The Experts below are selected from a list of 2469 Experts worldwide ranked by ideXlab platform

Anita D'amico - One of the best experts on this subject based on the ideXlab platform.

  • VizSEC - Visual analysis of goal-directed network defense decisions
    Proceedings of the 8th International Symposium on Visualization for Cyber Security - VizSec '11, 2011
    Co-Authors: Chris Horn, Anita D'amico
    Abstract:

    Security visualization has been focused largely on graphic representation of data and relationships between network activity, security sensor output, and attacker activity. Visual analysis tools have not been designed to facilitate the analysis of data related to defender activities and decisions. This paper reports on the initial effort of a research team to use visual analytics to support the modeling of the computer network defense (CND) decision process of an organization. We describe a tool to support the visual analysis of a hierarchical decision structure represented in a portable, file-based database. The tool visualizes and traces relationships between decision goals, sub-goals, decisions, information requirements, and data sources.

  • Mission Impact of Cyber Events: Scenarios and Ontology to Express the Relationships between Cyber Assets, Missions, and Users
    2009
    Co-Authors: Anita D'amico, John R. Goodall, Laurin Buchanan, Paul Walczak
    Abstract:

    Abstract : Awareness of the dependencies between cyber assets, missions and users is critical to assessing the mission impact of cyber attacks and maintaining continuity of business operations. However, there is no systematic method for defining the complex mapping between cyber assets (hardware, software, data), missions and users. This paper reports the results of an interdisciplinary workshop on how to map relationships between cyber assets and the users, missions, business processes and other entities that depend on those assets. The workshop yielded information about types of impact assessment beyond mission and financial analyses; scenarios illustrating the complex relationships between assets, mission and users; and models for expressing those relationships. The results will be used to develop a system that will automatically populate an ontology from commonly available network data and allow computer network defense, information technology and disaster recovery practitioners to query the system for information about the impact of the loss or degradation a cyber asset.

  • VizSEC - The Real Work of computer network defense Analysts
    VizSEC 2007, 2008
    Co-Authors: Anita D'amico, K Whitley
    Abstract:

    This paper reports on investigations of how computer network defense (CND) analysts conduct their analysis on a day-to-day basis and discusses the implications of these cognitive requirements for designing effective CND visualizations. The supporting data come from a cognitive task analysis (CTA) conducted to baseline the state of the practice in the U.S. Department of defense CND community. The CTA collected data from CND analysts about their analytic goals, workflow, tasks, types of decisions made, data sources used to make those decisions, cognitive demands, tools used and the biggest challenges that they face. The effort focused on understanding how CND analysts inspect raw data and build their comprehension into a diagnosis or decision, especially in cases requiring data fusion and correlation across multiple data sources. This paper covers three of the findings from the CND CTA: (1) the hierarchy of data created as the analytical process transforms data into security situation awareness; (2) the definition and description of different CND analysis roles; and (3) the workflow that analysts and analytical organizations engage in to produce analytic conclusions.

  • Visual Discovery in computer network defense
    IEEE Computer Graphics and Applications, 2007
    Co-Authors: Anita D'amico, John R. Goodall, D.r. Tesone, Jason K. Kopylec
    Abstract:

    computer network defense (CND) requires analysts to detect both known and novel forms of attacks in massive volumes of network data. It's through discovering the unexpected that CND analysts detect new versions of mal ware (such as viruses and Trojan horses) that have passed through their antivirus products, new methods of intrusion that have breached their firewalls and intrusion detection systems (IDSs), and new groups of cyber-criminals pressing the attack. This paper presents visual assistant for information assurance analysis. VIAssist is a visualization framework based on a comprehensive cognitive task analysis of CND analysts, and so fits their work practices and operational environment.

Chunhe Xia - One of the best experts on this subject based on the ideXlab platform.

  • A SDN-based deployment framework for computer network defense Policy
    2015 4th International Conference on Computer Science and Network Technology (ICCSNT), 2015
    Co-Authors: Jinghua Gao, Chunhe Xia, Shuguang Wang, Huajun Zhang
    Abstract:

    computer network defense Policy is a kind of policy-based network management method which aims to achieve specific security objectives. Although it brings much efficiency in the field of computer network defense, it can't be widely used because the existing computer network defense Policy models are all proposed on P2DRR architecture and lack specific deployment framework as well as methods. In this paper, we utilize programmability and centralized control of software defined networking and propose a SDN-based deployment framework. Also, we come up with defense selection method and “traffic steering” method for policy deployment. The implementation and experiments in cloud environment shows that under the proposed framework, we can execute the process of policy resolution and configuration deployment automatically and correctly.

