Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

The NASA Integrated Information Technology Architecture

This document defines an Information Technology Architecture for the National Aeronautics and Space Administration (NASA), where Information Technology (IT) refers to the hardware, software, standards, protocols and processes that enable the creation, manipulation, storage, organization and sharing of information. An architecture provides an itemization and definition of these IT structures, a view of the relationship of the structures to each other and, most importantly, an accessible view of the whole. It is a fundamental assumption of this document that a useful, interoperable and affordable IT environment is key to the execution of the core NASA scientific and project competencies and business practices. This Architecture represents the highest level system design and guideline for NASA IT related activities and has been created on the authority of the NASA Chief Information Officer (CIO) and will be maintained under the auspices of that office. It addresses all aspects of general purpose, research, administrative and scientific computing and networking throughout the NASA Agency and is applicable to all NASA administrative offices, projects, field centers and remote sites. Through the establishment of five Objectives and six Principles this Architecture provides a blueprint for all NASA IT service providers: civil service, contractor and outsourcer. The most significant of the Objectives and Principles are the commitment to customer-driven IT implementations and the commitment to a simpler, cost-efficient, standards-based, modular IT infrastructure. In order to ensure that the Architecture is presented and defined in the context of the mission, project and business goals of NASA, this Architecture consists of four layers in which each subsequent layer builds on the previous layer. They are: 1) the Business Architecture: the operational functions of the business, or Enterprise, 2) the Systems Architecture: the specific Enterprise activities within the context of IT systems, 3) the Technical Architecture: a common, vendor-independent framework for design, integration and implementation of IT systems and 4) the Product Architecture: vendor=specific IT solutions. The Systems Architecture is effectively a description of the end-user "requirements". Generalized end-user requirements are discussed and subsequently organized into specific mission and project functions. The Technical Architecture depicts the framework, and relationship, of the specific IT components that enable the end-user functionality as described in the Systems Architecture. The primary components as described in the Technical Architecture are: 1) Applications: Basic Client Component, Object Creation Applications, Collaborative Applications, Object Analysis Applications, 2) Services: Messaging, Information Broker, Collaboration, Distributed Processing, and 3) Infrastructure: Network, Security, Directory, Certificate Management, Enterprise Management and File System. This Architecture also provides specific Implementation Recommendations, the most significant of which is the recognition of IT as core to NASA activities and defines a plan, which is aligned with the NASA strategic planning processes, for keeping the Architecture alive and useful.

Baldridge, Tim↗

Deployment of an Advanced Electrocardiographic Analysis (A-ECG) to Detect Cardiovascular Risk in Career Firefighters

INTRODUCTION: Sudden cardiac death is the leading cause of line of duty death among firefighters, accounting for approximately 45% of fatalities annually. Firefighters perform strenuous muscular work while wearing heavy, encapsulating personal protective equipment in high ambient temperatures, under chaotic and emotionally stressful conditions. These factors can precipitate sudden cardiac events like myocardial infarction, serious dysrhythmias, or cerebrovascular accidents in firefighters with underlying cardiovascular disease. PURPOSE: The purpose of this study was to deploy and then evaluate the contribution of resting advanced ECG (A-ECG) in addition to other screening tools (family history, lipid profiles, and cardiopulmonary exercise tests, XT) in assessment of an individual fs cardiac risk profile. METHODS: Forty-four career firefighters were recruited to perform comprehensive baseline assessments including tests of aerobic performance, fasting lipids and glucose. Five-min resting 12-lead A-ECGs were obtained in a subset of firefighters (n=21) and transmitted over a secure networked system to a NASA physician collaborator. Using myocardial perfusion and other imaging as the gold standard, A-ECG scoring has been proven useful in accurately identifying a number of cardiac pathologies including coronary artery disease (CAD), left ventricular hypertrophy, hypertrophic cardiomyopathy, and non-ischemic and ischemic cardiomyopathy. RESULTS: Subjects f mean (SD) age was 43 (8) years, weight 91 (13) kg, and BMI 28 (3) kg/m2. Fifty-one percent of subjects had .3 cardiovascular risk factors. One subject had ST depression on XT ECG, at least one positive A-ECG score for CAD, and documented CAD based on cardiology referral. While all other subjects, including those with fewer risk factors, higher aerobic fitness, and normal exercise ECGs, were classified as healthy by A-ECG, there was no trend for association between risk factors and any of 20 A-ECG parameters in the grouped data.

