This report addresses the design of an Intelligent Security Console equipped with Intrusion Detection Message Exchange Format (IDMEF) Objects' data mining for the DARPA Ultra*Log Program. It supports the scalable Monitoring and Response security console architecture. The Data Mining capability requires scalability of message management, that has been ensured through incorporation of an XML Database (eXist). Security console is used to query for IDMEF alerts generated across the society by ...
The area of cyberspace defense mechanism design has received immense attention from the research community for more than two decades. However, the cyberspace security problem is far from completely solved. In this project we explored the applicability of game theoretic approaches to address some of the challenging cyber security issues: (a) We built a state-of-the-art attack taxonomy which can provide the system administrator with information on how to mitigate or ...