SBIR-STTR Award

Incident Response Decision Aid - irDA
Award last edited on: 2/22/2007

Sponsored Program
SBIR
Awarding Agency
DOD : AF
Total Award Amount
$99,999
Award Phase
1
Solicitation Topic Code
AF05-106
Principal Investigator
Joe Minieri

Company Information

OpenService Inc

67 Forest Street
Marlborough, MA 01752
   (508) 597-5300
   info@openservice.com
   www.openservice.com
Location: Multiple
Congr. District: 03
County: Middlesex

Phase I

Contract Number: ----------
Start Date: ----    Completed: ----
Phase I year
2005
Phase I Amount
$99,999
An event correlation and incident response capability is necessary for rapidly detecting damaging and disruptive incidents, minimizing disclosure, alteration, and destruction of digital assets, mitigating the vulnerabilities that were exploited, and restoring computing services. The first line of defense in this war is fought by the Level I information security operators tasked with monitoring the various security software tools. Here we propose to develop an incident response Decision Aid (irDA) that will guide Level I operators in the analysis, verification, notification and remediation of security incidents. In particular, we propose to integrate belief -net based course of action planning technology with our security threat management correlation engine. The belief net-based irDA will fuse the outputs of security threat manager with other in-context digital evidence and dynamically in real time recommend the optimal course of action (i.e. analysis, containment, notification, eradication, recovery) to the operator. Given the relatively inexperienced frequently changing Level I security operator cadre in the DoD workforce, the development of our incident response decision aid will have a substantial impact on improving the risk posture of DoD information assets by providing a 24x7 online help to operators

Phase II

Contract Number: ----------
Start Date: ----    Completed: ----
Phase II year
----
Phase II Amount
----