![]() |
|
|||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||
|
|
The security of the global information infrastructure is a concern of Southwest Research Institute (SwRI) and SwRI engineers are continually working to improve it. Through active research in information assurance and memberships in national working groups in cyber security, SwRI is extending the state of the art in:
High-Speed IP Traceback Research
SwRI has developed a novel, cost-effective approach for Internet Protocol (IP) Traceback that locates the source of Internet attacks at data rates greater than 1Gbps. IP Traceback leverages the autonomous system (AS) architecture of the Internet to combat denial-of-service attacks and improve attribution of malicious activity.
Intelligent Agents for Network DefenseNew network threats and attacks require revolutionary new protection concepts. SwRI is conducting research into semi-autonomous network agents that perform network health and status checking, security monitoring and management, integrated information protection, and reporting functions for information assurance. This new approach promises to improve the flexibility and response speed of network protection architectures.
Network Security Modeling and Simulation
Understanding the security relationships and interactions of computers and networked systems through the use of modeling and simulation is essential. The SwRI Network Visualization, Attack, Defense, and Analysis Resource (NetVADAR™), is a prototype simulation system that visualizes a networking environment operating under normal, attacked, or defensive conditions.
NetVADAR™ functionalities and interfaces were developed based on interviews with experts in network security operations. NetVADAR™ is designed as a basic framework upon which extensions can be constructed as new network and attack technologies emerge. The software consists of several main elements:
Advanced Botnet DetectionTo combat the increasing use of networks of compromised computers for large-scale denial of service attacks, SwRI has pioneered new techniques for detecting the command and control communications for these botnets, and is developing designs for automated botnet sensors for enterprise network protection.
Application Security AnalysisApplications are often the target of malicious attacks that compromise the confidentiality, integrity, and availability of information and systems. To address this challenge, SwRI enforces a configurable high-level security policy by automatically enhancing software applications through a complementary combination of static and dynamic data flow analysis. This approach enables precise, relevant, and scalable tracking of information flow in applications at a level previously impossible.
Insider ThreatsInsider attacks exhibit different characteristics than external threats and generally go unnoticed by standard intrusion detection systems. SwRI is cooperating with government, industry, and university researchers to investigate early indication and warning methods for insider threats involving the following methods:
Independent Technology Analysis and Policy Recommendations
National, state, and local government agencies as well as private industry rely on independent assessments and recommendations to formulate security and technology policy. SwRI has prepared a number of Technology Information Bulletins (TIBs) for the National Communications System (NCS), an office that assists the President and the Executive Office of the President in executing their national security/emergency preparedness communications functions. These reports analyze current and future technology trends and their impact on national security policy and strategies. For example, in TIB00-8, SwRI reports on the national security and emergency preparedness ramifications of the impending convergence of the voice and data networks.
SCADA Network Security
Control systems in industrial facilities are now being connected to Internet-accessible IP networks. SwRI is involved in assessing and improving the security of these SCADA (supervisory control and data acquisition) systems to protect against cyber attacks on:
Embedded Systems SecurityEmbedded systems face special security challenges, due to the limited processing power, storage, and communications capabilities many embedded systems must contend with. In addition, embedded systems can be susceptible to physical alteration. SwRI is working with government and commercial clients to develop security solutions for communications and processing functions in embedded systems for mechanical and aerospace applications.
Custom Communication Monitoring DevicesSecurity solutions in some environments require custom monitoring beyond the capabilities of network firewalls and intrusion detection systems (IDS). SwRI designs custom portable analog and digital telecommunications monitoring tools with remote network control, with expertise in the following disciplines:
For more information about cyber security and
information assurance capabilities at SwRI or how you can contract with SwRI,
please contact
Corey King at
cking@swri.org or (210) 522-3011. |
|
||||||||||||||||||||||||||
|
| Communications and Embedded Systems Department | Automation and Data Systems Division | SwRI Home | |
||||||||||||||||||||||||||||
|
Southwest Research Institute® (SwRI®), headquartered in San Antonio, Texas, is a multidisciplinary, independent, nonprofit, applied engineering and physical sciences research and development organization with 12 technical divisions. |
||||||||||||||||||||||||||||
|
August 31, 2009 |
||||||||||||||||||||||||||||