Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Computer security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 505 records · Page 28

Scenario Exploration and Timeline Analysis for Advanced Reactors [Slides]

Slides created to discuss the report "Approach and Model Used to Represent a Timeline Analysis for Security Design Enhancements" (August 2022 INL/ RPT-22-68664) for an upcoming DOE security workshop. Advanced reactors will be able to use risk insights for many design aspects. We need realistic scenarios for input into the licensing basis safety-case. These scenarios must include timing and physics. We need to automate the safety-case creation as much as possible.

97 MATHEMATICS AND COMPUTING↗

A 5G Enabled Adaptive Computing Workflow for Greener Power Grid

5G wireless technology can deliver higher data speeds, ultra low latency, more reliability, massive network capacity, increased availability, and a more uniform user experience to users. It brings additional power to help address the challenges brought by renewable integration and decarbonization. In this paper, a 5G enabled adaptive computing workflow tool has been presented that consists of various computing resources, such as 5G equipment, edge computing, cluster, Graphics processing unit (GPU) and cloud computing, with two examples showing technical feasibility for edge-grid-cloud interaction for real-time monitoring, security assessment, and forecasting. Benefiting from the high data transmission speed and massive connection capability of 5G, the workflow shows its potential to seamlessly integrate various applications at distributed and/or centralized locations to build more complex and powerful functions, with better flexibility.

5G technology, computational workflow, edge comput↗

Massively scalable workflows for quantum chemistry: BigChem and ChemCloud

Electronic structure theory, i.e., quantum chemistry, is the fundamental building block for many problems in computational chemistry. Here we present a new distributed computing framework (BigChem), which allows for an efficient solution of many quantum chemistry problems in parallel. BigChem is designed to be easily composable and leverages industry-standard middleware (e.g., Celery, RabbitMQ, and Redis) for distributed approaches to large scale problems. BigChem can harness any collection of worker nodes, including ones on cloud providers (such as AWS or Azure), local clusters, or supercomputer centers (and any mixture of these). BigChem builds upon MolSSI packages, such as QCEngine to standardize the operation of numerous computational chemistry programs, demonstrated here with Psi4, xtb, geomeTRIC, and TeraChem. BigChem delivers full utilization of compute resources at scale, offers a programable canvas for designing sophisticated quantum chemistry workflows, and is fault tolerant to node failures and network disruptions. We demonstrate linear scalability of BigChem running computational chemistry workloads on up to 125 GPUs. Finally, we present ChemCloud, a web API to BigChem and successor to TeraChem Cloud. ChemCloud delivers scalable and secure access to BigChem over the Internet.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Transportation Secure Data Center: Frequently Asked Questions for Data Owners/Contributors

The Transportation Secure Data Center is a centralized repository for detailed transportation data from travel and transit surveys and studies conducted across the nation. It makes vital transportation data broadly available to users while preserving the privacy of survey participants. Hundreds of datasets from surveys and studies of household travel and transit passenger travel are archived in the TSDC, including surveys and studies conducted by state departments of transportation, metropolitan planning organizations, transit agencies, cities, and other public agencies. Detailed data from travel surveys and studies are extremely valuable for research purposes. However, the fine-grained information they contain could potentially be misused to identify individual travelers, so access to these data should only be granted with safeguards in place to protect participant privacy. The TSDC was created to address this challenge and to relieve public agencies from the burden of archiving their data and responding to data requests.

33 ADVANCED PROPULSION SYSTEMS↗

Agent-Based Coordination Scheme for PV Integration (ABC4PV)

