
This paper is a conceptual paper that explores how the sensemaking process by intelligence analysts completed within a cognitive immersive environment might be impacted by the inclusion of a progressive dialog system. The tools enabled in the sensemaking room (a specific instance within the cognitive immersive environment) were informed by tools from the intelligence analysis domain. We explore how a progressive dialog system would impact the use of tools such as the collaborative brainstorming exercise [1]. These structured analytic techniques are well established in intelligence analysis training literature, and act as ways to access the intended users' cognitive schema as they use the cognitive immersive room and move through the sensemaking process. A prior user study determined that the sensemaking room encouraged users to be more concise and representative with information while using the digital brainstorming tool. We anticipate that addition of the progressive dialog function will enable a more cohesive link between information foraging and sensemaking behaviors for analysts.
Guidelines, directives, and policy statements are usually presented in "linear" text form - word after word, page after page. However necessary, this practice impedes full understanding, obscures feedback dynamics, hides mutual dependencies and cascading effects and the like-even when augmented with tables and diagrams. The net result is often a checklist response as an end in itself. All this creates barriers to intended realization of guidelines and undermines potential effectiveness. We present a solution strategy using text as "data", transforming text into a structured model, and generate network views of the text(s), that we then can use for vulnerability mapping, risk assessments and note control point analysis. For proof of concept we draw on NIST conceptual model and analysis of guidelines for smart grid cybersecurity, more than 600 pages of text.
Modern organizations need effective ways to assess cybersecurity risk. Successful cyber attacks can result in data breaches, which may inflict significant loss of money, time, and public trust. Small businesses and non-profit organizations have limited resources to invest in cybersecurity controls and often do not have the in-house expertise to assess their risk. Cyber threat actors also vary in sophistication, motivation, and effectiveness. This paper builds on the previous work of Lerums et al., who presented an AnyLogic model for simulating aspects of a cyber attack and the efficacy of controls in a generic enterprise network. This paper argues that their model is an effective quantitative means of measuring the probability of success of a threat actor and implements two primary changes to increase the model's accuracy. First, the authors modified the model's inputs, allowing users to select threat actors based on the organization's specific threat model. Threat actor effectiveness is evaluated based on publicly available breach data (in addition to security control efficacy), resulting in further refined attack success probabilities. Second, all three elements - threat effectiveness, control efficacy, and model variance - are computed and evaluated at each node to increase the estimation fidelity in place of pooled variance calculations. Visualization graphs, multiple simulation runs (up to 1 million), attack path customization, and code efficiency changes are also implemented. The result is a simulation tool that provides valuable insight to decision-makers and practitioners about where to most efficiently invest resources in their computing environment to increase cybersecurity posture. AttackSimulation and its source code are freely available on GitHub.
Robotic vehicles are becoming more widespread and used in many industries, including agriculture, manufacturing, and defense. They are safety-critical systems because of the fact that they are mobile, autonomous, and can operate in hazardous environments. The focus on robotic systems in the last several decades has been to add new complex functionality, in many cases using artificial intelligence. Many of these new technologies are fairly sophisticated and expose robotic vehicles to new vulnerabilities, especially when vehicles need to operate autonomously. Security and safety are connected and preventing intentional attacks on mobile robots improves safety and allows robots to complete their missions in challenging and hostile environments. In addition, robots that move can and need to adapt and counteract adversarial attacks and adapt to sensor and actuator faults. Robotic vehicles are also real-time systems; their ability to function is determined by their ability to maintain these characteristics all the time. In this work, we present the major classes of attacks on robotic vehicles and analyze the existing and propose some new mitigation strategies to counteract the attacks. Our scope is on robotic vehicles in general, with a specialized focus on UAVs as a class of vehicles receiving more attention and presenting significant security challenges. We discuss strategies based on simplex architecture, enforcers, partitioning, redundancy, self-adaptation, and dynamic architectures during run-time.
