You are here

Intelligent Distributed Intrusion Detection via Collaboration

Award Information
Agency: Department of Homeland Security
Branch: N/A
Contract: NBCHC050005
Agency Tracking Number: 0421200
Amount: $99,000.00
Phase: Phase I
Program: SBIR
Solicitation Topic Code: N/A
Solicitation Number: N/A
Timeline
Solicitation Year: N/A
Award Year: 2004
Award Start Date (Proposal Award Date): N/A
Award End Date (Contract End Date): N/A
Small Business Information
1525 Siesta Drive
Los Altos, CA 94024
United States
DUNS: N/A
HUBZone Owned: No
Woman Owned: No
Socially and Economically Disadvantaged: No
Principal Investigator
 Hilarie Orman
 Security Consultant
 (801) 423-1052
 hilarie@purplestreak.com
Business Contact
 Eitan Fenson
Title: Chief Executive Officer
Phone: (650) 964-7210
Email: eitan@pnphome.com
Research Institution
N/A
Abstract

We propose to design a cognitive, automated Distributed Intrusion Detection System that correlates IDS data from nodes across multiple administrative domains. In Phase I we will demonstrate that for multiple types of attacks across multiple administrative domains, such a system can detect incipient attacks and inhibit their success, where no single local IDS can be reasonably expected to do so. We will build on our existing multicast IP protocol, Collaboration Bus (CB), that enables local IDS data sharing. CB also allows remote connection to external listeners outside a LAN or local administrative domain. We will design and deploy a cognitive algorithm on a CB listener that uses Bayesian methods to correlate incoming IDS data and make diagnoses and judgments about action(s) to take. Using Emulab at the University of Utah, we will deploy CB on at least three independent target administrative domains together with a remote listener. We will deploy at least three known effective distributed attacks, and target them in an isolated environment at the target domains. We will run the cognitive listener and confirm that it has made appropriate judgments. We will generate innocuous traffic and confirm that the cognitive listener has not erroneously detected attacks.

* Information listed above is at the time of submission. *

US Flag An Official Website of the United States Government