Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “information security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie↗

Vegetation Monitoring Optimization with Normalized Difference Vegetation Index and Evapotranspiration Using Remote Sensing Measurements and Land Surface Models Over East Africa

The majority of people in East Africa rely on the agro-pastoral system for their livelihood, which is highly vulnerable to droughts and flooding. Agro-pastoral droughts are endemic to the region and are considered the main natural hazard that contributes to food insecurity. Drought begins with rainfall deficit, gradually leading to soil moisture deficit, higher land surface temperature, and finally impacts to vegetation growth. Therefore, monitoring vegetation conditions is essential in understanding the progression of drought, potential effects on food security, and providing early warning information needed for drought mitigation decisions. Because vegetation processes couple the land and atmosphere, monitoring of vegetation conditions requires consideration of both water provision and demand. While there is consensus in using either the Normalized Difference Vegetation Index (NDVI) or evapotranspiration(ET) for vegetation monitoring, a comprehensive assessment optimizing the use of both has not yet been done. Moreover, the evaluation methods for understanding the relationships between NDVI and ET for vegetation monitoring are also limited. Taking these gaps into account we have developed a framework to optimize vegetation monitoring using both NDVI and ET by identifying where they perform the best by using triple collocation and cross-correlation methods. We estimated the random error structure in Moderate Resolution Imaging Spectroradiometer (MODIS) NDVI; ET from the Operational Simplified Surface Energy Balance (SSEBop) model; and ET from land surface models (LSMs). LSM ET and SSEBop ET have been found to be better indicators for vegetation monitoring during extreme drought events, while NDVI could provide better information on vegetation condition during wetter than normal conditions. The random error structures of these variables suggest that LSM ET is most likely to provide important information for vegetation monitoring over low and high ends of the vegetation fraction areas. Over moderate vegetative areas, any of these variables could provide important vegetation information for drought characterization and food security assessments. While this study provides a framework for optimizing vegetation monitoring for drought and food security assessments over East Africa, the framework can be adopted to optimize vegetation monitoring over any other drought and food insecure region of the world.

triple collocation↗

Syntactic and Semantic Validation without a Metadata Management System

The ability to maintain quality information is essential to securing the confidence in any system for which the information serves as a data source. NASA's Global Change Master Directory (GCMD), an online Earth science data locator, holds over 9000 data set descriptions and is in a constant state of flux as metadata are created and updated on a daily basis. In such a system, the importance of maintaining the consistency and integrity of these-metadata is crucial. The GCMD has developed a metadata management system utilizing XML, controlled vocabulary, and Java technologies to ensure the metadata not only adhere to valid syntax, but also exhibit proper semantics.

Pollack, Janine↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Airport Information Sharing Concept Architecture

The National Airspace System (NAS) Air Traffic management, control and operation depends on a timely and efficient distribution of real time information generated by stakeholders and published from a variety of sources. The Federal Aviation Administration System Wide Information Management (SWIM) is a service oriented architecture design to provide stakeholders with timely NAS information. However, there are other sources of useful information generated by stakeholders that can be included in the management of NAS operations. Airport facilities are host to most stakeholders operating in the NAS (airspace user, airport authority, ground handling, controller tower) and thus large information is generated and consumed at these facilities. The NASA Glenn Research center has been investigating an information exchange architecture framework that would enable the timely, efficient and secure gathering and distribution information generated at airport facilities. This presentation describes the framework architecture concept for the efficient information exchange of airport information.

Airports↗

Characterization of Infrasonic Signatures of Earth-Grazing Fireballs as Analogues to Hypersonic Vehicles (Final Report)

Accurate detection, discrimination, and characterization of high-altitude hypersonic events using infrasonic monitoring are critical to planetary defense and global strategic surveillance. This report synthesizes recent advances achieved through rigorous analysis of infrasonic signatures from natural meteoroids, emphasizing shallow entry-angle meteoroids as essentially proxies for artificial hypersonic systems. Meteoroids naturally encompass diverse velocities, trajectories, altitudes, and fragmentation behaviors, enabling systematic validation of empirical period–yield relationships, waveform morphology classifiers, and trajectory-induced back-azimuth deviation models. Integration of adaptive array-processing enhancements within Cardinal software further extends infrasonic detection sensitivity and signal classification reliability. Collectively these advances, based solely on infrasonic signatures or limited optical data, offer robust methodologies for distinguishing natural from artificial hypersonic sources, significantly reducing event geolocation uncertainties and refining source-function determination. The outcomes detailed herein lay foundational groundwork for improved global hypersonic event-surveillance frameworks, supporting improved security preparedness and informing strategic monitoring and defense policies.

