The Experts below are selected from a list of 69 Experts worldwide ranked by ideXlab platform
Emil M. Petriu - One of the best experts on this subject based on the ideXlab platform.
-
A proactive risk-aware robotic sensor network for Critical Infrastructure Protection
2013 IEEE International Conference on Computational Intelligence and Virtual Environments for Measurement Systems and Applications (CIVEMSA), 2013Co-Authors: Jamieson Mccausland, George Di Nardo, Rafael Falcon, Rami Abielmona, Voicu Groza, Emil M. PetriuAbstract:In this paper, a risk-aware robotic sensor network (RSN) is proposed in the context of Critical Infrastructure Protection. Such a network will be comprised of mobile sensor nodes that perceive various aspects of their environment and topologically reconfigure in order to secure a strategic area of interest. Risk awareness is provided through the application of a recently developed Risk Management Framework to the RSN. The risk level of each node is assessed in terms of their degree of distress, proximity factor, and terrain maneuverability. Risk monitoring alerts are issued whenever any given sensor node's quantitative risk metric exceeds a user-defined threshold value. At this point, a node-in-distress (NID) has been identified as the weak point of the securing structure around which the RSN is deployed. The NID can no longer be used with confidence and the effective perimeter coverage of the RSN has been reduced, thus creating potential Security breaches in the area of interest. In response, the remaining nodes will self-organize to maximize the perimeter coverage while minimizing the cost of doing so. A limited set of contingency network topologies is produced via evolutionary multi-objective optimization using the Non-Dominated Sorting Genetic Algorithm (NSGA-II) and then ranked according to a human-guided alternative selection algorithm. The Security Operator picks the most suitable topology, which is then effectuated upon the environment. Results indicate that NSGA-II is capable of producing feasible network topologies to satisfy maximum perimeter coverage, while reducing the energy required for topology reconfiguration. As far as we are concerned, this is the first time a RSN applied to a CIP scenario is self-organized in response to a risk analysis conducted on every sensor node on the basis of multiple risk features.
-
ROSE - Auction-based node selection of optimal and concurrent responses for a risk-aware robotic sensor network
2013 IEEE International Symposium on Robotic and Sensors Environments (ROSE), 2013Co-Authors: Jamieson Mccausland, Rafael Falcon, Rami Abielmona, Ana-maria Cretu, Emil M. PetriuAbstract:In this paper, an auction-based node selection technique is considered for a risk-aware Robotic Sensor Network (RSN) applied to Critical Infrastructure Protection (CIP). The goal of this risk-aware RSN is to maintain a secure perimeter around the CIP, which is best maintained by detecting high-risk network events and mitigate them through a response involving the most suitable robotic nodes. These robotic nodes can operate without the use of a centralized system and select amongst themselves the nodes with the best fitness to risk mitigation plan. The robot node that is first aware of a high-risk event becomes an auctioneer. The risk mitigation task is advertised to the entire network. Each robotic node is responsible for calculating their bid metric (i.e. availability metric) for the risk mitigation task. We employ fuzzy logic in the process of the bid calculation, which incorporates the battery level, distance to the event, and redundant coverage to produce an appropriate bid value. The auctioneer only considers the top bidders. The nature of this system is to permit simultaneous mitigation plans to execute on a single RSN by effectively segmenting the network into discrete autonomous groups. Each autonomous group will utilize an evolutionary multi-objective algorithm - the Non-Dominated Sorting Genetic Algorithm (NSGA-II) - to optimize the segment's topology to mitigate the risk. A chromosome length is determined by the number of bids received, but the NSGA-II explored to separate solution spaces to achieve optimal Pareto results. The NSGA-II will seek optimal node positions and determine the optimal set of robotic nodes to utilize of the bids received. The NSGA-II will produce a set of optimized responses for each network segment for a Security Operator to pick the most suitable response.
Mika P Tarvainen - One of the best experts on this subject based on the ideXlab platform.
