• DocumentCode
    2858153
  • Title

    Stellar: a fusion system for scenario construction and security risk assessment

  • Author

    Boyer, Stephen ; Dain, Oliver ; Cunningham, Robert

  • Author_Institution
    Inf. Syst. Technol. Group, MIT Lincoln Lab., Lexington, MA, USA
  • fYear
    2005
  • fDate
    23-24 March 2005
  • Firstpage
    105
  • Lastpage
    116
  • Abstract
    Stellar is a real-time system which aggregates and correlates alerts from heterogeneous network defense systems, building scenarios and estimating the security risk of the entire scenario. Prior work considered Stellar scenario formation; in this paper we explore the advantages provided by using scenario context to assess the risk of actions occurring on a network. We describe the design and an evaluation of Stellar and its Security Assessment Declarative Language (SADL), a fast, stateful, simple-to-use language for assessing the priority of scenarios, on a high traffic network under constant attack. The evaluation of the Stellar system deployed on a large, operational enterprise network demonstrated its ability to scale to high alert volumes while accurately forming and prioritizing scenarios. Stellar not only produced high priority scenarios matching all incidents reported by human analysts, but also discovered additional scenarios of concern that had initially gone unnoticed. Furthermore, by following the simple formalism embedded in example SADL rules, system administrators quickly develop a correct understanding of the network they are protecting.
  • Keywords
    computer networks; real-time systems; risk management; security of data; sensor fusion; specification languages; system monitoring; Stellar; alert aggregation; alert correlation; fusion system; heterogeneous network defense systems; high traffic network; network protection; network risk assessment; operational enterprise network; real-time system; scenario building; scenario construction; security assessment declarative language; security risk assessment; security risk estimation; system administration; Aggregates; Buildings; Data security; Engines; Information security; Information systems; Laboratories; Protection; Risk management; Space technology;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance, 2005. Proceedings. Third IEEE International Workshop on
  • Print_ISBN
    0-7695-2317-X
  • Type

    conf

  • DOI
    10.1109/IWIA.2005.16
  • Filename
    1410706