Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Attack detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

NASA’s Secured Airspace for Urban Air Mobility (UAM)

The Urban Air Mobility (UAM) architecture is leveraged from the Unmanned Traffic Management (UTM) concept of operations. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within that environment. As a recognized need, various views of UAM flight information are provided to the public and public safety entities. To accomplish this, among other goals, the Federal Aviation Administration (FAA) can coordinate flight information between the FAA controlled National Airspace System (NAS) and the UAM environments through the FAA-Industry Data Exchange Protocol (FIDXP). This concept of UAM proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical take-off and landing (VTOL) or short take-off and landing (STOL) aircraft to overcome increasing surface congestion. To garner the support of UAM and to realize its potential, an assurance of cybersecurity is critical for public acceptance. Understanding the various components communicating with one-another cybersecurity, like in other industries, has come to the forefront highlighting the need to protect these networks and systems from cyberattacks. With the planned growth and reach of UAM systems, it’s clear that the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. Consequently, as these threats evolve, the UAM cybersecurity capabilities must adapt to these changes as well. While learning is always the goal, the overall intent of this workshop is to make recommendations on the following: (1) how future UAM environments can be protected against cyber-attacks, and (2) what mechanisms should be put in place to detect attacks against UAM environments.

UAM↗

Simple Method For Detection Of Intergranular Attack

Evidence of intergranular attack occurring on chemically milled and wire-electrical-discharge-machined metal parts detected with replicating tape which makes it unnecessary to manufacture and stock test coupons and inspect them microscopically. Tape pressed on part to be inspected. When removed, it presents visual evidence of intergranular attack.

Jackson, Amy A.↗

Detecting Distributed SQL Injection Attacks in a Eucalyptus Cloud Environment

The cloud computing environment offers malicious users the ability to spawn multiple instances of cloud nodes that are similar to virtual machines, except that they can have separate external IP addresses. In this paper we demonstrate how this ability can be exploited by an attacker to distribute his/her attack, in particular SQL injection attacks, in such a way that an intrusion detection system (IDS) could fail to identify this attack. To demonstrate this, we set up a small private cloud, established a vulnerable website in one instance, and placed an IDS within the cloud to monitor the network traffic. We found that an attacker could quite easily defeat the IDS by periodically altering its IP address. To detect such an attacker, we propose to use multi-agent plan recognition, where the multiple source IPs are considered as different agents who are mounting a collaborative attack. We show that such a formulation of this problem yields a more sophisticated approach to detecting SQL injection attacks within a cloud computing environment.

Kebert, Alan↗

Towards Reliable Evaluation of Anomaly-Based Intrusion Detection Performance

This report describes the results of research into the effects of environment-induced noise on the evaluation process for anomaly detectors in the cyber security domain. This research was conducted during a 10-week summer internship program from the 19th of August, 2012 to the 23rd of August, 2012 at the Jet Propulsion Laboratory in Pasadena, California. The research performed lies within the larger context of the Los Angeles Department of Water and Power (LADWP) Smart Grid cyber security project, a Department of Energy (DoE) funded effort involving the Jet Propulsion Laboratory, California Institute of Technology and the University of Southern California/ Information Sciences Institute. The results of the present effort constitute an important contribution towards building more rigorous evaluation paradigms for anomaly-based intrusion detectors in complex cyber physical systems such as the Smart Grid. Anomaly detection is a key strategy for cyber intrusion detection and operates by identifying deviations from profiles of nominal behavior and are thus conceptually appealing for detecting "novel" attacks. Evaluating the performance of such a detector requires assessing: (a) how well it captures the model of nominal behavior, and (b) how well it detects attacks (deviations from normality). Current evaluation methods produce results that give insufficient insight into the operation of a detector, inevitably resulting in a significantly poor characterization of a detectors performance. In this work, we first describe a preliminary taxonomy of key evaluation constructs that are necessary for establishing rigor in the evaluation regime of an anomaly detector. We then focus on clarifying the impact of the operational environment on the manifestation of attacks in monitored data. We show how dynamic and evolving environments can introduce high variability into the data stream perturbing detector performance. Prior research has focused on understanding the impact of this variability in training data for anomaly detectors, but has ignored variability in the attack signal that will necessarily affect the evaluation results for such detectors. We posit that current evaluation strategies implicitly assume that attacks always manifest in a stable manner; we show that this assumption is wrong. We describe a simple experiment to demonstrate the effects of environmental noise on the manifestation of attacks in data and introduce the notion of attack manifestation stability. Finally, we argue that conclusions about detector performance will be unreliable and incomplete if the stability of attack manifestation is not accounted for in the evaluation strategy.

