Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Threats”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Performance Evaluation of Vertical Federated Machine Learning Against Adversarial Threats on Wide-Area Control System: Preprint

Federated machine learning (FL) is gaining significant popularity to develop cybersecurity solutions in power grids because of its advanced capability to support decentralized data handing at local devices, its privacy preservation, and its low-bandwidth requirement. However, the evolving adversarial machine learning (AML) threats raise significant concerns for the cybersecurity of FL architectures. The FL-based split neural network (SplitNN) achieves high performance through the decentralized training of local neural network models while preserving data privacy across multiple entities. In this paper, we propose a methodology for evaluating the performance of a vertical FLbased anomaly detector against different types of AML attacks, including denial-of-service attacks, adversarial data injection attacks, and replay attacks on the trained local models deployed in the grid network. For a case study, we consider the modified IEEE 13-bus system, and we develop SplitNN-based binary and multiclass classification models to detect, locate, and identify different types of data integrity attacks on the volt-watt control with two pooling layers: maximum pooling and AvgPool. Our experimental results, computed through performance metrics, reveal that the severity of these AML attacks varies with the integrated pooling mechanism, the type of classification model, and the nature of the cyberattack. Further, the AML attacks negatively impacted the prediction time per sample for the pretrained SplitNN during the online testing.

adversarial threats

NASA analysis of space mission options for the 2025 planetary defense conference hypothetical asteroid impact threat scenario

The 2025 Planetary Defense Conference (PDC) hypothetical asteroid impact threat exercise is being conducted in coordination with the United Nations-endorsed Space Mission Planning Advisory Group (SMPAG), exercising SMPAG's processes for assessing space mission options and communicating to decision makers. Here, in this paper, we describe the work performed by our NASA-led team and present the results we contributed to the SMPAG effort for the exercise. Our NASA-led team assessed mission options for asteroid reconnaissance (flyby and rendezvous), deflection, and robust disruption using several viable techniques: kinetic impactors, ion beam deflection, and nuclear explosive devices. Our simulations and analyses considered how much change-in-velocity an asteroid can tolerate before fragmentation onset, and we worked towards establishing requirements for robustly disrupting an asteroid. Heuristics informed by the simulation results are incorporated into optimization of deflection and disruption mission campaign options. Finally, we make some observations about useful generalizations from these results with potential applicability to any planetary defense scenario.

Asteroid deflection

Users Guide for the Anvil Threat Corridor Forecast Tool V1.7.0 for AWIPS

The Applied Meteorology Unit (AMU) originally developed the Anvil Threat Sector Tool for the Meteorological Interactive Data Display System (MIDDS) and delivered the capability in three phases beginning with a feasibility study in 2000 and delivering the operational final product in December 2003. This tool is currently used operationally by the 45th Weather Squadron (45 WS) Launch Weather Officers (LWO) and Spaceflight Meteorology Group (SMG) forecasters. Phase I of the task established the technical feasibility of developing an objective, observations-based tool for short-range anvil forecasting. The AMU was subsequently tasked to develop short-term anvil forecasting tools to improve predictions of the threat of triggered lightning to space launch and landing vehicles. Under the Phase II effort, the AMU developed a nowcasting anvil threat sector tool, which provided the user with a threat sector based on the most current radiosonde upper wind data from a co-located or upstream station. The Phase II Anvil Threat Sector Tool computes the average wind speed and direction in the layer between 300 and 150 mb from the latest radiosonde for a user-designated station. The following threat sector properties are consistent with the propagation and lifetime characteristics of thunderstorm anvil clouds observed over Florida and its coastal waters (Short et al. 2002): a) 20 n mi standoff circle, b) 30 degree sector width, c) Orientation given by 300 to 150 mb average wind direction, d) 1-, 2-, and 3- hour arcs in upwind direction, and e) Arc distances given by 300 to 150 mb average wind speed. Figure 1 is an example of the MIDDS Anvil Threat Sector tool overlaid on a visible satellite image at 2132 UTC 13 May 2001. Space Launch Complex 39A was selected as the center point and the Anvil Threat Sector was determined from upper-level wind data at 1500 UTC in the preconvective environment. Narrow thunderstorm anvil clouds extend from central Florida to the space launch and landing facilities at the Kennedy Space Center (KSC) and Cape Canaveral Air Force Station (CCAFS) and beyond. The anvil clouds were generated around 1930 UTC (1430 EDT) by thunderstorm activity over central Florida and transported 90 n mi east-northeastward within 2 hours, as diagnosed by the anvil forecast tool. Phase III, delivered in February 2003, built upon the results of Phase II by enhancing the Anvil Threat Sector Tool with the capability to use national model forecast winds for depiction of potential anvil lengths and orientations over the KSC/CCAFS area with lead times from 3 through 168 hours (7 days). In September 2003, AMU customers requested the capability to use data from the KSC 50 MHz Doppler Radar Wind Profiler (DRWP) in the Anvil Threat Sector Tool and this capability was delivered by the AMU in December 2003. In March 2005, the AMU was tasked to migrate the MIDDS Anvil Threat Sector Tool capabilities onto the Advanced Weather Interactive Processing System (AWIPS) as the Anvil Threat Corridor Forecast Tool.

