Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Computer security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 739 records · Page 41

System Would Generate Virtual Heads-Up Display

Proposed helmet-mounted electronic display system superimposes full-color alphanumerical and/or graphical information onto observer's visual field. Displayed information projected directly onto observer's retinas, giving observer illusion of full-size computer display in foreground or background. Display stereoscopic, holographic, or in form of virtual image. Used by pilots to view navigational information while looking outside or at instruments, by security officers to view information about critical facilities while looking at visitors, or possibly even stock-exchange facilities to view desktop monitors and overhead displays simultaneously. System includes acousto-optical tunable filter (AOTF), which acts as both spectral filter and spatial light modulator.

Lambert, James L.↗

Technology for a NASA Space-Based Science Operations Grid

This viewgraph representation presents an overview of a proposal to develop a space-based operations grid in support of space-based science experiments. The development of such a grid would provide a dynamic, secure and scalable architecture based on standards and next-generation reusable software and would enable greater science collaboration and productivity through the use of shared resources and distributed computing. The authors propose developing this concept for use on payload experiments carried aboard the International Space Station. Topics covered include: grid definitions, portals, grid development and coordination, grid technology and potential uses of such a grid.

Bradford, Robert N.↗

Engineering Ultimate Self-Protection in Autonomic Agents for Space Exploration Missions

NASA's Exploration Initiative (EI) will push space exploration missions to the limit. Future missions will be required to be self-managing as well as self-directed, in order to meet the challenges of human and robotic space exploration. We discuss security and self protection in autonomic agent based-systems, and propose the ultimate self-protection mechanism for such systems-self-destruction. Like other metaphors in Autonomic Computing, this is inspired by biological systems, and is the analog of biological apoptosis. Finally, we discus the role it might play in future NASA space exploration missions.

Sterritt, Roy↗

Technical Challenges and Opportunities of Centralizing Space Science Mission Operations (SSMO) at NASA Goddard Space Flight Center

The NASA Goddard Space Science Mission Operations project (SSMO) is performing a technical cost-benefit analysis for centralizing and consolidating operations of a diverse set of missions into a unified and integrated technical infrastructure. The presentation will focus on the notion of normalizing spacecraft operations processes, workflows, and tools. It will also show the processes of creating a standardized open architecture, creating common security models and implementations, interfaces, services, automations, notifications, alerts, logging, publish, subscribe and middleware capabilities. The presentation will also discuss how to leverage traditional capabilities, along with virtualization, cloud computing services, control groups and containers, and possibly Big Data concepts.

Science↗

Applying the Cognitive Space Gateway to Swarm Topologies

NASA's future vision for interplanetary networking includes a lunar network, Cube Satellite (CubeSat) constellations, and deep space robotic missions, comprising what could be viewed as a network of networks. Delay-tolerant networking (DTN) architecture and protocols provide a standard network layer among these varying scenarios and mitigate many challenges of the space environment, such as long delays, unplanned service interruptions, and asymmetric links. The Cognitive Space Gateway (CSG) is a routing method in a DTN architecture that uses spiking neural networks as the learning element to optimize routing decisions in a complex environment. This work aims to further develop cognitive networking technologies in several critical areas, including DTN, the CSG algorithm, CubeSat swarm topologies, and cloud services. To test the algorithm in a realistic scenario, the emulated network topology is based on a CubeSat swarm. The swarm may function as a mesh of nodes or as a hub-and-spoke network. An emulation environment will be built upon a commercial cloud service, such as Amazon Web Services (AWS) Elastic Compute Cloud. The cloud environment may enable a flexible, lower maintenance approach versus a multi-hop network based in a physical laboratory. The cloud platform will provide a secure environment allowing for collaboration among government and academic entities.

