Engineering PapersSearch

SEARCH · Engineering Papers

Results for “network traffic analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Verifying Cyber Implementation Best Practices With Malcolm

Network traffic analysis can reveal a lot about what's right or wrong with a network's cybersecurity footing. Using Malcolm, a powerful open-source network traffic analysis tool suite for network security monitoring, cyber analysts and asset owners can validate cybersecurity best practices and uncover red flags in network configuration, including: proper network segmentation east-west (cross-segment) and north-south traffic unsecure or outdated network protocols authentication using clear text credentials rogue devices and services unexpected protocols (e.g., IPv6, DNS, DHCP, update checks, etc.) suspicious file transfers

99 GENERAL AND MISCELLANEOUS

SimUAM: A Comprehensive Microsimulation Toolchain to Evaluate the Impact of Urban Air Mobility in Metropolitan Areas

Over the past several years, Urban Air Mobility (UAM) has galvanized enthusiasm from investors and researchers, marrying expertise in aircraft design, transportation, logistics, artificial intelligence, battery chemistry, and broader policymaking. However, two significant questions remain unexplored: (1) What is the value of UAM in a region’s transportation network? and (2) How can UAM be effectively deployed to realize and maximize this value to all stakeholders, including riders and local economies? To adequately understand the value proposition of UAM for metropolitan areas, the authors develop a holistic multi-modal toolchain, SimUAM, to model and simulate UAM and its impacts on travel behavior. This toolchain has several components: (1) Microsimulation Analysis for Network Traffic Assignment (MANTA): A fast, high-fidelity regional-scale traffic microsimulator, (2) VertiSim: Agranular, discrete-event vertiport and pedestrian simulator, (3) Flexible Engine for Fast-time Evaluation of Flight Environments (Fe3): A high-fidelity, trajectory-based aerial microsimulation. SimUAM, rooted in granular, GPU-based microsimulation, models millions of trips and their movements in the street network and in the air, producing interpretable and actionable performance metrics for UAM designs and deployments. Once the ground-air interface is modeled, the authors find that the market for UAM decreases across all network designs relative to models with static assumptions about transfer times. However, significant improvements can be made to balance the demand and optimize the networks for transfer time, likely increasing the number of benefited trips. The modularity, extensibility, and speed of the platform will allow for rapid scenario planning and sensitivity analysis, effectively acting as a detailed performance assessment tool.

urban air mobility

The 30/20 GHz communications satellite trunking network study

Alternative transmission media for a CONUS-wide trunking network in the years 1990 and 2000 are examined. The alternative technologies comprised fiber optic cable, conventional C- and Ku-band satellites, and 30/20 GHz satellites. Three levels of implementation were considered - a 10-city network, a 20-city network, and a 40-city network. The cities selected were the major metropolitan areas with the greatest communications demand. All intercity voice, data, and video traffic carried more than 40 miles was included in the analysis. In the optimized network, traffic transmitted less than 500 miles was found to be better served by fiber optic cable in 1990. By the year 2000, the crossover point would be down to 200 miles, assuming availability of 30/20 GHz satellites.

Kolb, W.

Analysis of Traffic Flow in Structured Urban Airspace Networks with MFD-based Feedback Control

This research delves into applying the Macroscopic Fundamental Diagram (MFD) concept to structured airspace networks for comprehensive aggregate modeling and introduces a feedback-based departure function aimed at optimizing traffic flow. Previous studies have rarely examined structured airspace networks featuring non-stationary vehicles through the MFD perspective. We devised a scenario grounded in practical applications, featuring a multi-lane network with explicit lane-changing behavior. The MFD effectively captured the open-loop response, displaying a low-scatter, unimodal curve on the flow versus occupancy plot. Drawing inspiration from the ground transportation ramp-metering strategies, a proportional-integral-based controller was developed. Extensive simulation outcomes suggest that feedback control, informed by MFD, holds significant potential for managing traffic flow in Urban Air Mobility (UAM) environments; a reduction of 80% in the peak number of vehicles in a holding pattern was observed for a slight reduction in throughput in this study.

MFD

Analysis of Traffic Flow in Structured Urban Airspace Networks with MFD-based Feedback Control

This research delves into applying the Macroscopic Fundamental Diagram (MFD) concept to structured airspace networks for comprehensive aggregate modeling and introduces a feedback-based departure function aimed at optimizing traffic flow. Previous studies have rarely examined structured airspace networks featuring non-stationary vehicles through the MFD perspective. We devised a scenario grounded in practical applications, featuring a multi-lane network with explicit lane-changing behavior. The MFD effectively captured the open-loop response, displaying a low-scatter, unimodal curve on the flow versus occupancy plot. Drawing inspiration from the ground transportation ramp-metering strategies, a proportional-integral-based controller was developed. Extensive simulation outcomes suggest that feedback control, informed by MFD, holds significant potential for managing traffic flow in Urban Air Mobility (UAM) environments; a reduction of 80% in the peak number of vehicles in a holding pattern was observed for a slight reduction in throughput in this study.