Renewables and especially photovoltaics (PV) have benefitted significantly from a host of incentives and policies targeted toward enhanced integration and adoption of specific energy technologies. However, with the push to move forward into a subsidy-free market framework, behind-the-meter residential PV applications have generally struggled to retain their value (unlike utility scale and commercial projects) [1]. This project focused on developing control-theoretic solutions aimed at improving the integration and interaction of behind-the-meter residential PV with other distribution system assets (controllable and non-controllable) to enhance the integrated value of residential PV. To this end, a suite of decentralized control methodologies have been developed to enable effective coordination and control of behind-the-meter residential load customers’ PV, battery storage systems (BSS), controllable loads and other similar assets within a distribution feeder. This interaction aims at procuring energy savings and, thus, energy bill savings. The main source of savings is drawn from reducing the effect of demand charge pricing and is realized at the feeder level, assuming community level interaction and management among the aforementioned assets. Optimal control of the assets is implemented with a distributed optimization methodology, leveraging consensus-based algorithms. The results gathered from the optimal control simulations demonstrates that the savings can be duly achieved and the algorithm decision times (to dynamically control asset set points, for example) are fast. As for the overall efficiency of PV+BSS systems, to procure energy savings from curtailment of the demand charge pricing effects, the optimal control is set up so as to minimize the variance of the load for all customers, throughout a feeder and throughout time in a rolling horizon scheduling with model predictive control. The control takes into account inter-temporal electrochemical storage (battery) degradation costs: specifically, we have developed a long-term lifetime model for the BSS that weighs in the effect of the degradation factor in the dispatch formulations, thus, a considerable operating cost that affects energy decision making. The levelized cost of energy (LCOE – redefined for the purpose of quantifying asset integration effectiveness through the customers’ energy cost) is shown to be below the threshold set for the combined PV+BSS topology of $ 0.14/kWh for multiple cases of PV penetration all the way up to 50%, provided that a policy of shared ownership of and savings is in place. Further, the LCOE calculated for the case before the deployment PV+BSS systems is also achievable, i.e. the deployment of PV+BSS, if planned and scheduled optimally. will have no effect on customers’ energy costs. From the control methodology viewpoint, the developed consensus-based algorithms are shown to converge for a wide range of problem cases (spanning normal operating scenarios and contingencies), guaranteeing dispatch solutions under forecasting errors, communication break-downs and cyber-security attacks. The proposed control solutions are scalable and real-time implementable, with dispatch computations and device set-point updates converging in less than 2s in most practical instances of the above events.

14 SOLAR ENERGY↗

Protecting Websites from Cross-Site Scripting (XSS) Attacks: A Novel Configuration using Pulse Secure © Pulse Connect Secure © and Virtual Web Application Firewall (vWAF)

Cross-site scripting (XSS), one of the most prevalent forms of client-side attacks, is when bad actors attempt to access sensitive information from the backend web server and other systems on the backend network. Some XSS attacks attempt to access client-side sensitive information, such as cookies. Web application firewalls (WAFs) are a first line of defense where common Uniform Resource Locator (URL) patterns are analyzed to detect and block known attacks. This paper describes a novel configuration using the Pulse Secure © Pulse Connect Secure © (PCS © ) Secure Socket Layer Virtual Private Network software and Virtual Web Application Firewall (vWAF) that protects a website from XSS attacks. This paper also presents novel aspects of the configuration that control the redirection of traffic through the vWAF and provide fine-grained behavioral control at the application level while decoupling the PCS and vWAF configurations. The intended audience for this paper comprises system and site administrators who are familiar with standard web server environments. These configuration details might prove useful during the design of a more secure infrastructure.

97 MATHEMATICS AND COMPUTING↗

Y-12 Groundwater Protection Program Data Management Plan

This Data Management Plan (DMP) describes the processes in place to ensure the integrity of groundwater monitoring information collected by the U.S. Department of Energy (DOE), National Nuclear Security Administration (NNSA), Y-12 National Security Complex (Y-12), Groundwater Protection Program (GWPP). This information includes program plans, reports, and computer systems used to capture monitoring station information and analytical data. The primary computer system used by the GWPP is the Groundwater Information Management System (GIMS). Procedures used to ensure the integrity of the data are included in this document by reference.

54 ENVIRONMENTAL SCIENCES↗

Evaluating Named Data Networking for Industrial Control System [Slides]

Current proposed work is: See if the inherent security that comes with Named Networking (NDN) can be applied to Industrial Control Systems; and, Every packet is required to be cryptographically signed which makes every single piece of data communicated in the system secure and authenticated.

