Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

CFD Data Sets on the WWW for Education and Testing

The Numerical Aerodynamic Simulation (NAS) Systems Division at NASA Ames Research Center has begun the development of a Computational Fluid Dynamics (CFD) data set archive on the World Wide Web (WWW) at URL http://www.nas.nasa.gov/NAS/DataSets/. Data sets are integrated with related information such as research papers, metadata, visualizations, etc. In this paper, four classes of users are identified and discussed: students, visualization developers, CFD practitioners, and management. Bandwidth and security issues are briefly reviewed and the status of the archive as of May 1995 is examined. Routine network distribution of data sets is likely to have profound implications for the conduct of science. The exact nature of these changes is subject to speculation, but the ability for anyone to examine the data, in addition to the investigator's analysis, may well play an important role in the future.

Globus, Al↗

Real-Time Xenon Sensor Analysis Report

Radiotracer release experiments were performed at the Nevada National Security Site in October 2022. The overall experiment was called the RElease ACTivity (REACT) experiment. Twenty-two real-time xenon sensors were deployed for each of four releases. Initial, quick-look analysis results were reported in December 2022. This report reviews the more comprehensive offline analysis effort that was conducted during the remainder of fiscal year 2023 by the Dynamic Networks venture. Improved energy stabilization routines were implemented along with an improved background subtraction routine compared to the original quicklook calculations. The relative detection efficiencies of all real-time sensors were examined. Finally, simulated detector response functions were coupled to two different meteorological models using the measured conditions for the final release (REACT-04) to compare simulated detections with measurements. While there is some agreement between the models and measured data on the detection locations and timing, there is less agreement on the magnitude of those detections. Future sensor and meteorological modeling work will be needed to improve the agreement and to examine the additional releases (REACT-01 through REACT-03).

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Compact Microscope Imaging System With Intelligent Controls Improved

The Compact Microscope Imaging System (CMIS) with intelligent controls is a diagnostic microscope analysis tool with intelligent controls for use in space, industrial, medical, and security applications. This compact miniature microscope, which can perform tasks usually reserved for conventional microscopes, has unique advantages in the fields of microscopy, biomedical research, inline process inspection, and space science. Its unique approach integrates a machine vision technique with an instrumentation and control technique that provides intelligence via the use of adaptive neural networks. The CMIS system was developed at the NASA Glenn Research Center specifically for interface detection used for colloid hard spheres experiments; biological cell detection for patch clamping, cell movement, and tracking; and detection of anode and cathode defects for laboratory samples using microscope technology.

McDowell, Mark↗

Management of the Space Physics Analysis Network (SPAN)

Here, the purpose is to define the operational management structure and to delineate the responsibilities of key Space Physics Analysis Network (SPAN) individuals. The management structure must take into account the large NASA and ESA science research community by giving them a major voice in the operation of the system. Appropriate NASA and ESA interfaces must be provided so that there will be adequate communications facilities available when needed. Responsibilities are delineated for the Advisory Committee, the Steering Committee, the Project Scientist, the Project Manager, the SPAN Security Manager, the Internetwork Manager, the Network Operations Manager, the Remote Site Manager, and others.

Green, James L.↗

Hybrid Network Architectures for the Next Generation NAS

To meet the needs of the 21st Century NAS, an integrated, network-centric infrastructure is essential that is characterized by secure, high bandwidth, digital communication systems that support precision navigation capable of reducing position errors for all aircraft to within a few meters. This system will also require precision surveillance systems capable of accurately locating all aircraft, and automatically detecting any deviations from an approved path within seconds and be able to deliver high resolution weather forecasts - critical to create 4- dimensional (space and time) profiles for up to 6 hours for all atmospheric conditions affecting aviation, including wake vortices. The 21st Century NAS will be characterized by highly accurate digital data bases depicting terrain, obstacle, and airport information no matter what visibility conditions exist. This research task will be to perform a high-level requirements analysis of the applications, information and services required by the next generation National Airspace System. The investigation and analysis is expected to lead to the development and design of several national network-centric communications architectures that would be capable of supporting the Next Generation NAS.

