Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Threat”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

A Privacy-Preserving Cyber Threat Intelligence Sharing System

Cyber Threat Intelligence (CTI) is a key resource for developing defensive strategies against potential cyber adversaries. Entities typically access CTI through open-source platforms, national agencies, or specialized commercial services. However, the bi-directional exchange of CTI is hindered by organizational trust boundaries, which complicate the sharing processes between entities and CTI providers. Centralized CTI services benefit from receiving suspicious cyber observables such as IP addresses, domain names, and email addresses from various entities. The aggregation allows for the correlation of widespread adversarial activities to enhance the alert and response mechanisms across the network of involved parties. Despite these benefits, openly sharing such observables incurs potential legal, regulatory, and reputational risks for the disclosing entities.This paper introduces a system designed to facilitate the secure exchange of cyber observables across trust boundaries without compromising the anonymity of the sharing entities. Here, we propose an architecture that leverages common web protocols alongside zero-knowledge proofs to authenticate members while maintaining anonymity. Additionally, we outline a privacy model tailored for STIX (Structured Threat Information eXpression) cyber observables to minimize the risk of inadvertently disclosing private information. Through our threat models, we assess the privacy implications of our proposed system and demonstrate its potential to enhance collaborative cyber defense efforts without exposing entities to undue risk.

BBS+ Signatures↗

Near Earth Asteroid Characterization for Threat Assessment

Physical characteristics of NEAs are an essential input to modeling behavior during atmospheric entry and to assess the risk of impact but determining these properties requires a non-trivial investment of time and resources. The characteristics relevant to these models include size, density, strength and ablation coefficient. Some of these characteristics cannot be directly measured, but rather must be inferred from related measurements of asteroids and/or meteorites. Furthermore, for the majority of NEAs, only the basic measurements exist so often properties must be inferred from statistics of the population of more completely characterized objects. The Asteroid Threat Assessment Project at NASA Ames Research Center has developed a probabilistic asteroid impact risk (PAIR) model in order to assess the risk of asteroid impact. Our PAIR model and its use to develop probability distributions of impact risk are discussed in other contributions to PDC 2017 (e.g., Mathias et al.). Here we utilize PAIR to investigate which NEA characteristics are important for assessing the impact threat by investigating how changes in these characteristics alter the damage predicted by PAIR. We will also provide an assessment of the current state of knowledge of the NEA characteristics of importance for asteroid threat assessment. The relative importance of different properties as identified using PAIR will be combined with our assessment of the current state of knowledge to identify potential high impact investigations. In addition, we will discuss an ongoing effort to collate the existing measurements of NEA properties of interest to the planetary defense community into a readily accessible database.

Asteroid characterization↗

A Survey of Cyber Threats and Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Cyber Threats↗

Cyber Threats & Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Cyber Threats↗

Threat Landscape for BESS and IBR

The cyber risk landscape for BESS and IBR can be broken up by threats, vulnerabilities, and consequences for these systems. This presentation walks through the cyber risk landscape for BESS through the lens of consequence-informed awareness and mitigation for each risk factor. Threats with varying capabilities have been demonstrated in real-world events. Though threat actors can rarely be directly influenced by organizations, exposure of systems to adversaries can be limited (a known issue with IBR systems) to reduce likelihood of adversaries accessing systems with disruptive consequences. Common trends in disclosed IBR vulnerabilities include weak password generation or managements for various devices or services and web portal vulnerabilities that provide unauthorized access to data or capabilities or elevated user privileges. Understanding these common vulnerabilities and considering the consequences if these types of vulnerabilities were to occur can help mitigate risk. Consequences range from loss-of-view events that have no reliability impact to asset damage or grid stability impacts. Five case studies are briefly shared to highlight trends in real-world events affecting IBR.

14 - SOLAR ENERGY↗

Cybersecurity Enhancement in Digital Substations: Hidden Markov Model-Based Smart Cyber Switching and Threat Response

The rising incidence of cyber-attacks on critical infrastructure and power grids poses significant threats to the stability and reliability of electrical substations, with potentially devastating consequences such as extended blackouts. This paper introduces an advanced cybersecurity framework aimed at safeguarding IEC 61850-based substations through the integration of software-defined networking (SDN) and digital twin (DT) technologies. The proposed DT-based framework employs smart cyber switching (SCS) for proactive threat mitigation and concurrent intelligent electronic device (CIED) for swift system restoration, thereby maintaining continuous operational integrity and robust cybersecurity defenses. Central to this framework is the adaptive port controller (APC), which enables dynamic port management to adapt to evolving threats, and an intrusion detection system (IDS) designed to detect and neutralize malicious attacks on IEC 61850-based sampled value (SV) and generic object-oriented substation event (GOOSE) messages within the substation’s communication network. Further, novel predictive intrusion detection and response (PIDR) algorithm is implemented on a digital substation (DS) to predict the best route to be taken by the attacker. The efficacy of these comprehensive cybersecurity frameworks is validated through rigorous simulations and a hardware-in-the-loop (HIL) testbed, showcasing the system’s ability to sustain substation operations amidst cyber-attacks.