Ricardo Lent↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Remote operation of the DIII-D National Fusion Facility

Abstract Full remote scientific operation of the DIII-D National Fusion Facility is now possible through significant advances in the computer science hardware and software infrastructure made over the last decade. Capabilities around information visualization, data movement, and communication have all been enhanced. The level of capability deployed to remotely operate DIII-D required an infrastructure advancement over what had previously been achieved in the fusion community. The large quantity of real-time data that is automatically displayed on DIII-D’s control room screens can now be visualized by remote participants via web-based applications. New audio/video solutions using the VoIP and instant messaging application Discord have been implemented to mimic the dynamic and ad-hoc scientific conversations that are critical in successfully operating an experimental campaign. Discord’s ability for a user to rapidly move between audio channels, text with images, and share screens is a significant enhancement over traditional videoconferencing tools. In addition, multiple combinations of broadcast audio are made available via a web-based application to allow remote participants to simultaneously listen to general announcements/sounds while conducting their own specific conversations. Secure methodologies have been put into place to allow remote control of hardware including DIII-D’s plasma control system application. Secure methods also included the ability of the on-site team to closely coordinate their work with remote team members which has been enhanced through extensions to the wireless network and the use of tablet computers for audio/video/screen sharing. However, no amount of software can fully replace the need for ‘hands on hardware.’ This infrastructure was severely stress tested during the COVID-19 pandemic where occupancy of the DIII-D control room was restricted. Operational efficiency during the pandemic, measured in discharges per hour, remained high (3.8 ± 0.8) compared to values obtained pre-pandemic (3.7 ± 0.8).

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Legacy of Metropolis continues through new materials donated to classified library collections

“From the very beginning of the Los Alamos project, it was inevitable that the Laboratory would suffer total immersion in computing,” said Nicholas Constantine Metropolis in 1976, reflecting his characteristic humor. Metropolis had succinctly summarized the prominent place of computing in Los Alamos’s mission and history. Metropolis himself played no small role in that “total immersion,” exemplified by the Lab’s supercomputing center, a postdoctoral fellowship, and the world-famous algorithm that carry his name. So does a collection of legacy materials in the National Security Research Center (NSRC). The NSRC, the Lab’s classified library, which also houses unclassified artifacts, recently received a new addition to the Metropolis Collections. This donation, 22 years after his death on October 17, 1999, provides tangible evidence of Metropolis’s continuing legacy at Los Alamos.

97 MATHEMATICS AND COMPUTING↗

Semi-automatic image annotation using 3D LiDAR projections and depth camera data

Efficient image annotation is necessary to utilize deep learning object recognition neural networks in nuclear safeguards, such as for the detection and localization of target objects like nuclear material containers (NMCs). This capability can help automate the inventory accounting of different types of NMCs within nuclear storage facilities. The conventional manual annotation process is labor-intensive and time-consuming, hindering the rapid deployment of deep learning models for NMC identifications. This paper introduces a novel semi-automatic method for annotating 2D images of nuclear material containers (NMCs) by combining 3D light detection and ranging (LiDAR) data with color and depth camera images collected from a handheld scan system. The annotation pipeline involves an operator manually marking new target objects on a LiDAR-generated map, and projecting these 3D locations to images, thereby automatically creating annotations from the projections. The semi-automatic approach significantly reduces manual efforts and the expertise in image annotation that is required to perform the task, allowing deep learning models to be trained on-site within a few hours. The paper compares the performance of models trained on datasets annotated through various methods, including semi-automatic, manual, and commercial annotation services. The evaluation demonstrates that the semi-automatic annotation method achieves comparable or superior results, with a mean average precision (mAP) above 0.9, showcasing its efficiency in training object recognition models. Additionally, the paper explores the application of the proposed method to instance segmentation, achieving promising results in detecting multiple types of NMCs in various formations.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Federated learning for 2D synchrotron x-ray diffractometry: a cross-institutional approach for phase quantification of Ti–6Al–4V alloy

High-energy Two dimensional (2D) synchrotron x-ray diffractometry provides important insights into the atomistic structure and phase evolution of materials, yet traditional analysis methods remain complex, knowledge-intensive, and computationally demanding. Deep-learning models offer a powerful alternative for automating their analysis. Institutions that hold these datasets may be unwilling to share their data due to privacy and security policies, as well as the challenges associated with large-scale data transfer. As a result, models trained on local datasets often perform well only on their own data but exhibit bias and poor generalization across different instruments or facilities. To overcome these limitations, we explore federated learning (FL) for 2D synchrotron diffractograms, enabling collaborative model training without exchanging raw data. In this study, 2D synchrotron diffractograms of Ti–6Al–4V alloy collected from two independent facilities are used to train convolutional neural networks for predicting the β-phase volume fraction. Experimental results show that federated global models significantly outperform locally trained models in terms of generalization and achieve accuracy comparable to centralized trained models. These findings demonstrate the potential of FL to enable secure, cross-institutional collaboration and enhance the scalability of deep-learning-based materials characterization.