Madubata, Christian↗

Subsurface microbial communities as a tool for characterizing regional-scale groundwater flow

Subsurface microbial community distribution patterns are influenced by biogeochemical and groundwater fluxes and may inform hydraulic connections along groundwater-flow paths. This study examined the regional-scale microbial community of the Death Valley Regional Flow System and evaluated whether subsurface communities can be used to identify groundwater-flow paths between recharge and discharge areas. Samples were collected from 36 sites in three groundwater basins: Pahute Mesa–Oasis Valley (PMOV), Ash Meadows (AM), and Alkali Flat–Furnace Creek Ranch (AFFCR). Microbial diversity within and between communities varied by location, and communities were separated into two overall groups that affiliated with the AM and PMOV/AFFCR basins. Network analysis revealed patterns between clusters of common microbes that represented groundwaters with similar geochemical conditions and largely corroborated hydraulic connections between recharge and discharge areas. Null model analyses identified deterministic and stochastic ecological processes contributing to microbial community assemblages. Most communities were more different than expected and governed by dispersal limitation, geochemical differences, or undominating processes. However, certain communities from sites located within or near the Nevada National Security Site were more similar than expected and dominated by homogeneous dispersal or selection. Overall, the (dis)similarities between the microbial communities of DVRFS recharge and discharge areas supported previously documented hydraulic connections between: (1) Spring Mountains and Ash Meadows; (2) Frenchman and Yucca Flat and Amargosa Desert; and (3) Amargosa Desert and Death Valley. However, only a portion of the flow path between Pahute Mesa and Oasis Valley could be supported by microbial community analyses, likely due to well-associated artifacts in samples from the two Oasis Valley sites. This study demonstrates the utility of combining microbial data with hydrologic, geologic, and water-chemistry information to comprehensively characterize groundwater systems, highlighting both strengths and limitations of this approach.

54 ENVIRONMENTAL SCIENCES↗

MiniMOD

SAND2025-03854O MiniMod is a user-friendly software tool designed to assess the performance of high-performance computing (HPC) systems. Researchers can use the program to test communication methods and computational tasks to understand how different setups can affect application efficiency. This software is particularly useful for optimizing network performance in scientific research, simulations, and data analysis. MiniMod‘s flexible design allows users to make informed decisions about their computing environments, which can enhance productivity and results in real-world applications. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Dosanjh, Matthew [Sandia National Lab. (SNL-CA), L↗

Space Station Freedom environmental database system (FEDS) for MSFC testing

The Water Recovery Test (WRT) at Marshall Space Flight Center (MSFC) is the first demonstration of integrated water recovery systems for potable and hygiene water reuse as envisioned for Space Station Freedom (SSF). In order to satisfy the safety and health requirements placed on the SSF program and facilitate test data assessment, an extensive laboratory analysis database was established to provide a central archive and data retrieval function. The database is required to store analysis results for physical, chemical, and microbial parameters measured from water, air and surface samples collected at various locations throughout the test facility. The Oracle Relational Database Management System (RDBMS) was utilized to implement a secured on-line information system with the ECLSS WRT program as the foundation for this system. The database is supported on a VAX/VMS 8810 series mainframe and is accessible from the Marshall Information Network System (MINS). This paper summarizes the database requirements, system design, interfaces, and future enhancements.

Story, Gail S.↗

Neural Network Approaches for Mobile Spectroscopic Gamma-Ray Source Detection

Artificial neural networks (ANNs) for performing spectroscopic gamma-ray source identification have been previously introduced, primarily for applications in controlled laboratory settings. To understand the utility of these methods in scenarios and environments more relevant to nuclear safety and security, this work examines the use of ANNs for mobile detection, which involves highly variable gamma-ray background, low signal-to-noise ratio measurements, and low false alarm rates. Simulated data from a 2” × 4” × 16” NaI(Tl) detector are used in this work for demonstrating these concepts, and the minimum detectable activity (MDA) is used as a performance metric in assessing model performance.In addition to examining simultaneous detection and identification, binary spectral anomaly detection using autoencoders is introduced in this work, and benchmarked using detection methods based on Non-negative Matrix Factorization (NMF) and Principal Component Analysis (PCA). On average, the autoencoder provides a 12% and 23% improvement over NMF- and PCA-based detection methods, respectively. Additionally, source identification using ANNs is extended to leverage temporal dynamics by means of recurrent neural networks, and these time-dependent models outperform their time-independent counterparts by 17% for the analysis examined here. The paper concludes with a discussion on tradeoffs between the ANN-based approaches and the benchmark methods examined here.

