The Experts below are selected from a list of 21 Experts worldwide ranked by ideXlab platform

Christoph Meinel - One of the best experts on this subject based on the ideXlab platform.

  • an integrated Network Scanning Tool for attack graph construction
    Grid and Pervasive Computing, 2011
    Co-Authors: Feng Cheng, Sebastian Roschke, Christoph Meinel
    Abstract:

    Scanning is essential for gathering information about the actual state of computer systems or Networks. Therefore, it is always taken as the first step of potential attacks against targets. In certain cases, Scanning itself is categorized as an attack. Scanning can on the other hand be used for the right purposes, for example, checking the system configurations, verifying firewall rules, proofing security polices, as well as monitoring the large scale Network environment. From this point of view, Scanning is an effective method for system or Network management, security measurement and auditing. To visualize, analyze, and finally evaluate the data gathered by scanners, Attack Graph plays an important role. High quality information about the target system or Network is the prerequisite for constructing the attack graph. However, different implementations of scanners have different capabilities and always result in different kinds of outputs. These outputs are usually heterogeneous and not machine-readable, which makes the further analysis a challenging task. In this paper, we examine common types of scanners and demonstrate how to combine multiple types of scanners. The results of all the involved scanners are integrated into a well-designed and consistent data structure, which can not only be well interpreted by human security specialists but also be directly fed into an attack graph construction Tool.

  • GPC - An integrated Network Scanning Tool for attack graph construction
    Advances in Grid and Pervasive Computing, 2011
    Co-Authors: Feng Cheng, Sebastian Roschke, Christoph Meinel
    Abstract:

    Scanning is essential for gathering information about the actual state of computer systems or Networks. Therefore, it is always taken as the first step of potential attacks against targets. In certain cases, Scanning itself is categorized as an attack. Scanning can on the other hand be used for the right purposes, for example, checking the system configurations, verifying firewall rules, proofing security polices, as well as monitoring the large scale Network environment. From this point of view, Scanning is an effective method for system or Network management, security measurement and auditing. To visualize, analyze, and finally evaluate the data gathered by scanners, Attack Graph plays an important role. High quality information about the target system or Network is the prerequisite for constructing the attack graph. However, different implementations of scanners have different capabilities and always result in different kinds of outputs. These outputs are usually heterogeneous and not machine-readable, which makes the further analysis a challenging task. In this paper, we examine common types of scanners and demonstrate how to combine multiple types of scanners. The results of all the involved scanners are integrated into a well-designed and consistent data structure, which can not only be well interpreted by human security specialists but also be directly fed into an attack graph construction Tool.

Feng Cheng - One of the best experts on this subject based on the ideXlab platform.

  • an integrated Network Scanning Tool for attack graph construction
    Grid and Pervasive Computing, 2011
    Co-Authors: Feng Cheng, Sebastian Roschke, Christoph Meinel
    Abstract:

    Scanning is essential for gathering information about the actual state of computer systems or Networks. Therefore, it is always taken as the first step of potential attacks against targets. In certain cases, Scanning itself is categorized as an attack. Scanning can on the other hand be used for the right purposes, for example, checking the system configurations, verifying firewall rules, proofing security polices, as well as monitoring the large scale Network environment. From this point of view, Scanning is an effective method for system or Network management, security measurement and auditing. To visualize, analyze, and finally evaluate the data gathered by scanners, Attack Graph plays an important role. High quality information about the target system or Network is the prerequisite for constructing the attack graph. However, different implementations of scanners have different capabilities and always result in different kinds of outputs. These outputs are usually heterogeneous and not machine-readable, which makes the further analysis a challenging task. In this paper, we examine common types of scanners and demonstrate how to combine multiple types of scanners. The results of all the involved scanners are integrated into a well-designed and consistent data structure, which can not only be well interpreted by human security specialists but also be directly fed into an attack graph construction Tool.

  • GPC - An integrated Network Scanning Tool for attack graph construction
    Advances in Grid and Pervasive Computing, 2011
    Co-Authors: Feng Cheng, Sebastian Roschke, Christoph Meinel
    Abstract:

    Scanning is essential for gathering information about the actual state of computer systems or Networks. Therefore, it is always taken as the first step of potential attacks against targets. In certain cases, Scanning itself is categorized as an attack. Scanning can on the other hand be used for the right purposes, for example, checking the system configurations, verifying firewall rules, proofing security polices, as well as monitoring the large scale Network environment. From this point of view, Scanning is an effective method for system or Network management, security measurement and auditing. To visualize, analyze, and finally evaluate the data gathered by scanners, Attack Graph plays an important role. High quality information about the target system or Network is the prerequisite for constructing the attack graph. However, different implementations of scanners have different capabilities and always result in different kinds of outputs. These outputs are usually heterogeneous and not machine-readable, which makes the further analysis a challenging task. In this paper, we examine common types of scanners and demonstrate how to combine multiple types of scanners. The results of all the involved scanners are integrated into a well-designed and consistent data structure, which can not only be well interpreted by human security specialists but also be directly fed into an attack graph construction Tool.

Sebastian Roschke - One of the best experts on this subject based on the ideXlab platform.

