Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Security monitoring”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A model of security monitoring

A model of security monitoring is presented that distinguishes between two types of logging and auditing. Implications for the design and use of security monitoring mechanisms are drawn from this model. The usefulness of the model is then demonstrated by analyzing several different monitoring mechanisms.

Bishop, Matt↗

A model of security monitoring

A model of security monitoring is presented that distinguishes between two types of logging and auditing. Implications for the design and use of security monitoring mechanisms are drawn from this model. The usefulness of the model is then demonstrated by analyzing several different monitoring mechanisms.

Bishop, Matt↗

Using advanced data structures to enable responsive security monitoring

Write-optimized data structures (WODS), offer the potential to keep up with cyberstream event rates and give sub-second query response for key items like IP addresses. These data structures organize logs as the events are observed. To work in a real-world environment and not fill up the disk, WODS must efficiently expire older events. As the basis for our research into organizing security monitoring data, we implemented a tool, called Diventi, to index IP addresses in connection logs using RocksDB (a write-optimized LSM tree). In this work, we extended Diventi to automatically expire data as part of the data structures’ normal operations. We guarantee that Diventi always tracks the N most recent events and tracks no more than N + k events for a parameter k < N, while ensuring the index is opportunistically pruned. To test Diventi at scale in a controlled environment, we used anonymized traces of IP communications collected at SuperComputing 2019. We synthetically extended the 2.4 billion connection events to 100 billion events. We tested Diventi vs. Elasticsearch, a common log indexing tool. In our test environment, Elasticsearch saw an ingestion rate of at best 37,000 events/s while Diventi sustained ingestion rates greater than 171,000 events/s. Our query response times were as much as 100 times faster, typically answering queries in under 80 ms. Furthermore, we saw no noticeable degradation in Diventi from expiration. We have deployed Diventi for many months where it has performed well and supported new security analysis capabilities.

97 MATHEMATICS AND COMPUTING↗

Automating security monitoring and analysis for Space Station Freedom's electric power system

Operating a large, space power system requires classifying the system's status and analyzing its security. Conventional algorithms are used by terrestrial electric utilities to provide such information to their dispatchers, but their application aboard Space Station Freedom will consume too much processing time. A new approach for monitoring and analysis using adaptive pattern techniques is presented. This approach yields an on-line security monitoring and analysis algorithm that is accurate and fast; and thus, it can free the Space Station Freedom's power control computers for other tasks.

Dolce, James L.↗

Automating security monitoring and analysis for Space Station Freedom's electric power system

Operating a large, space power system requires classifying the system's status and analyzing its security. Conventional algorithms are used by terrestrial electric utilities to provide such information to their dispatchers, but their application aboard Space Station Freedom will consume too much processing time. A novel approach for monitoring and analysis using adaptive pattern techniques is presented. This approach yields an on-line security monitoring and analysis algorithm that is accurate and fast; and thus, it can free the Space Station Freedom's power control computers for other tasks.

Dolce, James L.↗

Remote Sensing for Food Security Monitoring in Afghanistan

Two decades of war have severely weakened Afghanistan s economy and infrastructure. Along with larger impacts on civil stability, education and health care, the current conflict in Afghanistan has resulted in widespread hunger and destitution. The 2005 National Risk and Vulnerability Assessment conducted by the United Nations found that 6.6 million Afghans do not meet their minimum food requirements and approximately 400,000 people each year are seriously affected by natural disasters, such as droughts, floods and extreme weather conditions. Given the poor security situation in the country, systems that will enable remote observations of variations of climate and their impacts on food production are critical for providing an appropriate and timely response. This chapter describes the remote sensing systems and food security analyses that the US Agency for International Development s Famine Early Warning Systems Network (FEWS NET) conducts in Afghanistan to monitor and provide information to international donors to ensure that adequate assistance is provided during this time of development and recovery.

Brown, Molly E.↗

Abstract for CRADA between National Energy Technology Laboratory and Colonial Pipeline Company

The National Energy Technology Laboratory (NETL) and Colonial Pipeline Company (Participant) will collaborate in the field demonstration of optical fiber sensor systems developed at NETL on Participant’s fuel pipeline. The optical fiber sensor technologies are capable of distributed temperature and strain sensing, distributed acoustic sensing, and ultrasensitive acoustic sensing. Real-time monitoring of these parameters enables pipeline integrity monitoring, security monitoring, flow rate monitoring, etc. Successful demonstration on a real fuel pipeline at Participant’s facilities will validate the sensor technologies and installation methods at a real scale. This effort aligns with NETL’s mission in reliable and sustainable energy and reducing environmental effects due to pipeline failures.

