Engineering PapersSearch

SEARCH · Engineering Papers

Results for “security controls”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A Survey of Cyber Threats and Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Cyber Threats

Cyber Threats and Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Urban Air Mobility

Cyber Threats & Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Cyber Threats

Tailoring NIST Security Controls for the Ground System: Selection and Implementation -- Recommendations for Information System Owners

The National Aeronautics and Space Administration (NASA) invests millions of dollars in spacecraft and ground system development, and in mission operations in the pursuit of scientific knowledge of the universe. In recent years, NASA sent a probe to Mars to study the Red Planet's upper atmosphere, obtained high resolution images of Pluto, and it is currently preparing to find new exoplanets, rendezvous with an asteroid, and bring a sample of the asteroid back to Earth for analysis. The success of these missions is enabled by mission assurance. In turn, mission assurance is backed by information assurance. The information systems supporting NASA missions must be reliable as well as secure. NASA - like every other U.S. Federal Government agency - is required to manage the security of its information systems according to federal mandates, the most prominent being the Federal Information Security Management Act (FISMA) of 2002 and the legislative updates that followed it. Like the management of enterprise information technology (IT), federal information security management takes a "one-size fits all" approach for protecting IT systems. While this approach works for most organizations, it does not effectively translate into security of highly specialized systems such as those supporting NASA missions. These systems include command and control (C&C) systems, spacecraft and instrument simulators, and other elements comprising the ground segment. They must be carefully configured, monitored and maintained, sometimes for several years past the missions' initially planned life expectancy, to ensure the ground system is protected and remains operational without any compromise of its confidentiality, integrity and availability. Enterprise policies, processes, procedures and products, if not effectively tailored to meet mission requirements, may not offer the needed security for protecting the information system, and they may even become disruptive to mission operations. Certain protective measures for the general enterprise may not be as efficient within the ground segment. This is what the authors have concluded through observations and analysis of patterns identified from the various security assessments performed on NASA missions such as MAVEN, OSIRIS-REx, New Horizons and TESS, to name a few. The security audits confirmed that the framework for managing information system security developed by the National Institute of Standards and Technology (NIST) for the federal government, and adopted by NASA, is indeed effective. However, the selection of the technical, operational and management security controls offered by the NIST model - and how they are implemented - does not always fit the nature and the environment where the ground system operates in even though there is no apparent impact on mission success. The authors observed that unfit controls, that is, controls that are not necessarily applicable or sufficiently effective in protecting the mission systems, are often selected to facilitate compliance with security requirements and organizational expectations even if the selected controls offer minimum or non-existent protection. This paper identifies some of the standard security controls that can in fact protect the ground system, and which of them offer little or no benefit at all. It offers multiple scenarios from real security audits in which the controls are not effective without, of course, disclosing any sensitive information about the missions assessed. In addition to selection and implementation of controls, the paper also discusses potential impact of recent legislation such as the Federal Information Security Modernization Act (FISMA) of 2014 - aimed at the enterprise - on the ground system, and offers other recommendations to Information System Owners (ISOs).

GOVERNANCE

Controlling multiple security robots in a warehouse environment

The Naval Command Control and Ocean Surveillance Center (NCCOSC) has developed an architecture to provide coordinated control of multiple autonomous vehicles from a single host console. The multiple robot host architecture (MRHA) is a distributed multiprocessing system that can be expanded to accommodate as many as 32 robots. The initial application will employ eight Cybermotion K2A Navmaster robots configured as remote security platforms in support of the Mobile Detection Assessment and Response System (MDARS) Program. This paper discusses developmental testing of the MRHA in an operational warehouse environment, with two actual and four simulated robotic platforms.

Everett, H. R.

The Spaceport Command and Control System Security Assessor Project

This Summer, I worked as a National Aeronautics and Space Administration (NASA) Internships and Fellowships (NIF) intern under my mentor, Jill Giles within the Software Engineering Branch. Within this project, I worked alongside the Cyber Security branch to identify a list of Commercial Off the Shelf (COTS) software to analyze, research, and gain insight about potential vulnerabilities within the software that could become a threat of attack. After identifying the list of COTS software, my team and I used Microsoft Excel to create a worksheet to easily organize and design a questionnaire about the software. Security reports weregiven to us to identify the software used on the machines in the firing rooms. With these reports, we created a script that would populate the database with the software information to identify potential security weaknesses of COTS software.The goal of the project was to produce a final report, summarizing the most vulnerable launch control system servers and configurations and document vulnerabilities, residual risk, likelihood, and consequence. This project is important for the Cyber Security and Information Technology branches because it will identify security weaknesses and help to mitigate risk. From the Spaceport Command and Control System Security Assessor Project, I learned how to properly identify weaknesses and vulnerabilities within software and how to mitigate the risks within the software. This project also taught me how to create databases using scripts and input files.

