DocumentCode :
2858153
Title :
Stellar: a fusion system for scenario construction and security risk assessment
Author :
Boyer, Stephen ; Dain, Oliver ; Cunningham, Robert
Author_Institution :
Inf. Syst. Technol. Group, MIT Lincoln Lab., Lexington, MA, USA
fYear :
2005
fDate :
23-24 March 2005
Firstpage :
105
Lastpage :
116
Abstract :
Stellar is a real-time system which aggregates and correlates alerts from heterogeneous network defense systems, building scenarios and estimating the security risk of the entire scenario. Prior work considered Stellar scenario formation; in this paper we explore the advantages provided by using scenario context to assess the risk of actions occurring on a network. We describe the design and an evaluation of Stellar and its Security Assessment Declarative Language (SADL), a fast, stateful, simple-to-use language for assessing the priority of scenarios, on a high traffic network under constant attack. The evaluation of the Stellar system deployed on a large, operational enterprise network demonstrated its ability to scale to high alert volumes while accurately forming and prioritizing scenarios. Stellar not only produced high priority scenarios matching all incidents reported by human analysts, but also discovered additional scenarios of concern that had initially gone unnoticed. Furthermore, by following the simple formalism embedded in example SADL rules, system administrators quickly develop a correct understanding of the network they are protecting.
Keywords :
computer networks; real-time systems; risk management; security of data; sensor fusion; specification languages; system monitoring; Stellar; alert aggregation; alert correlation; fusion system; heterogeneous network defense systems; high traffic network; network protection; network risk assessment; operational enterprise network; real-time system; scenario building; scenario construction; security assessment declarative language; security risk assessment; security risk estimation; system administration; Aggregates; Buildings; Data security; Engines; Information security; Information systems; Laboratories; Protection; Risk management; Space technology;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Assurance, 2005. Proceedings. Third IEEE International Workshop on
Print_ISBN :
0-7695-2317-X
Type :
conf
DOI :
10.1109/IWIA.2005.16
Filename :
1410706
Link To Document :
بازگشت