Critical infrastructure systems are increasingly at risk of failure due to extreme weather, exacerbated by climate change, and cyber-physical attack, due to reliance on digital information technology. When assessing the state of current infrastructure systems, and when planning new infrastructures, considerations of operational efficiency and resource constraints must be balanced with resilience. A resilient infrastructure design paradigm must account for low-probability, high-impact “grey swan” hazards, and resilience must be structurally embedded by design. This work extends the state-of-the-art in quantification of infrastructure resilience with compound natural-human hazard scenarios and focuses on urban rail transit networks as a proof-of-concept infrastructure system. With new and existing rail projects receiving funding opportunities, an imperative emerges to develop methodological frameworks which can address uncertainty and build resilience into design decisions in addition to operational efficiency. The contributions of this paper are threefold: (1) developing an analytical modeling framework for the simulation of compound failure and recovery in spatially-constrained rail transit networks leveraging system-level awareness; (2) characterizing the dynamics of an urban rail transit network by constructing resilience curves using the largest connected component of the network as a proxy measure for system functionality; and (3) leveraging network science and engineering principles to generate decision-support insights under uncertainty.
Hyperspectral images are represented by numerous narrow wavelength bands in the visible and near-infrared parts of the electromagnetic spectrum. As hyperspectral imagery gains traction for general computer vision tasks, there is an increased need for large and comprehensive datasets for use as training data. Recent advancements in sensor technology allow us to capture hyperspectral data cubes at higher spatial and temporal resolution. However, there are few publicly available multi-purpose hyperspectral datasets captured in outdoor terrestrial conditions. Furthermore, there are no publicly available datasets that include 3D mesh representations of objects captured in outdoor scenes. This article introduces the first hyperspectral dataset of 3D objects and terrestrial outdoor scenes, the Tufts Outdoor Hyper-spectral Dataset (TOHS Dataset). The dataset includes 100 2D + 3D hyperspectral scenes, each containing 164 spectral bands. The contributions of this work are 1) Detailed description of the content, acquisition procedure, and benchmark results on state-of-the-art neural networks for 3D object scenes in the Tufts Hyperspectral Database; 2) The first-of-its-kind hyperspectral 3D dataset of outdoor objects that will be publicly available to researchers worldwide, which will allow for the assessment and creation of more robust, consistent, and adaptable AI algorithms; and 3) a comprehensive and up-to-date review on hyperspectral systems and datasets.
Industrial Internet of Things (IIOT) is increasingly relying on over-the-air firmware updates (FOTA) to deliver tailored analytics to control systems for critical infrastructure. Connected IIOT with FOTA can deliver significant value by decreasing capital investments, enabling customizable functionalities, or improving operational efficiencies. FOTA also increases exposure to threats targeting critical infrastructure, which could lead to safety or mission damage (i.e., failures could result in loss of life or loss of critical functions). This paper presents a security baseline for FOTA by creating a secure “pipeline” for IIOT firmware. It first provides a generic reference architecture that defines connections between the IIOT device, a gateway for communication outside the control network, cloud storage and configuration logic, and the device-vendor's development environment. It describes attacks against various aspects of the reference architecture and explains the security controls that the device-vendor should implement to ensure that the benefits of FOTA for continuous upgradable security and efficiency outweigh the risks from additional exposure. It also provides some follow-on recommendations that utilities should consider before installing IIOT with FOTA capabilities, including: securing the device with secure boot and chain of trust, securing all communication channels with unique endpoint identification and encryption, taking the human out of the build and update processes, and hardening components involved in FOTA for continuous monitoring. This paper emphasizes that these types of connected devices promote a need for a shared responsibility model of cybersecurity.
The common vulnerabilities and exposures (CVE) database was created with a mission to “identify, define, and catalog publicly disclosed cybersecurity vulnerabilities”. This rich body of information can be used to enable rapid and efficient response to secure and defend cyber operations and protect critical cyber infrastructure. The main goal of this paper is to develop a visual analytic tool to enable deep analysis of CVEs using unsupervised clustering techniques. We enhance our analysis by first mapping CVEs to hierarchical-classes in Common Weakness Enumeration (CWE) using information in the National Vulnerability Database (NVD). Both the mapping and the numerical representation of CVEs are enabled by V2W-BERT, which uses natural language processing of the extensive information in NVD to generate a large tabular database of 137,226 CVE entries from 1999 to 2020, where each CVE is represented by a vector of 768 numerical features. The vectorized data is processed by Self-Organizing Maps (SOM), which is an unsupervised machine learning technique for dimensionality reduction, visual representation and clustering. Using a Torus map of 6417 units, we achieve 10-fold data compression of 140k CVEs using SOM. The trained map is further clustered using standard K-means clustering into 138 clusters of CVEs. We conducted a brief investigation of the rich mapping of CVEs to best-matching-units to K-means clusters, as well as CVEs to CWEs. For example, this novel mapping provided insight into the role of CWE-59 and CWE-264 in several CVEs that is otherwise hard to explore in the original data. We conclude that our this novel approach will not only enable deep analysis of the complex relationships between CVEs and CWEs, but also a mechanism to quickly respond to and design mitigation actions for rapidly evolving vulnerabilities that have not been mapped to existing CWEs.