42 ENGINEERING↗

Accessing Wind Tunnels From NASA's Information Power Grid

The NASA Ames wind tunnel customers are one of the first users of the Information Power Grid (IPG) storage system at the NASA Advanced Supercomputing Division. We wanted to be able to store their data on the IPG so that it could be accessed remotely in a secure but timely fashion. In addition, incorporation into the IPG allows future use of grid computational resources, e.g., for post-processing of data, or to do side-by-side CFD validation. In this paper, we describe the integration of grid data access mechanisms with the existing DARWIN web-based system that is used to access wind tunnel test data. We also show that the combined system has reasonable performance: wind tunnel data may be retrieved at 50Mbits/s over a 100 base T network connected to the IPG storage server.

Becker, Jeff↗

Support for Systematic Code Reviews with the SCRUB Tool

SCRUB is a code review tool that supports both large, team-based software development efforts (e.g., for mission software) as well as individual tasks. The tool was developed at JPL to support a new, streamlined code review process that combines human-generated review reports with program-generated review reports from a customizable range of state-of-the-art source code analyzers. The leading commercial tools include Codesonar, Coverity, and Klocwork, each of which can achieve a reasonably low rate of false-positives in the warnings that they generate. The time required to analyze code with these tools can vary greatly. In each case, however, the tools produce results that would be difficult to realize with human code inspections alone. There is little overlap in the results produced by the different analyzers, and each analyzer used generally increases the effectiveness of the overall effort. The SCRUB tool allows all reports to be accessed through a single, uniform interface (see figure) that facilitates brows ing code and reports. Improvements over existing software include significant simplification, and leveraging of a range of commercial, static source code analyzers in a single, uniform framework. The tool runs as a small stand-alone application, avoiding the security problems related to tools based on Web browsers. A developer or reviewer, for instance, must have already obtained access rights to a code base before that code can be browsed and reviewed with the SCRUB tool. The tool cannot open any files or folders to which the user does not already have access. This means that the tool does not need to enforce or administer any additional security policies. The analysis results presented through the SCRUB tool s user interface are always computed off-line, given that, especially for larger projects, this computation can take longer than appropriate for interactive tool use. The recommended code review process that is supported by the SCRUB tool consists of three phases: Code Review, Developer Response, and Closeout Resolution. In the Code Review phase, all tool-based analysis reports are generated, and specific comments from expert code reviewers are entered into the SCRUB tool. In the second phase, Developer Response, the developer is asked to respond to each comment and tool-report that was produced, either agreeing or disagreeing to provide a fix that addresses the issue that was raised. In the third phase, Closeout Resolution, all disagreements are discussed in a meeting of all parties involved, and a resolution is made for all disagreements. The first two phases generally take one week each, and the third phase is concluded in a single closeout meeting.

Holzmann, Gerald J.↗

Common Practice Lightning Strike Protection Characterization Technique to Quantify Damage Mechanisms on Composite Substrates

To support FAA certification airworthiness standards, composite substrates are subjected to lightning direct-effect electrical waveforms to determine performance characteristics of the lightning strike protection (LSP) conductive layers used to protect composite substrates. Test results collected from independent LSP studies are often incomparable due to variability in test procedures & applied practices at different organizations, which impairs performance correlations between different LSP data sets. Under a NASA supported contract, The Boeing Company developed technical procedures and documentation as guidance in order to facilitate a test method for conducting universal common practice lightning strike protection test procedures. The procedures obtain conformity in future lightning strike protection evaluations to allow meaningful performance correlations across data sets. This universal common practice guidance provides the manufacturing specifications to fabricate carbon fiber reinforced plastic (CFRP) test panels, including finish, grounding configuration, and acceptable methods for pretest nondestructive inspection (NDI) and posttest destructive inspection. The test operations guidance elaborates on the provisions contained in SAE ARP5416 to address inconsistencies in the generation of damage protection performance data, so as to provide for maximum achievable correlation across capable lab facilities. In addition, the guidance details a direct effects test bed design to aid in quantification of the multi-physical phenomena surrounding a lightning direct attachment supporting validation data requirements for the development of predictive computational modeling. The lightning test bed is designed to accommodate a repeatable installation procedure to secure the test panel and eliminate test installation uncertainty. It also facilitates a means to capture the electrical waveform parameters in 2 dimensions, along with the mechanical displacement and thermal heating parameters which occur during lightning attachment. Following guidance defined in the universal common practice LSP test documents, protected and unprotected CFRP panels were evaluated at 20, 40 and 100KAmps. This report presents analyzed data demonstrating the scientific usefulness of the common practice approach. Descriptions of the common practice CFRP test articles, LSP test bed fixture, and monitoring techniques to capture the electrical, mechanical and thermal parameters during lightning attachment are presented here. Two methods of measuring the electrical currents were evaluated, inductive current probes and a newly developed fiberoptic sensor. Two mechanical displacement methods were also examined, optical laser measurement sensors and a digital imaging correlation camera system. Recommendations are provided to help users implement the common practice test approach and obtain LSP test characterizations comparable across data sets.

