Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “security assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere was heightened from Airports to the communication among the military branches legionnaires. With advanced persistent threats (APTs) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning and configuration of network devices i.e. routers and IDSsIPSs. In addition I will be completing security assessments on software and hardware, vulnerability assessments and reporting, conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, policies and procedures.

computer information security↗

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere has heightened from airports to the communication among the military branches legionnaires. With advanced persistent threats (APT's) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning, and configuration of network devices i.e. routers and IDS's/IPS's. In addition, I will be completing security assessments on software and hardware, vulnerability assessments and reporting, and conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out the tasks stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, as well as policies and procedures.

security↗

Reducing Software Security Risk Through an Integrated Approach

This paper discusses new joint work by the California Institute of Technology's Jet Propulsion Laboratory and the University of California at Davis sponsored by the National Aeronautics and Space Administration to develop a security assessment instrument for the software development and maintenance life cycle.

risk matrix↗

Addressing software security risk mitigations in the life cycle

The NASA Office of Safety and Mission Assurance (OSMA) has funded the Jet Propulsion Laboratory (JPL) with a Center Initiative, 'Reducing Software Security Risk through an Integrated Approach' (RSSR), to address this need. The Initiative is a formal approach to addressing software security in the life cycle through the instantiation of a Software Security Assessment Instrument (SSAI) for the development and maintenance life cycles.

software tools↗

Addressing software security and mitigations in the life cycle

Traditionally, security is viewed as an organizational and Information Technology (IT) systems function comprising of firewalls, intrusion detection systems (IDS), system security settings and patches to the operating system (OS) and applications running on it. Until recently, little thought has been given to the importance of security as a formal approach in the software life cycle. The Jet Propulsion Laboratory has approached the problem through the development of an integrated formal Software Security Assessment Instrument (SSAI) with six foci for the software life cycle.

model checking↗

Addressing software security and mitigations in the life cycle

Traditionally, security is viewed as an organizational and Information Technology (IIJ systems function comprising of Firewalls, intrusion detection systems (IDS), system security settings and patches to the operating system (OS) and applications running on it. Until recently, little thought has been given to the importance of security as a formal approach in the software life cycle. The Jet Propulsion Laboratory has approached the problem through the development of an integrated formal Software Security Assessment Instrument (SSAI) with six foci for the software life cycle.

formal methods↗

Developing a Crop Mask for Agricultural Assessments in Kenya

Kenya relies on agricultural production for supporting local consumption and other processing value chains. The role of agriculture in supporting Kenya's economy is critical, with its contribution to the Gross Domestic product (GDP) estimated at over 277,000 Million in 2016. With changing climate in a rain-fed dependent agricultural production system, cropping zones are shifting and proper decision making will require updated data for proper delineation of cropping areas and extent; especially in agriculture and food security assessments. Where up-to-date data is not available it is important that it is generated and passed over to relevant stakeholders to inform their decision making processes. It is important that government agencies, non-governmental agencies and other agricultural stakeholders access updated tools and information to assist in their assessments. To support agricultural decision making, SERVIR E&SA will develop an updated agricultural crop mask. Due to intercropping especially in small holder farming, the mask will cover all crops to provide an overall map of cropped areas.

environment↗

ARC-100 Reactor Security-by-Design Summary

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the Advanced Reactor Concepts 100 (ARC-100) sodium-cooled fast reactor (SFR) design. The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, and used fuel assembly wash station. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. However, the consequence assessment results are the similar to a previously assessed generic SFR. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. This work will continue in the Fiscal Year 2025 for the remaining ARC-100 systems, including cesium trap, sodium cold trap, noble gas decay tanks (dewar bottles), and used fuel dry storage facility, to provide safety-and-security-by-design insights and recommendations on non-core systems. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

