22.01.2015 Views

Military Communications and Information Technology: A Trusted ...

Military Communications and Information Technology: A Trusted ...

Military Communications and Information Technology: A Trusted ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 4: <strong>Information</strong> Assurance & Cyber Defence<br />

351<br />

<strong>and</strong> carries the following information: categorized source called facility, severity<br />

(from debug to emergency), host or interface name, timestamp <strong>and</strong> message<br />

(unst<strong>and</strong>ardized description of event). Syslog supports hierarchical network architecture.<br />

Lack of reliable transfer of events from Sensors to local Decision Modules<br />

was unacceptable in SOPAS; thus decision about using Syslog-ng [7] implementation<br />

which support transport using TCP was made. To make the communication<br />

secure, a built in TLS mechanism based on X.509 certificates provides encryption<br />

<strong>and</strong> mutual authentication between the host <strong>and</strong> the server.<br />

B. Decision Module<br />

Each DM is responsible for acquiring <strong>and</strong> processing network events coming<br />

from sensors distributed over the domain. If the attack or its symptoms are detected<br />

in one domain, the relevant information are disseminated to other cooperating<br />

domains so that appropriate countermeasures can be applied.<br />

Decision module in the proposed federated system is responsible for correlating<br />

network events in order to detect <strong>and</strong> recognize malicious events in the network.<br />

DM consists of the following components [10]:<br />

• Correlation Engine (e.g. based on the Borealis system),<br />

• CLIPS rule engine,<br />

• Ontology (in OWL format),<br />

• Graphical User Interface.<br />

The Decision Module components are presented in Figure 2, while the UML<br />

diagram is shown in Figure 3.<br />

Figure 2. Decision Module architecture <strong>and</strong> components [10]<br />

Borealis is a distributed stream processing engine <strong>and</strong> is responsible for<br />

gathering information generated by the network sensors [11]. Correlation engine

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!