Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “security assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Vegetation Monitoring Optimization with Normalized Difference Vegetation Index and Evapotranspiration Using Remote Sensing Measurements and Land Surface Models Over East Africa

The majority of people in East Africa rely on the agro-pastoral system for their livelihood, which is highly vulnerable to droughts and flooding. Agro-pastoral droughts are endemic to the region and are considered the main natural hazard that contributes to food insecurity. Drought begins with rainfall deficit, gradually leading to soil moisture deficit, higher land surface temperature, and finally impacts to vegetation growth. Therefore, monitoring vegetation conditions is essential in understanding the progression of drought, potential effects on food security, and providing early warning information needed for drought mitigation decisions. Because vegetation processes couple the land and atmosphere, monitoring of vegetation conditions requires consideration of both water provision and demand. While there is consensus in using either the Normalized Difference Vegetation Index (NDVI) or evapotranspiration(ET) for vegetation monitoring, a comprehensive assessment optimizing the use of both has not yet been done. Moreover, the evaluation methods for understanding the relationships between NDVI and ET for vegetation monitoring are also limited. Taking these gaps into account we have developed a framework to optimize vegetation monitoring using both NDVI and ET by identifying where they perform the best by using triple collocation and cross-correlation methods. We estimated the random error structure in Moderate Resolution Imaging Spectroradiometer (MODIS) NDVI; ET from the Operational Simplified Surface Energy Balance (SSEBop) model; and ET from land surface models (LSMs). LSM ET and SSEBop ET have been found to be better indicators for vegetation monitoring during extreme drought events, while NDVI could provide better information on vegetation condition during wetter than normal conditions. The random error structures of these variables suggest that LSM ET is most likely to provide important information for vegetation monitoring over low and high ends of the vegetation fraction areas. Over moderate vegetative areas, any of these variables could provide important vegetation information for drought characterization and food security assessments. While this study provides a framework for optimizing vegetation monitoring for drought and food security assessments over East Africa, the framework can be adopted to optimize vegetation monitoring over any other drought and food insecure region of the world.

triple collocation↗

Handheld Raman Spectrometers: Assessment Report

In April 2022 the National Urban Security Technology Laboratory’s System Assessment and Validation for Emergency Responders program conducted an operational assessment of ten commercially available handheld Raman spectrometers. Additionally, prior to the operational assessment, the Pacific Northwest National Laboratory conducted laboratory testing of the devices, including scanning a number of samples in various containers. This report summarizes the results of the assessment.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Development of a Reference Design for a Cyber-Physical System

The purpose of this thesis is to develop a reference design to assist in the selection of security practices in power electronics design. A prototype will be developed from this reference design for evaluation. This evaluation will include a brief cost/benefit analysis to gauge the efficacy of implementing each layer of security throughout the power electronics design process. This thesis will also describe the obstacles and effectiveness of integrating a Trusted Platform Module (TPM) into a cyber-hardened grid-connected device. The TPM device is a secured crypto processor that assists in generating, storing, and restricting the use of cryptographic keys. The emphasis of this research is to establish integrity, authenticity, and confidentiality within a system by providing a baseline of security concerns for segments of the system. This research considers communication, control, and hardware level securities. The scope of this thesis will review the necessary security methods as well as consider the effects these methods have on the embedded system, to assess the desired security to responsiveness trade off. Applying this approach to a design process will alleviate various unknowns of appending security to a power electronics design. This thesis describes the specific vulnerabilities introduced within this grid-edge environment, and how the liabilities within the system can be mitigated. Initially, common security techniques will be considered to establish a guideline to benchmark performance and resource costs of the system. The foundation will be a non-hardened power electronic system platform with industry standard communication protocols. Several security techniques and attack vectors will then be evaluated to contribute to the base level platform. Other fail-safe features take place to gauge progress of the selected approach, non-inclusive to the TPM. Collectively, this investigation will determine a valid experiment by appraising and categorizing resource allocation, performance overhead, and monetary cost analysis results into a reference design. The prototype will then demonstrate methods to relieve common threats that are purposefully implemented into the design.