  • An Approach for Description of computer network defense Scheme and Its Simulation Verification
    Journal of Computers, 2014
    Co-Authors: Zhao Wei, Chunhe Xia, Yang Luo, Xiao Chen Liu
    Abstract:

    In order to solve the problem of which the existing defense policy description languages can only describe some aspects of defense, such as protection or detection, but cannot express relationship among actions and to cope with large-scale network attack, we proposed an approach for description of computer network defense scheme and its simulation verification. A computer network defense-oriented scheme description language (CNDSDL) was designed to describe actions of protection (i.e., access control, encryption communication, backup), detection (i.e., intrusion detection, vulnerability detection), analysis (i.e., log auditing), response (i.e., system rebooting, shutdown), recovery (i.e., rebuild, patch making), and relationship among actions (i.e., sequence-and, sequence-or, concurrent-and, concurrent-or, and xor). The Extend Backus-Naur Form (EBNF) of CNDSDL was provided. At last, we provided an implementation mechanism of CNDSDL. A task deadlock detection algorithm was given for the defense scheme. The simulation was completed in simulation platform of GTNetS. Three simulation experiments verified the description capability and effectiveness of CNDSDL. The results of the experiments show that the defense scheme described by CNDSDL can be transformed to detailed technique rules and realize the defense effect of expression.

  • A computer network defense-Oriented Scheme Description Language
    Advanced Materials Research, 2013
    Co-Authors: Wei Zhao, Chunhe Xia, Yang Luo, Xiao Chen Liu
    Abstract:

    Existing defense policy description language can describe some aspects of defense only, such as protection or detection but cannot express relationship among actions. Thus, it cannot accomplish a joint defense goal with the linkage of all kinds of defense mechanism for large-scale, distributed network attacking, such as Botnet. To solve this problem, we proposed a computer network defense-oriented scheme description language (CNDSDL), which can describe protection, detection, analysis, response, and recover actions as well as relationship among actions. These relations include sequence-and, sequence-or, concurrent-and, concurrent-or, and xor. It provides a unified coupling language description for linkage defense of different security devices. At last, we realized the simulation of schemes which are described by CNDSDL. The experiments results show that CNDSDL can be transformed to detailed technique rules and realize the defense effect of expression.

  • a computer network defense policy refinement method
    ICoC, 2013
    Co-Authors: Zhao Wei, Chunhe Xia, Yang Luo, Qing Wei
    Abstract:

    The existing methods of policy refinement in computer network defense (CND) can only support the refinement of access control policy, but not the policies of protection, detection, response, and recovery. To solve this problem, we constructed a computer network defense policy refinement model and its formalism specification. An algorithm of defense policy refinement is designed. At last, the effectiveness of our methods was verified through one experiment cases of the composition policies with intrusion detection, vulnerabilities detection, and access control.

  • ICoC - A computer network defense Policy Refinement Method
    Frontiers in Internet Technologies, 2013
    Co-Authors: Zhao Wei, Chunhe Xia, Yang Luo, Qing Wei
    Abstract:

    The existing methods of policy refinement in computer network defense (CND) can only support the refinement of access control policy, but not the policies of protection, detection, response, and recovery. To solve this problem, we constructed a computer network defense policy refinement model and its formalism specification. An algorithm of defense policy refinement is designed. At last, the effectiveness of our methods was verified through one experiment cases of the composition policies with intrusion detection, vulnerabilities detection, and access control.

Steve Winterfeld - One of the best experts on this subject based on the ideXlab platform.