MFD

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William

Complex Dynamics of Air Traffic Flow

Air traffic in the United States has continued to grow at a steady pace since 1980, except for a dip immediately after the tragic events of September 11, 2001. There are different growth scenarios associated both with the magnitude and the composition of the future air traffic. The Terminal Area Forecast (TAF), prepared every year by the FAA, projects the growth of traffic in the United States. Both Boeing and Airbus publish market outlooks for air travel annually. Although predicting the future growth of traffic is difficult, there are two significant trends: heavily congested major airports continue to see an increase in traffic, and the emergence of regional jets and other smaller aircraft with fewer passengers operating directly between non-major airports. The interaction between air traffic demand and the ability of the system to provide the necessary airport and airspace resources can be modeled as a network. The size of the resulting network varies depending on the choice of its nodes. It would be useful to understand the properties of this network to guide future design and development. Many questions, such as the growth of delay with increasing traffic demand and impact of the en route weather on future air traffic, require a systematic understanding of the properties of the air traffic network. There has been a major advance in the understanding of the behavior of networks with a large number of components. Several theories have been advanced about the evolution of large biological and engineering networks by authors in diversified disciplines like physics, mathematics, biology and computer science. Several networks exhibit a scale-free property in the sense that the probabilistic distribution of their nodes as a function of connections decreases slower than an exponential. These networks are characterized by the fact that a small number of components have a disproportionate influence on the performance of the network. Scale-free networks are tolerant to random failure of components, but are vulnerable to selective attack on components. This paper examines two network representations for the baseline air traffic system. A network defined with the 40 major airports as nodes and with standard flight routes as links has a characteristic scale: all nodes have 60 or more links and no node has more than 460 links. Another network is defined with baseline aircraft routing structure exhibits an exponentially truncated scale-free behavior. Its degree ranges from 2 connections to 2900 connections, and 225 nodes have more than 250 connections. Furthermore, those high-degree nodes are homogeneously distributed in the airspace. A consequence of this scale-free behavior is that the random loss of a single node has little impact, but the loss of multiple high-degree nodes (such as occurs during major storms in busy airspace) can adversely impact the system. Two future scenarios of air traffic growth are used to predict the growth of air traffic in the United States. It is shown that a three-times growth in the overall traffic may result in a ten-times impact on the density of traffic in certain parts of the United States.

Scale-free Networks

Flow Analysis Tool White Paper

Faster networks are continually being built to accommodate larger data transfers. While it is intuitive to think that implementing faster networks will result in higher throughput rates, this is often not the case. There are many elements involved in data transfer, many of which are beyond the scope of the network itself. Although networks may get bigger and support faster technologies, the presence of other legacy components, such as older application software or kernel parameters, can often cause bottlenecks. Engineers must be able to identify when data flows are reaching a bottleneck that is not imposed by the network and then troubleshoot it using the tools available to them. The current best practice is to collect as much information as possible on the network traffic flows so that analysis is quick and easy. Unfortunately, no single method of collecting this information can sufficiently capture the whole endto- end picture. This becomes even more of a hurdle when large, multi-user systems are involved. In order to capture all the necessary information, multiple data sources are required. This paper presents a method for developing a flow analysis tool to effectively collect network flow data from multiple sources and provide that information to engineers in a clear, concise way for analysis. The purpose of this method is to collect enough information to quickly (and automatically) identify poorly performing flows along with the cause of the problem. The method involves the development of a set of database tables that can be populated with flow data from multiple sources, along with an easyto- use, web-based front-end interface to help network engineers access, organize, analyze, and manage all the information.

Boscia, Nichole K.

The Processing of Airspace Concept Evaluations Using FASTE-CNS as a Pre- or Post-Simulation CNS Analysis Tool

As NASA speculates on and explores the future of aviation, the technological and physical aspects of our environment increasing become hurdles that must be overcome for success. Research into methods for overcoming some of these selected hurdles have been purposed by several NASA research partners as concepts. The task of establishing a common evaluation environment was placed on NASA's Virtual Airspace Simulation Technologies (VAST) project (sub-project of VAMS), and they responded with the development of the Airspace Concept Evaluation System (ACES). As one examines the ACES environment from a communication, navigation or surveillance (CNS) perspective, the simulation parameters are built with assumed perfection in the transactions associated with CNS. To truly evaluate these concepts in a realistic sense, the contributions/effects of CNS must be part of the ACES. NASA Glenn Research Center (GRC) has supported the Virtual Airspace Modeling and Simulation (VAMS) project through the continued development of CNS models and analysis capabilities which supports the ACES environment. NASA GRC initiated the development a communications traffic loading analysis tool, called the Future Aeronautical Sub-network Traffic Emulator for Communications, Navigation and Surveillance (FASTE-CNS), as part of this support. This tool allows for forecasting of communications load with the understanding that, there is no single, common source for loading models used to evaluate the existing and planned communications channels; and that, consensus and accuracy in the traffic load models is a very important input to the decisions being made on the acceptability of communication techniques used to fulfill the aeronautical requirements. Leveraging off the existing capabilities of the FASTE-CNS tool, GRC has called for FASTE-CNS to have the functionality to pre- and post-process the simulation runs of ACES to report on instances when traffic density, frequency congestion or aircraft spacing/distance violations have occurred. The integration of these functions require that the CNS models used to characterize these avionic system be of higher fidelity and better consistency then is present in FASTE-CNS system. This presentation will explore the capabilities of FASTE-CNS with renewed emphasis on the enhancements being added to perform these processing functions; the fidelity and reliability of CNS models necessary to make the enhancements work; and the benchmarking of FASTE-CNS results to improve confidence for the results of the new processing capabilities.

