Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “IP networks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

EV SALaD 2023 Demonstration: Best Practices and Mitigations for Protecting EVSE Infrastructure

The Electric Vehicle Secure Architecture Laboratory Demonstration (EV SALaD) program is a demonstration of cybersecurity best practices for high-power electric vehicle (EV) charging infrastructure led by Idaho National Laboratory (INL), in collaboration with other DOE National Laboratories participating in the EVs at Scale Consortium.a Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL) participated in the first 2-year (FY22-23) demonstration cycle for EV SALaD. This report documents the FY23 demonstration, the second in a series of demonstrations and collaborations in deploying and operating cybersecure EV charging infrastructure. It includes a summary of improvements from the FY22 demonstration, technical analysis of the FY23 demonstration, how the research demonstrates cyber-physical and cybersecurity best practices for high-power EV charging infrastructure, and related impacts to national and energy security. For EV SALaD, the FY22 demonstration focused on the detection, ranking, and prioritization of anomalous events for high-power EV charging. The FY23 demonstration additionally included the demonstration of cybersecurity best practices, which included protection and mitigation solutions to prevent, respond, and recover from anomalous events. During the demonstrations, the multi-lab EV SALaD team conducted a Test Effect Payload (TEP)b evaluation on extreme fast charger (XFC) hardware equipped with Cerberus, a detection and response solution, to demonstrate anomaly detection and mitigation cybersecurity best practices against cyber-enabled events.

33 ADVANCED PROPULSION SYSTEMS↗

System Administrator for LCS Development Sets

The Spaceport Command and Control System Project is creating a Checkout and Control System that will eventually launch the next generation of vehicles from Kennedy Space Center. KSC has a large set of Development and Operational equipment already deployed in several facilities, including the Launch Control Center, which requires support. The position of System Administrator will complete tasks across multiple platforms (Linux/Windows), many of them virtual. The Hardware Branch of the Control and Data Systems Division at the Kennedy Space Center uses system administrators for a variety of tasks. The position of system administrator comes with many responsibilities which include maintaining computer systems, repair or set up hardware, install software, create backups and recover drive images are a sample of jobs which one must complete. Other duties may include working with clients in person or over the phone and resolving their computer system needs. Training is a major part of learning how an organization functions and operates. Taking that into consideration, NASA is no exception. Training on how to better protect the NASA computer infrastructure will be a topic to learn, followed by NASA work polices. Attending meetings and discussing progress will be expected. A system administrator will have an account with root access. Root access gives a user full access to a computer system and or network. System admins can remove critical system files and recover files using a tape backup. Problem solving will be an important skill to develop in order to complete the many tasks.

Virtualizing in Linux↗

Integrating System to Edge-of-Network Architecture and Management for SHINES (SEAMS) Technologies of High Penetration Grids

Consistent with the U.S. DOE’s EERE SHINES FOA objectives, the goal of this project was to enable integration from EMS to variable DER in a way that delivered visibility and opportunities for managing and controlling distributed resources using SEAMS technologies. This project implemented several SHINES technologies, which included: (1) three Stem battery systems; (2) six ConnectDER PV collars; (3) two E-Gear PV/Battery storage interfaces; and (4) eight Kitu smart inverter emulators. A Siemens Energy IP DEMS was deployed in a development environment and integrated with the SHINES technologies via OpenADR and IEEE 2030.5 protocols with documented architecture. In the case of IEEE 2030.5, a suite of technologies including a gateway, an API, software and a server from Kitu Systems (the Citadel, Convoy, Kitu Crosslink API, and Kitu Spark) were used to demonstrate that the utility could achieve visibility of distributed energy resources (DER) and control of single and multiple DER systems with a single command. The project also included a LCOE analysis of SHINES technologies compared to traditional system and circuit mitigation measures.

