Stellar: A fusion system for scenario construction and security risk assessment

被引:5
作者
Boyer, S [1 ]
Dain, O [1 ]
Cunningham, R [1 ]
机构
[1] MIT Lincoln Lab, Informat Syst Technol Grp, Lexington, MA 02453 USA
来源
THIRD IEEE INTERNATIONAL WORKSHOP ON INFORMATION ASSURANCE, PROCEEDINGS | 2005年
关键词
D O I
10.1109/IWIA.2005.16
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Stellar aggregates and correlates alerts from heterogeneous network defense systems, building scenarios and estimating the security risk of the entire scenario. Prior work considered Stellar scenario formation; in this paper we explore the advantages provided by using scenario context to assess the risk of actions occurring on a network. We describe the design and an evaluation of Stellar and its Security Assessment Declarative Language (SADL), a fast, stateful, simple-to-use language for assessing the priority of scenarios, on a high traffic network tinder constant attack. The evaluation of the Stellar system deployed on a large, operational enterprise network demonstrated its ability, to scale to high alert volumes while accurately forming and prioritizing scenarios. Stellar not only produced high priority scenarios matching all incidents reported by human analysts, but also discovered additional scenarios of concern that had initially gone unnoticed. Furthermore, by following the simple formalism embedded in example SADL rules, system administrators quickly develop a correct understanding of the network they are protecting(1).
引用
收藏
页码:105 / 116
页数:12
相关论文
共 23 条
[1]  
[Anonymous], 2003, P 36 ANN HAW INT C S
[2]   IMPLEMENTATION OF A STRUCTURED ENGLISH QUERY LANGUAGE [J].
ASTRAHAN, MM ;
CHAMBERLIN, DD .
COMMUNICATIONS OF THE ACM, 1975, 18 (10) :580-588
[3]  
BELCHER T, 2002, 7 RIPT
[4]  
BENFERHAT S, 2003, P 2 INT WORKSH MATH
[5]  
*CHECK POINT FIR T, 1997, FIR WALL 1 US GUID 3
[6]  
CUNNINGHAM RK, 1999, IEEE MIL COMM C P AT
[7]  
Dain O., 2004, P 4 SIAM INT C DAT M
[8]  
DAIN O, 2002, FUSING HETEROGENEOUS
[9]  
Debar H., 2001, P S RECENT ADV INTRU, P85
[10]  
Goldman RP, 2001, DISCEX'01: DARPA INFORMATION SURVIVABILITY CONFERENCE & EXPOSITION II, VOL I, PROCEEDINGS, P329, DOI 10.1109/DISCEX.2001.932228