Mainger, Steve

Traffic Modeling for Deep Space Network in the Human Mars Exploration Era

In this article we describe the analysis and simulation effort of the end-to-end traffic flow for the Deep Space Network (DSN) in the Human Exploration Era, when DSN will provide communication and navigation services for human missions to distant celestial objects like the Moon, asteroids, and Mars. Using the network traffic derived for the 30-day period within July/August 2039 from the Space Communications Mission Model (SCMM), we simulate the bandwidths of the ground links and the buffer profiles of the network nodes. We also use a 2-state Markov scheme that models the store-and-forward mechanism that regulates the ground network traffic. The network traffic modeling and simulation generates ground bandwidth and buffer statistics, which in turn are used to formulate the future DSN ground network bandwidth and storage requirements.

Cheung, Kar-ming

MSU IETC ML for Modbus (AN EDGE)

This study explores machine learning for decoding Modbus RTU data using K-Nearest Neighbors (KNN) models. An initial KNN model trained on 8,000 packets achieved 95.15% accuracy. Although ML improves generalization, accuracy still falls short of deterministic methods. These findings have implications for Modbus traffic analysis, intrusion detection in industrial networks, and adaptive error correction in real-time monitoring systems. By refining ML-based decoding, future work could enable more efficient anomaly detection and predictive maintenance in industrial automation and cybersecurity applications.

Communication Protocol

Reducing Communication Overhead in Federated Learning for Network Anomaly Detection with Adaptive Client Selection

Communication overhead in federated learning (FL) poses a significant challenge for network anomaly detection systems, where the myriad of client configurations and network conditions can severely impact system efficiency and detection accuracy. While existing approaches attempt to address this through individual optimization techniques, they often fail to maintain the delicate balance between reduced overhead and detection performance. This paper presents an adaptive FL framework that dynamically combines batch size optimization, client selection, and asynchronous updates to achieve efficient anomaly detection. Through extensive profiling and experimental analysis on two distinct datasets-UNSW-NBIS for general network traffic and ROAD for automotive networks-our framework reduces communication overhead by 97.6%; (from 700.0s to 16.8s) compared to synchronous baseline approaches while maintaining comparable detection accuracy (95.10%; vs. 95.12%;). Statistical validation using Mann-Whitney U test confirms significant improvements (p < 0.05) over existing FL approaches across both datasets, demonstrating the framework's adaptability to different network security contexts. Detailed profiling analysis reveals the efficiency gains through dramatic reductions in GPU operations and memory transfers while maintaining robust detection performance under varying client conditions.

Marfo, William [University of Texas at El Paso]

Analysis of a Dynamic Multi-Track Airway Concept for Air Traffic Management

The Dynamic Multi-track Airways (DMA) Concept for Air Traffic Management (ATM) proposes a network of high-altitude airways constructed of multiple, closely spaced, parallel tracks designed to increase en-route capacity in high-demand airspace corridors. Segregated from non-airway operations, these multi-track airways establish high-priority traffic flow corridors along optimal routes between major terminal areas throughout the National Airspace System (NAS). Air traffic controllers transition aircraft equipped for DMA operations to DMA entry points, the aircraft use autonomous control of airspeed to fly the continuous-airspace airway and achieve an economic benefit, and controllers then transition the aircraft from the DMA exit to the terminal area. Aircraft authority within the DMA includes responsibility for spacing and/or separation from other DMA aircraft. The DMA controller is responsible for coordinating the entry and exit of traffic to and from the DMA and for traffic flow management (TFM), including adjusting DMA routing on a daily basis to account for predicted weather and wind patterns and re-routing DMAs in real time to accommodate unpredicted weather changes. However, the DMA controller is not responsible for monitoring the DMA for traffic separation. This report defines the mature state concept, explores its feasibility and performance, and identifies potential benefits. The report also discusses (a) an analysis of a single DMA, which was modeled within the NAS to assess capacity and determine the impact of a single DMA on regional sector loads and conflict potential; (b) a demand analysis, which was conducted to determine likely city-pair candidates for a nationwide DMA network and to determine the expected demand fraction; (c) two track configurations, which were modeled and analyzed for their operational characteristic; (d) software-prototype airborne capabilities developed for DMA operations research; (e) a feasibility analysis of key attributes in the concept design; (f) a near-term, transitional application of the DMA concept as a proving ground for new airborne technologies; and (g) conclusions. The analysis indicates that the operational feasibility of a national DMA network faces significant challenges, especially for interactions between DMAs and between DMA and non-DMA traffic. Provided these issues are resolved, sectors near DMAs could experience significant local capacity benefits.

Wing, David J.