Dolezal, B. A.↗

Resilient Autonomous Wind Farms: Preprint

With the advent of an increasing number of control strategies that seek to optimize wind turbine performance on a farm-level, taking account of individual wind turbine information to achieve wind farm-level objectives has become an increasingly important goal. Methods for controlling wind turbines on an individual and farm level have seen significant development, and an abundance of new implementations for gathering and using data from turbines have created potential for novel control mechanisms which can further optimize the performance and delivery characteristics of a wind farm. A key element of making these wind farms more efficient is to develop reliable algorithms that use local sensor information that is already being collected, such as supervisory control and data acquisition (SCADA) data, local meteorological stations, and nearby radars/sodars/lidars. Making use of information from all wind turbines in a wind farm can enable such approaches as determining the atmospheric conditions across the farm, improving fault-finding, and enabling more efficient overall control of farm-wide optimizations through mechanisms such as wake-steering. However, these approaches typically involve a centralized communications and control center. In order to ensure the resilient operation of the farm, it is necessary to develop an approach which distributes the calculation and communication amongst multiple nodes throughout the farm. In this fashion, a redundant, robust, and secure network can be created, which can tolerate faults in calculation, communication, and even external attacks which seek to disrupt the operation of the wind farm. This paper introduces the use of the Raft Byzantine Fault Tolerance algorithm in the implementation of autonomous control of a wind farm. This implementation will allow for fault tolerance for malfunctioning nodes, sensors, transmitters, and connectors. This approach is equally extensible to account for malicious actors. It will be shown to achieve overall consensus, provided the number of faults/malicious nodes is less than 3$n$+1, where $n$ is the number of turbine cluster faults which may occur, and to be robust in the face of multiple arbitrary faults.

autonomous↗

Remote Instrumentation and Data Acquisition: An Internship Research Report

This report outlines the development and implementation of a remote data acquisition system for waveform analysis using a Rohde & Schwarz oscilloscope. The project involved capturing waveform data, and transferring it to a local machine for visualization and analysis. The core logic was developed in C++ with a focus on object oriented programming and the use of polymorphism so the main application can interact with any instrument without knowing its exact type, simplifying the overall logic and making it easier to add or swap out components without changing the rest of the codebase.. The system issues Standard Commands for Programmable Instruments (SCPI) via a socket connection and parses the oscilloscope’s ASCII waveform data. The C++ application was containerized using Docker for ease of portability, and reproducibility. Emphasis was placed on secure networking practices, error handling, and effective data capture. The report describes the technical steps taken, challenges encountered, and lessons learned, providing insight into the practical integration of hardware interfacing with remote computational environments.

Parikh, Jaymil [Fermilab]↗

Streaming authentication and multi-level security for communications networks using quantum cryptography

Message authenticators for quantum-secured communications facilitate low-latency authentication with assurances of security. Low-latency message authenticators are especially valuable in infrastructure systems where security and latency constraints are difficult to satisfy with conventional non-quantum cryptography. For example, a message transmitter receives a message and derives an authentication tag for the message based at least in part on an authenticator that uses one or more quantum keys. The message transmitter outputs the message and its authentication tag. A message receiver receives a message and authentication tag for the message. The message receiver derives a comparison tag for the message based at least in part on an authenticator that uses one or more quantum keys. The message receiver checks whether the message is authentic based on a comparison of the authentication tag and the comparison tag. In example implementations, the authenticator uses stream-wise cyclic redundancy code operations.

Hughes, Richard J.↗

Multilayered Network Models for Security: Enhancing System Security Engineering with Orchestration