Bilton, Kyle J. (ORCID:0000000184553689)↗

A Cybersecurity Threat Profile for a Connected Lighting System

In anticipation of improved energy performance and cost savings, cities and building owners are increasingly considering “smart lighting initiatives” that aim to convert their collection of simple luminaires (i.e., lighting fixtures) into an intelligent connected lighting system (CLS) capable of remotely monitoring energy consumption and fault conditions, and possibly implementing adaptive lighting schemes. The U.S. Department of Energy (DOE) has set an national goal of tripling the energy efficiency and demand flexibility of the buildings sector by 2030, relative to 2020 levels 1. It is forecast that connected lighting systems can contribute to that goal by delivering 125 TWh of annual energy savings by 2035 2, equivalent to the annual output of 50 typical (500 MW) power plants. However, these energy savings and the DOE goal are put at significant risk if connected technologies are not adopted due to real or perceived cybersecurity concerns. Connected IoT devices such as these have historically been rife with vulnerabilities which sometimes put security considerations secondary to functionality and operability. What are the cybersecurity threats that will impact these systems, as formerly banal luminaires transition into intelligent connected devices that collect information about themselves, their surrounding environment, and possibly us? In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement. Fifty-seven threats were identified. Among our key findings: (1) 65% (37/57) of the threats did not involve the luminaires, but rather the other components needed to communicate with and manage them; (2) 63% (36/57) of the threats could have been mitigated through manufacturer-implemented defensive techniques or “controls”; and (3) 23% (13/57) of the threats were dependent on the network configuration. Recommendations based on the results of this work are made to key stakeholder groups. Notably, lighting technology developers are advised to address all threats that can be reasonably controlled with baked-in technology solutions (e.g., encryption or authentication controls), and employ some form of secure supply chain management and tracking where other parts (e.g., sensors, microprocessors) of a luminaire must also be built and manufactured with the proper security controls in place. Developers should also review threats involving assets not developed in-house to understand how connectivity with other devices will affect their product during system operation and determine if a compensating control for a defense-in-depth strategy will be needed. Finally, those interested in deploying CLS should compare the differences between cloud and on-premise models to determine which is more suitable for their needs and the abilities of their security team.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Tight Practical Bounds for Subgraph Densities in Ego-centric Networks

SAND2025-11782O Tight Practical Bounds for Subgraph Densities in Ego-centric Networks is a software tool for calculating the “subgraph spread ratio” for social network analysis. This value is useful in network analysis for determining the amount of exogenous and endogenous pressure on a graph. It can distinguish between networks coming from different sources, e.g. distinguishing a graph of Facebook data versus a graph of Wikipedia data. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Mattes, Connor↗

PLC Vulnerabilities and Mitigations

Programmable Logic Controllers (PLCs) are used extensively in many high-importance industrial and nonindustrial settings including controlling elevators, manufacturing machines, and utility facilities such as power and natural gas, however cybersecurity protection for them has been neglected. Within recent years, PLCs have been put under more security scrutiny and experts have advocated for changes from the addition of protocol encryption and network segmentation to intrusion detection systems on the PLCs themselves. While PLC security is critical, a large portion of the PLCs available today will never receive these changes due to being legacy or the difficulty of overhauling the security on existing systems. Due to the infeasibility of applying many recommended security measures towards currently available machines, we aim to provide realistic and affordable best practices for hardening PLCs. We will first conduct security analysis and consider attack vectors within our target PLC. Once we’ve analyzed the device’s security, we will evaluate a variety of mitigation methods and create guidelines to effectively reduce the threat posed by PLC attacks with minimal disruption to operations.

42 ENGINEERING↗

Towards a New Supply Chain Cybersecurity Risk Analysis Technique

Supply chain cyber-attacks, such as the SolarWinds Orion attack, are occurring with greater frequency. These attacks compromise a digital device before it is sent to customers, bypassing traditional security controls to remain persistent and undetected in operational environments. While supply chain attacks are prevalent, methods for analyzing the risk of these attacks are currently unavailable. This paper proposes new supply chain cyber-attack difficulty and risk metrics to evaluate the relative risk of an attack throughout the supply chain lifecycle. Difficulty metrics for each stakeholder in a digital device’s supply chain (e.g., hardware manufacturing, firmware development, software development, storage, and distribution entities) are calculated using scores from cybersecurity maturity questionnaires in a Bayesian Network leaky Noisy-MAX model. These difficulty metrics are then used to calculate an overall supply chain cyber-attack risk. Vulnerability and recoverability metrics are also proposed to evaluate the relative stakeholder influence in the attack risk. These proposed relative risk metrics enable continuous supply chain monitoring, provide decision-makers with information necessary for improved supplier selection, and help drive improvements in the cybersecurity posture of the stakeholders in their supply chain.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Envisioning a 21st Century, National, Spacecraft Servicing and Protection Infrastructure and Demand Potential: A Logical Development of the Earth Orbit Economy