Bauman, William H., III

Computing Proximity to Threat Along Uncertain Trajectory to Support Urban Air Mobility

Many airspace threats affect the selection of a flight route, such as terrain, physical obstacles, adverse weather, and special-use airspace, among others. Threat avoidance during Urban Air Mobility (UAM) and Low Altitude Mobility (LAM) flights is especially challenging due to their lower cruising altitudes. These operations may be exposed to buildings, towers, trees, terrain undulations, etc., along much of their flight route. Moreover, these low-altitude flights in urban environments are expected to encounter very busy airspace, increasing the workload associated with threat avoidance. The Proximity to Threat (PtT) function aims to support onboard or remote pilots by computing the risk from geospatial threats in the airspace along an aircraft’s flight path. The threats are both static entities and dynamic airspace restrictions that have been modeled and stored in geo-referenced mapping databases. The flight path may be specified by waypoints, airways, or similar discrete route elements or by a time series of closely spaced position and altitude points. Flight path uncertainty can also be taken into account by assuming both the position and altitude to be sampled from two normal distributions, each being specified by a mean and variance. PtT uses this additional information to verify that the flight path remains clear of threats along a wider path or if a position is reached earlier or later than anticipated, assuring the pilot or operator that there will be an available safety margin even if the aircraft deviates due to one or more occurrences of unexpected wind gusts, mechanical failures, airspeed changes, collision avoidance maneuvers, etc. The client can specify an uncertainty confidence level to bound the set of trajectories evaluated for threats so that the confidence level corresponds to the client’s risk tolerance under the expected conditions. PtT can be used as a pre-flight planning tool to determine a safe route through known threats and in-flight to avoid emerging or changing threats. In this report, we present the PtT function, discuss how the trajectory uncertainty is incorporated into the PtT function, and describe the use of this PtT function in a representative scenario.

urban air mobility

Using Cloud-to-Ground Lightning Climatologies to Initialize Gridded Lightning Threat Forecasts for East Central Florida

Each morning, the forecasters at the National Weather Service in Melbourn, FL (NWS MLB) produce an experimental cloud-to-ground (CG) lightning threat index map for their county warning area (CWA) that is posted to their web site (http://www.srh.weather.gov/mlb/ghwo/lightning.shtml) . Given the hazardous nature of lightning in central Florida, especially during the warm season months of May-September, these maps help users factor the threat of lightning, relative to their location, into their daily plans. The maps are color-coded in five levels from Very Low to Extreme, with threat level definitions based on the probability of lightning occurrence and the expected amount of CG activity. On a day in which thunderstorms are expected, there are typically two or more threat levels depicted spatially across the CWA. The locations of relative lightning threat maxima and minima often depend on the position and orientation of the low-level ridge axis, forecast propagation and interaction of sea/lake/outflow boundaries, expected evolution of moisture and stability fields, and other factors that can influence the spatial distribution of thunderstorms over the CWA. The lightning threat index maps are issued for the 24-hour period beginning at 1200 UTC (0700 AM EST) each day with a grid resolution of 5 km x 5 km. Product preparation is performed on the AWIPS Graphical Forecast Editor (GFE), which is the standard NWS platform for graphical editing. Currently, the forecasters create each map manually, starting with a blank map. To improve efficiency of the forecast process, NWS MLB requested that the Applied Meteorology Unit (AMU) create gridded warm season lightning climatologies that could be used as first-guess inputs to initialize lightning threat index maps. The gridded values requested included CG strike densities and frequency of occurrence stratified by synoptic-scale flow regime. The intent is to increase consistency between forecasters while enabling them to focus on the mesoscale detail of the forecast, ultimately benefiting the end-users of the product. Several studies took place at the Florida State University (FSU) and NWS Tallahassee (TAE) for which they created daily flow regimes using Florida 1200 UTC synoptic soundings and CG strike densities from National Lightning Detection Network (NLDN) data. The densities were created on a 2.5 km x 2.5 km grid for every hour of every day during the warm seasons in the years 1989-2004. The grids encompass an area that includes the entire state of Florida and adjacent Atlantic and Gulf of Mexico waters. Personnel at the two organizations provided this data and supporting software for the work performed by the AMU. The densities were first stratified by flow regime, then by time in 1-, 3-, 6-, 12-, and 24-hour increments while maintaining the 2.5 km x 2.5 km grid resolution. A CG frequency of occurrence was calculated for each stratification and grid box by counting the number of days with lightning and dividing by the total number of days in the data set. New CG strike densities were calculated for each stratification and grid box by summing the strike number values over all warm seasons, then normalized by dividing the summed values by the number of lightning days. This makes the densities conditional on whether lightning occurred. The frequency climatology values will be used by forecasters as proxy inputs for lightning prObability, while the density climatology values will be used for CG amount. In addition to the benefits outlined above, these climatologies will provide improved temporal and spatial resolution, expansion of the lightning threat area to include adjacent coastal waters, and potential to extend the forecast to include the day-2 period. This presentation will describe the lightning threat index map, discuss the work done to create the maps initialized with climatological guidance, and show examples of the climatological CG lightning densities and frequencies of occurren based on flow regime.