Szatkowski, George N.↗

IRI Technology Landscape – A survey of re-usable components and methodologies

This document describes technical implementation details on network access schemes connecting API-driven workflows to supercomputer centers. API-driven workflows are a central theme in connected computing, since they bring the terminal-mainframe' access pattern present since the 1970s up to the task of interfacing with modern web browser technologies. Both security (HTTPS/TLS/IPSec/VPNs/public key cryptography/digital signatures) and network protocol stacks (HTTP-REST APIs, tokens, gRPC, SRTP) have evolved to the point where implementing API-driven workflows is possible using stable, secure off-the-shelf software.

97 MATHEMATICS AND COMPUTING↗

Approach and Model Used to Represent a Timeline Analysis for Security Design Enhancements

Next-generation reactors will be able to use risk to inform and performance base the licensing of many aspects of the reactor, facility, and site design, including attributes of physical security. There are several factors related to security, including site topography, reactor design, and physical protection system components, to consider when designing the physical protection system into the overall facility design and plan of operation. With the versatility of advanced reactors, especially micro reactors, methods are needed to simplify and quickly evaluate potential timelines for designing a site configuration. This report describes an approach to generate qualitative and quantitative insights using a risk-informed simulation. The modeling process is described in detail, focusing on three aspects: (1) the facility mission time (the time required to control the plant until safe), (2) the attacker timeline (the time to potential sabotage), and (3) the response timeline (the time to counter the facility attack). The modeling capabilities also are extended to include facility physical phenomena such as thermal-hydraulics and heat transfer to capture realistic representation of dynamic changes to a facility. While the plant models and examples are hypothetical and do not represent a real facility, these modeling approaches could be used for future security-by-design engineering in advanced reactors. The outputs and insights from the modeling approach may be used to modify and optimize the security posture of a facility by efficiently making modifications to the model and seeing the overall impact from the modification. Lastly, use of the approach described in this report can also provide the technical basis for a physical protection program, describing how the facility and security strategy will cope with off-normal events.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

National-Tribal Critical Infrastructure Protection: Collaboration for Extraordinary National Security Benefit

This paper examines national and tribal collaborative opportunities to get ahead of the critical infrastructure insecurity problem. Recommendations are viewed through the lens of the Sandia Labs Tribal Cyber-Energy initiative and national security projects. Recommendations include 1) Collaboratively address national priority and shared challenges to gain faster and better solutions to national priority problems on a smaller yet comprehensive American Indian and Alaskan Native sovereign single-point of authority scale 2) Utilize newer standards-based technologies to provide scalable, capable, and manageable solutions for greatly expanded and connected national critical infrastructures 3) Employ Cyber-Physical-Resilient design preliminary analysis to define concept- to-disposition design requirements for preemptive critical infrastructure risk mitigation and baked-in security; 4) Develop data-centric protection to provide increased information asset protection as data shifts from data-owner operated on-premises infrastructure to virtual service provider data-steward owned and operated off-premises infrastructure; and 5) Balance shared solutions with the National Institute of Science and Technology (NIST) Cybersecurity and Risk Management frameworks, and the System Security Engineering Guidelines. As yet unallocated federal funding would support research, development, the timely application of National-Tribal critical infrastructure protection, and critical infrastructure Cyber disruption response and recovery with extraordinary mutual benefits for the foreseeable future. The Critical Infrastructure Insecurity Problem: Rapid modernization and expansive connectivity are due to advances in Information and Communications Technologies that have sweeping cyber impact across all critical infrastructure sectors. Supervisory Control and Data Acquisition and Industrial Control Systems are particularly impacted as systems long separated from the Internet are now being connected and computerized. Virtualization and mobility create a Data Everywhere-User Anywhere paradigm that has evaporated the enterprise network perimeter. There are multi-front technological challenges at play, where long depended on technologies simply don't scale to current needs resulting in a digital dichotomy of competing old and new standards. New standards-based technologies scale but are not as well-known or as widely deployed, which leaves decision makers, stakeholders, and the workforce in a quandary, caught mid-stream between the technological past and the virtual future. Rapid and expansive cyber threat accompanies disruptive change in connectivity and computational dependencies. A lack of action will exacerbate the problem if new technologies roll out without baked-in security design. The Risk: If National-Tribal CIP collaboration to design in security is not done, then an ongoing state of insufficient bolt-on security and elevated threat exposure will remain for years to come.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Selective Recovery of Critical Minerals from Simulated Electronic Wastes Via Reaction‐Diffusion Coupling