14 SOLAR ENERGY↗

NASA Tech Briefs, October 2010

Topics covered include: Hybrid Architecture Active Wavefront Sensing and Control; Carbon-Nanotube-Based Chemical Gas Sensor; Aerogel-Positronium Technology for the Detection of Small Quantities of Organic and/or Toxic Materials; Graphene-Based Reversible Nano-Switch/Sensor Schottky Diode; Inductive Non-Contact Position Sensor; High-Temperature Surface-Acoustic-Wave Transducer; Grid-Sphere Electrodes for Contact with Ionospheric Plasma; Enabling IP Header Compression in COTS Routers via Frame Relay on a Simplex Link; Ka-Band SiGe Receiver Front-End MMIC for Transponder Applications; Robust Optimization Design Algorithm for High-Frequency TWTs; Optimal and Local Connectivity Between Neuron and Synapse Array in the Quantum Dot/Silicon Brain; Method and Circuit for In-Situ Health Monitoring of Solar Cells in Space; BGen: A UML Behavior Network Generator Tool; Platform for Post-Processing Waveform-Based NDE; Electrochemical Hydrogen Peroxide Generator; Fabrication of Single, Vertically Aligned Carbon Nanotubes in 3D Nanoscale Architectures; Process to Create High-Fidelity Lunar Dust Simulants; Lithium-Ion Electrolytes Containing Phosphorous-Based, Flame-Retardant Additives; InGaP Heterojunction Barrier Solar Cells; Straight-Pore Microfilter with Efficient Regeneration; Determining Shear Stress Distribution in a Laminate; Self-Adjusting Liquid Injectors for Combustors; Handling Qualities Prediction of an F-16XL-Based Reduced Sonic Boom Aircraft; Tele-Robotic ATHLETE Controller for Kinematics - TRACK; Three-Wheel Brush-Wheel Sampler; Heterodyne Interferometer Angle Metrology; Aligning Astronomical Telescopes via Identification of Stars; Generation of Optical Combs in a WGM Resonator from a Bichromatic Pump; Large-Format AlGaN PIN Photodiode Arrays for UV Images; Fiber-Coupled Planar Light-Wave Circuit for Seed Laser Control in High Spectral Resolution Lidar Systems; On Calculating the Zero-Gravity Surface Figure of a Mirror; Optical Modification of Casimir Forces for Improved Function of Micro- and Nano-Scale Devices; Analysis, Simulation, and Verification of Knowledge-Based, Rule-Based, and Expert Systems; Core and Off-Core Processes in Systems Engineering; Digital Reconstruction Supporting Investigation of Mishaps; and Template Matching Approach to Signal Prediction.

Source record↗

Classification of Small Negative Lightning Reports at the KSC-ER

The NASA Kennedy Space Center (KSC) and Air Force Eastern Range (ER) operate an extensive suite of lightning sensors because Florida experiences the highest area density of ground strikes in the United States, with area densities approaching 16 fl/sq km/yr when accumulated in 10x10 km (100 sq km) grids. The KSC-ER use data derived from two cloud-to-ground (CG) lightning detection networks, the "Cloud-to-Ground Lightning Surveillance System" (CGLSS) and the U.S. National Lightning Detection Network (TradeMark) (NLDN) plus a 3-dimensional lightning mapping system, the Lightning Detection and Ranging (LDAR) system, to provide warnings for ground operations and to insure mission safety during space launches. For operational applications at the KSC-ER it is important to understand the performance of each lightning detection system in considerable detail. In this work we examine a specific subset of the CGLSS stroke reports that have low values of the negative inferred peak current, Ip, i.e. values between 0 and -7 kA, and were thought to produce a new ground contact (NGC). When possible, the NLDN and LDAR systems were used to validate the CGLSS classification and to determine how many of these reported strokes were first strokes, subsequent strokes in a pre-existing channel (PEC), or cloud pulses that the CGLSS misclassified as CG strokes. It is scientifically important to determine the smallest current that can reach the ground either in the form of a first stroke or by way of a subsequent stroke that creates a new ground contact. In Biagi et al (2007), 52 low amplitude, negative return strokes ([Ip] < or = 10 kA) were evaluated in southern Arizona, northern Texas, and southern Oklahoma. The authors found that 50-87% of the small NLDN reports could be classified as CG (either first or subsequent strokes) on the basis of video and waveform recordings. Low amplitude return strokes are interesting because they are usually difficult to detect, and they are thought to bypass conventional lightning protection that relies on a sufficient attractive radius to prevent "shielding failure" (Golde, 1977). They also have larger location errors compared to the larger current events. In this study, we use the estimated peak current provided by the CGLSS and the results of our classification to determine the minimum Ip for each category of CG stroke and its probability of occurrence. Where possible, these results are compared to the findings in the literature.

