Intelligent Automation, Inc. — Department of Defense SBIR Phase I: Cyber security analysts are inundated with heterogeneous threat feeds created by different

Intelligent Automation, Inc. — SBIR Phase I award from Department of Defense.

Amount
$150,000
Agency
Department of Defense · Army
Program / Phase
SBIR · Phase I
Solicitation
2012.3
NAICS
Place of performance
MD
Period
2013-05-22 → 2013-11-23

Description

Cyber security analysts are inundated with heterogeneous threat feeds created by different kinds of cyber security monitoring tools such as Snort, Nessus, Symantec etc. There is a need for streamlining threat analysis to help operators focus on prompt identification and comprehension of security threats early on. To address this critical need, Intelligent Automation Inc. (IAI), with Prof. Peng Liu from Penn State University, is proposing an integrated tool for heterogeneous and multi-structured Threat feed Aggregation, Analysis, and Visualization (TAAV). The proposed framework will execute automated expert and data driven multi-dimensional and time correlated threat feed analysis that will categorize threat feeds into"threat baskets". The identified relevant threat baskets will be prioritized according to their perceived scale of vulnerability by performing latent threat association detection and alert correlation over ongoing as well as historical attack information. The result of the automated analysis will be presented in an easily understandable display with accompanying maps and charts. An empirical study will be performed on the Phase I prototype using a scalable test bed. TAAV will be developed end-to-end in Java using open source tools (e.g. Quartz scheduler, Spring Batch, Talend, JBoss Drools, Accumulo).