22.01.2015 Views

Military Communications and Information Technology: A Trusted ...

Military Communications and Information Technology: A Trusted ...

Military Communications and Information Technology: A Trusted ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Federated Cyber Defence System<br />

– Applied Methods <strong>and</strong> Techniques 1<br />

Bartosz Jasiul 1 , Rafał Piotrowski 1 , Przemysław Bereziński 1 ,<br />

Michał Choraś 2, 3 , Rafał Kozik 2, 3 , Juliusz Brzostek 4<br />

1 <strong>Military</strong> Communication Institute, Zegrze, Pol<strong>and</strong>,<br />

{b.jasiul, r.piotrowski, p.berezinski}@wil.waw.pl<br />

2 ITTI Sp. z o.o., Poznań, michal.choras@itti.com.pl<br />

3 University of <strong>Technology</strong> <strong>and</strong> Life Sciences, Bydgoszcz, Pol<strong>and</strong>, chorasm@utp.edu.pl<br />

4 NASK, Warszawa, Pol<strong>and</strong>, juliusz.brzostek@nask.pl<br />

Abstract: In this paper implementation details of the Federated Cyber Defence System (FCDS) are<br />

presented. The main system components are described including their architecture, used protocols<br />

<strong>and</strong> security mechanisms. Moreover the benefits of the system are highlighted as well as recommendations<br />

<strong>and</strong> future work are proposed.<br />

Keywords: Cyber defence, cyber security, attack detection, Federation of Systems, Intrusion Prevention<br />

System, Intrusion Detection System<br />

I. Introduction<br />

Nowadays information exchange between companies as well as among common<br />

network users is natural. Internet as a global communication medium is used for<br />

business, social, personal but also criminal purposes. Cyber terrorism has become<br />

one of the most significant threats to public institutions using the Internet in everyday<br />

communication. Potential threats for a wide range of various networks <strong>and</strong> critical<br />

public infrastructures may be generated by both domestic <strong>and</strong> foreign users. Harmful<br />

activities cover broad spectrum of cyber threats <strong>and</strong> potential cyber attacks. They<br />

can influence communication links, data resources, their integrity, confidentiality<br />

<strong>and</strong> availability. According to the Open Web Application Project [1] nowadays top<br />

ten security risks in the Internet are: 1) Injection, 2) Cross-Site Scripting (XSS),<br />

3) Broken Authentication <strong>and</strong> Session Management, 4) Insecure Direct Object<br />

References, 5) Cross-Site Request Forgery (CSRF), 6) Security Misconfiguration,<br />

7) Insecure Cryptographic Storage, 8) Failure to Restrict URL Access, 9) Insufficient<br />

Transport Layer Protection, 10) Unvalidated Redirects <strong>and</strong> Forwards.<br />

Prototype of Federated Cyber Defence System (FCDS) is a developed to minimize<br />

number of threats <strong>and</strong> attacks that may affect the domain connected to the open

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!