Abstract Atom‐ and energy‐efficient chemical separations are urgently needed to meet the surging demand for critical materials that has strained supply chains and threatened environmental damage. In this study, we used reaction‐diffusion coupling to separate iron, neodymium, and dysprosium ions from model feedstocks of permanent magnets, which are typically found in electronic wastes. Feedstock solutions were placed in contact with a hydrogel loaded with potassium hydroxide and/or dibutyl phosphate, resulting in complex precipitation patterns as the various metal ions diffused into the reaction medium. Specifically, we observed the precipitation of up to 40 mM of iron from the feedstock, followed by the enrichment of 73 % dysprosium, and the extraction of >95 % neodymium product at a further distance from the solution‐gel interface. We designed a series of experiments and simulations to determine the relevant ion diffusivities, D Nd =5.4×10 −10 and D Dy =5.1×10 −10 m 2 /s, and precipitation rates, k Nd =1.0×10 −5 and k Dy =5.0×10 −3 m 9 mol −3 s −1 , which enabled a numerical model to be established for predicting the distribution of products in the reaction medium. Our proof‐of‐concept study validates reaction‐diffusion coupling as an effective and versatile approach for critical materials separations, without relying on ligands, membranes, resins, or other specialty chemicals.

Wang, Qingpu [Physical and Computational Sciences ↗

Vulnerabilities in Artificial Intelligence and Machine Learning Applications and Data

Artificial intelligence (AI) applications driven by machine learning (ML) are transformational technologies within the international nuclear security regime. Advancements realized by AI—faster and improved data insights, more efficient and automated processes, reductions in human error—enable nuclear security applications such as behavior analysis for insider threat mitigation, source tracking of stolen nuclear material, and facial recognition software for physical protection. In addition to the advantages, however, there are also inherent vulnerabilities and threats associated with its use and risk mitigations must be built into any AI/ML-enabled systems. This work provides a background on AI and ML and different data types used in the field, including open-source intelligence information (OSINT) that is discoverable by AI tools and application data that are used by AI tools for decision-making and automation. Current and potential AI applications and vulnerabilities related to their use within the nuclear security regime are also discussed.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Flight design system level C requirements. Solid rocket booster and external tank impact prediction processors

The prediction of the SRB and ET impact areas requires six separate processors. The SRB impact prediction processor computes the impact areas and related trajectory data for each SRB element. Output from this processor is stored on a secure file accessible by the SRB impact plot processor which generates the required plots. Similarly the ET RTLS impact prediction processor and the ET RTLS impact plot processor generates the ET impact footprints for return-to-launch-site (RTLS) profiles. The ET nominal/AOA/ATO impact prediction processor and the ET nominal/AOA/ATO impact plot processor generate the ET impact footprints for non-RTLS profiles. The SRB and ET impact processors compute the size and shape of the impact footprints by tabular lookup in a stored footprint dispersion data base. The location of each footprint is determined by simulating a reference trajectory and computing the reference impact point location. To insure consistency among all flight design system (FDS) users, much input required by these processors will be obtained from the FDS master data base.

Seale, R. H.↗