Blair, Nicholas Paul↗

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Assessing Impacts of Climate Change on Food Security Worldwide

The combination of a warming Earth and an increasing population will likely strain the world's food systems in the coming decades. Experts involved with the Agricultural Model Intercomparison and Improvement Project (AgMIP) focus on quantifying the changes through time. AgMIP, a program begun in 2010, involves about 800 climate scientists, economists, nutritionists, information technology specialists, and crop and livestock experts. In mid-September 2015, the Aspen Global Change Institute convened an AgMIP workshop to draft plans and protocols for assessing global- and regional-scale modeling of crops, livestock, economics, and nutrition across major agricultural regions worldwide. The goal of this Coordinated Global and Regional Integrated Assessments (CGRA) project is to characterize climate effects on large- and small-scale farming systems.

farm crops↗

Identifying University Chemicals That Pose Security Risks: A Simple Qualitative Approach

Various laboratory-focused tools and methodologies for completing a safety risk assessment have been published, yet few similar resources to address chemical security exist. Herein, we describe a chemical security risk assessment case study at a university in a developing country. In this case study, we demonstrate a chemical security risk assessment for a university chemistry department, using an original inventory of 645 entries which was condensed to 295 chemicals after removing duplicates and erroneous entries. We then prioritized to highlight 83 chemicals of interest based on hazardous or dual-use properties that could lead to unacceptable consequences. We further refined to a list of 34 high-risk chemicals that required action, 48 chemicals that may need further justification and consideration for additional protection, and 1 chemical that did not need further consideration for additional protection.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Evaluation of a Regional Crop Model Implementation for Sub-National Yield Assessments in Kenya

CONTEXT: Cropping system models can be used to both assess regional food security and to monitor and predict agricultural drought. Agriculture in Kenya is extremely important to both the economy and food security of the country. OBJECTIVE: This study evaluated a regional implementation of a widely used crop model, the Decision Support System for Agrotechnology Transfer (DSSAT), within a coupled modeling framework, the Regional Hydrologic Extremes Assessment System (RHEAS), over Kenya. The goal of this study was to assess the ability of RHEAS to simulate the annual variability of maize yields at the county level and evaluate the uncertainty inherent in the model and inputs. METHODS: The RHEAS system implements a stochastic ensemble approach to account for field scale variabilities in crop management practices and underlying soil and weather conditions. Satellite-derived datasets were used to evaluate the land surface component of the system and seasonally disaggregated yield for 5 years was used to assess the performance of the cropping system model. RESULTS AND CONCLUSIONS: The median correlation between RHEAS and satellite-derived soil moisture and evapotranspiration estimates were 0.78, and 0.51, respectively, indicating that the model is able to capture the key drivers of the hydrological budget. Overall, RHEAS simulated yearly yield variations with a median correlation of 0.7 with reported yields, with the best performance in the short rains season. However, across both seasons, the RHEAS model was positively biased on the order of ~1.6 MT/ha. The overall median unbiased RMSE was 0.66 MT/ha. The RHEAS system shows skill at simulating extreme departures in anomalies, and a majority of the time (62.5%) the reported yields fall within the interquartile range of the simulations. SIGNIFICANCE: One of the most important areas of improvement for the next generation of agricultural data and models is to better understand and communicate the inherent uncertainties. This is especially critical in data-limited regions. Here we present a modeling system and its implementation that begins to address these concerns. We demonstrate the ability to simulate broad trends in yields at the county level for sub-annual yields with skills that commensurate previous national/annual level studies.

Crop model↗

Smart Microgrids

The Nation’s electrical power depends on one bulk power grid to support security and economic prosperity. According to the Department of Homeland Security’s Homeland Threat Assessment of 2020, the largest cyber threat to homeland security is potential disruption to critical infrastructure, including power grids. Critical infrastructure includes the physical and cyber systems which generate, transmit, and distribute electricity with an impact on economic security, public health, or safety. The surety of the Nation’s power grid is vital for providing essential services and would put the population at risk if disrupted. Power outages can have catastrophic consequences for critical organizations such as hospitals and military installations. Additionally, the current fossil-fuel dependent power grid is extremely fragile and vulnerable to overloads, storms that destroy power lines, and cyber-attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Using Satellite Remote Sensing Data in a Spatially Explicit Price Model