Lambert, Winnie

Estimating Tropical Cyclone Threats to Floating Rigs in the Gulf of Mexico

Offshore drilling operations in the Gulf of Mexico are particularly vulnerable during hurricane season. When a weather threat arises, a decision to evacuate the rig and/or move to a safe location may need to be made. Depending on the activities in progress at the time of the threat, securing the well, evacuating, and/or moving to a safe location can take a considerable amount of time. This transition time is called T-time. T-time is not only rig dependent, but also depends on the activity being performed at the time of the threat. For these reasons it is important to assess tropical cyclone threats and the time it takes for them to reach the rig location. The objective of this study is to use the available 50 years of past cyclone history to estimate cyclone threats at any location in the Gulf of Mexico. The cyclone threat is estimated based on the rig location as well as the start date and duration of the offshore activity. By threat, it is meant the likelihood that a specific location with an associated offshore activity would be exposed to an upcoming cyclone whose forecasted track cone and storm size lies within that location. Three representative rig locations in the Gulf of Mexico were selected as assessment sites to evaluate the threat of incoming cyclones for different T-times. To conduct this tropical cyclone study, an Excel spreadsheet tool was developed to automate the analysis of the tropical cyclone data from the Best Track Archive for Climate Stewardship (IBTrACS) Version 4. The spreadsheet tool allows the user to input any location (i.e., longitude and latitude) in the Gulf of Mexico and displays a list of historical cyclones that have passed within 150 nautical miles of that location during the activity period selected by the user. Also, the tool allows the user to input a T-time to assess the threat of cyclones that would not provide adequate time to secure the well, evacuate, and/or move to a safe location.

Risk

The spatial distribution of ionospheric threats to WAAS integrity, 2000 – 2019: a systematic analysis

The United States’ Wide Area Augmentation System (WAAS) broadcasts data to facilitate aircraft navigation. This paper examines the spatial dependence of ionospheric disturbances that have threatened the accuracy and reliability of position estimates derived from these data over the period 2000 – 2019. We address two distinct aspects of this spatial dependence: (1) the geographic distribution of these threats, in particular, in relation to geomagnetic latitude, and (2) the geometric dependence of threats relative to the locations of the receiver sites that comprise the WAAS network. We analyze threat distributions in terms of the various means that WAAS employs to mitigate these threats, including the Extreme Storm Detector, the Moderate Storm Detector, local irregularity detectors, and the ionospheric threat model. Distinct distributions are presented for threats occurring in Solar Cycle 23 and those of Solar Cycle 24. To study the geometric dependence of threats on receiver locations, we use as a metric the distance separating a threat from the centroid of the nearest Ncentroid receivers. Large values of this metric identify threats at or beyond the edge of coverage. We conclude by discussing the implications of our results for WAAS operations.

