optimizing GPU utilization across various platforms and frameworks. This paper presents an in-depth study on distributed High Throughput Computing (HTC), specifically focusing on the HTCondor framework and its resource provisioning tools, GlideinWMS and HEPCloud. These systems enable large-scale scientific experiments like CMS and DUNE to efficiently access and utilize vast computational resources. The paper explores the core architectural components of GlideinWMS, including jobs, user pools, and worker nodes, and discusses their integration with GPUs and the Triton server. The primary aim of this research is to develop a solution that optimizes GPU utilization by leveraging Glideins and containers. This approach allows computational jobs, particularly those involving AI models, to use GPUs only when essential, thereby facilitating efficient sharing of limited GPU resources. To validate this architecture, the study conducted three key tests involving custom scripts, container-based servers, and Triton server deployments. However, the study faces challenges, notably in locating the Triton server and ensuring secure remote access. To address these issues, future work will focus on developing a proxy mechanism and enhancing security protocols. In conclusion, this study offers a comprehensive roadmap for effective and efficient GPU utilization in distributed High Throughput Computing. It aims to contribute significantly to the scientific community by solving pressing problems and implementing robust solutions in collaboration with the GlideinWMS and HEPCloud teams. The research sets the stage for a more efficient, scalable, and cost-effective paradigm in scientific computing.

97 MATHEMATICS AND COMPUTING↗