Destani Satora Van Arsdalen

Analyzing Risks and Vulnerabilities of Various Computer Systems and Undergoing Exploitation using Embedded Devices

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere has heightened from airports to communication among the military branches legionnaires. With advanced persistent threats (APTs) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated, patched and secured state in a launch control system environment. Attacks on critical systems are becoming more and more relevant and frequent. Nation states are hacking into critical networks that might control electrical power grids or water dams as well as carrying out advanced persistent threat (APTs) attacks on government entities. NASA, as an organization, must protect its self from attacks from all different types of attackers with different motives. Although the International Space Station was created, there is still competition between the different space programs. With that in mind, NASA might get attacked and breached for various reasons such as espionage or sabotage. My project will provide a way for NASA to complete an in house penetration test which includes: asset discovery, vulnerability scans, exploit vulnerabilities and also provide forensic information to harden systems. Completing penetration testing is a part of the compliance requirements of the Federal Information Security Act (FISMA) and NASA NPR 2810.1 and related NASA Handbooks. This project is to demonstrate how in house penetration testing can be conducted that will satisfy all of the compliance requirements of the National Institute of Standards and Technology (NIST), as outlined in FISMA. By the end of this project, I hope to have carried out the tasks stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, as well as policies and procedures.

Penetration Testing

Developing a Cybersecurity Architecture for Extensible Traffic Management (xTM)

This paper explores the development of a cybersecurity architecture tailored for Extensible Traffic Management (xTM) to address emerging challenges in managing diverse aerial vehicles within the National Airspace System (NAS). Driven by technological advances and the rise of uncrewed aerial systems (UAS), urban air mobility (UAM), and high-altitude traffic (ETM), the NAS is undergoing a paradigm shift. Traditional air traffic management, reliant on traditional Federal Aviation Administration (FAA) control, will give way to decentralized coordination among autonomous and semi-autonomous systems. The proposed xTM Security Architecture, designed as a high-level framework, focuses on ensuring the confidentiality, integrity, and availability of data and operations in this evolving ecosystem. Utilizing threat modeling, the research identifies potential risks across key flight phases, operations and use cases to offer security control recommendations. Key objectives include analyzing interactions between novel airspace entrants and existing NAS traffic, cataloging vulnerabilities, and developing mitigative strategies to ensure safety, operational stability, and secure data exchanges. This research lays the groundwork for regulatory and industry adaptation, providing critical insights into managing cybersecurity risks in this complex, multi-domain environment.

UAM

Virtualization - A Key Cost Saver in NASA Multi-Mission Ground System Architecture

With science team budgets being slashed, and a lack of adequate facilities for science payload teams to operate their instruments, there is a strong need for innovative new ground systems that are able to provide necessary levels of capability processing power, system availability and redundancy while maintaining a small footprint in terms of physical space, power utilization and cooling.The ground system architecture being presented is based off of heritage from several other projects currently in development or operations at Goddard, but was designed and built specifically to meet the needs of the Science and Planetary Operations Control Center (SPOCC) as a low-cost payload command, control, planning and analysis operations center. However, this SPOCC architecture was designed to be generic enough to be re-used partially or in whole by other labs and missions (since its inception that has already happened in several cases!)The SPOCC architecture leverages a highly available VMware-based virtualization cluster with shared SAS Direct-Attached Storage (DAS) to provide an extremely high-performing, low-power-utilization and small-footprint compute environment that provides Virtual Machine resources shared among the various tenant missions in the SPOCC. The storage is also expandable, allowing future missions to chain up to 7 additional 2U chassis of storage at an extremely competitive cost if they require additional archive or virtual machine storage space.The software architecture provides a fully-redundant GMSEC-based message bus architecture based on the ActiveMQ middleware to track all health and safety status within the SPOCC ground system. All virtual machines utilize the GMSEC system agents to report system host health over the GMSEC bus, and spacecraft payload health is monitored using the Hammers Integrated Test and Operations System (ITOS) Galaxy Telemetry and Command (TC) system, which performs near-real-time limit checking and data processing on the downlinked data stream and injects messages into the GMSEC bus that are monitored to automatically page the on-call operator or Systems Administrator (SA) when an off-nominal condition is detected. This architecture, like the LTSP thin clients, are shared across all tenant missions.Other required IT security controls are implemented at the ground system level, including physical access controls, logical system-level authentication authorization management, auditing and reporting, network management and a NIST 800-53 FISMA-Moderate IT Security plan Risk Assessment Contingency Plan, helping multiple missions share the cost of compliance with agency-mandated directives.The SPOCC architecture provides science payload control centers and backup mission operations centers with a cost-effective, standardized approach to virtualizing and monitoring resources that were traditionally multiple racks full of physical machines. The increased agility in deploying new virtual systems and thin client workstations can provide significant savings in personnel costs for maintaining the ground system. The cost savings in procurement, power, rack footprint and cooling as well as the shared multi-mission design greatly reduces upfront cost for missions moving into the facility. Overall, the authors hope that this architecture will become a model for how future NASA operations centers are constructed!