Artificial Intelligence (AI) has been widely applied to homeland security to speed up target recognition, threat analysis, and decision-making. The intensive computation required by AI approaches could be an obstacle that prevents AI from achieving real-time responses. Approximate computing techniques that leverage accuracy for better performance have the potential to accelerate the computation in AI. However, since the AI techniques are applied in homeland security applications, which have high requirements for piracy and security, it is critical to deploy the approximation methods in a secure way. In this work, we analyze the stealthiness of the attacks in an approximate computing system and reveal that the primary outputs are not the best location to detect the presence of attacks. We propose an intermediate node evaluation-based attack detection (INEAD) method to examine the attacks in approximate computing systems. Our case studies on approximate Finite Impulse Response (FIR) filter and artificial neural network (ANN) show that intermediate nodes are better position for attack detection than the primary output. We observe that the attack detection speed has increased by 80% when INEAD method is deployed in FIR filter. The compile time for attack detection can be reduced by 52.7% for the case of ANN when our INEAD method is deployed.
Search and Rescue (SAR) missions in remote environments often employ autonomous multi-robot systems that learn, plan, and execute a combination of local single-robot control actions, group primitives, and global mission-oriented coordination and collaboration. Often, SAR coordination strategies are manually designed by human experts who can remotely control the multi-robot system and enable semi-autonomous operations. However, in remote environments where connectivity is limited and human intervention is often not possible, decentralized collaboration strategies are needed for fully-autonomous operations. Nevertheless, decentralized coordination may be ineffective in adversarial environments due to sensor noise, actuation faults, or manipulation of inter-agent communication data. In this paper, we propose an algorithmic approach based on adversarial multi-agent reinforcement learning (MARL) that allows robots to efficiently coordinate their strategies in the presence of adversarial inter-agent communications. In our setup, the objective of the multi-robot team is to discover targets strategically in an obstacle-strewn geographical area by minimizing the average time needed to find the targets. It is assumed that the robots have no prior knowledge of the target locations, and they can interact with only a subset of neighboring robots at any time. Based on the centralized training with decentralized execution (CTDE) paradigm in MARL, we utilize a hierarchical meta-learning framework to learn dynamic team-coordination modalities and discover emergent team behavior under complex cooperative-competitive scenarios. The effectiveness of our approach is demonstrated on a collection of prototype grid-world environments with different specifications of benign and adversarial agents, target locations, and agent rewards.
The marine transportation system (MTS) is a critical part of the nation's supply chain. Malicious actors, natural disasters, pandemics, geo-political events and larger marine casualties such as the 2021 Suez Canal grounding incident can disrupt the MTS and domestic and global supply chains. To date, most research and contingency planning has focused on singleevent disruptions such as oil spills or security issues. While supply chains may be resilient enough to cope with a wide variety of single disruptions, aggregated challenges may result in cascading failures. There has been little analysis of the impacts of multiple disruptions that build on each other in complex ways. This suggests that modeling the impact of multiple vector disruptions on multiple MTS targets can help policy makers, business leaders, and others anticipate, plan for, mitigate, and rapidly recover from future complex disruptions. This paper describes an approach to research questions like: What are plausible examples of complex, multi-vector disruptions to the MTS? What could make their outcomes more complicated and challenging than those of single disruptions? What are their consequences for different components of the MTS? What are some pre-disruption mitigations and post-disruption resilience tactics that might be useful in such cases? How can we estimate the time to implement them, the costs of implementation, and the reduction of impact of such measures? The project described is developing a framework to address such questions. The framework will be used to analyze the impact of different combinations of individual disruptions, including natural disasters and climate change; security events, including cyber, accidents and marine casualties; and social/political disruptions. The analysis will focus on the total economic consequences of these threat combinations and transition into a user-friendly decision- support tool to improve risk management.