  • computer network defense
    Cyber Warfare (Second Edition)#R##N#Techniques Tactics and Tools for Security Practitioners, 2014
    Co-Authors: Jason Andress, Steve Winterfeld
    Abstract:

    computer network defense is the defensive and largely proactive component of computer network Operations, and is one of the few places where military and civilian approaches are similar. But how does computer network defense fit into the category of defensive actions? To answer that question, one must understand what is being defended. This chapter explains what type of information should be protected from cyber attacks, and highlights the key principles of security—namely the CIA triad of confidentiality, integrity, and availability, and AAA which covers authentication, authorization, and auditing. Of course, no attempt at defending information assets is complete if users’ security mindset is weak, so this chapter also discusses security awareness and the types of training available today, along with strategies for defending against attacks, such as surveillance tactics, data mining, pattern matching, intrusion detection and prevention, vulnerability assessment and penetration testing, disaster recovery planning, and defense in depth.

  • cyber warfare techniques tactics and tools for security practitioners
    2011
    Co-Authors: Jason Andress, Steve Winterfeld
    Abstract:

    Cyber Warfare explores the battlefields, participants and the tools and techniques used during today's digital conflicts. The concepts discussed in this book will give those involved in information security at all levels a better idea of how cyber conflicts are carried out now, how they will change in the future and how to detect and defend against espionage, hacktivism, insider threats and non-state actors like organized criminals and terrorists. Every one of our systems is under attack from multiple vectors-our defenses must be ready all the time and our alert systems must detect the threats every time. Provides concrete examples and real-world guidance on how to identify and defend your network against malicious attacks Dives deeply into relevant technical and factual information from an insider's point of view Details the ethics, laws and consequences of cyber war and how computer criminal law may change as a result Table of Contents Foreword Introduction Chapter 1. What is Cyber Warfare? Chapter 2. The Cyberspace Battlefield Chapter 3. Cyber Doctrine Chapter 4. Cyber Warriors Chapter 5. Logical Weapons Chapter 6. Physical Weapons Chapter 7. Psychological Weapons Chapter 8. computer network Exploitation Chapter 9. computer network Attack Chapter 10. computer network defense Chapter 11. Non-State Actors in computer network Operations Chapter 12. Legal System Impacts Chapter 13. Ethics Chapter 14. Cyberspace Challenges Chapter 15. The Future of Cyber War Appendix: Cyber Timeline

  • Chapter 10 – computer network defense
    Cyber Warfare, 2011
    Co-Authors: Jason Andress, Steve Winterfeld
    Abstract:

    Publisher Summary computer network defense is defined as “Actions taken through the use of computer networks to protect, monitor, analyze, detect and respond to unauthorized activity within Department of defense information systems and computer networks.” In the world of the military and government, information of a sensitive nature being exposed can have far greater consequences than mere financial loss. Information housed by such agencies can include Operations Orders (OPORDERS), war plans, troop movements, technical specifications for weapons or intelligence collection systems, identities of undercover intelligence agents, and any number of other items critical to the functioning of military and government. When such information is accessed in an unauthorized fashion, lives can be lost on a large scale and the balance of power can be shifted significantly. Laws do exist to protect these types of information, but they are, in many cases, still a work in progress.

  • chapter 10 computer network defense
    Cyber Warfare#R##N#Techniques Tactics and Tools for Security .. Practitioners.., 2011
    Co-Authors: Jason Andress, Steve Winterfeld
    Abstract:

    Publisher Summary computer network defense is defined as “Actions taken through the use of computer networks to protect, monitor, analyze, detect and respond to unauthorized activity within Department of defense information systems and computer networks.” In the world of the military and government, information of a sensitive nature being exposed can have far greater consequences than mere financial loss. Information housed by such agencies can include Operations Orders (OPORDERS), war plans, troop movements, technical specifications for weapons or intelligence collection systems, identities of undercover intelligence agents, and any number of other items critical to the functioning of military and government. When such information is accessed in an unauthorized fashion, lives can be lost on a large scale and the balance of power can be shifted significantly. Laws do exist to protect these types of information, but they are, in many cases, still a work in progress.

Christopher J. Garneau - One of the best experts on this subject based on the ideXlab platform.