  • an integrated Network Scanning Tool for attack graph construction
    Grid and Pervasive Computing, 2011
    Co-Authors: Feng Cheng, Sebastian Roschke, Christoph Meinel
    Abstract:

    Scanning is essential for gathering information about the actual state of computer systems or Networks. Therefore, it is always taken as the first step of potential attacks against targets. In certain cases, Scanning itself is categorized as an attack. Scanning can on the other hand be used for the right purposes, for example, checking the system configurations, verifying firewall rules, proofing security polices, as well as monitoring the large scale Network environment. From this point of view, Scanning is an effective method for system or Network management, security measurement and auditing. To visualize, analyze, and finally evaluate the data gathered by scanners, Attack Graph plays an important role. High quality information about the target system or Network is the prerequisite for constructing the attack graph. However, different implementations of scanners have different capabilities and always result in different kinds of outputs. These outputs are usually heterogeneous and not machine-readable, which makes the further analysis a challenging task. In this paper, we examine common types of scanners and demonstrate how to combine multiple types of scanners. The results of all the involved scanners are integrated into a well-designed and consistent data structure, which can not only be well interpreted by human security specialists but also be directly fed into an attack graph construction Tool.

  • GPC - An integrated Network Scanning Tool for attack graph construction
    Advances in Grid and Pervasive Computing, 2011
    Co-Authors: Feng Cheng, Sebastian Roschke, Christoph Meinel
    Abstract:

    Scanning is essential for gathering information about the actual state of computer systems or Networks. Therefore, it is always taken as the first step of potential attacks against targets. In certain cases, Scanning itself is categorized as an attack. Scanning can on the other hand be used for the right purposes, for example, checking the system configurations, verifying firewall rules, proofing security polices, as well as monitoring the large scale Network environment. From this point of view, Scanning is an effective method for system or Network management, security measurement and auditing. To visualize, analyze, and finally evaluate the data gathered by scanners, Attack Graph plays an important role. High quality information about the target system or Network is the prerequisite for constructing the attack graph. However, different implementations of scanners have different capabilities and always result in different kinds of outputs. These outputs are usually heterogeneous and not machine-readable, which makes the further analysis a challenging task. In this paper, we examine common types of scanners and demonstrate how to combine multiple types of scanners. The results of all the involved scanners are integrated into a well-designed and consistent data structure, which can not only be well interpreted by human security specialists but also be directly fed into an attack graph construction Tool.

Moises Sudit - One of the best experts on this subject based on the ideXlab platform.

  • Symbolic Reasoning in the Cyber Security Domain
    2007
    Co-Authors: Michael Kandefer, Stuart C Shapiro, Adam Stotz, Moises Sudit
    Abstract:

    Cyber Security can benefit greatly from the association and combination of data and information from multiple sources. A data repository of system vulnerabilities, a Network Scanning Tool, and the advice of a systems analyst trained in cyber security can all aid in identifying and preventing intruders. Previous attempts at information fusion in cyber security have largely concerned themselves with the "tangible" information sources, but this ignores an important resource in solving problems in this particular domain --- the cyber security expert's reasoning process. The National Center for Information Fusion (NCMIF) has begun implementing a solution that partially automates the cyber security expert in the intrusion detection process through a combination of information fusion techniques and symbolic reasoning, using the SNePS knowledge representation, reasoning, and acting system. Our methodology approaches cyber security problems by fusing information from external information repositories into a SNePS-based agent‟s knowledge base. We have identified five information sources that are useful: the background knowledge of a cyber security subject matter expert (SME); Nessus security scan reports; the Common Vulnerabilities and Exposures (CVE) database; and INFERD template graphs. The SNePS system makes use of higher-order logic to represent information about the external world. Facts are represented as proposition-valued terms, and the SME‟s reasoning procedures are represented as logical rules.

Michael Kandefer - One of the best experts on this subject based on the ideXlab platform.

  • Symbolic Reasoning in the Cyber Security Domain
    2007
    Co-Authors: Michael Kandefer, Stuart C Shapiro, Adam Stotz, Moises Sudit
    Abstract:

    Cyber Security can benefit greatly from the association and combination of data and information from multiple sources. A data repository of system vulnerabilities, a Network Scanning Tool, and the advice of a systems analyst trained in cyber security can all aid in identifying and preventing intruders. Previous attempts at information fusion in cyber security have largely concerned themselves with the "tangible" information sources, but this ignores an important resource in solving problems in this particular domain --- the cyber security expert's reasoning process. The National Center for Information Fusion (NCMIF) has begun implementing a solution that partially automates the cyber security expert in the intrusion detection process through a combination of information fusion techniques and symbolic reasoning, using the SNePS knowledge representation, reasoning, and acting system. Our methodology approaches cyber security problems by fusing information from external information repositories into a SNePS-based agent‟s knowledge base. We have identified five information sources that are useful: the background knowledge of a cyber security subject matter expert (SME); Nessus security scan reports; the Common Vulnerabilities and Exposures (CVE) database; and INFERD template graphs. The SNePS system makes use of higher-order logic to represent information about the external world. Facts are represented as proposition-valued terms, and the SME‟s reasoning procedures are represented as logical rules.