Famine early warning organizations use data from multiple disciplines to assess food insecurity of communities and regions in less-developed parts of the World. In this paper we integrate several indicators that are available to enhance the information for preparation for and responses to food security emergencies. The assessment uses a price model based on the relationship between the suitability of the growing season and market prices for coarse grain. The model is then used to create spatially continuous maps of millet prices. The model is applied to the dry central and northern areas of West Africa, using satellite-derived vegetation indices for the entire region. By coupling the model with vegetation data estimated for one to four months into the future, maps are created of a leading indicator of potential price movements. It is anticipated that these maps can be used to enable early warning of famine and for planning appropriate responses.

Brown, Molly E.↗

Control and Non-Payload Communications (CNPC) Prototype Radio - Generation 2 Security Architecture Lab Test Report

NASA Glenn Research Center, in cooperation with Rockwell Collins, is working to develop a prototype Control and Non-Payload Communications (CNPC) radio platform as part of NASA Integrated Systems Research Program's (ISRP) Unmanned Aircraft Systems (UAS) Integration in the National Airspace System (NAS) project. A primary focus of the project is to work with the FAA and industry standards bodies to build and demonstrate a safe, secure, and efficient CNPC architecture that can be used by industry to evaluate the feasibility of deploying a system using these technologies in an operational capacity. GRC has been working in conjunction with these groups to assess threats, identify security requirements, and to develop a system of standards-based security controls that can be applied to the current GRC prototype CNPC architecture as a demonstration platform. The security controls were integrated into a lab test bed mock-up of the Mobile IPv6 architecture currently being used for NASA flight testing, and a series of network tests were conducted to evaluate the security overhead of the controls compared to the baseline CNPC link without any security. The aim of testing was to evaluate the performance impact of the additional security control overhead when added to the Mobile IPv6 architecture in various modes of operation. The statistics collected included packet captures at points along the path to gauge packet size as the sample data traversed the CNPC network, round trip latency, jitter, and throughput. The effort involved a series of tests of the baseline link, a link with Robust Header Compression (ROHC) and without security controls, a link with security controls and without ROHC, and finally a link with both ROHC and security controls enabled. The effort demonstrated that ROHC is both desirable and necessary to offset the additional expected overhead of applying security controls to the CNPC link.

Communication Networks↗

Control and Non-Payload Communications (CNPC) Prototype Radio - Generation 2 Security Flight Test Report

NASA Glenn Research Center (GRC), in cooperation with Rockwell Collins, is working to develop a prototype Control and Non-Payload Communications (CNPC) radio platform as part of NASA Integrated Systems Research Program's (ISRP) Unmanned Aircraft Systems (UAS) Integration in the National Airspace System (NAS) project. A primary focus of the project is to work with the Federal Aviation Administration (FAA) and industry standards bodies to build and demonstrate a safe, secure, and efficient CNPC architecture that can be used by industry to evaluate the feasibility of deploying a system using these technologies in an operational capacity. GRC has been working in conjunction with these groups to assess threats, identify security requirements, and to develop a system of standards-based security controls that can be applied to the GRC prototype CNPC architecture as a demonstration platform. The proposed security controls were integrated into the GRC flight test system aboard our S-3B Viking surrogate aircraft and several network tests were conducted during a flight on November 15th, 2014 to determine whether the controls were working properly within the flight environment. The flight test was also the first to integrate Robust Header Compression (ROHC) as a means of reducing the additional overhead introduced by the security controls and Mobile IPv6. The effort demonstrated the complete end-to-end secure CNPC link in a relevant flight environment.