Ward, Jennifer G.↗

Monitoring Floods with NASA's ST6 Autonomous Sciencecraft Experiment: Implications on Planetary Exploration

NASA's New Millennium Program (NMP) Autonomous Sciencecraft Experiment (ASE) [1-3] has been successfully demonstrated in Earth-orbit. NASA has identified the development of an autonomously operating spacecraft as a necessity for an expanded program of missions exploring the Solar System. The versatile ASE spacecraft command and control, image formation, and science processing software was uploaded to the Earth Observer 1 (EO-1) spacecraft in early 2004 and has been undergoing onboard testing since May 2004 for the near real-time detection of surface modification related to transient geological and hydrological processes such as volcanism [4], ice formation and retreat [5], and flooding [6]. Space autonomy technology developed as part of ASE creates the new capability to autonomously detect, assess, react to, and monitor dynamic events such as flooding. Part of the challenge has been the difficulty to observe flooding in real time at sufficient temporal resolutions; more importantly, it is the large spatial extent of most drainage networks coupled with the size of the data sets necessary to be downlinked from satellites that make it difficult to monitor flooding from space. Below is a description of the algorithms (referred to as ASE Flood water Classifiers) used in tandem with the Hyperion spectrometer instrument on EO-1 to identify flooding and some of the test results.

Ip, Felipe↗

GEWEX (Global Energy and Water Exchanges Project): Surface Radiation Budget (SRB) Release 4 Integrated Product (IP4) - Algorithm Theoretical Basis Document and Evaluation

The World Climate Research Programme’s (WCRP) Global Energy and Water Exchanges (GEWEX) program is an integrated program of research, observations, and science activities with the mission to “Observe, understand and model the hydrological cycle and energy fluxes in the Earth’s atmosphere and at the surface.” Since the public release in 2010 of SRB Release 3, GEWEX reorganized to formulate the Data and Assessments Panel (GDAP) aimed at performing community assessments of the long-term global data products with focus on integrating various data products to address issues in the closing of the global energy and water cycles. SRB Release 4 Intergrated Product (Rel4-IP) integrates data products from the cloud, aerosol, atmosphere, ocean surface, and land surface projects within GDAP to produce a long-term time series of Top-of-Atmosphere (TOA) and surface radiative estimates. This Algorithm Theoretical Basis Document (ATBD) describes the various inputs, algorithms and resulting top-of-atmosphere and surface flux products that span from July 1983 through June 2017. Comparisons of the TOA flux products are made to overlapping CERES data products when possible. The surface radiative flux products are assessed relative to the globally distribution Baseline Surface Radiation Network measurements sites. Variability of the various products are compared to ERBE and CERES during overlapping time periods. The variability of the product show excellent correspondent to CERES during overlap years and improved statistical agreement with surface measurements. This document also discusses known issues with the data products to help the user understand the uncertainty and known issues.

