CT-ISG: Improving Measurable Performance with QoS-Adaptive Cyber-defense Techniques (IMPACT) PROJECT SUMMARY
ثبت نشده
چکیده
The past few years have seen significant increase in cyber attacks on the Internet, resulting in degraded confidence and trusts in the use of the Internet and computer systems. The cyber attacks are becoming more sophisticated, spreading quicker, and causing more damage. Attacks originally exploited the weakness of individual protocols and systems, but now start to target the basic infrastructure of the Internet. There is an urgent need to enhance the effectiveness of the cyber-defense, to provide end users with timely information and more control, and to improve the measurable performance of network systems when under attacks. Current intrusion detection systems (IDSs) lack of adaptivity and dynamic reconfiguration capability under uncertain threats and new cyber attacks. They also lack coordination in sharing intrusion detection information and have few mechanisms for sharing resources to form collective cyber defense against cyber attacks. Equally important in improving trustiness of cyber infrastructures is the design of evaluation tools to allow the computation of statistical confidence intervals. This IMPACT project focuses on the research and design of a high confidence software framework that supports the dynamic configuration and deployment of adaptive intrusion detection systems, and support real-time distributed control for managing intrusion detection and responses. In particular, this project will (1) design adaptive IDSs with dynamic reconfiguration capability, taking into account quality-of-service (QoS) control technologies and novel intrusion tolerance capabilities, (2) design a distributed real-time control infrastructure for managing and correlating intrusion detection and responses, (3) enhancement of existing core networks and systems QoS support technologies for intrusion mitigation under uncertain and new threats, (4) development of novel intrusion tolerance approaches to reduce the impact of the severe cyber attacks by making new network capabilities such as multi-path indirect routing and delivering timely network/system information to end users, and (5) development of evaluation tools to allow at least statistical confidence in the experimental results. This interdisciplinary aspect will use ideas from biometric system evaluation to produce evaluation methodologies that include confidence intervals and predictive measures. This project will also develop a prototype cyberdefense system, integrating the designed novel technologies, to demonstrate the success and effectiveness of IMPACT framework on improving measurable performance of cyber infrastructures. Intellectual merits: The intellectual merit of this proposal lies in the adaptivity design of IDSs with consideration of QoS control technologies, the design of a distributed real-time intrusion correlation infrastructure, and the interdisciplinary study of performance evaluation tool sets. Applying evaluation methodologies to provide sound statistical confidence is a necessary precursor to improving performance predictability, and will impact many other research groups in the area. The resulting innovations and practice will help protect our critical cyber infrastructures and enhance their trustiness. Broader impacts: The broader impacts are the promotion of the education of graduate and undergraduate students in a critical area of the US national security, and the training of existing workforce on new information assurance technologies. Our novel outreach components will help bridge the gap between advanced cyber-defense research and general community awareness of these issues....to be enhanced by the existing IA curriculum and the development of PhD program in security...
منابع مشابه
A Cyber-Physical Systems Approach to Data Center Modeling and Control for Energy Efficiency
This paper presents data centers from a cyberphysical system (CPS) perspective. Current methods for controlling information technology (IT) and cooling technology (CT) in data centers are classified according to the degree to which they take into account both cyber and physical considerations. To evaluate the potential impact of coordinated CPS strategies at the data-center level, we introduce ...
متن کاملQoS-Assured In-Network Processing in Wireless Cyber-Physical Systems: A Survey
Cyber-physical systems (CPS) are expected to transform how people interact with and manipulate the physical world and thus have farreaching impact on science and engineering. In many CPS such as next-generation vehicle networks, communication via wireless sensor and actuator networks is not only the approach to send or collect data, but also the basis of the adaptive control in the whole system...
متن کاملQoS-Aware In-Network Processing for Mission-Critical Wireless Cyber-Physical Systems
As wireless cyber-physical systems(WCPS) are increasingly being deployed in mission-critical applications, it becomes imperative that we consider application QoS requirements in in-network processing(INP). In this dissertation study, we are exploring the potential of two INP methods, packet packing and random network coding, on improving network performance while satisfying application QoS requ...
متن کاملAn Adaptive Weighted Fuzzy Controller Applied on Quality of Service of Intelligent 5G Environments
in computational intelligence area, it is suitable to fulfill the analysis in order to interpret the concept and sources of uncertainty and the conditions of its incidence, and hence pursuit for reliable techniques of dealing with it. Dealing with uncertainties in this case is a challenging and multidisciplinary activity. So, there is a need for a capable tool for modeling, control, and analyti...
متن کاملArtificial Diversity as Maneuvers in a Control Theoretic Moving Target Defense
Moving target cyber-defense systems encompass a wide variety of techniques in multiple areas of cyber-security. The dynamic system reconfiguration aspect of moving target cyber-defense can be used as a basis for providing an adaptive attack surface. The goal of this research is to develop novel control theoretic mechanisms by which a range of cyber maneuver techniques are provided such that whe...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2006