Ground System Architecture

Secure, Autonomous, Intelligent Controller for Integrating Distributed Emergency Response Satellite Operations

This report describes a Secure, Autonomous, and Intelligent Controller for Integrating Distributed Emergency Response Satellite Operations. It includes a description of current improvements to existing Virtual Mission Operations Center technology being used by US Department of Defense and originally developed under NASA funding. The report also highlights a technology demonstration performed in partnership with the United States Geological Service for Earth Resources Observation and Science using DigitalGlobe(Registered TradeMark) satellites to obtain space-based sensor data.

Ivancic, William D.

Automatic documentation system extension to multi-manufacturers' computers and to measure, improve, and predict software reliability. Appendix A and B

A manual which explains how to use the DOMONIC command language is presented. The manual consists of the following sections: 1. Introduction 2. What You Must Know to Use DOMONIC 3. Functions of DOMONIC 4. Entering and Manipulating Data 5. Templates and Data Definitions 6. Recipes and Document Generation 7. Initiating A Project and 8. Entering and Changing Security Controls. The first four sections must be known by all DOMONIC users. Sections five, seven and eight describe functions normally used only by project management. Section six tells how to generate documents. The manual specifies what commands to use in performing each of the functions mentioned above.

Simmons, D. B.

Optimal Inflatable Space Towers with 3 - 100 km Height

Theory and computations are provided for building inflatable space towers up to one hundred kilometers in height. These towers can be used for tourism, scientific observation of space, observation of the Earth's surface, weather and upper atmosphere, and for radio, television, and communication transmissions. These towers can also be used to launch space ships and Earth satellites. These projects are not expensive and do not require rockets. They require thin strong films composed from artificial fibers and fabricated by current industry. The towers can be built using present technology. The towers can be used (for tourism, communication, etc.) during the construction process and provide self-financing for further construction. The tower design does not require work at high altitudes; all construction can be done at the Earth's surface. The transport system for a tower consists of a small engine (used only for friction compensation) located at the Earth's surface. The tower is separated into sections and has special protection mechanisms in case of damage. Problems involving security, control, repair, and stability of the proposed towers are addressed in other publications. The author is prepared to discuss these and other problems with serious organizations desiring to research and develop these projects.

Bolonkin, Alexander

Pharmacovigilance in Space: Stability Payload Compliance Procedures

Pharmacovigilance is the science of, and activities relating to the detection, assessment, understanding, and prevention of drug-related problems. Over the lase decade, pharmacovigilance activities have contributed to the development of numerous technological and conventional advances focused on medication safety and regulatory intervention. The topics discussed include: 1) Proactive Pharmacovigilance; 2) A New Frontier; 3) Research Activities; 4) Project Purpose; 5) Methods; 6) Flight Stability Kit Components; 7) Experimental Conditions; 8) Research Project Logistics; 9) Research Plan; 10) Pharmaceutical Stability Research Project Pharmacovigilance Aspects; 11) Security / Control; 12) Packaging/Containment Actions; 13) Shelf-Life Assessments; 14) Stability Assessment Parameters; 15) Chemical Content Analysis; 16) Preliminary Results; 17) Temperature/Humidity; 18) Changes in PHysical and Chemical Assessment Parameters; 19) Observations; and 20) Conclusions.