Surface radiation budget↗

Advancing the Standards for Unmanned Air System Communications, Navigation and Surveillance

Under NASA program NNA16BD84C, new architectures were identified and developed for supporting reliable and secure Communications, Navigation and Surveillance (CNS) needs for Unmanned Air Systems (UAS) operating in both controlled and uncontrolled airspace. An analysis of architectures for the two categories of airspace and an implementation technology readiness analysis were performed. These studies produced NASA reports that have been made available in the public domain and have been briefed in previous conferences. We now consider how the products of the study are influencing emerging directions in the aviation standards communities. The International Civil Aviation Organization (ICAO) Communications Panel (CP), Working Group I (WG-I) is currently developing a communications network architecture known as the Aeronautical Telecommunications Network with Internet Protocol Services (ATN/IPS). The target use case for this service is secure and reliable Air Traffic Management (ATM) for manned aircraft operating in controlled airspace. However, the work is more and more also considering the emerging class of airspace users known as Remotely Piloted Aircraft Systems (RPAS), which refers to certain UAS classes. In addition, two Special Committees (SCs) in the Radio Technical Commission for Aeronautics (RTCA) are developing Minimum Aviation System Performance Standards (MASPS) and Minimum Operational Performance Standards (MOPS) for UAS. RTCA SC-223 is investigating an Internet Protocol Suite (IPS) and AeroMACS aviation data link for interoperable (INTEROP) UAS communications. Meanwhile, RTCA SC-228 is working to develop Detect And Avoid (DAA) equipment and a Command and Control (C2) Data Link MOPS establishing LBand and C-Band solutions. These RTCA Special Committees along with ICAO CP WG/I are therefore overlapping in terms of the Communication, Navigation and Surveillance (CNS) alternatives they are seeking to provide for an integrated manned- and unmanned air traffic management service as well as remote pilot command and control. This paper presents UAS CNS architecture concepts developed under the NASA program that apply to all three of the aforementioned committees. It discusses the similarities and differences in the problem spaces under consideration in each committee, and considers the application of a common set of CNS alternatives that can be widely applied. As the works of these committees progress, it is clear that the overlap will need to be addressed to ensure a consistent and safe framework for worldwide aviation. In this study, we discuss similarities and differences in the various operational models and show how the CNS architectures developed under the NASA program apply.

Ponchak, Denise S.↗

Evaluation of VIIRS, GOCI, and MODIS Collection 6 AOD Retrievals Against Ground Sunphotometer Observations Over East Asia

Persistent high aerosol loadings together with extremely high population densities have raised serious air quality and public health concerns in many urban centers in East Asia. However, ground-based air quality monitoring is relatively limited in this area. Recently, satellite-retrieved Aerosol Optical Depth (AOD) at high resolution has become a powerful tool to characterize aerosol patterns in space and time. Using ground AOD observations from the Aerosol Robotic Network (AERONET) and the Distributed Regional Aerosol Gridded Observation Networks (DRAGON)-Asia Campaign, as well as from handheld sunphotometers, we evaluated emerging aerosol products from the Visible Infrared Imaging Radiometer Suite (VIIRS) aboard the Suomi National Polar-orbiting Partnership (S-NPP), the Geostationary Ocean Color Imager (GOCI) aboard the Communication, Ocean, and Meteorology Satellite (COMS), and Terra and Aqua Moderate Resolution Imaging Spectroradiometer (MODIS) (Collection 6) in East Asia in 2012 and 2013. In the case study in Beijing, when compared with AOD observations from handheld sunphotometers, 51% of VIIRS Environmental Data Record (EDR) AOD, 37% of GOCI AOD, 33% of VIIRS Intermediate Product (IP) AOD, 26% of Terra MODIS C6 3km AOD, and 16% of Aqua MODIS C6 3km AOD fell within the reference expected error (EE) envelope (+/-0.05/+/- 0.15 AOD). Comparing against AERONET AOD over the JapanSouth Korea region, 64% of EDR, 37% of IP, 61% of GOCI, 39% of Terra MODIS, and 56% of Aqua MODIS C6 3km AOD fell within the EE. In general, satellite aerosol products performed better in tracking the day-to-day variability than tracking the spatial variability at high resolutions. The VIIRS EDR and GOCI products provided the most accurate AOD retrievals, while VIIRS IP and MODIS C6 3km products had positive biases.