Altshuler, Eric

Estimating Tropical Cyclone Threats to Floating Rigs in the Gulf of Mexico

Offshore drilling operations in the Gulf of Mexico are particularly vulnerable during hurricane season. When a weather threat arises, a decision to evacuate the rig and/or move to a safe location may need to be made. Securing the well, evacuating, and/or moving to a safe location can take a considerable amount of time. This transition time is called T-time. T-time is not only rig dependent, but also depends on the activity being performed at the time of the threat. For these reasons, it is important to assess tropical cyclone threats and the estimated time it will take the storm to reach the rig location from the time it is first detected. The objective of this study is to use 50 years of cyclone history from a National Oceanic and Atmospheric Administration’s (NOAA) database, the International Best Track Archive for Climate Stewardship (IBTrACS) to estimate cyclone threats at any location in the Gulf of Mexico. The cyclone threat is estimated based on the rig location as well as the start date and duration of the offshore activity. By threat, it is meant the likelihood that a specific location with an associated offshore activity lies within the forecasted track cone and storm size of the upcoming cyclone. Three representative rig locations in the Gulf of Mexico were selected as assessment sites to evaluate the threat of incoming cyclones for different T-times. To conduct this tropical cyclone study, an Excel spreadsheet tool was developed to automate the analysis of the tropical cyclone data. The spreadsheet tool allows the user to input any location (i.e., longitude and latitude) in the Gulf of Mexico and displays a list of historical cyclones that have passed within 150 nautical miles of that location during the activity period selected by the user. In addition, the tool allows the user to input any T-time to assess the threat of cyclones that would not provide adequate time to secure the well, evacuate, and/or move to a safe location.

Offshore Oil Drilling

MetaPoL: Immersive VR based Indoor Patterns of Life (PoL) and Anomalies Data Generation for Insider Threat Modeling in Nuclear Security

Insider threats are perhaps the most serious challenges that nuclear and radiological security systems face. Insiders pose such a great threat due to their access, authority, and knowledge, granting them opportunities to bypass dedicated nuclear and radiological security elements. For example, in one of the latest major insider threat incidents to nuclear security, the Doel-4 nuclear powerplant in Belgium suffered a shutdown, the threat of nuclear materials diversion, and long-term loss of tens of millions of dollars. Seven years of investigation concluded that it was an inside job and attempted sabotage. In this regard, there is an immediate need for R&D and technology integration in the domain of modeling indoor Patterns-of-Life (PoL) and anomaly detection. This can be achieved by using datasets of facility users’ mobility and activity, which can support the design of algorithms for insider threat modeling and detection. However, due to classification, privacy, sensitivity, and safety protocols, such datasets from real physical nuclear reactor facilities are not only hard to share, but also not always feasible to deploy and collect. Aiming to find an alternate solution, our proposed demonstration work - MetaPoL, is the first-ever (for the application space) immersive VR (virtual reality) environment of a real-world secure facility and allows users to move-and-stay through the designed indoor physical layout and also encounter NPCs (non-player characters) that emulate other facility users. In the MetaPoL an interactive user performs realistic spatio-temporal movement, dwelling and activities using a Meta Quest Pro VR headset, and that generates high-frequency (in time) high-resolution (in space) indoor spatial-temporal datasets that are valuable for PoL modeling and anomaly detection research specifically for insider threat modeling and detection mission. Such generated realistic, rich in context, and mission specific datasets can boost AI/Machine Learning based research for modeling and detecting insider threats in nuclear security and nonproliferation.

Gunaratne, Chathika

Capability Building Progression of an Insider Threat Mitigation Program at an International Research Reactor

The nuclear industry recognizes the difficulties involved in developing effective managerial and leadership skills in a highly technical and proficient workforce such as that found in nuclear facilities. Implementing an insider threat mitigation program (ITMP) within the nuclear industry is a complex and ongoing process that demands a comprehensive understanding of human behavior, an organization’s security culture, and rigorous regulatory requirements yet also accounts for facility characteristics, physical security, material flow, and activities involving nuclear material. Given the high-consequence nature of research reactor operations, even minor lapses can lead to safety, security, and reputational risks. An effective ITMP requires a defense-in-depth approach that incorporates behavioral analysis, robust vetting procedures, continuous monitoring, and cross-disciplinary coordination. It must also promote a culture of vigilance and accountability at all levels up to and including executive leadership but be flexible enough to adapt to evolving global threats and technological advances. Insider threat mitigation is not a one-time effort but rather a sustained commitment to excellence in safety and security. Establishing a culture in which personnel proactively report incidents and issues that could affect nuclear safety and security is vital to maintaining a safe and secure operational environment. This document was developed to guide senior management and research reactor organizations in creating comprehensive programs to effectively manage and mitigate insider threat behaviors and actions. It focuses on the key pillars of an effective ITMP, including the national legal framework, security culture, preventive and protective measures, cyber security, and performance evaluation. By using a systematic approach during implementation, facilities can foster environments conducive to insider threat detection and support long-term program sustainability. The document also provides strategies for improving communication across all levels of an organization, helping to eliminate barriers that hinder the development of robust ITMPs and enhance overall security culture. In today’s organizations, the concept of leveraging safety and security culture lessons to facilitate knowledge transfer is rapidly evolving to expedite insider threat management and security culture improvements. This document outlines the rationale for evaluating an ITMP based on national customs, culture, and stakeholders. The elements are all germane to reliability and trustworthiness and relate to security concerns that states may encounter. The document focuses not only on individual perceptions regarding security issues and capability building but also on team building and how to resolve concerns. The implementers of a facility’s ITMP may zero in on indicators of insider threats within their enterprise. This material will benefit organizations when it is applied using a systematic and structured approach as demonstrated throughout the document.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