54 ENVIRONMENTAL SCIENCES↗

Exploring Connections between Global Climate Indices and African Vegetation Phenology

Variations in agricultural production due to rainfall and temperature fluctuations are a primary cause of food insecurity on the continent in Africa. Agriculturally destructive droughts and floods are monitored from space using satellite remote sensing by organizations seeking to provide quantitative and predictive information about food security crises. Better knowledge on the relation between climate indices and food production may increase the use of these indices in famine early warning systems and climate outlook forums on the continent. Here we explore the relationship between phenology metrics derived from the 26 year AVHRR NDVI record and the North Atlantic Oscillation index (NAO), the Indian Ocean Dipole (IOD), the Pacific Decadal Oscillation (PDO), the Multivariate ENSO Index (MEI) and the Southern Oscillation Index (SOI). We explore spatial relationships between growing conditions as measured by the NDVI and the five climate indices in Eastern, Western and Southern Africa to determine the regions and periods when they have a significant impact. The focus is to provide a clear indication as to which climate index has the most impact on the three regions during the past quarter century. We found that the start of season and cumulative NDVI were significantly affected by variations in the climate indices. The particular climate index and the timing showing highest correlation depended heavily on the region examined. The research shows that climate indices can contribute to understanding growing season variability in Eastern, Western and Southern Africa.

Brown, Molly E.↗

Modernization of B-2 Data, Video, and Control Systems Infrastructure

The National Aeronautics and Space Administration (NASA) Glenn Research Center (GRC) Plum Brook Station (PBS) Spacecraft Propulsion Research Facility, commonly referred to as B-2, is NASA s third largest thermal-vacuum facility with propellant systems capability. B-2 has completed a modernization effort of its facility legacy data, video and control systems infrastructure to accommodate modern integrated testing and Information Technology (IT) Security requirements. Integrated systems tests have been conducted to demonstrate the new data, video and control systems functionality and capability. Discrete analog signal conditioners have been replaced by new programmable, signal processing hardware that is integrated with the data system. This integration supports automated calibration and verification of the analog subsystem. Modern measurement systems analysis (MSA) tools are being developed to help verify system health and measurement integrity. Legacy hard wired digital data systems have been replaced by distributed Fibre Channel (FC) network connected digitizers where high speed sampling rates have increased to 256,000 samples per second. Several analog video cameras have been replaced by digital image and storage systems. Hard-wired analog control systems have been replaced by Programmable Logic Controllers (PLC), fiber optic networks (FON) infrastructure and human machine interface (HMI) operator screens. New modern IT Security procedures and schemes have been employed to control data access and process control flows. Due to the nature of testing possible at B-2, flexibility and configurability of systems has been central to the architecture during modernization.

Cmar, Mark D.↗

Modernization of B-2 Data, Video, and Control Systems Infrastructure

The National Aeronautics and Space Administration (NASA) Glenn Research Center (GRC) Plum Brook Station (PBS) Spacecraft Propulsion Research Facility, commonly referred to as B-2, is NASA's third largest thermal-vacuum facility with propellant systems capability. B-2 has completed a modernization effort of its facility legacy data, video and control systems infrastructure to accommodate modern integrated testing and Information Technology (IT) Security requirements. Integrated systems tests have been conducted to demonstrate the new data, video and control systems functionality and capability. Discrete analog signal conditioners have been replaced by new programmable, signal processing hardware that is integrated with the data system. This integration supports automated calibration and verification of the analog subsystem. Modern measurement systems analysis (MSA) tools are being developed to help verify system health and measurement integrity. Legacy hard wired digital data systems have been replaced by distributed Fibre Channel (FC) network connected digitizers where high speed sampling rates have increased to 256,000 samples per second. Several analog video cameras have been replaced by digital image and storage systems. Hard-wired analog control systems have been replaced by Programmable Logic Controllers (PLC), fiber optic networks (FON) infrastructure and human machine interface (HMI) operator screens. New modern IT Security procedures and schemes have been employed to control data access and process control flows. Due to the nature of testing possible at B-2, flexibility and configurability of systems has been central to the architecture during modernization.