cyber defense↗

Pre-visual detection of stress in pine forests

Pre-visual, or early, detection of forest stress with particular reference to detection of attacks by pine bark beetles is discussed. Preliminary efforts to obtain early detection of attacks by pine bark beetles, using MSS data from the ERIM M-7 scanner, were not sufficiently successful to demonstrate an operational capability, but indicate that joint processing of the 0.71 to 0.73, 2.00 to 2.60, and 9.3 to 11.7 micrometer bands holds some promise. Ratio processing of transformed data from the 0.45 to 0.52, 1.55 to 2.60, and 4.5 to 5.5 or 9.3 to 11.7 micrometer regions appears even more promising.

Olson, C. E., Jr.↗

NASA's Research in Aircraft Vulnerability Mitigation

Since its inception in 1958, the National Aeronautics and Space Administration s (NASA) role in civil aeronautics has been to develop high-risk, high-payoff technologies to meet critical national aviation challenges. Following the events of Sept. 11, 2001, NASA recognized that it now shared the responsibility for improving homeland security. The NASA Strategic Plan was modified to include requirements to enable a more secure air transportation system by investing in technologies and collaborating with other agencies, industry, and academia. NASA is conducting research to develop and advance innovative and commercially viable technologies that will reduce the vulnerability of aircraft to threats or hostile actions, and identify and inform users of potential vulnerabilities in a timely manner. Presented in this paper are research plans and preliminary status for mitigating the effects of damage due to direct attacks on civil transport aircraft. The NASA approach to mitigation includes: preventing loss of an aircraft due to a hit from man-portable air defense systems; developing fuel system technologies that prevent or minimize in-flight vulnerability to small arms or other projectiles; providing protection from electromagnetic energy attacks by detecting directed energy threats to aircraft and on/off-board systems; and minimizing the damage due to high-energy attacks (explosions and fire) by developing advanced lightweight, damage-resistant composites and structural concepts. An approach to preventing aircraft from being used as weapons of mass destruction will also be discussed.

Allen, Cheryl L.↗

Real-time diagnostics for a reusable rocket engine

A hierarchical, decentralized diagnostic system is proposed for the Real-Time Diagnostic System component of the Intelligent Control System (ICS) for reusable rocket engines. The proposed diagnostic system has three layers of information processing: condition monitoring, fault mode detection, and expert system diagnostics. The condition monitoring layer is the first level of signal processing. Here, important features of the sensor data are extracted. These processed data are then used by the higher level fault mode detection layer to do preliminary diagnosis on potential faults at the component level. Because of the closely coupled nature of the rocket engine propulsion system components, it is expected that a given engine condition may trigger more than one fault mode detector. Expert knowledge is needed to resolve the conflicting reports from the various failure mode detectors. This is the function of the diagnostic expert layer. Here, the heuristic nature of this decision process makes it desirable to use an expert system approach. Implementation of the real-time diagnostic system described above requires a wide spectrum of information processing capability. Generally, in the condition monitoring layer, fast data processing is often needed for feature extraction and signal conditioning. This is usually followed by some detection logic to determine the selected faults on the component level. Three different techniques are used to attack different fault detection problems in the NASA LeRC ICS testbed simulation. The first technique employed is the neural network application for real-time sensor validation which includes failure detection, isolation, and accommodation. The second approach demonstrated is the model-based fault diagnosis system using on-line parameter identification. Besides these model based diagnostic schemes, there are still many failure modes which need to be diagnosed by the heuristic expert knowledge. The heuristic expert knowledge is implemented using a real-time expert system tool called G2 by Gensym Corp. Finally, the distributed diagnostic system requires another level of intelligence to oversee the fault mode reports generated by component fault detectors. The decision making at this level can best be done using a rule-based expert system. This level of expert knowledge is also implemented using G2.