Forecasting Lightning Threat Using WRF Proxy Fields

Objectives: Given that high-resolution WRF forecasts can capture the character of convective outbreaks, we seek to: 1. Create WRF forecasts of LTG threat (1-24 h), based on 2 proxy fields from explicitly simulated convection: - graupel flux near -15 C (captures LTG time variability) - vertically integrated ice (captures LTG threat area). 2. Calibrate each threat to yield accurate quantitative peak flash rate densities. 3. Also evaluate threats for areal coverage, time variability. 4. Blend threats to optimize results. 5. Examine sensitivity to model mesh, microphysics. Methods: 1. Use high-resolution 2-km WRF simulations to prognose convection for a diverse series of selected case studies. 2. Evaluate graupel fluxes; vertically integrated ice (VII). 3. Calibrate WRF LTG proxies using peak total LTG flash rate densities from NALMA; relationships look linear, with regression line passing through origin. 4. Truncate low threat values to make threat areal coverage match NALMA flash extent density obs. 5. Blend proxies to achieve optimal performance 6. Study CAPS 4-km ensembles to evaluate sensitivities.

McCaul, E. W., Jr.

Using Flow Regime Lightning and Sounding Climatologies to Initialize Gridded Lightning Threat Forecasts for East Central Florida

Each morning, the forecasters at the National Weather Service in Melbourne, FL (NWS MLB) produce an experimental cloud-to-ground (CG) lightning threat index map for their county warning area (CWA) that is posted to their web site (http://www.srh.weather.gov/mlb/ghwo/lightning.shtml) . Given the hazardous nature of lightning in East Central Florida, especially during the warm season months of May September, these maps help users factor the threat of lightning, relative to their location, into their daily plans. The maps are color-coded in five levels from Very Low to Extreme, with threat level definitions based on the probability of lightning occurrence and the expected amount of CG activity. On a day in which thunderstorms are expected, there are typically two or more threat levels depicted spatially across the CWA. The locations of relative lightning threat maxima and minima often depend on the position and orientation of the low-level ridge axis, forecast propagation and interaction of sea/lake/outflow boundaries, expected evolution of moisture and stability fields, and other factors that can influence the spatial distribution of thunderstorms over the CWA. The lightning threat index maps are issued for the 24-hour period beginning at 1200 UTC each day with a grid resolution of 5 km x 5 km. Product preparation is performed on the AWIPS Graphical Forecast Editor (GFE), which is the standard NWS platform for graphical editing. Currently, the forecasters create each map manually, starting with a blank map. To improve efficiency of the forecast process, NWS MLB requested that the Applied Meteorology Unit (AMU) create gridded warm season lightning climatologies that could be used as first-guess inputs to initialize lightning threat index maps. The gridded values requested included CG strike densities and frequency of occurrence stratified by synoptic-scale flow regime. The intent is to improve consistency between forecasters while allowing them to focus on the mesoscale detail of the forecast, ultimately benefiting the end-users of the product. Several studies took place at the Florida State University (FSU) and NWS Tallahassee (TAE) in which they created daily flow regimes using Florida 1200 UTC synoptic soundings and CG strike densities, or number of strikes per specified area. The soundings used to determine the flow regimes were taken at Miami (MIA), Tampa (TBW), and Jacksonville (JAX), FL, and the lightning data for the strike densities came from the National Lightning Detection Network (NLDN). The densities were created on a 2.5 km x 2.5 km grid for every hour of every day during the warm seasons in the years 1989-2004. The grids encompass an area that includes the entire state of Florida and adjacent Atlantic and Gulf of Mexico waters. Personnel at FSU and NWS TAE provided this data and supporting software for the work performed by the AMU.