Cmar, Mark D.↗

NASA Blue Team: Determining Operational Security Posture of Critical Systems and Networks

Emergence of Cybersecurity has increased the focus on security risks to Information Technology (IT) assets going beyond traditional Information Assurance (IA) concerns: More sophisticated threats have emerged from increasing sources as advanced hacker tools and techniques have emerged and proliferated to broaden the attack surface available across globally interconnected networks.

cybersecurity↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Emergency Response Manual

Safety and security is very important at NASA. The Security Management and Safeguards Office goal is ensure safety and security for all NASA Lewis and Plum Brook Station visitors and workers. The office protects against theft, sabotage, malicious damage, espionage, and other threats or acts of violence. There are three types of security at NASA: physical, IT, and personnel. IT is concerned with sensitive and classified information and computers. Physical security includes the officers who check visitors and workers in and patrol the facility. Personnel security is concerned with background checks during hiring. During my internship, I met people from and gained knowledge about all three types of security. I primarily worked with Dr. Richard Soppet in physical security. During my experience with physical security, I observed and worked with many aspects of it. I attended various security meetings at both NASA Lewis and Plum Brook. The meetings were about homeland security and other improvements that will be made to both facilities. I also spent time with a locksmith. The locksmith makes copies of keys and unlocks doors for people who need them. I rode around in a security vehicle with an officer as he patrolled. I also observed the officer make a search of a visitor s vehicle. All visitors vehicles are searched upon entering NASA. I spent time and observed in the dispatch office. The officer answers calls and sends out officers when needed. The officer also monitors the security cameras. My primary task was completing an emergency response manual. This manual would assist local law enforcement and fire agencies in case of an emergency. The manual has pictures and descriptions of the buildings. It also contains the information about hazards inside of the buildings. This information will be very helpul to law enforcement so that when called upon during an emergency, they will not create an even bigger problem with collateral damage.

Barnett, Traci M.↗

Cyber Resilience and Social Equity: Twin Pillars of a Sustainable Energy Future

This paper examines the intersection of security and accessibility within energy systems amidst the rise of grid modernization and digitization, especially considering the regulatory changes and the imperatives of inclusive energy strategies. It addresses the dual need for secure, resilient infrastructure and a commitment to mitigate energy poverty while maintaining equitable access to energy. Amid escalating cybersecurity and physical threats, the paper advocates for sustainable energy delivery systems that ensure robust defenses without compromising the goals of reducing energy poverty and ensuring energy security. This paper identifies the pressing need for Cyber-Informed Engineering (CIE) and Secure-by-Design (SbD) principles, highlighting how these strategies can protect critical infrastructure and democratize access to secure energy, particularly for disadvantaged communities. The analysis underscores the challenges presented by the expansion of attack surfaces, interoperability requirements, and grid-edge analytics, offering innovative solutions that leverage advanced technologies and data-driven insights. Furthermore, this paper addresses the workforce development gap, emphasizing the necessity for public-private partnerships and vendor engagement in creating a skilled cybersecurity workforce. This paper has a dual focus on both the technological aspect of cybersecurity and the social dimension of equity within the context of sustainable energy development. It suggests a comprehensive examination of how these two critical elements interact and support the overarching goal of a sustainable energy future.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Secure Peer-to-Peer Networks for Scientific Information Sharing

The most common means of remote scientific collaboration today includes the trio of e-mail for electronic communication, FTP for file sharing, and personalized Web sites for dissemination of papers and research results. With the growth of broadband Internet, there has been a desire to share large files (movies, files, scientific data files) over the Internet. Email has limits on the size of files that can be attached and transmitted. FTP is often used to share large files, but this requires the user to set up an FTP site for which it is hard to set group privileges, it is not straightforward for everyone, and the content is not searchable. Peer-to-peer technology (P2P), which has been overwhelmingly successful in popular content distribution, is the basis for development of a scientific collaboratory called Scientific Peer Network (SciPerNet). This technology combines social networking with P2P file sharing. SciPerNet will be a standalone application, written in Java and Swing, thus insuring portability to a number of different platforms. Some of the features include user authentication, search capability, seamless integration with a data center, the ability to create groups and social networks, and on-line chat. In contrast to P2P networks such as Gnutella, Bit Torrent, and others, SciPerNet incorporates three design elements that are critical to application of P2P for scientific purposes: User authentication, Data integrity validation, Reliable searching SciPerNet also provides a complementary solution to virtual observatories by enabling distributed collaboration and sharing of downloaded and/or processed data among scientists. This will, in turn, increase scientific returns from NASA missions. As such, SciPerNet can serve a two-fold purpose for NASA: a cost-savings software as well as a productivity tool for scientists working with data from NASA missions.