IT Security Support for Spaceport Command and Control System

During the fall 2013 semester, I worked at the Kennedy Space Center as an IT Security Intern in support of the Spaceport Command and Control System under the guidance of the IT Security Lead Engineer. Some of my responsibilities included assisting with security plan documentation collection, system hardware and software inventory, and malicious code and malware scanning. Throughout the semester, I had the opportunity to work on a wide range of security related projects. However, there are three projects in particular that stand out. The first project I completed was updating a large interactive spreadsheet that details the SANS Institutes Top 20 Critical Security Controls. My task was to add in all of the new commercial of the shelf (COTS) software listed on the SANS website that can be used to meet their Top 20 controls. In total, there are 153 unique security tools listed by SANS that meet one or more of their 20 controls. My second project was the creation of a database that will allow my mentor to keep track of the work done by the contractors that report to him in a more efficient manner by recording events as they occur throughout the quarter. Lastly, I expanded upon a security assessment of the Linux machines being used on center that I began last semester. To do this, I used a vulnerability and configuration tool that scans hosts remotely through the network and presents the user with an abundance of information detailing each machines configuration. The experience I gained from working on each of these projects has been invaluable, and I look forward to returning in the spring semester to continue working with the IT Security team.

computer security↗

ARC-100 Reactor Security-by-Design Summary 2025

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the ARC-100, a sodium-cooled fast reactor (SFR) being developed by ARC Clean Technology, Inc (ARC). The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, used fuel assembly wash station, cesium trap, sodium cold trap, noble gas decay tanks, used fuel dry storage facility, damaged fuel storage facility, and radioactive waste building. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

A 5G Enabled Adaptive Computing Workflow for Greener Power Grid

5G wireless technology can deliver higher data speeds, ultra low latency, more reliability, massive network capacity, increased availability, and a more uniform user experience to users. It brings additional power to help address the challenges brought by renewable integration and decarbonization. In this paper, a 5G enabled adaptive computing workflow tool has been presented that consists of various computing resources, such as 5G equipment, edge computing, cluster, Graphics processing unit (GPU) and cloud computing, with two examples showing technical feasibility for edge-grid-cloud interaction for real-time monitoring, security assessment, and forecasting. Benefiting from the high data transmission speed and massive connection capability of 5G, the workflow shows its potential to seamlessly integrate various applications at distributed and/or centralized locations to build more complex and powerful functions, with better flexibility.

5G technology, computational workflow, edge comput↗

Exploring Advanced Computational Tools and Techniques with Artificial Intelligence and Machine Learning in Operating Nuclear Plants

This report presents the project Idaho National Laboratory conducted for Nuclear Regulatory Commission to explore the advanced computational tools and techniques, such as artificial intelligence (AI) and machine learning (ML), for operating nuclear plants. The report reviews the nuclear data sources, with the focus on the operating experience data, that could be applied by advanced computational tools and techniques. Plant-specific and generic (national and international) data from different sources are described. The report describes the relationships between statistics and AI/ML and then introduces the most widely used AI/ML algorithms in both supervised and unsupervised learning. The report reviews the recent applications of advanced computational tools and techniques in various fields of nuclear industry, such as reactor system design and analysis, plant operation and maintenance, and nuclear safety and risk analysis. Finally, the report presents the insights from the project on the potential applicability of AI/ML techniques in improving advanced computational capabilities, how the advanced tools and techniques could contribute to the understanding of safety and risk, and what information would be needed to provide meaningful insights to decision makers. The report also documents an NRC survey on the current state of commercial nuclear power operations relative to the use of AI and ML tools as well as the role of AI/ML tools in nuclear power operations was published by the NRC as in FRN NRC-2021-0048 in April 2021. A summary of the survey including the survey questions, survey participants, survey responses, and the conclusions and insights derived from the survey is provided in the report. Finally, the report investigates potential applications of using AI/ML in operating NPPs and advanced reactors (both advanced LWRs and advanced NLWRs) to improve nuclear plant safety and efficiency. Three main application fields are defined and discussed: (1) plant safety and security assessments; (2) plant degradation modeling, fault and accident diagnosis and prognosis; and (3) plant operation and maintenance efficiency improvement.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Impacts of Substrate Thinning on FPGA Performance and Reliability [Slides]

Substrate thinning is necessary in devices with flip-chip BGA packages to enable both radiation testing and component qualification and high-spatial resolution beam-based failure analysis methods. We investigated three factors affecting device performance: subsurface damage from the thinning process, reduced heat spreading in thin substrates, and changes in device switching speed. We conclude subsurface damage to crystalline Si caused by the thinning process is removable with sufficient SiO 2 slurry polishing. Local temperature differences increase minimally in devices thinned to 3 μm. Compressive stress in the Si increases globally after device thinning and leads to slowing of ring oscillator frequency by about 0.5% compared to full-thickness devices. Future work will include extending the results to submicron Si thickness values, which also has important benefits for failure analysis, debug, and security assessments. We also plan to extend this type of work to other FPGAs and other devices like memory and processors.

