You are here

Adversarial Detection, Inference & Defensive Response (ADIDRUS)

Award Information
Agency: Department of Defense
Branch: Air Force
Contract: FA8650-18-C-1661
Agency Tracking Number: O113-IA2-1059
Amount: $1,499,790.00
Phase: Phase II
Program: SBIR
Solicitation Topic Code: OSD11-IA2
Solicitation Number: 2011.3
Solicitation Year: 2011
Award Year: 2018
Award Start Date (Proposal Award Date): 2018-09-17
Award End Date (Contract End Date): 2020-09-17
Small Business Information
421 SW Sixth Ave
Portland, OR 97204
United States
DUNS: 098009918
HUBZone Owned: N
Woman Owned: N
Socially and Economically Disadvantaged: N
Principal Investigator
 David Burke
 (503) 626-6616
Business Contact
 Anne Marie McClaran
Phone: (503) 626-6616
Research Institution

Insider threat poses one of the most problematic cyber challenges facing the warfighter today. This threat to Air Force assets is particularly insidiousas trusted individuals have easy access to sensitive and classified information. Galois, Inc. has developed a multi-layered attack inference engine called ADIDRUS, originally designed to help UAVs fight through cyber attacks. ADIDRUS continuously monitors sensor inputs as error-correction data to make inferences over a set of hierarchical models and generate hypotheses that best account for the observed behavior. ADIDRUS uses these hypotheses to guide context-appropriate responses, (e.g., quarantining suspicious system components). The purpose of this STTP is to apply the ADIDRUS capability to insider threat mitigation. The ADIDRUS hierarchical architecture is naturally suited to doing hypothesis generation within a context (in this case, normal enterprise workflows). Instead of relying only on passive indicators to identify potential insiders, the ADIDRUS system uses active indicators to learn more effectively the difference between false positives and true positives. Finally, by automating most of the analysis of insider threat behavior, the system does triage for the human analysts, who can then concentrate on the highest probability cases for further investigation.

* Information listed above is at the time of submission. *

US Flag An Official Website of the United States Government