Urban resilience has become the new norm for cities as they cope with, among other things, extreme weather and climate disasters. Cities throughout the United States have begun to develop plans to prepare for these emerging risks. Despite cities' planning efforts, implementation of changes and evaluation of the effects of those changes on urban resilience remains a challenge. This is in part due to the lack of understanding of what it means to operationalize resilience. In many ways, resilience remains a “fuzzy concept” that is subject to interpretation and being “coopted” by local planners and policymakers. In this paper, we explore the feasibility of applying a homeland security capability analysis methodology to the field of urban resilience, using the City of Los Angeles as an example to demonstrate its application. We suggest employing this methodology might lead to an improved understanding of cities' abilities to operationalize resilience. This should, in turn, provide improved processes and guidance for how cities approach implementing and evaluating these plans and policies. Our exploratory research focuses specifically on extreme weather and climate disaster risk, although it could hold value for managing other types of risk.
Detection of surface vessels, semisubmersibles, and underwater vehicles is required for several Maritime Law Enforcement missions, including drug and alien migrant interdiction, monitoring, control, and surveillance of illegal, unregulated, and unreported (IUU) fishing, as well as protection from maritime terrorism. Detection and monitoring of vessels involved in illegal activity occurs principally through the collection, analysis, and dissemination of tactical information and strategic intelligence combined with effective sensors operating from land, air, and surface assets. Stevens Institute of Technology (SIT) built and tested an experimental low-cost sensor suite dubbed the Boat Detection System (BDS) prototype that can work autonomously on the shore or at sea using available platforms. The suggested low-cost automated sensor system costs less than current land and air-based sensors and does not require a human in the loop for its operation. The experimental sensor suite uses low-cost COTS sensors including marine radar, optical and infrared cameras, and AIS receivers in conjunction with an underwater acoustic array, the Stevens Passive Acoustic System (SPADES-2) prototype, outfitted with Stevens custom-made low-cost hydrophones.
In this work, we study the problem of band selection in multimodal remote sensing scenes. We present a deep learning system based on a three-dimensional variation of the DenseNet model architecture that we further modify to incorporate early and late feature fusion for multimodal learning of land cover classification. Band selection is applied during data preprocessing in order to counteract the Hughes' phenomenon (also known as the “Curse of Dimensionality”), with the intent of improving classification performance. We evaluate this deep learning data fusion system with the IEEE Geoscience and Remote Sensing Society (GRSS) data fusion contest (DFC) 2018 University of Houston dataset, a multimodal urban land usage and land cover (LULC) dataset. The experimental test harness for this work uses the TensorFlow and Keras deep learning frameworks to implement the proposed system, and our models are trained in the cloud via Google Colab notebooks. Our findings show that intelligent selection of hyperspectral bands and careful arrangement of feature fusion can result in an 8%-15% improvement in classification accuracy from the GRSS DFC 2018 contest winners when ignoring ad-hoc postprocessing. Finally, we present tables and plots comparing the efficacy of various modality fusion combinations and band selection methods to provide an in-depth analysis of how different bands and sensor modalities affect classification.
Use cases for Small Unmanned Aerial Systems (sUAS) have expanded significantly over the past few years. One use case that is relevant to both civilian and defense missions is reliable operation in GPS-denied indoor and subterranean (subT) environments such as urban underground, tunnel systems, and cave networks. While many sUAS evaluation studies exist for outdoor environments, there have been limited studies to evaluate the characteristics of sUAS in GPS-denied indoor and subT environments. This paper attempts to resolve this knowledge gap by presenting a methodology for evaluating the navigation performance of sUAS in such environments, including operations such as waypoint navigation, path traversal, trajectory keeping, and navigation around corners. Specifically, we determine and present results for the navigation performance of five commercially available sUAS via the presented evaluation methodology.
