SBIR-STTR Award

Detection & Containment of Computer Epidemics Through Correlation of Communication Anomalies
Award last edited on: 5/2/2014

Sponsored Program
SBIR
Awarding Agency
DHS
Total Award Amount
$99,867
Award Phase
1
Solicitation Topic Code
H-SB04.2-002
Principal Investigator
K Narayanaswamy

Company Information

Computing Services Support Solutions (AKA: Cs3)

5777 West Century Boulevard Suite 1185
Los Angeles, CA 90045
   (310) 337-3013
   info@cs3-inc.com
   www.cs3-inc.com
Location: Single
Congr. District: 43
County: Los Angeles

Phase I

Contract Number: ----------
Start Date: ----    Completed: ----
Phase I year
2004
Phase I Amount
$99,867
This Phase I SBIR project investigates the detection and mitigation of fast-spreading computer infections that we call network epidemics. We wish to avoid packet payload inspection for several reasons. For one, increasing use of encrypted communication makes it impossible to interpret the payload. Further, payload anomaly analysis introduces delays that can be unacceptable when stopping fast-spreading epidemics. In our project, detection of a network epidemic is based upon communication anomalies and the detection of similar shifts in behavior in a very large number of machines across the network. It is our hypothesis that epidemics can be detected by analyzing just communication patterns of the machines, without reference to packet payloads. Innovations of our approach include efficient traffic summaries that can store traffic data indefinitely. We also include sophisticated correlation features that make it possible to detect shifts in behavior of many machines across an entire network. Both exponential and slow spreading epidemics are discovered using this approach. The approach also generates filters for the traffic that spreads the infection thereby providing a defense. In Phase I, we validate the approach with a proof of concept prototype, and analyze the scalability issues of the approach to larger and faster networks

Phase II

Contract Number: ----------
Start Date: ----    Completed: ----
Phase II year
----
Phase II Amount
----