Guo, T. H.↗

Mapping Boreal Forest Spruce Beetle Health Status at the Individual Crown Scale Using Fused Spectral and Structural Data

The frequency and severity of spruce bark beetle outbreaks are increasing in boreal forests leading to widespread tree mortality and fuel conditions promoting extreme wildfire. Detection of beetle infestation is a forest health monitoring (FHM) priority but is hampered by the challenges of detecting early stage (“green”) attack from the air. There is indication that green stage might be detected from vertical gradients of spectral data or from shortwave infrared information distributed within a single crown. To evaluate the efficacy of discriminating “non-infested”, “green”, and “dead” health statuses at the landscape scale in Alaska, USA, this study conducted spectral and structural fusion of data from: (1) Unoccupied aerial vehicle (UAV) multispectral (6 cm) + structure from motion point clouds (~700 pts per sq. m); and (2) Goddard Lidar Hyperspectral Thermal (G-LiHT) hyperspectral (400 to 1000 nm, 0.5 m) + SWIR-band lidar (~32 pts per sq.m). We achieved 78% accuracy for all three health statuses using spectral + structural fusion from either UAV or G-LiHT and 97% accuracy for non-infested/dead using G-LiHT. We confirm that UAV 3D spectral (e.g., greenness above versus below median height in crown) and lidar apparent reflectance metrics (e.g., mean reflectance at 99th percentile height in crown), are of high value, perhaps capturing the vertical gradient of needle degradation. In most classification exercises, UAV accuracy was lower than G-LiHT indicating that collecting ultra-high spatial resolution data might be less important than high spectral resolution information. While the value of passive optical spectral information was largely confined to the discrimination of non-infested versus dead crowns, G-LiHT hyperspectral band selection (~400, 675, 755, and 940 nm) could inform future FHM mission planning regarding optimal wavelengths for this task. Interestingly, the selected regions mostly did not align with the band designations for our UAV multispectral data but do correspond to, e.g., Sentinel-2 red edge bands, suggesting a path forward for moderate scale bark beetle detection when paired with suitable structural data.

Janice Cessna↗

The dynamic character of the wake of an axisymmetric body at an angle of attack

The flow around a hemisphere-cylinder was studied at angles of attack alpha = 0-90 deg. The work was carried out in two wind tunnels, using hot wire anemometers and seven-hole probes at Reynolds number of 2.7 x 10 exp 4. Five distinct states of vortex unsteadiness were detected. For angles of attack less than 14 deg, the flow is rather stable. For alpha between 15 and 23 deg, meandering occurs at a reduced frequency of 0.065. For alpha between 24 and 32 deg, three frequencies were recorded at 0.11, 0.21, and 0.31. At even higher angles of attack, alpha between 33 and 41 deg, two frequencies were seen at 0.11 and 0.19. The onset of alternate shedding is at alpha = 42 deg, above which, alternate shedding occurred at 0.065. However, above 55 deg, shedding occurred at 0.15. Asymmetric wake structures over the hemisphere-cylinder were also investigated. It was found that asymmetric structures too are not steady but engage in periodic organized motions.

Hoang, N. T.↗

Transition Measurements on the SWiFT Model in the National Transonic Facility

Boundary layer transition locations on the Swept Wing Flow Test (SWiFT) Hybrid Wing Body model were measured in the National Transonic Facility (NTF) at the NASA Langley Research Center using several different methods. These methods include sublimating chemical flow visualization for a limited number of low Reynolds number conditions, as well as mean static pressure and dynamic pressure measurements. Results are presented for a range of conditions in the NTF, demonstrating Mach and Reynolds number effects. The transition front locations obtained from the different techniques agree well. A variation of the static pressure transition detection method is described in which continuous angle of attack polars are performed. This approach enables detection of the transition front at more challenging (high Reynolds number) conditions than is possible with sparser data from pitch-pause angle-of-attack polars. The trip dot effectiveness is also verified using all of the available diagnostics. Additionally, low Reynolds number results are compared with those acquired on the same model at the Aircraft Research Association (ARA) facility, and these results show good agreement overall, suggesting similar freestream flow quality conditions of the two facilities.

National Transonic Facility↗

Transition Measurements on the SWiFT Model in the National Transonic Facility

Boundary layer transition locations on the Swept Wing Flow Test (SWiFT) Hybrid Wing Body model were measured in the National Transonic Facility (NTF) at the NASA Langley Research Center using several different methods. These methods include sublimating chemical flow visualization for a limited number of low Reynolds number conditions, as well as mean static pressure and dynamic pressure measurements. Results are presented for a range of conditions in the NTF, demonstrating Mach and Reynolds number effects. The transition front locations obtained from the different techniques agree well. A variation of the static pressure transition detection method is described in which continuous angle of attack polars are performed. This approach enables detection of the transition front at more challenging (high Reynolds number) conditions than is possible with sparser data from pitch-pause angle-of-attack polars. The trip dot effectiveness is also verified using all of the available diagnostics. Additionally, low Reynolds number results are compared with those acquired on the same model at the Aircraft Research Association (ARA) facility, and these results show good agreement overall, suggesting similar freestream flow quality conditions of the two facilities.

