Intelligent Automation, Inc. — Department of Defense SBIR Phase I: Cyber intrusion and anomaly detection techniques suffer from their reliance upon the prese
Intelligent Automation, Inc. — SBIR Phase I award from Department of Defense.
- Amount
- $150,000
- Agency
- Department of Defense · Army
- Program / Phase
- SBIR · Phase I
- Solicitation
- 2012.3
- NAICS
- —
- Place of performance
- MD
- Period
- 2013-06-04 → 2013-12-06
Description
Cyber intrusion and anomaly detection techniques suffer from their reliance upon the presence of known malicious signatures or unusual conditions that warrant further investigation. The use of signature-based detection cannot effectively eliminate false negatives when dealing with advanced persistent threats (APTs). Furthermore, current detection tools incur very high false positives. To address such challenges, Intelligent Automation, Inc. (IAI), along with Prof. Guofei Gu from Texas A & M University, proposes to develop novel non-signature based APT detection algorithms that allow proper identification, prioritization, and understanding of attacks. The key innovation is to place detectors within the network and individual hosts to provide real-time purpose and correlation inputs and then use this information combined with network-specific knowledge to create a dynamic"spider web"-like set of threads that, when touched by a given alert, allow the immediate identification of the context surrounding the alert and thus the automatic calculation of the alert"s legitimacy and severity. The result is that much of the follow-up investigation of each alert is shifted into the attack prioritization process, allowing this context to correctly prioritize alerts. The burden on operators is thus reduced both by significantly improved prioritization and by providing a contextual picture of each potential attack identified.