SBIR-STTR Award

A System for Accurate Detection of Known and Novel Attacks in High Speed Networks
Award last edited on: 4/17/2003

Sponsored Program
SBIR
Awarding Agency
DOE
Total Award Amount
$100,000
Award Phase
1
Solicitation Topic Code
-----

Principal Investigator
Umamaheswari Ganapathy

Company Information

Immunet Security Solutions Inc

75 East Loop Road
Stony Brook, NY 11790
   (631) 632-8672
   uma@immunetsecurity.com
   www.immunetsecurity.com
Location: Single
Congr. District: 01
County: Suffolk

Phase I

Contract Number: ----------
Start Date: ----    Completed: ----
Phase I year
2002
Phase I Amount
$100,000
Networks and systems owned by DoD and DOE are particularly attractive targets for cyberattacks by highly skilled and organized adversaries. Current intrusion detection products are mainly limited to detection of previously seen attacks, and cannot cope with new types of attacks that can be crafted by such adversaries. Moreover, these products are typically overwhelmed at low network speeds (below 100Mbps), and thus are not applicable to modern high-speed networks that operate at gigabit rates. This project will develop an approach for detecting novel attacks with low false alarm rates by combining specification-based and anomaly-based intrusion detection approaches with advanced statistical, machine-learning, and data-mining techniques. Advanced data structures and algorithms will be used to speed up the compute-intensive operations. Phase I will focus on developing capabilities for identifying attacks and their origin from the output of an anomaly detector. Data-reconciliation, data-mining, and model-based event correlation techniques will be used to build these capabilities.

Commercial Applications and Other Benefits as described by the awardee:
Target customers for the attack-identification software would include DoD, DOE, governmental and commercial institutions that administer critical infrastructures (such as banks, power distribution, and law-enforcement), and high-speed network providers (such as ISPs and backbone network providers). These customers are not satisfied with the 'after-the-fact' protection offered by today's products

Phase II

Contract Number: ----------
Start Date: ----    Completed: ----
Phase II year
----
Phase II Amount
----