Xiao, Q.↗

Orbit Transfers for Dawn's Vesta Operations : Navigation and Mission Design Experience

Dawn, a mission belonging to NASA's Discovery Program, was launched on September 27, 2007 to explore main belt asteroids in order to yield insights into important questions about the formation and evolution of the solar system. From July of 2011 to August of 2012, the Dawn spacecraft successfully returned valuable science data, collected during the four planned mapping orbits at its first target asteroid, Vesta. Each mapping orbit was designed to enable a different set of scientific observations. Such a mission would have been impossible without the low thrust ion propulsion system (IPS). Maneuvering a spacecraft using only the IPS for the transfers between the mapping orbits posed many technical challenges to Dawn's flight team at NASA's Jet Propulsion Laboratory. Each transfer needs a robust plan that accounts for uncertainties in maneuver execution, orbit determination, and physical characteristics of Vesta. This paper discusses the mission design and navigational experience during Dawn's Vesta operations. Topics include requirements and constraints from Dawn's science and spacecraft teams, orbit determination and maneuver design and building process for transfers, developing timelines for thrust sequence build cycles, and the process of scheduling very demanding coverage with ground antennae at NASA's Deep Space Network.

low thrust↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

ACTS 118x: High Speed TCP Interoperability Testing

With the recent explosion of the Internet and the enormous business opportunities available to communication system providers, great interest has developed in improving the efficiency of data transfer over satellite links using the Transmission Control Protocol (TCP) of the Internet Protocol (IP) suite. The NASA's ACTS experiments program initiated a series of TCP experiments to demonstrate scalability of TCP/IP and determine to what extent the protocol can be optimized over a 622 Mbps satellite link. Through partnerships with the government technology oriented labs, computer, telecommunication, and satellite industries NASA Glenn was able to: (1) promote the development of interoperable, high-performance TCP/IP implementations across multiple computing / operating platforms; (2) work with the satellite industry to answer outstanding questions regarding the use of standard protocols (TCP/IP and ATM) for the delivery of advanced data services, and for use in spacecraft architectures; and (3) conduct a series of TCP/IP interoperability tests over OC12 ATM over a satellite network in a multi-vendor environment using ACTS. The experiments' various network configurations and the results are presented.

Brooks, David E.↗

Automated Instrumentation, Monitoring and Visualization of PVM Programs Using AIMS

We present views and analysis of the execution of several PVM codes for Computational Fluid Dynamics on a network of Sparcstations, including (a) NAS Parallel benchmarks CG and MG (White, Alund and Sunderam 1993); (b) a multi-partitioning algorithm for NAS Parallel Benchmark SP (Wijngaart 1993); and (c) an overset grid flowsolver (Smith 1993). These views and analysis were obtained using our Automated Instrumentation and Monitoring System (AIMS) version 3.0, a toolkit for debugging the performance of PVM programs. We will describe the architecture, operation and application of AIMS. The AIMS toolkit contains (a) Xinstrument, which can automatically instrument various computational and communication constructs in message-passing parallel programs; (b) Monitor, a library of run-time trace-collection routines; (c) VK (Visual Kernel), an execution-animation tool with source-code clickback; and (d) Tally, a tool for statistical analysis of execution profiles. Currently, Xinstrument can handle C and Fortran77 programs using PVM 3.2.x; Monitor has been implemented and tested on Sun 4 systems running SunOS 4.1.2; and VK uses X11R5 and Motif 1.2. Data and views obtained using AIMS clearly illustrate several characteristic features of executing parallel programs on networked workstations: (a) the impact of long message latencies; (b) the impact of multiprogramming overheads and associated load imbalance; (c) cache and virtual-memory effects; and (4significant skews between workstation clocks. Interestingly, AIMS can compensate for constant skew (zero drift) by calibrating the skew between a parent and its spawned children. In addition, AIMS' skew-compensation algorithm can adjust timestamps in a way that eliminates physically impossible communications (e.g., messages going backwards in time). Our current efforts are directed toward creating new views to explain the observed performance of PVM programs. Some of the features planned for the near future include: (a) ConfigView, showing the physical topology of the virtual machine, inferred using specially formatted IP (Internet Protocol) packets; and (b) LoadView, synchronous animation of PVM-program execution and resource-utilization patterns.

