High-Speed IP Traceback Research SwRI has developed a novel, cost-effective approach for Internet Protocol (IP) Traceback that locates the source of Internet attacks at data rates greater than 1Gbps. IP Traceback leverages the autonomous system (AS) architecture of the Internet to combat denial-of-service attacks and improve attribution of malicious activity. Intelligent Agents for Network Defense New network threats and attacks require revolutionary new protection concepts. SwRI is conducting research into semiautonomous network agents that perform network health and status checking, security monitoring and management, integrated information protection, and reporting functions for information assurance. This new approach promises to improve the flexibility and response speed of network protection architectures. IP Traceback architecture is being developed at SwRI for determining the source of an Internet attack. To combat the increasing use of networks of compromised computers for largescale denial of service attacks, SwRI has pioneered new techniques for detecting the command and control communications for these botnets, and is developing designs for automated botnet sensors for enterprise network protection. Application Security Analysis Applications are often the target of malicious attacks that compromise the confidentiality, integrity and availability of information and systems. To address this challenge, SwRI enforces a configurable high-level security policy by automatically enhancing software applications through a complementary combination of static and dynamic data flow analysis. This approach enables precise, relevant and scalable tracking of information flow in applications at a level previously impossible. Insider Threats Insider attacks exhibit different characteristics than external threats and generally go unnoticed by standard intrusion detection systems. SwRI is cooperating with government, industry and university researchers to investigate early indication and warning methods for insider threats involving the following methods: ❏ Building threat models of malicious insider behavior ❏ Integrating data from multiple network and application-level sensors ❏ Determining the most appropriate sensors ❏ Constructing appropriate sensors without compromising user privacy or system performance D015257_0051 ❏ Internet-scale cyber security and traceback ❏ Network attack and defense modeling and simulation ❏ Application security and secure middleware ❏ High-speed security sensors and monitoring hardware ❏ Embedded systems security and intellectual property protection Advanced Botnet Detection D015266/D015268/D015265 S outhwest Research Institute® (SwRI®) is working to improve the security of the global information infrastructure. Through active research in information assurance and memberships in national cyber security working groups, SwRI is extending the state of the art in: Custom Communication Monitoring Devices SCADA Network Security Security solutions in some environments require custom monitoring beyond the capabilities of network firewalls and intrusion detection systems (IDS). SwRI designs custom portable analog and digital telecommunications monitoring tools with remote network control, with expertise in the following disciplines: Control systems in industrial facilities are now being connected to Internet-accessible IP networks. SwRI is involved in assessing and improving the security of these SCADA (supervisory control and data acquisition) systems to protect against cyber attacks on: ❏ ❏ ❏ ❏ ❏ ❏ ❏ ❏ ❏ Multiple signal types Encoding Communication protocols Encryption methods Cyber Security Chemical refineries Water treatment plants Electrical transmission systems Telecommunications Natural gas distribution and Information Assurance D015268 SwRI researchers design custom-built hardware for monitoring telecommunications transmissions. We welcome your inquiries. For additional information, please contact: Joseph Loomis Group Leader Phone: (210) 522-3367 jloomis@swri.org www.swri.org www.cybersecurity.swri.org Benefiting government, industry and the public through innovative science and technology An Equal Opportunity Employer M/F/D/V Committed to Diversity in the Workplace 10-0513 JCN243456 tp Embedded Systems Security Group Automation and Data Systems Division Southwest Research Institute 6220 Culebra Road • P.O. Drawer 28510 San Antonio, Texas 78228-0510 Southwest Research Institute is an independent, nonprofit, applied engineering and physical sciences research and development organization using multidisciplinary approaches to problem solving. The Institute occupies 1,200 acres in San Antonio, Texas, and provides more than 2 million square feet of laboratories, test facilities, workshops and offices for more than 3,000 employees who perform contract work for industry and government clients.