This paper considers network protection games for a heterogeneous network system with $N$ nodes against cyber-attackers of two different types of intentions. The first type tries to maximize damage based on the value of each net-worked node, while the second type only aims at successful infiltration. A defender, by applying defensive resources to networked nodes, can decrease those nodes' vulnerabilities. Meanwhile, the defender needs to balance the cost of using defensive resources and potential security benefits. Existing literature shows that, in a Nash equilibrium, the defender should adopt different resource allocation strategies against different types of attackers. However, it could be difficult for the defender to know the type of incoming cyber-attackers. A Bayesian game is investigated considering the case that the defender is uncertain about the attacker's type. We demonstrate that the Bayesian equilibrium defensive resource allocation strategy is a mixture of the Nash equilibrium strategies from the games against the two types of attackers separately.
A radio direction finding (RDF) system to find line-of-bearing (LOB) towards communication used by nefarious actors may be a useful tool for illegal boat activity detection. Crews of boats involved in illegal activities, such as smuggling, may communicate with their accomplices on other boats or land using various RF communication systems with different frequencies. The Citizen Band (CB) radios have less of a chance to be intercepted by Electronic Intelligence (ELINT) and direction finding used by the USCG than VHF, UHF two-way radios. Also, 27 MHz GPS buoys are used by smugglers to tag packages left afloat in open water to be picked up by an accomplice. To detect such activity RDF system should be able to detect transmissions that are: distant, few, and short and occurring on any channel. The system should support installation on a vehicle or a boat for mobility. Stevens Institute of Technology has developed and tested a low-cost RDF system, that is capable of simultaneous direction-finding towards distant transmissions with simultaneous detection on multiple channels based on software-defined radio (SDR) and pseudo-doppler (PD) principles of direction-finding. Software with a user-friendly interface has been developed to process, display results, and integrate with mapping systems in real-time. The same approach can be used for RDF working in the other frequency bands.
As a next-generation DNA sequencing technique, metabarcoding aids in identifying biotic trace materials such as pollen, fungal spores, and other environmental DNA samples. This paper aims to develop a geographic attribution framework using pollen samples associated with objects or persons of interest to reduce search space for law enforcement investigations. We use plant occurrence data from the open-source Global Biodi-versity Information Facility (GBIF) to model individual genus and species distributions which were subsequently combined to inform possible geolocations objects or persons of interest have traveled. Results indicate that the geographic attribution frame-work could potentially aid forensic investigations by eliminating geographic search areas to determine the possible location history of people and objects.
Object classification is a rapidly growing topic that is proving to serve many uses in both civilian and military professions. With continued development in this field, the Army and its units can accomplish tasks in more safe and efficient manners as unmanned drones and other technologies can carry out missions that have not been possible in the past. The purpose of this project is to develop a classifier model that can autonomously identify and track personnel during search and rescue (SAR) missions. The implementation of this technology would potentially improve the efficiency and reduce the risk of SAR missions in the Army by allowing soldiers to send out dispensable robots instead of risking indispensable lives.
Many Emergency Medical Service (EMS) and Fire services across the United States still rely on analog voice paging technology to communicate emergency incident information to responders. The infrastructure for these paging systems is typically owned, operated, and maintained by the local government or agency to ensure coverage includes as close to 100% of the jurisdiction as possible. This paper proposes the use of datacasting technology to provide a redundant method for critical data distribution over a wide area to serve the paging needs of public safety and uses North Carolina as a test case. This concept could lead to cost-sharing, higher reliability, greater collaboration across jurisdictions, and reduced response times. The public deserves the best possible response from the public safety sector and therefore, public safety deserves the best technology available in order to achieve their mission. PBS North Carolina, along with the North Carolina Department of Information Technology First Responder Emerging Technologies Program (FirstTech), presented this concept at the 2019 National Association of Broadcasters (NAB) Broadcast Engineering and Information Technology Conference. Much progress has been made since then. Starting in early 2020, a United States Department of Homeland Security Small Business Innovation Research grant was awarded to develop a prototype system that included an encoder and a custom ATSC 3.0 paging receiver with a miniature antenna. This paper will discuss the overall concept and current progress using ATSC 3.0 to address a critical emergency communications need [1].