National Transonic Facility↗

Coherent Doppler Laser Radar: Technology Development and Applications

NASA's Marshall Space Flight Center has been investigating, developing, and applying coherent Doppler laser radar technology for over 30 years. These efforts have included the first wind measurement in 1967, the first airborne flights in 1972, the first airborne wind field mapping in 1981, and the first measurement of hurricane eyewall winds in 1998. A parallel effort at MSFC since 1982 has been the study, modeling and technology development for a space-based global wind measurement system. These endeavors to date have resulted in compact, robust, eyesafe lidars at 2 micron wavelength based on solid-state laser technology; in a factor of 6 volume reduction in near diffraction limited, space-qualifiable telescopes; in sophisticated airborne scanners with full platform motion subtraction; in local oscillator lasers capable of rapid tuning of 25 GHz for removal of relative laser radar to target velocities over a 25 km/s range; in performance prediction theory and simulations that have been validated experimentally; and in extensive field campaign experience. We have also begun efforts to dramatically improve the fundamental photon efficiency of the laser radar, to demonstrate advanced lower mass laser radar telescopes and scanners; to develop laser and laser radar system alignment maintenance technologies; and to greatly improve the electrical efficiency, cooling technique, and robustness of the pulsed laser. This coherent Doppler laser radar technology is suitable for high resolution, high accuracy wind mapping; for aerosol and cloud measurement; for Differential Absorption Lidar (DIAL) measurements of atmospheric and trace gases; for hard target range and velocity measurement; and for hard target vibration spectra measurement. It is also suitable for a number of aircraft operations applications such as clear air turbulence (CAT) detection; dangerous wind shear (microburst) detection; airspeed, angle of attack, and sideslip measurement; and fuel savings through headwind minimization. In addition to the airborne and space platforms, a coherent Doppler laser radar system in an unmanned aerial vehicle (UAV) could provide battlefield weather and target identification.

Kavaya, Michael J.↗

Remote sensing in agriculture

Some examples are presented of the use of remote sensing in cultivated crops, forestry, and range management. Areas of concern include: the determination of crop areas and types, prediction of yield, and detection of disease; the determination of forest areas and types, timber volume estimation, detection of insect and disease attack, and forest fires; and the determination of range conditions and inventory, and livestock inventory. Articles in the literature are summarized and specific examples of work being performed at the Marshall Space Flight Center are given. Primarily, aerial photographs and photo-like ERTS images are considered.

Downs, S. W., Jr.↗

Failure detection and fault management techniques for flush airdata sensing systems

Methods based on chi-squared analysis are presented for detecting system and individual-port failures in the high-angle-of-attack flush airdata sensing system on the NASA F-18 High Alpha Research Vehicle. The HI-FADS hardware is introduced, and the aerodynamic model describes measured pressure in terms of dynamic pressure, angle of attack, angle of sideslip, and static pressure. Chi-squared analysis is described in the presentation of the concept for failure detection and fault management which includes nominal, iteration, and fault-management modes. A matrix of pressure orifices arranged in concentric circles on the nose of the aircraft indicate the parameters which are applied to the regression algorithms. The sensing techniques are applied to the F-18 flight data, and two examples are given of the computed angle-of-attack time histories. The failure-detection and fault-management techniques permit the matrix to be multiply redundant, and the chi-squared analysis is shown to be useful in the detection of failures.

Whitmore, Stephen A.↗

R2U2: Monitoring and Diagnosis of Security Threats for Unmanned Aerial Systems

We present R2U2, a novel framework for runtime monitoring of security properties and diagnosing of security threats on-board Unmanned Aerial Systems (UAS). R2U2, implemented in FPGA hardware, is a real-time, REALIZABLE, RESPONSIVE, UNOBTRUSIVE Unit for security threat detection. R2U2 is designed to continuously monitor inputs from the GPS and the ground control station, sensor readings, actuator outputs, and flight software status. By simultaneously monitoring and performing statistical reasoning, attack patterns and post-attack discrepancies in the UAS behavior can be detected. R2U2 uses runtime observer pairs for linear and metric temporal logics for property monitoring and Bayesian networks for diagnosis of security threats. We discuss the design and implementation that now enables R2U2 to handle security threats and present simulation results of several attack scenarios on the NASA DragonEye UAS.

Formal Methods↗