Mehra, Pankaj↗

Automated Instrumentation, Monitoring and Visualization of PVM Programs Using AIMS

We present views and analysis of the execution of several PVM (Parallel Virtual Machine) codes for Computational Fluid Dynamics on a networks of Sparcstations, including: (1) NAS Parallel Benchmarks CG and MG; (2) a multi-partitioning algorithm for NAS Parallel Benchmark SP; and (3) an overset grid flowsolver. These views and analysis were obtained using our Automated Instrumentation and Monitoring System (AIMS) version 3.0, a toolkit for debugging the performance of PVM programs. We will describe the architecture, operation and application of AIMS. The AIMS toolkit contains: (1) Xinstrument, which can automatically instrument various computational and communication constructs in message-passing parallel programs; (2) Monitor, a library of runtime trace-collection routines; (3) VK (Visual Kernel), an execution-animation tool with source-code clickback; and (4) Tally, a tool for statistical analysis of execution profiles. Currently, Xinstrument can handle C and Fortran 77 programs using PVM 3.2.x; Monitor has been implemented and tested on Sun 4 systems running SunOS 4.1.2; and VK uses XIIR5 and Motif 1.2. Data and views obtained using AIMS clearly illustrate several characteristic features of executing parallel programs on networked workstations: (1) the impact of long message latencies; (2) the impact of multiprogramming overheads and associated load imbalance; (3) cache and virtual-memory effects; and (4) significant skews between workstation clocks. Interestingly, AIMS can compensate for constant skew (zero drift) by calibrating the skew between a parent and its spawned children. In addition, AIMS' skew-compensation algorithm can adjust timestamps in a way that eliminates physically impossible communications (e.g., messages going backwards in time). Our current efforts are directed toward creating new views to explain the observed performance of PVM programs. Some of the features planned for the near future include: (1) ConfigView, showing the physical topology of the virtual machine, inferred using specially formatted IP (Internet Protocol) packets: and (2) LoadView, synchronous animation of PVM-program execution and resource-utilization patterns.

Mehra, Pankaj↗

NASA/DOD Aerospace Knowledge Diffusion Research Project. Report 30: Computer-Mediated Communication (CMC) and the communication of technical information in aerospace

This research used survey research to examine the use of communication media in general and electronic media specifically in the U.S. aerospace industry. The survey population included 1,006 randomly selected U.S. aerospace engineers and scientists who belong to the American Institute of Aeronautics and Astronautics (AIAA). Survey data were compared with qualitative information obtained from 32 AIAA members in telephone and face-to-face conversations. The Information Processing (IP) model developed by Tushman and Nadler and Daft and Lengel constituted the study's theoretical basis. This research analyzed responses regarding communication methods of U.S. aerospace engineers and scientists who create use and disseminate aerospace knowledge and explored selected contextual environmental variables related to media use and effective performance. The results indicate that uncertainty is significantly reduced in environments when levels of analyzability are high. When uncertainty is high there is significantly more use of electronic media. However no relation was found between overall effectiveness and media use in environments stratified by levels by analyzability or equivocality. The results indicate modest support for the influences of uncertainty and analyzability on electronic media use. Although most respondents reported that electronic networks are important for their work the data suggest that there are sharply disparate levels of use.

