Cauldron Mission-Centric Cyber Situational Awareness with Defense in Depth

被引:0
作者
Jajodia, Sushil [1 ]
Noel, Steven [1 ]
Kalapa, Pramod [1 ]
Albanese, Massimiliano [1 ]
Williams, John [2 ]
机构
[1] George Mason Univ, Ctr Secure Informat Syst, Fairfax, VA 22193 USA
[2] CyVision Technol Inc, Bethesda, MD 20817 USA
来源
2011 - MILCOM 2011 MILITARY COMMUNICATIONS CONFERENCE | 2011年
关键词
cyber situational awareness; attack graphs; cauldron security tool; vulneratilty analysis; intrusion detection;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The cyber situational awareness of an organization determines its effectiveness in responding to attacks. Mission success is highly dependent on the availability and correct operation of complex computer networks, which are vulnerable to various types of attacks. Today, situational awareness capabilities are limited in many ways, such as inaccurate and incomplete vulnerability analysis, failure to adapt to evolving networks and attacks, inability to transform raw data into cyber intelligence, and inability for handling uncertainty. We describe advanced capabilities for mission-centric cyber situational awareness, based on defense in depth, provided by the Cauldron tool. Cauldron automatically maps all paths of vulnerability through networks, by correlating, aggregating, normalizing, and fusing data from a variety of sources. It provides sophisticated visualization of attack paths, with automatically generated mitigation recommendations. Flexible modeling supports multi-step analysis of firewall rules as well as host-to-host vulnerability, with attack vectors inside the network as well as from the outside. We describe alert correlation based on Caldron attack graphs, along with analysis of mission impact from attacks.
引用
收藏
页码:1339 / 1344
页数:6
相关论文
共 18 条
  • [1] [Anonymous], NAT VULN DAT NVD
  • [2] [Anonymous], OPEN SOURCE VULNERAB
  • [3] eEye Digital Security, FOUNDSCAN
  • [4] First, BASELINE NETWORK VUL
  • [5] FIRST, COMPL GUID COMM VULN
  • [6] Jajodia S., 2011, US Patent, Patent No. 7904962
  • [7] Jajodia S, 2010, ADV INFORM SECUR, V46, P139, DOI 10.1007/978-1-4419-0140-8_7
  • [8] MITRE, CVE COMM VULN EXP
  • [9] NIST, BUGTR
  • [10] NOEL S, 2004, P 20 ANN COMP SEC AP