The modern world is extremely dependent on thin strings of several hundred civil, military, and commercial spacecraft/satellites currently stationed in space. They provide a steady stream of commerce, defense, and knowledge data. This dependency will in all likelihood increase significantly during this century. A major disruption of any kind in these essential systems and networks could be socially, economically, and politically catastrophic, on a global scale. The development of a space-based, robotic services economy could be useful in mitigating this growing risk, from an efficiency and security standpoint. This paper attempts to suggest what makes sense to invest in next for the logical, economic development of Earth orbit i.e., after ISS completion. It expands on the results of an advanced market research and analysis study that sampled the opinions of several satellite industry executives and presents these results within a broad policy context. The concept of a spacecraft carrier that serves as the nucleus of a national, space-based or on-orbit, robotic services infrastructure is introduced as the next logical step for United States leadership in space. This is viewed as a reasonable and appropriate followon to the development of ELVs and satellites in the 1950s and 1960s, the Space Shuttle/PRLV in the 1970s and 1980s, and the International Space Station (ISS) in the 1980s, 1990s and 2000s. Large-scale experience in LEO-to-GEO spacecraft/satellite servicing and protection by robotic means is assumed to be an indispensable prerequisite or stepping-stone toward the development and preservation of the large scientific exploration facilities that are envisioned by NASA for operation beyond GEO. A balanced, return on national investment (RONI) strategy for space, focused on the provision of enhanced national/homeland security for increased protection, national economic/industrial expansion for increased revenue, and national scientific exploration for increased knowledge is recommended as the next strong, irrepressible goal toward realizing and achieving the official NASA vision and mission.

Horsham, Gary A.↗

Detection and Diagnosis of Data Integrity Attacks in Solar Farms Based on Multilayer Long Short-Term Memory Network

Photovoltaic (PV) systems are becoming more vulnerable to cyber threats. In response to this emerging concern, developing cyber-secure power electronics converters has received increased attention from the IEEE Power Electronics Society that recently launched a cyber-physical-security initiative. Here this letter proposes a deep sequence learning based diagnosis solution for data integrity attacks on PV systems in smart grids, including dc–dc and dc–ac converters. The multilayer long short-term memory networks are used to leverage time-series electric waveform data from current and voltage sensors in PV systems. The proposed method has been evaluated in a PV smart grid benchmark model with extensive quantitative analysis. As a comparison, we have evaluated classic data-driven methods, including K-nearest neighbor, decision tree, support vector machine, artificial neural network, and convolutional neural network. Comparison results verify performances of the proposed method for detection and diagnosis of various data integrity attacks on PV systems.

42 ENGINEERING↗

scANN

SAND2025-00656O scANN, also known as sampling by coinflips artificial neural networks, is a software tool that estimates uncertainty in artificial intelligence by performing Monte Carlo analysis on the weight matrices of feedforward neural networks. This computationally intensive process aims to explore the potential value added by future probabilistic hardware. The program’s output helps researchers gain insights into how probabilistic neural networks work. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

SciDAC↗

Runtime Analysis with R2U2: A Tool Exhibition Report

We present R2U2 (Realizable, Responsive, Unobtrusive Unit), a hardware- supported tool and framework for the continuous monitoring of safetycritical and embedded cyber-physical systems.With the widespread advent of autonomous systems such as Unmanned Aerial Systems (UAS), satellites, rovers, and cars, real-time, on-board decision making requires unobtrusive monitoring of properties for safety, performance, security, and system health. R2U2 models combine past-time and future-time Metric Temporal Logic, “mission time” Linear Temporal Logic, probabilistic reasoning with Bayesian Networks, and modelbased prognostics. The R2U2 monitoring engine can be instantiated as a hardware solution, running on an FPGA, or as a software component. The FPGA realization enables R2U2 to monitor complex cyber-physical systems without any overhead or instrumentation of the flight software. In this tool exhibition report, we present R2U2 and demonstrate applications on system runtime monitoring, diagnostics, software health management, and security monitoring for a UAS. Our tool demonstration uses a hardware-based processor-in-the-loop “iron-bird” configuration.

Johann Martin Schumann↗

Evolution of the large Deep Space Network antennas

The evolution of the largest antenna of the US NASA Deep Space Network (DSN) is described. The design, performance analysis, and measurement techniques, beginning with its initial 64-m operation at S-band (2295 MHz) in 1966 and continuing through the present ka-band (32-GHz) operation at 70 m, is described. Although their diameters and mountings differ, these parabolic antennas all employ a Cassegrainian feed system, and each antenna dish surface is constructed of precision-shaped perforated-aluminum panels that are secured to an open steel framework

Imbriale, William A.↗