36 MATERIALS SCIENCE↗

Mitigate: An Adaptive Network Data Anonymization Tool Using Condensation-Based Differential Privacy

Modern network devices collect a large amount of data that can be analyzed to identify bottlenecks, anomalies, cyber-attacks, etc. Therefore, there is often a need to analyze such collections of network data quite often by an external expert or by the research community. However, these collections of data contain sensitive, proprietary information. In order for the network data to be shared, it must first be anonymized. The overall objective of this project is to develop an innovative privacy management tool to anonymize network data and achieve sufficient privacy, acceptable data utility, and efficient data analysis at the same time. No existing anonymization methods can achieve all of these at the same time. The core of this technology is a differential private clustering algorithm that provides strong privacy protection, preserves data properties important for subsequent analysis, and allows the party receiving the anonymized data to conduct analysis directly on anonymized data without the need of decryption or any extra processing. The research carried out was to design, implement and verify a solution to this problem by completing the following tasks: 1) developing the core technology; 2) developing a context based method that automatically recommends fields that must be anonymized; 3) conducted experiments showing superior results using our approach compared to existing tools, and 4) developed an intuitive but basic user interface. The research that was conducted generated novel algorithmic techniques that utilize state-of-the-art methods such as condensation, differential privacy preservation, clustering, automated tuning based on contextual awareness, and recommendation techniques to specify columns to users for anonymization leading to optimal privacy that allows research analysis on the dataset. Experiments were conducted to evaluate the efficacy of these novel algorithmic techniques by performing analysis on original non-anonymized datasets, then conducting analysis on the same yet anonymized datasets and comparing the results of the analyses. Overall, the anonymized analysis results were within 1% of the original results, verifying that the generated technology not only guarantees a high level of privacy but also enables research analysis as if it were conducted on the original dataset. Potential applications of this technology include anonymization of any type of structured network datasets that contain sensitive identifiers, such as IP addresses, that can be used in multiple applications. For example, to create an AI or machine learning model for cyber security, e.g., to detect attacks, or for performance analysis, e.g., identify bottlenecks or predict performance. In addition, a market analysis that was conducted for potential applications of this technology identified a broader range of applications of our anonymization technology beyond the network sector that includes healthcare, banking, insurance, securities, finance (FISB), data brokering, cloud services, ad sales, and government.

97 MATHEMATICS AND COMPUTING↗

Physically rigorous reduced-order flow models of fractured subsurface environments without explosive computational cost

Fractured media models comprise discontinuities of multiple lengths (e.g. fracture lengths and apertures, wellbore area) that fall into the relatively insignificant length scales spanning millimeter-scale fractures to centimeter-scale wellbores in comparison to the extensions of the field of interest, and challenge the conventional discretization methods imposing highly-fine meshing and formidably large numerical cost. By utilizing the recent developments in the finite element analysis of electromagnetics that allow to represent material properties on a hierarchical geometry, this project develops computational capabilities to model fluid flow, heat conduction, transport and induced polarization in large-scale geologic environments that possess geometrically-complex fractures and man-made infrastructures without explosive computational cost. The computational efficiency and robustness of this multi-physics modeling tool are demonstrated by considering various highly-realistic complex geologic environments that are common in many energy and national security related engineering problems.