-
processing intrusion detection alert aggregates with time series modeling
Information Fusion, 2009Co-Authors: Jouni Viinikka, Hervé Debar, Anssi Lehikoinen, Mika P TarvainenAbstract:The main use of intrusion detection systems (IDS) is to detect attacks against information systems and networks. Normal use of the network and its functioning can also be monitored with an IDS. It can be used to control, for example, the use of management and signaling protocols, or the network traffic related to some less critical aspects of system policies. These complementary usages can generate large numbers of alerts, but still, in operational environment, the collection of such data may be mandated by the Security policy. Processing this type of alerts presents a different problem than correlating alerts directly related to attacks or filtering incorrectly issued alerts. We aggregate individual alerts to alert flows, and then process the flows instead of individual alerts for two reasons. First, this is necessary to cope with the large quantity of alerts - a common problem among all alert correlation approaches. Second, individual alert's relevancy is often indeterminable, but irrelevant alerts and interesting phenomena can be identified at the flow level. This is the particularity of the alerts created by the complementary uses of IDSes. Flows consisting of alerts related to normal system behavior can contain strong regularities. We propose to model these regularities using non-stationary autoregressive models. Once modeled, the regularities can be filtered out to relieve the Security Operator from manual analysis of true, but low impact alerts. We present experimental results using these models to process voluminous alert flows from an operational network.
Byrav Ramamurthy - One of the best experts on this subject based on the ideXlab platform.
-
OpenSec: Policy-Based Security Using Software-Defined Networking
IEEE Transactions on Network and Service Management, 2016Co-Authors: Adrian Lara, Byrav RamamurthyAbstract:As the popularity of software-defined networks (SDN) and OpenFlow increases, policy-driven network management has received more attention. Manual configuration of multiple devices is being replaced by an automated approach where a software-based, network-aware controller handles the configuration of all network devices. Software applications running on top of the network controller provide an abstraction of the topology and facilitate the task of operating the network. We propose OpenSec, an OpenFlow-based Security framework that allows a network Security Operator to create and implement Security policies written in human-readable language. Using OpenSec, the user can describe a flow in terms of OpenFlow matching fields, define which Security services must be applied to that flow (deep packet inspection, intrusion detection, spam detection, etc.) and specify Security levels that define how OpenSec reacts if malicious traffic is detected. In this paper, we first provide a more detailed explanation of how OpenSec converts Security policies into a series of OpenFlow messages needed to implement such a policy. Second, we describe how the framework automatically reacts to Security alerts as specified by the policies. Third, we perform additional experiments on the GENI testbed to evaluate the scalability of the proposed framework using existing datasets of campus networks. Our results show that up to 95% of attacks in an existing data set can be detected and 99% of malicious source nodes can be blocked automatically. Furthermore, we show that our policy specification language is simpler while offering fast translation times compared to existing solutions.
Jamieson Mccausland - One of the best experts on this subject based on the ideXlab platform.
-
A proactive risk-aware robotic sensor network for Critical Infrastructure Protection
2013 IEEE International Conference on Computational Intelligence and Virtual Environments for Measurement Systems and Applications (CIVEMSA), 2013Co-Authors: Jamieson Mccausland, George Di Nardo, Rafael Falcon, Rami Abielmona, Voicu Groza, Emil M. PetriuAbstract:In this paper, a risk-aware robotic sensor network (RSN) is proposed in the context of Critical Infrastructure Protection. Such a network will be comprised of mobile sensor nodes that perceive various aspects of their environment and topologically reconfigure in order to secure a strategic area of interest. Risk awareness is provided through the application of a recently developed Risk Management Framework to the RSN. The risk level of each node is assessed in terms of their degree of distress, proximity factor, and terrain maneuverability. Risk monitoring alerts are issued whenever any given sensor node's quantitative risk metric exceeds a user-defined threshold value. At this point, a node-in-distress (NID) has been identified as the weak point of the securing structure around which the RSN is deployed. The NID can no longer be used with confidence and the effective perimeter coverage of the RSN has been reduced, thus creating potential Security breaches in the area of interest. In response, the remaining nodes will self-organize to maximize the perimeter coverage while minimizing the cost of doing so. A limited set of contingency network topologies is produced via evolutionary multi-objective optimization using the Non-Dominated Sorting Genetic Algorithm (NSGA-II) and then ranked according to a human-guided alternative selection algorithm. The Security Operator picks the most suitable topology, which is then effectuated upon the environment. Results indicate that NSGA-II is capable of producing feasible network topologies to satisfy maximum perimeter coverage, while reducing the energy required for topology reconfiguration. As far as we are concerned, this is the first time a RSN applied to a CIP scenario is self-organized in response to a risk analysis conducted on every sensor node on the basis of multiple risk features.