Digital substation↗

Responsible Artificial Intelligence for Insider Threat Mitigation

This report examines the application of artificial intelligence (AI) technologies for insider threat mitigation (ITM) programs in nuclear security facilities. Insider threat detection presents unique challenges due to the subtle and adaptive nature of these threats, the complex signatures involved, and the scarcity of available data for analysis. Traditional human-centered approaches, while essential, face limitations in processing large amounts of data continuously and detecting subtle patterns across multiple systems. AI technologies can potentially address these limitations by providing 24/7 monitoring capabilities, identifying complex patterns that might escape human observation, and offering consistent application of security criteria. However, the deployment of AI in nuclear security contexts introduces significant new risks, including workflow disruption, expanded attack surfaces, potential for misuse, and ethical concerns regarding privacy, fairness, transparency, safety, and security. The high-consequence nature of nuclear security decisions demands careful consideration of these risks and systematic approaches to their mitigation.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Mapping Historic Gypsy Moth Defoliation with MODIS Satellite Data: Implications for Forest Threat Early Warning System

This viewgraph presentation reviews a project, the goal of which is to study the potential of MODIS data for monitoring historic gypsy moth defoliation. A NASA/USDA Forest Service (USFS) partnership was formed to perform the study. NASA is helping USFS to implement satellite data products into its emerging Forest Threat Early Warning System. The latter system is being developed by the USFS Eastern and Western Forest Threat Assessment Centers. The USFS Forest Threat Centers want to use MODIS time series data for regional monitoring of forest damage (e.g., defoliation) preferably in near real time. The study's methodology is described, and the results of the study are shown.

Spurce, Joseph P.↗

Use of Vertically Integrated Ice in WRF-Based Forecasts of Lightning Threat

Previously reported methods of forecasting lightning threat using fields of graupel flux from WRF simulations are extended to include the simulated field of vertically integrated ice within storms. Although the ice integral shows less temporal variability than graupel flux, it provides more areal coverage, and can thus be used to create a lightning forecast that better matches the areal coverage of the lightning threat found in observations of flash extent density. A blended lightning forecast threat can be constructed that retains much of the desirable temporal sensitivity of the graupel flux method, while also incorporating the coverage benefits of the ice integral method. The graupel flux and ice integral fields contributing to the blended forecast are calibrated against observed lightning flash origin density data, based on Lightning Mapping Array observations from a series of case studies chosen to cover a wide range of flash rate conditions. Linear curve fits that pass through the origin are found to be statistically robust for the calibration procedures.

McCaul, E. W., jr.↗

Use of Current 2010 Forest Disturbance Monitoring Products for the Conterminous United States in Aiding a National Forest Threat Early Warning System

This presentation discusses contributions of near real time (NRT) MODIS forest disturbance detection products for the conterminous United States to an emerging national forest threat early warning system (EWS). The latter is being developed by the USDA Forest Service s Eastern and Western Environmental Threat Centers with help from NASA Stennis Space Center and the Oak Ridge National Laboratory. Building off work done in 2009, this national and regional forest disturbance detection and viewing capability of the EWS employs NRT MODIS NDVI data from the USGS eMODIS group and historical NDVI data from standard MOD13 products. Disturbance detection products are being computed for 24 day composites that are refreshed every 8 days. Products for 2010 include 42 dates of the 24 day composites. For each compositing date, we computed % change in forest maximum NDVI products for 2010 with respect to each of three historical baselines of 2009, 2007-2009, and 2003-2009,. The three baselines enable one to view potential current, recent, and longer term forest disturbances. A rainbow color table was applied to each forest change product so that potential disturbances (NDVI drops) were identified in hot color tones and growth (NDVI gains) in cold color tones. Example products were provided to end-users responsible for forest health monitoring at the Federal and State levels. Large patches of potential forest disturbances were validated based on comparisons with available reference data, including Landsat and field survey data. Products were posted on two internet mapping systems for US Forest Service internal and collaborator use. MODIS forest disturbance detection products were computed and posted for use in as little as 1 day after the last input date of the compositing period. Such products were useful for aiding aerial disturbance detection surveys and for assessing disturbance persistence on both inter- and intra-annual scales. Multiple 2010 forest disturbance events were detected across the nation, including damage from ice storms, tornadoes, caterpillars, bark beetles, and wildfires. This effort enabled improved NRT forest disturbance monitoring capabilities for this nation-wide forest threat EWS.