42 ENGINEERING↗

FiberFlex: Real-time FPGA-based Intelligent and Distributed Fiber Sensor System for Pedestrian Recognition

In recent years, security monitoring of public places and critical infrastructure has heavily relied on the widespread use of cameras, raising concerns about personal privacy violations. To balance the need for effective security monitoring with the protection of personal privacy, we explore the potential of optical fiber sensors for this application. This article proposes FiberFlex, an intelligent and distributed fiber sensor system. Ultizing Field Programmable Gate Arrays (FPGA) high-level synthesis (HLS) acceleration, FiberFlex offers real-time pedestrian detection by co-designing the entire pipeline of optical signal acquisition, processing, and recognition networks based on the principles of optical fiber sensing. As a promising alternative to traditional camera-based monitoring systems, FiberFlex achieves pedestrian detection by analyzing the vibration patterns caused by pedestrian footsteps, enabling security monitoring while preserving individual privacy. FiberFlex comprises three modules: First , fiber-optic sensing system: A fiber-optic distributed acoustic sensing (DAS) system is built and used to measure the ground vibration waves generated by people walking. Second , algorithms: We first collect the training data by measuring the ground vibration waves, label the data, and use the data to train the neural network models to perform pedestrian recognition. Third , hardware accelerators: We use HLS tools to design hardware modules on FPGA for data collection and pre-processing and integrate them with the downstream neural network accelerators to perform in-line real-time pedestrian detection. The final detection results are sent back from FPGA to the host CPU. We implement our system FiberFlex with the in-house built DAS system and AMD/Xilinx Kintex7 FPGA KC705 board and verify the whole system using the real-world collected data. We conduct recognition tests on five test subjects of varying ages, heights, and weights in a fixed sensing area. Each subject experienced 20 real-time recognition tests using their daily walking habits, and the subjects were given adequate rest between tests. After 100 tests on five test subjects, the overall real-time recognition accuracy exceeded \(88.0\%\) . The whole system uses 55 W of power, 33 W in the optical DAS system and 22 W in the FPGA. Relying on its end-to-end interdisciplinary design, FiberFlex seamlessly combines fiber-optic sensors with FPGA accelerators to enable low-power real-time security monitoring without compromising privacy, making it a valuable addition to the existing security monitoring network. According to FiberFlex, more valuable research can be conducted in the future, such as fall monitoring for the elderly, migration of identification networks between different application scenarios, and improvement of anti-interference performance in more complex environments. In future perception networks, where the “eyes” are not feasible, let’s use fiber optic touch instead.

Distributed↗

Service-Based, Segmented, 5G Network-Based Architecture for Securing Distributed Energy Resources: Preprint

As the number of connected devices in the energy grid increase exponentially, so too are the cybersecurity risks. With the development of modern communications standards such as 5G and beyond the extent to which devices will continue to connect will continue to increase exponentially along with the inherent risks. However, 5G also includes features to help address cybersecurity concerns and therefore helping to mitigate many of these risks. This paper proposes a new service-based network architecture implementing network-slicing capabilities for connected systems and devices to improve performance, availability, security, and reliability of the grid devices and services. This paper considers the quality of service requirements and criticality of services needed for securely monitoring, operating, and securing Distributed Energy Resource (DER) devices. From developed use cases, network slicing is implemented based on these requirements and resource allocations. This work then highlights examples of how slicing can help prevent standard existing attack methods such as a denial-of-service or similar attack which limits resource availability and network bandwidth to the service and thus limiting its ability to affect other services by misbehaving. The designed network architecture use case will be further tested on a local virtualized testbed to verify secure operation and availability of services. Using hardware-in-the-loop devices and systems on this local testbed, this fully segmented, secure network may be realized and evaluated. Finally, this paper presents the results of this testing.

5G↗

Use of Radiofrequency Tamper Indicating Devices (RFTID) to Enhance Remotely Monitoring the Security of Advanced and Small Modular Reactors (A/SMRs)

A/SMRs will likely be deployed in remote locations that are difficult to access, thereby requiring limited on-site staff. • Vendors are considering remote monitoring as a solution to enhance nuclear security. RFTIDs are a candidate technology for maintaining nuclear security of A/SMRs but need to be evaluated for feasibility and implementation into the wider physical protection system.

O'Dowd, Kevin [Savannah River National Laboratory ↗

Progress in knowledge-based flight monitoring

Features and applications of the script-based flight monitor SECURE are described. Implemented on an on-board computer, SECURE treats a flight as a regular sequence of contexts (situations) defined in a knowledge base with a hierarchical structure for successively more finely delineated flight phases, i.e., takeoff, cruise and landing. SECURE provides normalcy references for flight monitoring and allows context identification, which allows the presentation of checklists. An implementation of SECURE, written in MACLISP, on a DC-10 flight simulator is described.

Chen, D. C.↗

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Security warning system monitors up to fifteen remote areas simultaneously

Security warning system consisting of 15 television cameras is capable of monitoring several remote or unoccupied areas simultaneously. The system uses a commutator and decommutator, allowing time-multiplexed video transmission. This security system could be used in industrial and retail establishments.

Fusco, R. C.↗