Security engineering approaches can often focus on a particular domain—physical security, cyber security, or personnel security, for example. Yet, security systems engineering consistently faces challenges requiring socio-technical solutions to address evolving and dynamic complexity. While some drivers of this complexity stem from complex risk environments, innovative adversaries, and disruptive technologies, other drivers are endogenous and emerge from the interactions across security engineering approaches. In response, INCOSE's Systems Security Working Group identified the need to better coordinate “disparate security solutions [that] operate independently” as one of eleven key concepts in their IS21 FuSE Security Roadmap. From this perspective, this need for “security orchestration” aligns with the perspective that security is a property that emerges from interactions within complex systems. Current efforts at Sandia National Laboratories are developing a systems security engineering approach that describes high consequence facility (HCF) security as a multidomain set of interacting layers. The result is a multilayered network (MLN)-based approach that captures the interactions between infrastructure, physical components, digital components, and humans in nuclear security systems. This article will summarize the MLN-based approach to HCF security and describe two preliminary results demonstrating potential benefits from incorporating interactions across disparate security solutions. Here, leveraging the logical structure of networks, this MLN model-based approach provides an example of how security orchestration provides enhanced systems security engineering solutions.

42 ENGINEERING↗

Security-Enhanced Autonomous Network Management

Ensuring reliable communication in next-generation space networks requires a novel network management system to support greater levels of autonomy and greater awareness of the environment and assets. Intelligent Automation, Inc., has developed a security-enhanced autonomous network management (SEANM) approach for space networks through cross-layer negotiation and network monitoring, analysis, and adaptation. The underlying technology is bundle-based delay/disruption-tolerant networking (DTN). The SEANM scheme allows a system to adaptively reconfigure its network elements based on awareness of network conditions, policies, and mission requirements. Although SEANM is generically applicable to any radio network, for validation purposes it has been prototyped and evaluated on two specific networks: a commercial off-the-shelf hardware test-bed using Institute of Electrical Engineers (IEEE) 802.11 Wi-Fi devices and a military hardware test-bed using AN/PRC-154 Rifleman Radio platforms. Testing has demonstrated that SEANM provides autonomous network management resulting in reliable communications in delay/disruptive-prone environments.

Zeng, Hui↗

INSEN 2023 Yearly Updates

The International Nuclear Security Education Network (INSEN) is the primary international network for nuclear security educational initiatives. INSEN plays a central role in fostering collaboration and knowledge-sharing among nuclear security education experts worldwide. In the wake of the global pandemic, INSEN remained committed to strengthening nuclear security education and resumed in-person activities. The International Atomic Energy Agency (IAEA) confirmed its continued dedication and support to the network’s mission and presented new activities aimed at elevating global nuclear security efforts. Throughout the year and during the annual and leadership meetings, working groups showcased their vibrant work and presented innovative ideas, invigorating the attendees’ dedication to their crucial work. Comprehensive presentations by the IAEA during the INSEN annual and leadership meetings highlighted the importance of the network and its continued commitment to promoting nuclear security on a global scale. One notable and encouraging trend was the increase in network membership, signifying a growing commitment to nuclear security worldwide and the continued interest in nuclear security from member states and international organizations. The value of initiatives such as the Women in Nuclear Security Initiative was emphasized at the annual meeting, accenting the need for diverse perspectives and expertise to ensure a secure nuclear landscape.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

Resilient Hierarchical Networked Control Systems: Secure Controls for Critical Locations and at Edge

Integration of information and communication technology (ICT) offers new opportunities in improving the management and operation of critical infrastructures such as power systems as it allows connection of different sensors and control components via a communication network, leading to the so-called networked control systems (NCS). However, the use of open and pervasive ICT such as the Internet or wireless communication technologies comes at a price of making NCS vulnerable to cyber intrusions/attacks which may cause physical damage. Here, this chapter presents control algorithms to ensure resilient and safe operation of NCS under unknown cyberattacks. Specifically, a variant of dynamic watermarking strategies is presented by embedding encoding/decoding components of chaotic signals into the NCS for secure control for critical locations where the measurement/control signals are transmitted to/from the control center via a communication network. In addition, resilient cooperative control algorithms are discussed to ensure safe operation at edge of the NCS which consists of a large number of distributed controllable devices. Several numerical examples are provided to illustrate the proposed control strategies.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

