Physical Optics Corporation — Department of Energy SBIR Phase I: 04a
Physical Optics Corporation — SBIR Phase I award from Department of Energy.
- Amount
- $231,499
- Agency
- Department of Energy
- Program / Phase
- SBIR · Phase I
- Topic
- 04a
- Solicitation
- DE-FOA-0001940
- NAICS
- —
- Place of performance
- CA
- Period
- 2019-02-19 → 2019-11-18
Description
The facilities, centers, infrastructure, and resources of the sponsor of the proposed project are designed to be easily accessible to users over the worldwide network, while ensuring the important tasks of effective cybersecurity monitoring, situational awareness, logging, reporting, intrusion prevention, remediation, etc. Although many existing cybersecurity (detection or prevention) software tools have been developed, all of them have limitations and, thus, cannot deliver protection against cyberattacks in large-scale systems: Cybersecurity in a high- performance computing environment is still an open problem. A new approach must be developed that provides more intelligent shields to fend off known and new-generation cyberattacks to help secure high-performance computing facilities, infrastructure, or large-scale distributed systems. The proposed high-performance distributed intrusion detection system integrates (1) non- statistical anomaly detection and a prediction framework based on advanced unsupervised machine learning, (2) a bottom-up approach in cyber sensor data processing, (3) an open-source intrusion detection system event management engine, and (4) an interactive graphical user interface. These provide the artificial intelligence needed to detect, with high accuracy (low false positive and false negative rates), and mitigate both known and new cyberattacks in high-performance computing systems and hosts. The new tool allows for continuous monitoring of network traffic and/or hosts in high-performance computing clusters and detection, classification, and mitigation of attacks in real time. Cybersecurity information collected by cybersecurity sensors is processed by an analyzer using advanced deep machine learning and prediction algorithms. The analyzer makes intrusion detection decisions, which are passed in the form of alerts to an existing intrusion response mechanism. Large-scale distributed intrusion detection system architecture, framework, and algorithms will be developed to evaluate system performance. Feasibility of the approach will be demonstrated by assembling and testing a technology readiness level-4 prototype. The prototype will demonstrate the capability to detect attack patterns and predict attacks in real time in a large-bandwidth (100 Gbps) network. The metrics that determine the prototype’s efficacy and performance will be identified. The proposed technology is expected to have widespread applications in cybersecurity, including secure high-performance computing facilities and enterprise-scale networks, and in computing systems that are used for critical data processing (e.g., in financial and healthcare services). Cyberattacks cost several trillions of dollars worldwide annually. The proposed intrusion detection/prevention system will provide real-time defense against known and new cyberattacks.