Situational Awareness: Detecting Critical Dependencies and Devices in a Network



Rok publikování 2017
Druh Článek ve sborníku
Konference AIMS 2017 - 11th IFIP WG 6.6 International Conference on Autonomous Infrastructure, Management, and Security
Ústav výpočetní techniky

Obor Informatika
Klíčová slova situational awareness; cybersecurity; device importance evaluation; threat impact estimation; graph theory; network monitoring
Popis Large-scale networks consisting of thousands of connected devices are like a living organism, constantly changing and evolving. It is very difficult for a human administrator to orient in such environment and to react to emerging security threats. With such motivation, this PhD proposal aims to find new methods for automatic identification of devices, the services they provide, their dependencies and importance. The main focus of the proposal is to find novel approaches to building cyber situational awareness in an unknown network for the purpose of computer security incident response. Our research is at the initial phase and will contribute to a PhD thesis in four years.