Karimabadi, Homa↗

Center of Excellence for Operational Technology

The Center of Excellence for Operational Technology Traditional Presentation Abstract 2025 National Laboratories Information Technology Summit | Denver, CO Traditional Presentation Session Managing cybersecurity risk in Operational Technology (OT) presents a significant challenge across the Department, and critically, at many of the national laboratories. This includes IT-OT convergence, aging OT systems, cost of updating OT systems, and increased Advanced Persistent Threat efforts against OT including the 16 critical infrastructure sectors as listed in Presidential Policy Directive 21. DoE’s Office of Science and NNSA’s Office of the Chief Information Officer are taking the lead in addressing this challenge to include critical systems, by establishing the Center of Excellence (CoE) for Operational Technology. Championed by NNSA Deputy Chief Information Officer Steven McAndrews and the Office of Science Chief Information Officer Shila Cooch, the CoE for OT was chartered in February 2025 to address the challenges of OT cybersecurity and compliance. The CoE for OT will create partnerships and leverage expertise from across the NNSA National Security Enterprise and DOE Labs, Plants and Sites. The CoE will also collaborate with colleagues in other government agencies, industry partners and academia. The CoE for OT discussion at the National Laboratories Information Technology Summit ’25 will include the genesis of the CoE, stated goals, organizational structure, and the effort to attract OT subject matter experts to join the CoE effort to share knowledge and expertise. The discussion will include opportunities to get involved and contribute to this important effort. This session will be led by CoE for OT Co-Chairs Matt Kwiatkowski, Fermi National Laboratory Chief Information Security Officer, and Steven Weldon, Savannah River National Laboratory Cyber Program Director at the Georgia Cyber Center. The session will be of particular interest to CIOs, CTOs, CISOs, as well as IT and OT practitioners.

Kwiatkowski, Matt [Fermilab]↗

The Influence of Future Command, Control, Communications, and Computers (C4) on Doctrine and the Operational Commander's Decision-Making Process

Future C4 systems will alter the traditional balance between force and information, having a profound influence on doctrine and the operational commander's decision making process. The Joint Staff's future vision of C4 is conceptualized in 'C4I for the Warrior' which envisions a joint C4I architecture providing timely sensor to shoot information direct to the warfighter. C4 system must manage and filter an overwhelming amount of information; deal with interoperability issues; overcome technological limitations; meet emerging security requirements; and protect against 'Information Warfare.' Severe budget constraints necessitate unified control of C4 systems under singular leadership for the common good of all the services. In addition, acquisition policy and procedures must be revamped to allow new technologies to be fielded quickly; and the commercial marketplace will become the preferred starting point for modernization. Flatter command structures are recommended in this environment where information is available instantaneously. New responsibilities for decision making at lower levels are created. Commanders will have to strike a balance between exerting greater control and allowing subordinates enough flexibility to maintain initiative. Clearly, the commander's intent remains the most important tool in striking this balance.

Mayer, Michael G.↗

Organizing Diverse, Distributed Project Information

SemanticOrganizer is a software application designed to organize and integrate information generated within a distributed organization or as part of a project that involves multiple, geographically dispersed collaborators. SemanticOrganizer incorporates the capabilities of database storage, document sharing, hypermedia navigation, and semantic-interlinking into a system that can be customized to satisfy the specific information-management needs of different user communities. The program provides a centralized repository of information that is both secure and accessible to project collaborators via the World Wide Web. SemanticOrganizer's repository can be used to collect diverse information (including forms, documents, notes, data, spreadsheets, images, and sounds) from computers at collaborators work sites. The program organizes the information using a unique network-structured conceptual framework, wherein each node represents a data record that contains not only the original information but also metadata (in effect, standardized data that characterize the information). Links among nodes express semantic relationships among the data records. The program features a Web interface through which users enter, interlink, and/or search for information in the repository. By use of this repository, the collaborators have immediate access to the most recent project information, as well as to archived information. A key advantage to SemanticOrganizer is its ability to interlink information together in a natural fashion using customized terminology and concepts that are familiar to a user community.

Keller, Richard M.↗

The Johnson Space Center Management Information Systems (JSCMIS). 1: Requirements Definition and Design Specifications for Versions 2.1 and 2.1.1. 2: Documented Test Scenario Environments. 3: Security Design and Specifications

The Johnson Space Center Management Information System (JSCMIS) is an interface to computer data bases at NASA Johnson which allows an authorized user to browse and retrieve information from a variety of sources with minimum effort. This issue gives requirements definition and design specifications for versions 2.1 and 2.1.1, along with documented test scenario environments, and security object design and specifications.

Source record↗