SBIR-STTR Award

Multiple Hypothesis Tracking of Cyberthreats
Award last edited on: 6/18/2021

Sponsored Program
STTR
Awarding Agency
DOD : AF
Total Award Amount
$149,999
Award Phase
1
Solicitation Topic Code
AFX20D-TCSO1
Principal Investigator
C Thomas Savell

Company Information

GCAS Inc

1531 Grand Avenue Suite A
San Marcos, CA 92069
   (760) 591-4227
   info@gcas.net
   www.gcas.net

Research Institution

Carnegie Mellon University

Phase I

Contract Number: FA8649-21-P-0059
Start Date: 12/18/2020    Completed: 6/18/2021
Phase I year
2021
Phase I Amount
$149,999
This Proposal addresses the tracking and forecasting a cyberthreat’s future maneuvers in compromised network. Our approach is as follows: Movement in the Network observed by Intrusion Detection System (IDS) Sensor Data = Discrete States (e.g., IP or Port Addressed per IDMEF alert format) Forecast Threat Track Vector using Multiple Hypothesis Method (MHM) Use Probabilistic Relational Model (PRM) framework to Develop Tracking Algorithms. Model Threat Movement using a Dynamic Decision Network (DDN) with Multi-Tactics & Trafficability Extend Bayesian Inference with Second Order Uncertainty (SOU) which Increases the precision of the forecast. Select multiple hypothesis of movement tactics from MITRE ATT&CK framework Apply weights to hypothesis paths based on the value of the target assets, Use data association methods, select and save the top-3 likely threat vectors for further tracking This is different from Today’s Technology in that it adds the ability to predict the likely next move in the attack vector using Multi Hypothesis Method (MHM) within a Bayesian representation of the cyber network. The Phase-I validation of the method will be performed using a simplified simulation of a Cyberattack. Namely, a single Intruder with a limited number of maneuver tactics

Phase II

Contract Number: ----------
Start Date: 00/00/00    Completed: 00/00/00
Phase II year
----
Phase II Amount
----