Researchers create next-generation software to identify complex cyber network attacks

March 17, 2008

Researchers in George Mason University’s Center for Secure Information Systems have developed new software that can reduce the impact of cyber attacks by identifying the possible vulnerability paths through an organization’s networks.

By their very nature networks are highly interdependent and each machine’s overall susceptibility to attack depends on the vulnerabilities of the other machines in the network. Attackers can take advantage of multiple vulnerabilities in unexpected ways, allowing them to incrementally penetrate a network and compromise critical systems. In order to protect an organization’s networks, it is necessary to understand not only individual system vulnerabilities, but also their interdependencies.

“Currently, network administrators must rely on labor-intensive processes for tracking network configurations and vulnerabilities, which requires a great deal of expertise and is error prone because of the complexity, volume and frequent changes in security data and network configurations,” says Sushil Jajodia, university professor and director of the Center for Secure Information Systems. “This new software is an automated tool that can analyze and visualize vulnerabilities and attack paths, encouraging ‘what-if analysis’.”

The software developed at Mason, CAULDRON, allows for the transformation of raw security data into roadmaps that allow users to proactively prepare for attacks, manage vulnerability risks and have real-time situational awareness. CAULDRON provides informed risk analysis, analyzes vulnerability dependencies and shows all possible attack paths into a network. In this way, it accounts for sophisticated attack strategies that may penetrate an organization’s layered defenses.

CAULDRON’s intelligent analysis engine reasons through attack dependencies, producing a map of all vulnerability paths that are then organized as an attack graph that conveys the impact of combined vulnerabilities on overall security. To manage attack graph complexity, CAULDRON includes hierarchical graph visualizations with high-level overviews and detail drilldown, allowing users to navigate into a selected part of the big picture to get more information.

“One example of this software in use is at the Federal Aviation Administration. They recently installed CAULDRON in their Cyber Security Incident Response Center and it is helping them prioritize security problems, reveal unseen attack paths and protect across large numbers of attack paths,” says Jajodia. “While currently being used by the FAA and defense community, the software is applicable in almost any industry or organization with a network and resources they want to keep protected, such as banking or education.”

Source: George Mason University


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 3.3 /5 (6 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first


March 17, 2008 all stories

Comments: 1

3.3 /5 (6 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

  • casio calculator that's similar to TI-89
    created Nov 08, 2009
  • Mathematica Question: Finding local maximums
    created Nov 08, 2009
  • Advice on what cell phone to get
    created Nov 08, 2009
  • Read multiple binary files to ascii
    created Nov 07, 2009
  • More from Physics Forums - Computing & Technology

Other News

Oracle logo

EU objects to Oracle's takeover of Sun

Technology / Business

created 2 hours ago | popularity 5 / 5 (1) | comments 0

(AP) -- European antitrust regulators have formally objected to Sun Microsystems Inc.'s planned $7.4 billion sale to Oracle Corp., escalating a battle over a deal that has already been cleared in the U.S.


Video fingerprinting offers search solution

Video fingerprinting offers search solution

Technology / Computer Sciences

created 8 hours ago | popularity not rated yet | comments 0

(PhysOrg.com) -- The explosive growth of video on the internet calls for new ways of sorting and searching audiovisual content. A team of European researchers has developed a groundbreaking solution that is ...


Commercialization of new solar technology to boost solar efficiency

Technology / Energy

created 8 hours ago | popularity 3.8 / 5 (5) | comments 0

A pioneer in solar power in the 1990s before it became "sexy," University of Houston Professor Alex Freundlich recently entered into a collaborative research agreement with U.K.-based start-up QuantaSol for the development ...


Solar LED lamps

Solar Cells with LEDs Provide Inexpensive Lighting

Technology / Energy

created 10 hours ago | popularity 4.8 / 5 (11) | comments 1

(PhysOrg.com) -- Of the 1.5 billion people in developing countries who do not have electricity, many rely on kerosene lamps for light after the sun goes down. But now, researchers from Denmark have designed ...


Google snaps up mobile ad startup for $750 million (Update)

Technology / Internet

created 9 hours ago | popularity 5 / 5 (1) | comments 0

(AP) -- Google Inc. is buying mobile advertising network AdMob for $750 million, underscoring the Internet search leader's determination to ensure its marketing machine reaches the growing number of people surfing the Web ...