Lambert, Winifred

Using Flow Regime Lightning and Sounding Climatologies to Initialize Gridded Lightning Threat Forecasts for East Central Florida

Each morning, the forecasters at the National Weather Service in Melbourne, FL (NWS MLB) produce an experimental cloud-to-ground (CG) lightning threat index map for their county warning area (CWA) that is posted to their web site (httl://www.srh.weather.gov/mlb/ghwo/lightning.shtml) . Given the hazardous nature of lightning in East Central Florida, especially during the warm season months of May September, these maps help users factor the threat of lightning, relative to their location, into their daily plans. The maps are color-coded in five levels from Very Low to Extreme, with threat level definitions based on the probability of lightning occurrence and the expected amount of CG activity. On a day in which thunderstorms are expected, there are typically two or more threat levels depicted spatially across the CWA. The locations of relative lightning threat maxima and minima often depend on the position and orientation of the low-level ridge axis, forecast propagation and interaction of sea/lake/outflow boundaries, expected evolution of moisture and stability fields, and other factors that can influence the spatial distribution of thunderstorms over the CWA. The lightning threat index maps are issued for the 24-hour period beginning at 1200 UTC each day with a grid resolution of 5 km x 5 km. Product preparation is performed on the AWIPS Graphical Forecast Editor (GFE), which is the standard NWS platform for graphical editing. Until recently, the forecasters created each map manually, starting with a blank map. To improve efficiency of the forecast process, NWS MLB requested that the Applied Meteorology Unit (AMU) create gridded warm season lightning climatologies that could be used as first-guess inputs to initialize lightning threat index maps. The gridded values requested included CG strike densities and frequency of occurrence stratified by synoptic-scale flow regime. The intent was to improve consistency between forecasters while allowing them to focus on the mesoscale detail of the forecast. Several studies took place at the Florida State University (FSU) and NWS Tallahassee (TAE) in which they created daily flow regimes using Florida 1200 UTC synoptic soundings and CG strike densities, or number of strikes per specified area. The soundings used to determine the flow regimes were taken at Miami (MIA), Tampa (TBW), and Jacksonville (JAX), FL, and the lightning data for the strike densities came from the National Lightning Detection Network (NLDN). The densities were created on a 2.5 km x 2.5 km grid for every hour of every day during the warm seasons in the years 1989-2004. The grids encompass an area that includes the entire state of Florida and adjacent Atlantic and Gulf of Mexico waters. Personnel at FSU and NWS TAE provided this data and supporting software for the work performed by the AMU.

Lambert, Winifred

Digital-Threat Bias and Psychological Distance: Barriers to Foundational Digital-Security Improvement

Modern life is held together by a web of digital dependencies that enable and provide delivery of critical services and functions—think the provision of utilities such as electricity and water, as well as our dependency on digital services for social and economic services (internet, communication, etc.). As this dependency grows, the complexity related to the delivery of these critical services increases as well. As complexity increases, the understanding of the risk and impact associated with potential disruption, degradation, or destruction—due to either malicious or non-malicious events of those digitally enabled functions—decreases. One potential explanation for the difficulty to 1) understand the risks faced and 2) address them appropriately and effectively is the abstractness and psychological distance assigned to “digital threat.” The complexity of these digitally enabled services creates a perceived complicatedness; as a result, digital threats are treated differently than similarly devasting (but more easily understood) kinetic or physical threats. How we categorize these threats also matters. Acts of cyber-enabled sabotage to critical infrastructure need to be defined as irregular warfare. By inadequately defining the threat, we compound the problem. Acknowledging this digital-threat bias is foundational to improving the ability to protect critical infrastructure. Using construal-level theory and psychological-distance concepts provides an intriguing starting point to address these issues, to reframe the challenges faced, and pursue more effective critical infrastructure security and defense policy.

29 - ENERGY PLANNING, POLICY AND ECONOMY

Automated Generation of Graph-based Cyber Threat Intel

With the advancement of AI technology and tools, specifically in the cybersecurity domain, both cyber defenders and threat actors are continuously adapting the use of these capabilities to expedite their operations. With this phenomenon, threat intelligence that is up to date, refreshable, and has relevant context to a specific threat becomes more and more important as it enables cybersecurity professionals to gain insight into relevant data and relationships to guide their operations. This project enables users to frequently aggregate threat intelligence from various sources, such as vendor vulnerability advisories affecting critical infrastructure, malware reports, and adversary writeups into a centralized, standardized database. The project utilizes the Structured Threat Intelligence eXpression (STIX) for a standardized, shareable threat intelligence data format and Neo4j as a graph database solution to store STIX nodes and relationships. Initial results of the project include datasets of over 8,000 nodes and 20,000 relationships extracted from over 500 data sources that have been released within the past month.