Murphy, Daniel J.↗

Distributed Intrusion Detection System using Semantic-based Rules for SCADA in Smart Grid

Cyber-physical system (CPS) security for the smart grid enables secure communication for the SCADA and wide-area measurement system data. Power utilities world-wide use various SCADA protocols, namely DNP3, Modbus, and IEC 61850, for the data exchanges across substation field devices, remote terminal units (RTUs), and control center applications. Adversaries may exploit compromised SCADA protocols for the reconnaissance, data exfiltration, vulnerability assessment, and injection of stealthy cyberattacks to affect power system operation. In this paper, we propose an efficient algorithm to generate robust rule sets. We integrate the rule sets into an intrusion detection system (IDS), which continuously monitors the DNP3 data traffic at a substation network and detects intrusions and anomalies in real-time. To enable CPS-aware wide-area situational awareness, we integrated the methodology into an open-source distributed-IDS (D-IDS) framework. The D-IDS facilitates central monitoring of the detected anomalies from the geographically distributed substations and to the control center. The proposed algorithm provides an optimal solution to detect network intrusions and abnormal behavior. Different types of IDS rules based on packet payload, packet flow, and time threshold are generated. Further, IDS testing and evaluation is performed with a set of rules in different sequences. The detection time is measured for different IDS rules, and the results are plotted. All the experiments are conducted at Power Cyber Lab, Iowa State University, for multiple power grid models. After successful testing and evaluation, knowledge and implementation are transferred to field deployment.

24 POWER TRANSMISSION AND DISTRIBUTION↗

TF9 Dataset Analysis

Incident Overview: In the time between November 2, 2019 and November 11, 2019, WheelByte was plagued by breaches in security. These insecurities led to breaches in customer data, company data, and even the death of an employee, Matthew Swift. They have launched an investigation into the company’s computer systems in hopes to find the root cause. We have been provided with the following artifacts from WheelByte: memory images, disk images, network packet captures, and emails. We have found multiple cyber-system attacks against WheelByte. Our investigation lasted from July 13th - August 3rd, 2023. WheelByte allowed us to look at any and every file, and there were no restrictions on what we could or could not use in our investigation. By the end of our investigation, we have been able to deduce who is behind the attack, what they have done, and why they did it. A company that is closely related to WheelByte is called Slyde. Slyde sells electric scooters and it is known that the Chief Executive Officer (CEO) of Slyde, Kimberly Holmes, sees WheelByte as a threat to business, as Wheelbyte sells electric skateboards. We have been able to deduce that Slyde is likely behind many of the malicious attacks. We have seen exfiltration addresses to Slyde domains, along with other Slyde information within their malware. We can see lots of traffic to and from Slyde Internet Protocol (IP) addresses. This may be an attempt to cripple WheelByte’s productivity to remove Slyde’s competitor from the market.

97 MATHEMATICS AND COMPUTING↗

ACTS 118x Final Report High-Speed TCP Interoperability Testing

With the recent explosion of the Internet and the enormous business opportunities available to communication system providers, great interest has developed in improving the efficiency of data transfer using the Transmission Control Protocol (TCP) of the Internet Protocol (IP) suite. The satellite system providers are interested in solving TCP efficiency problems associated with long delays and error-prone links. Similarly, the terrestrial community is interested in solving TCP problems over high-bandwidth links. Whereas the wireless community is interested in improving TCP performance over bandwidth constrained, error-prone links. NASA realized that solutions had already been proposed for most of the problems associated with efficient data transfer over large bandwidth-delay links (which include satellite links). The solutions are detailed in various Internet Engineering Task Force (IETF) Request for Comments (RFCs). Unfortunately, most of these solutions had not been tested at high-speed (155+ Mbps). Therefore, the NASA's ACTS experiments program initiated a series of TCP experiments to demonstrate scalability of TCP/IP and determine how far the protocol can be optimized over a 622 Mbps satellite link. These experiments were known as the 118i and 118j experiments. During the 118i and 118j experiments, NASA worked closely with SUN Microsystems and FORE Systems to improve the operating system, TCP stacks. and network interface cards and drivers. We were able to obtain instantaneous data throughput rates of greater than 520 Mbps and average throughput rates of 470 Mbps using TCP over Asynchronous Transfer Mode (ATM) over a 622 Mbps Synchronous Optical Network (SONET) OC12 link. Following the success of these experiments and the successful government/industry collaboration, a new series of experiments. the 118x experiments. were developed.

Ivancic, William D.↗