Security Enhancement of Network Constraint Grid-Edge Energy Management System

Network constrained grid edge energy management system (EMS) provides economic solution for active and reactive power dispatch of distributed energy resources (DERs) at the grid edge level. Grid edge EMS ensures secure interconnection of a circuit segment to the distribution system by maintaining grid code requirements (e.g. IEEE 1547–2018). Grid edge EMS is dependent on communication to receive load measurement, which brings a risk of unobservable false data injection attacks (FDIAs). To mitigate the risk, this paper proposes a framework to enhance resilient operation of grid edge EMS by detecting the unobservable FDIAs on loads and replacing them with forecasted values. In this work, a two-step detection algorithm is proposed. In first step, conventional residual based algorithm is deployed. Autoencoder (AE) based data driven mechanism is included in second step to detect the presence of unobservable FDIAs. After ensuring the presence of FDIA, its specific location is detected by checking the maximum residue values till the predefined threshold value is reached. Detected false data injected loads are then replaced with forecasted load values following long-short term memory (LSTM) based forecast to ensure resilient performance of grid edge EMS in the presence of attacks. This proposed security enhancement framework for grid edge EMS is evaluated in IEEE 13 bus system with three integrated DERs. Numerical simulation shows the validation of the proposed framework by reducing voltage violation in real operation of grid edge EMS.

cyber attack detection↗

Method of Performance-Aware Security of Unicast Communication in Hybrid Satellite Networks

A method and apparatus utilizes Layered IPSEC (LES) protocol as an alternative to IPSEC for network-layer security including a modification to the Internet Key Exchange protocol. For application-level security of web browsing with acceptable end-to-end delay, the Dual-mode SSL protocol (DSSL) is used instead of SSL. The LES and DSSL protocols achieve desired end-to-end communication security while allowing the TCP and HTTP proxy servers to function correctly.

Roy-Chowdhury, Ayan↗

SPAN security policies and guidelines

A guide is provided to system security with emphasis on requirements and guidelines that are necessary to maintain an acceptable level of security on the network. To have security for the network, each node on the network must be secure. Therefore, each system manager, must strictly adhere to the requirements and must consider implementing the guidelines discussed. There are areas of vulnerability within the operating system that may not be addressed. However, when a requirement or guideline is discussed, implementation techniques are included. Information related to computer and data security is discussed to provide information on implementation options. The information is presented as it relates to a VAX computer environment.

Sisson, Patricia L.↗

An Overview of SBIR Phase 2 Communications Technology and Development

Technological innovation is the overall focus of NASA's Small Business Innovation Research (SBIR) program. The program invests in the development of innovative concepts and technologies to help NASA's mission directorates address critical research and development needs for agency projects. This report highlights innovative SBIR Phase II projects from 2007-2012 specifically addressing areas in Communications Technology and Development which is one of six core competencies at NASA Glenn Research Center. There are eighteen technologies featured with emphasis on a wide spectrum of applications such as with a security-enhanced autonomous network management, secure communications using on-demand single photons, cognitive software-defined radio, spacesuit audio systems, multiband photonic phased-array antenna, and much more. Each article in this booklet describes an innovation, technical objective, and highlights NASA commercial and industrial applications. This report serves as an opportunity for NASA personnel including engineers, researchers, and program managers to learn of NASA SBIR's capabilities that might be crosscutting into this technology area. As the result, it would cause collaborations and partnerships between the small companies and NASA Programs and Projects resulting in benefit to both SBIR companies and NASA.

secure communications software defined radio anten↗

Service-Based, Segmented, 5G Network-Based Architecture for Securing Distributed Energy Resources: Preprint

As the number of connected devices in the energy grid increase exponentially, so too are the cybersecurity risks. With the development of modern communications standards such as 5G and beyond the extent to which devices will continue to connect will continue to increase exponentially along with the inherent risks. However, 5G also includes features to help address cybersecurity concerns and therefore helping to mitigate many of these risks. This paper proposes a new service-based network architecture implementing network-slicing capabilities for connected systems and devices to improve performance, availability, security, and reliability of the grid devices and services. This paper considers the quality of service requirements and criticality of services needed for securely monitoring, operating, and securing Distributed Energy Resource (DER) devices. From developed use cases, network slicing is implemented based on these requirements and resource allocations. This work then highlights examples of how slicing can help prevent standard existing attack methods such as a denial-of-service or similar attack which limits resource availability and network bandwidth to the service and thus limiting its ability to affect other services by misbehaving. The designed network architecture use case will be further tested on a local virtualized testbed to verify secure operation and availability of services. Using hardware-in-the-loop devices and systems on this local testbed, this fully segmented, secure network may be realized and evaluated. Finally, this paper presents the results of this testing.

5G↗