Cyber Security and Information Assurance

advertisement
High-Speed IP
Traceback Research
SwRI has developed a novel, cost-effective
approach for Internet Protocol (IP)
Traceback that locates the source of
Internet attacks at data rates greater than
1Gbps. IP Traceback leverages the autonomous system (AS) architecture of the
Internet to combat denial-of-service
attacks and improve attribution of
malicious activity.
Intelligent Agents for
Network Defense
New network threats and attacks require
revolutionary new protection concepts.
SwRI is conducting research into semiautonomous network agents that perform
network health and status checking,
security monitoring and management,
integrated information protection, and
reporting functions for information assurance.
This new approach promises to improve
the flexibility and response speed of
network protection architectures.
IP Traceback
architecture is
being developed
at SwRI for
determining the
source of an
Internet attack.
To combat the increasing use of networks
of compromised computers for largescale denial of service attacks, SwRI has
pioneered new techniques for detecting
the command and control communications for these botnets, and is developing
designs for automated botnet sensors for
enterprise network protection.
Application Security
Analysis
Applications are often the target of
malicious attacks that compromise the
confidentiality, integrity and availability of
information and systems. To address this
challenge, SwRI enforces a configurable
high-level security policy by automatically
enhancing software applications through
a complementary combination of static
and dynamic data flow analysis. This
approach enables precise, relevant and
scalable tracking of information flow in
applications at a level previously impossible.
Insider Threats
Insider attacks exhibit different characteristics than external threats and generally
go unnoticed by standard intrusion detection systems. SwRI is cooperating with
government, industry and university
researchers to investigate early indication
and warning methods for insider threats
involving the following methods:
❏ Building threat models of malicious insider behavior
❏ Integrating data from multiple network
and application-level sensors
❏ Determining the most appropriate
sensors
❏ Constructing appropriate sensors
without compromising user privacy
or system performance
D015257_0051
❏ Internet-scale cyber security and
traceback
❏ Network attack and defense modeling
and simulation
❏ Application security and secure
middleware
❏ High-speed security sensors and
monitoring hardware
❏ Embedded systems security and
intellectual property protection
Advanced Botnet
Detection
D015266/D015268/D015265
S
outhwest Research Institute®
(SwRI®) is working to improve the
security of the global information infrastructure. Through active research in information
assurance and memberships in national
cyber security working groups, SwRI is
extending the state of the art in:
Custom Communication
Monitoring Devices
SCADA Network
Security
Security solutions in some environments require custom
monitoring beyond the capabilities of network firewalls and
intrusion detection systems (IDS). SwRI designs custom
portable analog and digital telecommunications monitoring
tools with remote network control, with expertise in the
following disciplines:
Control systems in industrial facilities are now being connected to Internet-accessible IP networks. SwRI is involved
in assessing and improving the security of these SCADA
(supervisory control and data acquisition) systems to
protect against cyber attacks on:
❏
❏
❏
❏
❏
❏
❏
❏
❏
Multiple signal types
Encoding
Communication protocols
Encryption methods
Cyber Security
Chemical refineries
Water treatment plants
Electrical transmission systems
Telecommunications
Natural gas distribution
and
Information
Assurance
D015268
SwRI researchers design custom-built
hardware for monitoring telecommunications transmissions.
We welcome your inquiries.
For additional information, please contact:
Joseph Loomis
Group Leader
Phone: (210) 522-3367
jloomis@swri.org
www.swri.org
www.cybersecurity.swri.org
Benefiting government, industry and the public
through innovative science and technology
An Equal Opportunity Employer M/F/D/V
Committed to Diversity in the Workplace
10-0513 JCN243456 tp
Embedded Systems Security Group
Automation and Data Systems Division
Southwest Research Institute
6220 Culebra Road • P.O. Drawer 28510
San Antonio, Texas 78228-0510
Southwest Research Institute is an independent, nonprofit,
applied engineering and physical sciences research and
development organization using multidisciplinary approaches
to problem solving. The Institute occupies 1,200 acres in San
Antonio, Texas, and provides more than 2 million square feet
of laboratories, test facilities, workshops and offices for more
than 3,000 employees who perform contract work for
industry and government clients.
Download