Communication Networks↗

End-to-end Analytics for Grid Arch Design & All-hazard Assessment

Resiliency, reliability, and security of the next-generation smart grid depend upon leveraging advanced communication and computing technologies, integrating them with physical power systems, and developing real-time, fast, data-based applications to help in wide-area monitoring and control of the grid. Using a high sampling data rate from phasor measurement units (PMUs) to develop applications has opened the door to achieving the next-generation grid requirements. The North American Synchrophasor Initiative Network (NASPlnet) was developed in 2007-09 to create a standard and guide for PMU data exchanges. With the advancement in both networking and grid requirements, it is necessary to evaluate the performance of different NASPInet versions and their impact on applications. Therefore, we need a cyber-power cosimulation framework that supports very large-scale co-simulation capable of running in parallel, high-performance computing platforms and capturing real-life network behavior. This work presents a cyber-physical co-simulation testbed using NS3 to model the communication network, GridPACK to model the power grid, and HELICS as a co-simulation engine. Comparative analysis of latency in synchrophasor networks and a performance evaluation of a power system stabilizer application based on PMU data in an Institute of Electrical and Electronics Engineers 39-bus test system is presented using this co-simulation testbed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Adaptable Standards for Discovery, Access, and Usability of Oak Ridge National Laboratory’s Data Portals and Catalogs

Oak Ridge National Laboratory (ORNL) is leveraging its established capabilities and subject matter expertise in data curation, governance, management, national security, and risk assessment and mitigation to support the US Department of Energy (DOE) Grid Modernization Initiative. Using standards modeled by the National Institute of Standards and Technology (NIST), the Data Curation Network (DCN), the Oak Ridge Leadership Computing Facility (OLCF), and other leading organizations in the fields of energy research, high-performance computing, and national and homeland security, ORNL seeks to provide a federated approach to research data discovery, use, and interoperability.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

New Local, National and Regional Cereal Price Indices for Improved Identification of Food Insecurity

Large price increases over a short time period can be indicative of a deteriorating food security situation. Food price indices developed by the United Nations Food and Agriculture Organization (FAO) are used to monitor food price trends at a global level, but largely reflect supply and demand conditions in export markets. However, reporting by the United States Agency for International Development (USAID)'s Famine Early Warning Systems Network (FEWS NET) indicates that staple cereal prices in many markets of the developing world, especially in surplus-producing areas, often have a delayed and variable response to international export market price trends. Here we present new price indices compiled for improved food security monitoring and assessment, and specifically for monitoring conditions of food access across diverse food insecure regions. We found that cereal price indices constructed using market prices within a food insecure region showed significant differences from the international cereals price, and had a variable price dispersion across markets within each marketshed. Using satellite-derived remote sensing information that estimates local production and the FAO Cereals Index as predictors, we were able to forecast movements of the local or national price indices in the remote, arid and semi-arid countries of the 38 countries examined. This work supports the need for improved decision-making about targeted aid and humanitarian relief, by providing earlier early warning of food security crises.

Brown, Molly E.↗

A Comprehensive Assessment of the Viability of Small Modular Reactors in Africa: A Nuclear Security and Nonproliferation Perspective

In response to escalating global energy demands driven by industrialization and the pressing need for decarbonization, this paper explores the potential of Small Modular Reactors (SMRs) as a sustainable energy solution in Africa. Focusing on nuclear security and non-proliferation concerns, the study assesses Africa's energy landscape, emphasizing the need for diverse and reliable power sources. While highlighting the scalability and cost-effectiveness of SMRs, the analysis acknowledges potential challenges associated with their introduction, particularly concerning nuclear security and non-proliferation. Given the recommendation to use High Assay Low Enriched Uranium (HALEU) in some SMRs, it is important to critically consider the security implications of transporting nuclear materials, the proximity of the public to the plant, and the time taken to respond to planned assaults. The possibility of using HALEU makes the nuclear material more prone to adversaries such as sabotage, theft, and terrorism. Utilizing PESTLE analysis, this research seeks to outline the detailed political, economic, social, technological, environmental, and legal readiness of Africa to embrace the first-of-a-kind technology (SMR) while fulfilling its mandate to the Non-Proliferation Treaty (NPT). Examining regulatory frameworks, international cooperation, and safety protocols, the study underscores the importance of regional collaboration to prevent the misuse of nuclear technology for military and malicious intent. Drawing insights from successful case studies, the paper concludes by synthesizing key findings and proposing recommendations for policymakers and stakeholders. These recommendations encompass regulatory enhancement, capacity building, technology transfer, and diplomatic efforts to strengthen nuclear security, non-proliferation, and safeguards in Africa.