Threat Intelligence

Forecasting Lightning Threat using Cloud-Resolving Model Simulations

Two new approaches are proposed and developed for making time and space dependent, quantitative short-term forecasts of lightning threat, and a blend of these approaches is devised that capitalizes on the strengths of each. The new methods are distinctive in that they are based entirely on the ice-phase hydrometeor fields generated by regional cloud-resolving numerical simulations, such as those produced by the WRF model. These methods are justified by established observational evidence linking aspects of the precipitating ice hydrometeor fields to total flash rates. The methods are straightforward and easy to implement, and offer an effective near-term alternative to the incorporation of complex and costly cloud electrification schemes into numerical models. One method is based on upward fluxes of precipitating ice hydrometeors in the mixed phase region at the-15 C level, while the second method is based on the vertically integrated amounts of ice hydrometeors in each model grid column. Each method can be calibrated by comparing domain-wide statistics of the peak values of simulated flash rate proxy fields against domain-wide peak total lightning flash rate density data from observations. Tests show that the first method is able to capture much of the temporal variability of the lightning threat, while the second method does a better job of depicting the areal coverage of the threat. Our blended solution is designed to retain most of the temporal sensitivity of the first method, while adding the improved spatial coverage of the second. Exploratory tests for selected North Alabama cases show that, because WRF can distinguish the general character of most convective events, our methods show promise as a means of generating quantitatively realistic fields of lightning threat. However, because the models tend to have more difficulty in predicting the instantaneous placement of storms, forecasts of the detailed location of the lightning threat based on single simulations can be in error. Although these model shortcomings presently limit the precision of lightning threat forecasts from individual runs of current generation models,the techniques proposed herein should continue to be applicable as newer and more accurate physically-based model versions, physical parameterizations, initialization techniques and ensembles of forecasts become available.

McCaul, Eugene W., Jr.

Potential of VIIRS Time Series Data for Aiding the USDA Forest Service Early Warning System for Forest Health Threats: A Gypsy Moth Defoliation Case Study