42 ENGINEERING↗

Laboratory Directed Research and Development Program: FY 2021 Completed Projects

Oak Ridge National Laboratory (ORNL) is the US Department of Energy’s (DOE’s) largest multiprogram science, technology, and energy laboratory. It possesses distinctive capabilities in neutron science, computing, advanced materials, nuclear science and technology, and other fields. Using these capabilities, ORNL conducts basic and applied R&D to support DOE’s overarching mission “to ensure America’s security and prosperity by addressing its energy, environmental and nuclear challenges through transformative science and technology solutions.”1 As a national resource, ORNL also applies its capabilities and skills to specific needs of other federal agencies and customers through the DOE Strategic Partnership Projects (SPP) Program. Information about the laboratory and its programs is available on the ORNL website.2 The Laboratory Directed Research and Development (LDRD) Program at ORNL operates under the authority of the DOE Order 413.2C, “Laboratory Directed Research and Development,”3 which establishes DOE’s requirements for the program while providing the laboratory director broad flexibility for program implementation. The LDRD Program funds are obtained through a charge to all laboratory programs. Although it represents a relatively small portion of the overall research budget, the LDRD Program plays an essential role in maintaining the laboratory’s ability to respond to national needs. The program allows ORNL to improve its distinctive capabilities and to enhance its ability to conduct cutting-edge R&D. In accordance with the DOE order, R&D projects funded through the LDRD Program at ORNL support the following goals: (1) maintain the scientific and technical vitality of the laboratory; (2) enhance the laboratory’s ability to address future DOE missions; (3) foster creativity and stimulate exploration of forefront areas of science and technology; (4) serve as a proving ground for new concepts in R&D; and (5) support high-risk, potentially high-value R&D. This report provides an overview of the LDRD Program at ORNL in FY 2021 and contains summaries of all LDRD research projects that concluded between October 1, 2020, and September 30, 2021.

99 GENERAL AND MISCELLANEOUS↗

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS↗

Investigating Material Properties of Subsurface Rock Formations Modified by Engineering Mineral Precipitation (Final Scientific and Technical Report)

Montana State University’s (MSU) Energy Research Institute (ERI), in collaboration with the Center for Biofilm Engineering (CBE) and the Department of Civil Engineering (CE), has conducted a long‐term research program aimed at developing a novel cementing agent to address wellbore integrity and reduce the unwanted upward migration of fluids and greenhouse gases from the subsurface. The primary technology developed through this research program is known as ureolysis‐induced calcite precipitation (UICP), which harnesses bio‐chemical processes to precipitate calcium carbonate (CaCO 3 ). The same general process can also be called microbially-induced calcium carbonate precipitation (MICP) when microbes provide the process-catalyzing urease enzyme. Both terms are used in this report. Results have conclusively demonstrated that, if properly controlled, UICP can successfully seal fractures, high permeability zones, and compromised cement in the vicinity of wellbores and in nearby caprock. This technology has been successfully deployed to mitigate annular leakage in two test wells and over sixty commercial wells with a 100% success rate. This success in downhole deployment generates consideration of other subsurface applications where UICP could provide benefit to the energy sector, such as shale property modification for unconventional oil and gas recovery. The focus of this research project was to investigate fundamental material and mechanical properties of select shale cores and analyze how these properties change due to engineered mineral precipitation with the intent to control these properties to achieve a range of engineering objectives. Ultimately, the project aim was to identify valuable new areas where application of UICP might contribute to national energy security and environmental protection. The research workplan coupled UICP treatment of core samples, nuclear magnetic resonance (NMR) characterization, and mechanical strength testing at MSU with advanced X‐Ray micro-computed tomography (μCT) imaging and numerical modeling performed by collaborators at two national laboratories, the National Energy Technology Laboratory (NETL) and Lawrence Berkeley National Laboratory (LBNL). Experimental results are useful to inform geo-mechanical models which could be applied to predict mineralized rock formation behavior at field scale. Our findings suggest that NMR and μCT methods to detect and quantify biomineral formation in shale fractures are complementary and consistent with each other. Either could be used to estimate the volume of new mineral formed by UICP in shale fractures. The use of surfactants and guar gum to enhance biomineral precipitation in shale fractures merits further research. UICP can, under some conditions, increase the tensile strength of sealed shale fractures beyond that of the intact shale. These findings demonstrate that continued research in this area may be valuable to understanding and improving shale resource recovery techniques.

58 GEOSCIENCES↗