Spruce, Joseph P.↗

Monitoring Regional Forest Disturbances across the US with near Real Time MODIS NDVI Products Resident to the ForWarn Forest Threat Early Warning System

Forest threats across the US have become increasingly evident in recent years. Sometimes these have resulted in regionally evident disturbance progressions (e.g., from drought, bark beetle outbreaks, and wildfires) that can occur across multiyear durations and have resulted in extensive forest overstory mortality. In addition to stand replacement disturbances, other forests are subject to ephemeral, sometimes yearly defoliation from various insects and varying types and intensities of ephemeral damage from storms. Sometimes, after prolonged severe disturbance, signs of recovery in terms of Normalized Difference Vegetation Index (NDVI) can occur. The growing prominence and threat of forest disturbances in part have led to the formation and implementation of the 2003 Healthy Forest Restoration Act which mandated that national forest threat early warning system be developed and deployed. In response, the US Forest Service collaborated with NASA, DOE Oakridge National Laboratory, and the USGS Eros Data Center to build and roll-out the near real time ForWarn early warning system for monitoring regionally evident forest disturbances. Given the diversity of disturbance types, severities, and durations, ForWarn employs multiple historical baselines that are used with current NDVI to derive a suite of six forest change products that are refreshed every 8 days. ForWarn employs daily quarter kilometer MODIS NDVI data from the Aqua and Terra satellites, including MOD13 data for deriving historical baseline NDVIs and eMODIS 7 NDVI for compiling current NDVI. In doing so, the Time Series Product Tool and the Phenological Parameters Estimation Tool are used to temporally de-noise, fuse, and aggregate current and historical MODIS NDVIs into 24 day composites refreshed every 8 days with 46 dates of products per year. The 24 day compositing interval enables disturbances to be detected, while minimizing the frequency of residual atmospheric contamination. Forest change products are computed versus the previous 1, previous 3, and all previous years in the MODIS record for a given 24 day interval. Other "weekly" forest change products include one computed using an adaptive length compositing method for quicker detection of disturbances, two others that adjust for seasonal fluctuations in normal vegetation phenology (e.g., early versus late springs). This overall approach enables forest disturbance dynamics from a variety of regionally evident biotic and abiotic forest disturbances to be viewed and assessed through the calendar year. The change products are also being utilized for forest change trend analysis and for developing regional forest overstory mortality products. ForWarn's forest change products are used to alert forest health specialists about new forest disturbances. Such alerts are also typically based on available Landsat, aerial, and ground data as well as communications with forest health specialists and previous experience. ForWarn products have been used to detect and track many types of regional disturbances to multiple forest types, including defoliation from caterpillars and severe storms, as well as mortality from both biotic and abiotic agents (e.g., bark beetles, drought, fire, anthropogenic clearing). ForWarn offers products that could be combined with other geospatial data on forest biomass to assess forest disturbance carbon impacts within the conterminous US.

Spruce, Joseph P.↗

Cyber Threats and Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Urban Air Mobility↗

Risk Assessment for Asteroid Impact Threat Scenarios

Asteroid impacts can cause a wide range of damage through multiple potential hazards, from localized blast waves or thermal radiation, to tsunami inundation, to global climatic effects. The level of risk posed by these hazards depends not only upon their extent and severity, but also upon the likelihood of the various damage ranges. Some consequences may be more moderate but very likely, while others may be unlikely but catastrophic. Evaluating the risk from these hazards involves substantial uncertainties across all aspects of the problem, including the properties of the asteroid itself, the specifics of its entry, and the complex high-energy damage physics involved. NASA’s Asteroid Threat Assessment Project performs Probabilistic Asteroid Impact Risk (PAIR) assessments that use fast-running entry and hazard models to evaluate millions of impact cases representing the distributions of these many uncertain parameters. This paper presents current probabilistic asteroid impact risk assessment modeling tools and approaches used for evaluating specific asteroid impact threat cases. We give an overview of the current PAIR model used to support impact threat scenarios and discuss some of the key applications of these assessment in supporting response decisions and planetary defense preparedness. We then present the results and key findings from the recent 2023 PDC hypothetical impact exercise as an example of the primary types of risk results and metrics being developed to inform and support those mitigation and response decisions.