This report details one of three experiments performed during FY 2007 for the NASA RPC (Rapid Prototyping Capability) at Stennis Space Center. This RPC experiment assesses the potential of VIIRS (Visible/Infrared Imager/Radiometer Suite) and MODIS (Moderate Resolution Imaging Spectroradiometer) data for detecting and monitoring forest defoliation from the non-native Eurasian gypsy moth (Lymantria dispar). The intent of the RPC experiment was to assess the degree to which VIIRS data can provide forest disturbance monitoring information as an input to a forest threat EWS (Early Warning System) as compared to the level of information that can be obtained from MODIS data. The USDA Forest Service (USFS) plans to use MODIS products for generating broad-scaled, regional monitoring products as input to an EWS for forest health threat assessment. NASA SSC is helping the USFS to evaluate and integrate currently available satellite remote sensing technologies and data products for the EWS, including the use of MODIS products for regional monitoring of forest disturbance. Gypsy moth defoliation of the mid-Appalachian highland region was selected as a case study. Gypsy moth is one of eight major forest insect threats listed in the Healthy Forest Restoration Act (HFRA) of 2003; the gypsy moth threatens eastern U.S. hardwood forests, which are also a concern highlighted in the HFRA of 2003. This region was selected for the project because extensive gypsy moth defoliation occurred there over multiple years during the MODIS operational period. This RPC experiment is relevant to several nationally important mapping applications, including agricultural efficiency, coastal management, ecological forecasting, disaster management, and carbon management. In this experiment, MODIS data and VIIRS data simulated from MODIS were assessed for their ability to contribute broad, regional geospatial information on gypsy moth defoliation. Landsat and ASTER (Advanced Spaceborne Thermal Emission and Reflection Radiometer) data were used to assess the quality of gypsy moth defoliation mapping products derived from MODIS data and from simulated VIIRS data. The project focused on use of data from MODIS Terra as opposed to MODIS Aqua mainly because only MODIS Terra data was collected during 2000 and 2001-years with comparatively high amounts of gypsy moth defoliation within the study area. The project assessed the quality of VIIRS data simulation products. Hyperion data was employed to assess the quality of MODIS-based VIIRS simulation datasets using image correlation analysis techniques. The ART (Application Research Toolbox) software was used for data simulation. Correlation analysis between MODIS-simulated VIIRS data and Hyperion-simulated VIIRS data for red, NIR (near-infrared), and NDVI (Normalized Difference Vegetation Index) image data products collectively indicate that useful, effective VIIRS simulations can be produced using Hyperion and MODIS data sources. The r(exp 2) for red, NIR, and NDVI products were 0.56, 0.63, and 0.62, respectively, indicating a moderately high correlation between the 2 data sources. Temporal decorrelation from different data acquisition times and image misregistration may have lowered correlation results. The RPC experiment also generated MODIS-based time series data products using the TSPT (Time Series Product Tool) software. Time series of simulated VIIRS NDVI products were produced at approximately 400-meter resolution GSD (Ground Sampling Distance) at nadir for comparison to MODIS NDVI products at either 250- or 500-meter GSD. The project also computed MODIS (MOD02) NDMI (Normalized Difference Moisture Index) products at 500-meter GSD for comparison to NDVI-based products. For each year during 2000-2006, MODIS and VIIRS (simulated from MOD02) time series were computed during the peak gypsy moth defoliation time frame in the study area (approximately June 10 through July 27). Gypsy moth defoliation mapping products from simated VIIRS and MOD02 time series were produced using multiple methods, including image classification and change detection via image differencing. The latter enabled an automated defoliation detection product computed using percent change in maximum NDVI for a peak defoliation period during 2001 compared to maximum NDVI across the entire 2000-2006 time frame. Final gypsy moth defoliation mapping products were assessed for accuracy using randomly sampled locations found on available geospatial reference data (Landsat and ASTER data in conjunction with defoliation map data from the USFS). Extensive gypsy moth defoliation patches were evident on screen displays of multitemporal color composites derived from MODIS data and from simulated VIIRS vegetation index data. Such defoliation was particularly evident for 2001, although widespread denuded forests were also seen for 2000 and 2003. These visualizations were validated using aforementioned reference data. Defoliation patches were visible on displays of MODIS-based NDVI and NDMI data. The viewing of apparent defoliation patches on all of these products necessitated adoption of a specialized temporal data processing method (e.g., maximum NDVI during the peak defoliation time frame). The frequency of cloud cover necessitated this approach. Multitemporal simulated VIIRS and MODIS Terra data both produced effective general classifications of defoliated forest versus other land cover. For 2001, the MOD02-simulated VIIRS 400-meter NDVI classification produced a similar yet slightly lower overall accuracy (87.28 percent with 0.72 Kappa) than the MOD02 250-meter NDVI classification (88.44 percent with 0.75 Kappa). The MOD13 250-meter NDVI classification had a lower overall accuracy (79.13 percent) and a much lower Kappa (0.46). The report discusses accuracy assessment results in much more detail, comparing overall classification and individual class accuracy statistics for simulated VIIRS 400-meter NDVI, MOD02 250-meter NDVI, MOD02-500 meter NDVI, MOD13 250-meter NDVI, and MOD02 500-meter NDMI classifications. Automated defoliation detection products from simulated VIIRS and MOD02 data for 2001 also yielded similar, relatively high overall classification accuracy (85.55 percent for the VIIRS 400-meter NDVI versus 87.28 percent for the MOD02 250-meter NDVI). In contrast, the USFS aerial sketch map of gypsy moth defoliation showed a lower overall classification accuracy at 73.64 percent. The overall classification Kappa values were also similar for the VIIRS (approximately 0.67 Kappa) versus the MOD02 (approximately 0.72 Kappa) automated defoliation detection product, which were much higher than the values exhibited by the USFS sketch map product (overall Kappa of approximately 0.47). The report provides additional details on the accuracy of automated gypsy moth defoliation detection products compared with USFS sketch maps. The results suggest that VIIRS data can be effectively simulated from MODIS data and that VIIRS data will produce gypsy moth defoliation mapping products that are similar to MODIS-based products. The results of the RPC experiment indicate that VIIRS and MODIS data products have good potential for integration into the forest threat EWS. The accuracy assessment was performed only for 2001 because of time constraints and a relative scarcity of cloud-free Landsat and ASTER data for the peak defoliation period of the other years in the 2000-2006 time series. Additional work should be performed to assess the accuracy of gypsy moth defoliation detection products for additional years.The study area (mid-Appalachian highlands) and application (gypsy moth forest defoliation) are not necessarily representative of all forested regions and of all forest threat disturbance agents. Additional work should be performed on other inland and coastal regions as well as for other major forest threats.

Spruce, Joseph P.