Current analysis, detection and protection systems are mainly static and manually intensive. At the same time, the complexity of networked computing systems, their dynamic behavior, and the availability of many heterogeneous devices that are static and mobile make these tools incapable to accurately characterize current states, detect malicious attacks, and stop them or their fast propagation and/or minimize their impacts. ?In this phase I project, we propose a closed-loop control system (AMAP) that continuously monitors the cyber resources and services 24 by 7, performs anomaly behavior analysis to detect malicious activities and proactively either recommends actions to stop attacks and minimize their impacts and/or responds automatically depending on the severity of the detected malicious attacks and their potential impacts on the overall system operations. Our proposed solution is based on the following novel features: Novel data structure that we refer to as Cyber DNA (CDNA) that will be the basis of our anomaly behavior analysis as well as root-cause analysis, Self-Management Engine (SME), and Knowledge Representation and Visualization. ?
Benefit:The benefits include the unprecedented autonomic management and protection capabilities for cyber resources and their applications as well as the knowledge representation and visualization tools. ?The AMAP will be able to accurately characterize current states, detect malicious attacks, and stop them or their fast propagation and/or minimize their impacts.