INFOBEYOND TECHNOLOGY LLC — Department of Defense SBIR Phase I: N181-043
INFOBEYOND TECHNOLOGY LLC — SBIR Phase I award from Department of Defense.
- Amount
- $125,000
- Agency
- Department of Defense · Navy
- Program / Phase
- SBIR · Phase I
- Topic
- N181-043
- Solicitation
- 2018.1
- NAICS
- —
- Place of performance
- KY
- Period
- 2018-06-20 → 2018-12-17
Description
Navy needs a standardized and automated tool for quantitative cybersecurity risk assessment that can be applied in the early design stage of Naval Control System (NCS) so that cybersecurity can be "built-in" during the acquisition lifecycle with less expense and design time. In this proposal, InfoBeyond advocates Multilevel Quantitative Cybersecurity Risk Assessment Using Bayesian Attack Graph (MQCRA) system to address this challenge. MQCRA automatically collect the cybersecurity data and generates the attack graph of the NCS system that represents the dependencies, relations and transition states between vulnerability and exploits as attack paths and computes the exploitation likelihood using Bayesian theory. Also, multiple risk metrics on different levels are designed to quantitatively assess the cybersecurity risk of the NCS regarding vulnerability exploitation possibility, mission impacts, cost, and recommended solutions, etc.. MQCRA enables quantitative risk assessment of an NCS system in the early design stage with following capabilities: (i) Automatic cybersecurity data collection and aggregation. (ii) Bayesian attack graph to generate/update attack paths, exploitation likelihoods, and risk metrics based on current/new arrival information, and (iii) Multilevel risk evaluation for full security risk awareness on different levels and user-friendly visualization to support decision-making in the early design stage.