Daniels, Vernie R.

NASA Biological Specimen Repository

The NASA Biological Specimen Repository (NBSR) has been established to collect, process, annotate, store, and distribute specimens under the authority of the NASA/JSC Committee for the Protection of Human Subjects. The International Space Station (ISS) provides a platform to investigate the effects of microgravity on human physiology prior to lunar and exploration class missions. The NBSR is a secure controlled storage facility that is used to maintain biological specimens over extended periods of time, under well-controlled conditions, for future use in approved human spaceflight-related research protocols. The repository supports the Human Research Program, which is charged with identifying and investigating physiological changes that occur during human spaceflight, and developing and implementing effective countermeasures when necessary. The storage of crewmember samples from many different ISS flights in a single repository will be a valuable resource with which researchers can validate clinical hypotheses, study space-flight related changes, and investigate physiological markers All samples collected require written informed consent from each long duration crewmember. The NBSR collects blood and urine samples from all participating long duration ISS crewmembers. These biological samples are collected pre-flight at approximately 45 days prior to launch, during flight on flight days 15, 30, 60 120 and within 2 weeks of landing. Postflight sessions are conducted 3 and 30 days following landing. The number of inflight sessions is dependent on the duration of the mission. Operations began in 2007 and as of October 2009, 23 USOS crewmembers have completed or agreed to participate in this project. As currently planned, these human biological samples will be collected from crewmembers covering multiple ISS missions until the end of U.S. presence on the ISS or 2017. The NBSR will establish guidelines for sample distribution that are consistent with ethical principles, protection of crewmember confidentiality, prevailing laws and regulations, intellectual property policies, and consent form language. A NBSR Advisory Board composed of representatives of all participating agencies will be established to evaluate each request by an investigator for use of the samples to ensure the request reflects the mission of the NBSR.

Pietrzyk, Robert

L-Band Digital Aeronautical Communications System Engineering - Initial Safety and Security Risk Assessment and Mitigation

This document is being provided as part of ITT's NASA Glenn Research Center Aerospace Communication Systems Technical Support (ACSTS) contract NNC05CA85C, Task 7: "New ATM Requirements--Future Communications, C-Band and L-Band Communications Standard Development." ITT has completed a safety hazard analysis providing a preliminary safety assessment for the proposed L-band (960 to 1164 MHz) terrestrial en route communications system. The assessment was performed following the guidelines outlined in the Federal Aviation Administration Safety Risk Management Guidance for System Acquisitions document. The safety analysis did not identify any hazards with an unacceptable risk, though a number of hazards with a medium risk were documented. This effort represents a preliminary safety hazard analysis and notes the triggers for risk reassessment. A detailed safety hazards analysis is recommended as a follow-on activity to assess particular components of the L-band communication system after the technology is chosen and system rollout timing is determined. The security risk analysis resulted in identifying main security threats to the proposed system as well as noting additional threats recommended for a future security analysis conducted at a later stage in the system development process. The document discusses various security controls, including those suggested in the COCR Version 2.0.

Zelkin, Natalie

Secure, Autonomous, Intelligent Controller for Integrating Distributed Sensor Webs

This paper describes the infrastructure and protocols necessary to enable near-real-time commanding, access to space-based assets, and the secure interoperation between sensor webs owned and controlled by various entities. Select terrestrial and aeronautics-base sensor webs will be used to demonstrate time-critical interoperability between integrated, intelligent sensor webs both terrestrial and between terrestrial and space-based assets. For this work, a Secure, Autonomous, Intelligent Controller and knowledge generation unit is implemented using Virtual Mission Operation Center technology.

Ivancic, William D.

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere was heightened from Airports to the communication among the military branches legionnaires. With advanced persistent threats (APTs) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning and configuration of network devices i.e. routers and IDSsIPSs. In addition I will be completing security assessments on software and hardware, vulnerability assessments and reporting, conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, policies and procedures.

computer information security

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere has heightened from airports to the communication among the military branches legionnaires. With advanced persistent threats (APT's) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning, and configuration of network devices i.e. routers and IDS's/IPS's. In addition, I will be completing security assessments on software and hardware, vulnerability assessments and reporting, and conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out the tasks stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, as well as policies and procedures.

security