Prah, Christina↗

U.S. Nuclear Declaratory Policy 2021: the Renewed Debate about Sole Purpose and No-First-Use. Annotated Bibliography

Declaratory policy and public statements about the potential use of nuclear weapons serve many important roles. They provide an assessment of the security environment, and inform the public debate. These statements also enhance deterrence messages and signals towards adversaries, and reassure allies and partners. On the global level, U.S. declaratory policy has the potential to shape international trends and norms, influence nuclear proliferation, and it may also affect the policy decisions of other nuclear possessors. As the Biden administration reviews the elements of U.S. nuclear declaratory policy, the issue of sole purpose and no-first-use is likely to resurface. Previous administrations have examined these policies in multiple rounds of review, and they decided that the time was not right for such declarations. This literature review was prepared to inform the debate by collecting some of the most prominent articles on the topic that highlight the potential risks and benefits of these policies.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

High-Resolution Modeling of the Gulf of Mexico using E3SM

Coastal ocean modeling is a high priority in the DOE‘s Energy Exascale Earth System Model (E3SM). The goal is to accurately predict the risk of damage to coastal resources and infrastructure due to a changing climate in the coming decades. North American coastal communities are areas of particular interest, as this fits under the topic of US national security and planning assessments in a changing climate. LANL Institutional Computing time for the Tier 1 allocation ”Coastal Ocean and Sea Ice Modeling” have been used for development and testing of numerical methods needed for E3SM coastal applications.

54 ENVIRONMENTAL SCIENCES↗

Virtualization - A Key Cost Saver in NASA Multi-Mission Ground System Architecture

With science team budgets being slashed, and a lack of adequate facilities for science payload teams to operate their instruments, there is a strong need for innovative new ground systems that are able to provide necessary levels of capability processing power, system availability and redundancy while maintaining a small footprint in terms of physical space, power utilization and cooling.The ground system architecture being presented is based off of heritage from several other projects currently in development or operations at Goddard, but was designed and built specifically to meet the needs of the Science and Planetary Operations Control Center (SPOCC) as a low-cost payload command, control, planning and analysis operations center. However, this SPOCC architecture was designed to be generic enough to be re-used partially or in whole by other labs and missions (since its inception that has already happened in several cases!)The SPOCC architecture leverages a highly available VMware-based virtualization cluster with shared SAS Direct-Attached Storage (DAS) to provide an extremely high-performing, low-power-utilization and small-footprint compute environment that provides Virtual Machine resources shared among the various tenant missions in the SPOCC. The storage is also expandable, allowing future missions to chain up to 7 additional 2U chassis of storage at an extremely competitive cost if they require additional archive or virtual machine storage space.The software architecture provides a fully-redundant GMSEC-based message bus architecture based on the ActiveMQ middleware to track all health and safety status within the SPOCC ground system. All virtual machines utilize the GMSEC system agents to report system host health over the GMSEC bus, and spacecraft payload health is monitored using the Hammers Integrated Test and Operations System (ITOS) Galaxy Telemetry and Command (TC) system, which performs near-real-time limit checking and data processing on the downlinked data stream and injects messages into the GMSEC bus that are monitored to automatically page the on-call operator or Systems Administrator (SA) when an off-nominal condition is detected. This architecture, like the LTSP thin clients, are shared across all tenant missions.Other required IT security controls are implemented at the ground system level, including physical access controls, logical system-level authentication authorization management, auditing and reporting, network management and a NIST 800-53 FISMA-Moderate IT Security plan Risk Assessment Contingency Plan, helping multiple missions share the cost of compliance with agency-mandated directives.The SPOCC architecture provides science payload control centers and backup mission operations centers with a cost-effective, standardized approach to virtualizing and monitoring resources that were traditionally multiple racks full of physical machines. The increased agility in deploying new virtual systems and thin client workstations can provide significant savings in personnel costs for maintaining the ground system. The cost savings in procurement, power, rack footprint and cooling as well as the shared multi-mission design greatly reduces upfront cost for missions moving into the facility. Overall, the authors hope that this architecture will become a model for how future NASA operations centers are constructed!

Ground System Architecture↗