METRON INCORPORATED — Department of Defense SBIR Phase I: ABSTRACT: Metron, Inc. (Metron) proposes a unique cyber security training environment whi
METRON INCORPORATED — SBIR Phase I award from Department of Defense.
- Amount
- $149,930
- Agency
- Department of Defense · Air Force
- Program / Phase
- SBIR · Phase I
- Solicitation
- 2014.1
- NAICS
- —
- Place of performance
- VA
- Period
- 2014-07-08 → 2015-03-19
Description
ABSTRACT: Metron, Inc. (Metron) proposes a unique cyber security training environment which will be overlaid on training networks as a set of distributed host and network-based agents. These agents will communicate with an automated cyber war gaming engine to conduct mock cyber attack and defense in real-time on the training network in pursuit of instructor-configurable mission objectives. Software agents will use real tools like file transfer agents, network scanners, and built-in operating system commands to pursue their objectives, thereby creating realistic, detectable patterns of network traffic and sensing and responding in real-time to real effects created by the actions of human agents. Trainees will therefore be able to engage the software agents in real-time using real tools in a real network environment. In essence, the training environment will conduct on-demand, automated Red team exercises and war gaming scenarios in which trainees may participate. Software agents will also be able to emulate network users in order to generate a realistic baseline of network traffic. This approach will be amenable to both physical and virtual machines. Instructors will be able to overlay the training environment on their own custom network architectures, effectively turning a network of their choice into a virtual cyber range. BENEFIT: Metron"s proposed cyber war gaming environment integrates network intelligence into cyber security training. Trainees would build invaluable tacit knowledge of real systems while also learning to recognize cyber threat indicators and apply mitigation techniques. The proposed system would provide trainees the kind of experience usually attained through costly Red team penetration testing and Red team/Blue team cyber war gaming scenarios like the recent Waking Shark II simulation carried out by financial organizations in London. The proposed system would provide similar instructional value on-demand at a fraction of the cost because it would provide automated Red team and Blue team actors. Large organizations would be able to make cyber war gaming a more regular aspect of their cyber security training regimens. Small and medium-size organizations which could not formerly afford to conduct cyber war gaming scenarios would gain access to a new form of cyber security training. The potential benefits of the proposed system to Air Force cyber security training are huge. Instructors could roll out much more timely and realistic training environments than is possible with current systems. However, many other sectors of government or industry could benefit from enhanced cyber security training as well. Critical infrastructure has become a major target of cyber attacks. In 2012, the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) received 198 cyber incident reports, 41% targeting the energy sector and 15% the water sector. Online gaming and cloud services are increasing being co-opted as attack vectors to target end users. Government agencies like the Department of Energy (DOE) and Department of Justice (DOJ), brick-and-mortar retailers, cloud service providers, and industrial control system (ICS) engineers alike will be able to benefit from this technology.