-
ROSE - Auction-based node selection of optimal and concurrent responses for a risk-aware robotic sensor network
2013 IEEE International Symposium on Robotic and Sensors Environments (ROSE), 2013Co-Authors: Jamieson Mccausland, Rafael Falcon, Rami Abielmona, Ana-maria Cretu, Emil M. PetriuAbstract:In this paper, an auction-based node selection technique is considered for a risk-aware Robotic Sensor Network (RSN) applied to Critical Infrastructure Protection (CIP). The goal of this risk-aware RSN is to maintain a secure perimeter around the CIP, which is best maintained by detecting high-risk network events and mitigate them through a response involving the most suitable robotic nodes. These robotic nodes can operate without the use of a centralized system and select amongst themselves the nodes with the best fitness to risk mitigation plan. The robot node that is first aware of a high-risk event becomes an auctioneer. The risk mitigation task is advertised to the entire network. Each robotic node is responsible for calculating their bid metric (i.e. availability metric) for the risk mitigation task. We employ fuzzy logic in the process of the bid calculation, which incorporates the battery level, distance to the event, and redundant coverage to produce an appropriate bid value. The auctioneer only considers the top bidders. The nature of this system is to permit simultaneous mitigation plans to execute on a single RSN by effectively segmenting the network into discrete autonomous groups. Each autonomous group will utilize an evolutionary multi-objective algorithm - the Non-Dominated Sorting Genetic Algorithm (NSGA-II) - to optimize the segment's topology to mitigate the risk. A chromosome length is determined by the number of bids received, but the NSGA-II explored to separate solution spaces to achieve optimal Pareto results. The NSGA-II will seek optimal node positions and determine the optimal set of robotic nodes to utilize of the bids received. The NSGA-II will produce a set of optimized responses for each network segment for a Security Operator to pick the most suitable response.
Jouni Viinikka - One of the best experts on this subject based on the ideXlab platform.
-
processing intrusion detection alert aggregates with time series modeling
Information Fusion, 2009Co-Authors: Jouni Viinikka, Hervé Debar, Anssi Lehikoinen, Mika P TarvainenAbstract:The main use of intrusion detection systems (IDS) is to detect attacks against information systems and networks. Normal use of the network and its functioning can also be monitored with an IDS. It can be used to control, for example, the use of management and signaling protocols, or the network traffic related to some less critical aspects of system policies. These complementary usages can generate large numbers of alerts, but still, in operational environment, the collection of such data may be mandated by the Security policy. Processing this type of alerts presents a different problem than correlating alerts directly related to attacks or filtering incorrectly issued alerts. We aggregate individual alerts to alert flows, and then process the flows instead of individual alerts for two reasons. First, this is necessary to cope with the large quantity of alerts - a common problem among all alert correlation approaches. Second, individual alert's relevancy is often indeterminable, but irrelevant alerts and interesting phenomena can be identified at the flow level. This is the particularity of the alerts created by the complementary uses of IDSes. Flows consisting of alerts related to normal system behavior can contain strong regularities. We propose to model these regularities using non-stationary autoregressive models. Once modeled, the regularities can be filtered out to relieve the Security Operator from manual analysis of true, but low impact alerts. We present experimental results using these models to process voluminous alert flows from an operational network.