  • Evaluation of Visualization Tools for computer network defense Analysts: Display Design, Methods, and Results for a User Study
    2016
    Co-Authors: Christopher J. Garneau, Robert F. Erbacher
    Abstract:

    Abstract : computer network defense (CND) analysts serve an increasingly vital role in the defense of our nations computing infrastructure. An important component of their work is the monitoring of suspicious activity identified by an intrusion detection system (IDS). While analysts are trained to quickly recognize abnormal patterns in textual log files, humans are generally not well suited for such processing in any large quantity. Many authors have proposed the use of visualization techniques to aid the cyber security analysts search activities; however, such techniques are not widely used by analysts. This report describes an evaluation of 2 graphical displays (a parallel coordinates display and a node-link display) compared against a traditional tabular arrangement with the goal of better understanding analyst performance and obtaining subjective feedback on the graphical alternatives. Both expert analysts and novices (students) participated in the study. Results show that analysts generally preferred familiar tools but were able to use some graphical alternatives (node-link) to achieve similar performance in less time. Students were not found to be effective surrogates for experienced analysts for research/validation of techniques. This report describes the development and design of the displays and the experiment, and provides insight into analyst needs and evidence on effective methods for validating cyber defense visualization tools based on results obtained.

  • Evaluation of the Presentation of network Data via Visualization Tools for network Analysts
    2014
    Co-Authors: Renee E Etoty, Robert F. Erbacher, Christopher J. Garneau
    Abstract:

    Abstract : In response to chaotic nature of network traffic, making it very difficult to differentiate normal from malicious traffic, we have designed a user study that tests the effectiveness and usefulness of tabular versus graphical displays on such data. The U.S. Army Research Laboratory s (ARL) in-house defense service providers are expert subjects, who undergo a simplified version of their computer network defense (CND) analyst tasks. We use their performance to acquire initial insights to their interpretation of display components, cognitive processes, and contextual knowledge. We quantitatively compare tabular versus graphical displays and compare their feedback with that of students, who serve as primary test subjects for developing visual displays for network monitoring. In this study, all participants act as analysts; their job is to identify evidence of compromise within a dataset of intrusion attempts on the fabricated network visually provided. We observe the participants responses to the pattern matching activity created with interacting with the visual displays. The design variables are the distinct graphical layouts: tabular, parallel coordinates, and node-link. The response variables are true positive and false positive rates of event identification, the time required for event identification, and the qualitative questionnaire. Results help us better understand which of the visual layouts is most effective and useful for predicting cyber attacks.

Thomas Owens - One of the best experts on this subject based on the ideXlab platform.

  • Situational Awareness in computer network defense: Principles, Methods and Applications
    2012
    Co-Authors: Cyril Onwubiko, Thomas Owens
    Abstract:

    Worldwide computer crimes cost organizations and governments billions of dollars each year. In response, organizations use a plethora of heterogeneous security devices and software such as firewalls, Intrusion Detection Systems (IDS), and Security Information and Event Management (SIEM) to monitor networks in conjunction with computer Security Incident Response Teams (CSIRT) that are responsible for ensuring availability, integrity, and confidentiality of network services.Situational Awareness in computer network defense: Principles, Methods and Applications provides academia and organizations insights into practical and applied solutions, frameworks, technologies, and implementations for situational awareness in computer networks. This book presents situational awareness solutions in computer network defense (CND) currently being researched or deployed. The key objective is to fill a gap that exists in the way CND and security are being approached by formalizing the use of situational awareness in computer network security and defense.

  • Review of Situational Awareness for computer network defense
    Situational Awareness in Computer Network Defense, 2012
    Co-Authors: Cyril Onwubiko, Thomas Owens
    Abstract:

    The importance of situational awareness to air traffic control, and hence the safety and security of aircraft, is evident, demonstrable, and has been hugely significant. The main purpose of this book is to convey an understanding of the impact of situational awareness on the design of the next generation computer systems, network architectures, and platform infrastructures. The book achieves its purpose by presenting principles, methods, and applications of situational awareness for computer network defense; in doing so, it makes clear the benefits situational awareness can provide for information security, computer security and computer network defense. This book contributes to cross-multidisciplinary discussion among researchers, academia, and practitioners who are engaged objectively in sharing, contributing, and showcasing how situational awareness can be adapted to computer systems, network infrastructure designs, and architecture patterns. The goal of this chapter is to explain situational awareness for computer network defense from the point of view of its most basic foundations as a spring board to discuss how situational awareness can be relevant to computer network defense, whose operations and environment are similar to air traffic control where the application of situational awareness has been hugely successful.