SBIR-STTR Award

FRONDES
Award last edited on: 10/21/2019

Sponsored Program
SBIR
Awarding Agency
DOD : Navy
Total Award Amount
$1,074,816
Award Phase
2
Solicitation Topic Code
N141-071
Principal Investigator
Jorge Tierno

Company Information

Barnstorm Research Corporation

PO Box 2148
Methuen, MA 01844
   (339) 224-2562
   ideas@barnstormresearch.com
   www.barnstormresearch.com
Location: Single
Congr. District: 03
County: Middlesex

Phase I

Contract Number: N00014-14-P-1164
Start Date: 5/5/2014    Completed: 3/5/2015
Phase I year
2014
Phase I Amount
$79,579
Security Information and Event Management (SIEM) systems are only able to support static analysis based on predefined event rules. Instead, a flexible user-programmable information triage approach is needed tha can process the volume, variety and velocity of all relevant internal and external data. Bonsai will provide security managers the ability to quickly craft data triage workflows using natural language expressions Bonsai will: + Guide the user to alternate between two broad categories of short natural language queries: ones that narrow collection and ones tha expand it. Alternating narrowing and expanding queries are naturally composable, and produce expressive sequences. + Translate into Language Integrated Query each natural language query in the sequence. LIQ was developed from strong mathematical foundations that guarantee composability, and can translate into most major databases, streaming data and unstructured data query frameworks We will demonstrate the value of Bonsai in relevant scenario such as a potential phishing attack. Bonsai will combine and triage textual sources (such as emails or webpages), structured sources such as networking logs and semistructured sources such as new threat information. To enhance commercialization potential, Bonsai will operate on the data in-situ, and will integrate its components using the http protocol and RESTful interfaces.

Keywords:
Dynamic Network Monitoring, Dynamic Network Monitoring, Natural Language Query, Language Integrated Query

Phase II

Contract Number: D17PC00093
Start Date: 00/00/00    Completed: 00/00/00
Phase II year
2017
Phase II Amount
$995,237
Recent technology evelution has turned power grids into complex networks comprised of multiple layers with strong coupling between. Security risks now arise from fragile interactions between the cyber and physical layers. Adversarial cyber attacks can exploit this fragility to cause physical harm. Since we can't stop all intrusions before they damage the infrastructure, it is critical to respond quickly to attacks underway. To facilitate a quick response grid supervisors are to be at all times aware of the state of the grid, and receive ample warning that an event is underway. Difficulties in anomaly detection lead to false alarm rates that can trigger the cry-wolf effect on grid supervisors Instead of setting unrealistic false alarm rate goals for anomaly detectors, FRONDES focuses directly on supervisor situation awareness and on mitigating the cry-wolf effect, even with moderately high rates of false alarms. FRONDES will work in conjunction with an anomaly detector and an anomaly triage engine. For each detection class, FRONDES will develop engaging supervisor workflows devised to blend response to the detection with other on-going supervisory activities. Such workflows will promote engagement, build situational awareness and enhance the supervisor's chances of successfully dealing with true malicious events.