36 MATERIALS SCIENCE↗

Generative Artificial Intelligence Tools for Red Teams

This document analyzes the role of Generative Artificial Intelligence (GenAI) tools in cybersecurity, particularly for red teaming. While GenAI accelerates initial security assessments, its effectiveness wanes with complexity, necessitating experienced assessors. The review critiques marketing claims, highlights ethical concerns regarding uncensored models for cybercrime, and advocates for a robust defense strategy supported by skilled professionals.

97 MATHEMATICS AND COMPUTING↗

Incipient fault detection and power system protection for spaceborne systems

A program was initiated to study the feasibility of using advanced terrestrial power system protection techniques for spacecraft power systems. It was designed to enhance and automate spacecraft power distribution systems in the areas of safety, reliability and maintenance. The proposed power management/distribution system is described as well as security assessment and control, incipient and low current fault detection, and the proposed spaceborne protection system. It is noted that the intelligent remote power controller permits the implementation of digital relaying algorithms with both adaptive and programmable characteristics.

Russell, B. Don↗

An Example of Unsupervised Networks Kohonen's Self-Organizing Feature Map

Kohonen's self-organizing feature map belongs to a class of unsupervised artificial neural network commonly referred to as topographic maps. It serves two purposes, the quantization and dimensionality reduction of date. A short description of its history and its biological context is given. We show that the inherent classification properties of the feature map make it a suitable candidate for solving the classification task in power system areas like load forecasting, fault diagnosis and security assessment.

Kohonen Feature Map↗

Famine Early Warning Systems and Their Use of Satellite Remote Sensing Data

Famine early warning organizations have experience that has much to contribute to efforts to incorporate climate and weather information into economic and political systems. Food security crises are now caused almost exclusively by problems of food access, not absolute food availability, but the role of monitoring agricultural production both locally and globally remains central. The price of food important to the understanding of food security in any region, but it needs to be understood in the context of local production. Thus remote sensing is still at the center of much food security analysis, along with an examination of markets, trade and economic policies during food security analyses. Technology including satellite remote sensing, earth science models, databases of food production and yield, and modem telecommunication systems contributed to improved food production information. Here we present an econometric approach focused on bringing together satellite remote sensing and market analysis into food security assessment in the context of early warning.

Brown, Molly E.↗

Famine Early Warning Systems Network (FEWS NET) Land Data Assimilation System (LDAS) and Other Assimilated Hydrological Data at NASA GES DISC

The NASA Goddard Earth Sciences Data and Information Services Center (GES DISC) provides science support for several data sets relevant to agriculture and food security, including the Famine Early Warning Systems Network (FEWS NET) Land Data Assimilation System (LDAS), or FLDAS data set. The GES DISC is one of twelve NASA Earth Observing System (EOS) data centers that process, archive, document, and distribute data from Earth science missions and related projects. The GES DISC hosts a wide range of remote sensing and model data, and provides reliable and robust data access and other services to users worldwide. Beyond data archive and access, the GES DISC offers many services to visualize and analyze the data. This presentation provides a summary of the hydrological data available at the GES DISC, along with an overview of related data services. Specifically, the FLDAS data set has been adapted to work with domains, data streams, and monitoring and forecast requirements associated with food security assessment in data-sparse, developing country settings. The FLDAS global monthly data have a 0.1 x 0.1 degree spatial resolution covering the period from January 1982 to present. Global FLDAS monthly anomaly and monthly climatology data are also available at the GES DISC to evaluate how current conditions compare to averages over the FLDAS 35-year period. Several case studies using the FLDAS soil moisture, evapotranspiration, rainfall, runoff, and surface temperature data will be presented.

Loeser, Carlee↗