SMD↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗

An Innovative Solution to NASA's NEO Impact Threat Mitigation Grand Challenge and Flight Validation Mission Architecture Development

This paper presents the results of a NASA Innovative Advanced Concept (NIAC) Phase 2 study entitled "An Innovative Solution to NASA's Near-Earth Object (NEO) Impact Threat Mitigation Grand Challenge and Flight Validation Mission Architecture Development." This NIAC Phase 2 study was conducted at the Asteroid Deflection Research Center (ADRC) of Iowa State University in 2012-2014. The study objective was to develop an innovative yet practically implementable mitigation strategy for the most probable impact threat of an asteroid or comet with short warning time (< 5 years). The mitigation strategy described in this paper is intended to optimally reduce the severity and catastrophic damage of the NEO impact event, especially when we don't have sufficient warning times for non-disruptive deflection of a hazardous NEO. This paper provides an executive summary of the NIAC Phase 2 study results. Detailed technical descriptions of the study results are provided in a separate final technical report, which can be downloaded from the ADRC website (www.adrc.iastate.edu).

NEO Impact Threat Mitigation↗

An Optimal Mitigation Strategy Against the Asteroid Impact Threat with Short Warning Time

This paper presents the results of a NASA Innovative Advanced Concept (NIAC) Phase 2 study entitled "An Innovative Solution to NASA's Near-Earth Object (NEO) Impact Threat Mitigation Grand Challenge and Flight Validation Mission Architecture Development." This NIAC Phase 2 study was conducted at the Asteroid Deflection Research Center (ADRC) of Iowa State University in 2012-2014. The study objective was to develop an innovative yet practically implementable mitigation strategy for the most probable impact threat of an asteroid or comet with short warning time (less than 5 years). The mitigation strategy described in this paper is intended to optimally reduce the severity and catastrophic damage of the NEO impact event, especially when we don't have sufficient warning times for non-disruptive deflection of a hazardous NEO. This paper provides an executive summary of the NIAC Phase 2 study results.

NEO Impact threat↗

An Innovative Solution to NASA's NEO Impact Threat Mitigation Grand Challenge and Flight Validation Mission Architecture Development

This final technical report describes the results of a NASA Innovative Advanced Concept (NIAC) Phase 2 study entitled "An Innovative Solution to NASA's NEO Impact Threat Mitigation Grand Challenge and Flight Validation Mission Architecture Development." This NIAC Phase 2 study was conducted at the Asteroid Deflection Research Center (ADRC) of Iowa State University in 2012-2014. The study objective was to develop an innovative yet practically implementable solution to the most probable impact threat of an asteroid or comet with short warning time (less than 5 years). The technical materials contained in this final report are based on numerous technical papers, which have been previously published by the project team of the NIAC Phase 1 and 2 studies during the past three years. Those technical papers as well as a NIAC Phase 2 Executive Summary report can be downloaded from the ADRC website (www.adrc.iastate.edu).

NEO↗

An Integrated Physics-Based Risk Model for Assessing the Asteroid Threat

Although most asteroids and other near-Earth objects (NEOs) do not pose a threat to Earth’s inhabitants, impacts from objects that are just tens of meters in diameter can cause significant damage if they occur over a populated area. This paper forms the foundation of an effort at NASA Ames Research Center to quantify these risks and identify the greatest risk-driving parameters and uncertainties. An integrated risk model that couples dynamic probabilistic simulations of strike occurrences with physics-based models of NEO impact damage factors has been developed to generate casualty estimates for a range of NEO impact properties. Currently, the model focuses on the risk due to blast overpressure damage from airbursts and impacts on land. The model is first used to reproduce results from established sources, and then is extended to perform sensitivity studies that yield greater insights into risk driving parameters. Results show that meteor strength and entry angle play a role for small to mid-size NEOs, and that accounting for the specific target location significantly affects casualty estimates and dominates the risk. Future work will continue to refine and expand the models to better characterize key impact risk factors, include additional types of threats such as tsunamis and climate effects, and ultimately support assessments of potential asteroid mitigation strategies.

Asteroid Threat↗