INFOBEYOND TECHNOLOGY LLC — Department of Energy SBIR Phase I: 04a

INFOBEYOND TECHNOLOGY LLC — SBIR Phase I award from Department of Energy.

Amount
$225,000
Agency
Department of Energy
Program / Phase
SBIR · Phase I
Topic
04a
Solicitation
DE-FOA-0001770
NAICS
Place of performance
KY
Period
2018-04-09 → 2019-01-08

Description

In order to improve the cybersecurity of HPC system, it is essential to develop software tools that enable continuous monitoring of the security status of the system in real-time, so that the effectiveness of current security control can be evaluated- Despite substantial work has been proposed for continuous monitoring in the desktop network, e-g-, Ipost, FireMon Security Manager and Tenable Security Center CV, many shortcomings have not well addressed for HPC system- In this proposal, Infobeyond advocates HPC2M: Scalable HPC Continuous Monitoring for Real-time Risk Assessment Using Distributed Bayesian Attack Graph to address the technical challenges of continuous monitoring of large-scale HPC networks for cybersecurity- By using Bayesian attack graph (BAG), the proposed HPC2M system is designed as software to perform collection, aggregation, analysis, and presentation of security-related data of the large-scale HPC network for real-time risk assessment in a distributed manner- From the view point of architectural operation, HPC2M is a four-stage data analysis procedure, where the first stage automatically collects the required security related information of the HPC system in a distributed manner- At the second stage, the collected information is utilized locally to generate and update the partial Bayesian attack graph of the sub-network for risk assessment- At the third stage, the partial BAGs of sub-networks are collected and merged at a central point to generate the BAG of the entire HPC network- At last stage, security risk metrics are calculated based on the Bayesian attack graph, then visualized to enable in-depth awareness of cybersecurity situation of entire HPC system- We will analyze and develop four key software modules corresponding to these stages, namely, Automatic Data Collection and Standardization (ADCS), Distributed Bayesian Attack Graph Generation (DBAG), Bayesian Attack Graph Merger (BAGM), and Multilevel Risk Evaluation and Visualization (MREV) for continuous monitoring of security status of the large scale HPC network- Additionally, we also develop APIs and Adapter for the software for easy implementation and smooth integration with the existing infrastructures of HPC network-