首页> 外文会议>International Symposium on Resilient Control Systems >A framework for resilient remote monitoring
【24h】

A framework for resilient remote monitoring

机译:弹性远程监控的框架

获取原文

摘要

Today's activities in cyber space are more connected than ever before, driven by the ability to dynamically interact and share information with a changing set of partners over a wide variety of networks. To support dynamic sharing, computer systems and network are stood up on a continuous basis to support changing mission critical functionality. However, configuration of these systems remains a manual activity, with misconfigurations staying undetected for extended periods, unneeded systems remaining in place long after they are needed, and systems not getting updated to include the latest protections against vulnerabilities. This environment provides a rich environment for targeted cyber attacks that remain undetected for weeks to months and pose a serious national security threat. To counter this threat, technologies have started to emerge to provide continuous monitoring across any network-attached device for the purpose of increasing resiliency by virtue of identifying and then mitigating targeted attacks. For these technologies to be effective, it is of utmost importance to avoid any inadvertent increase in the attack surface of the monitored system. This paper describes the security architecture of Gestalt, a next-generation cyber information management platform that aims to increase resiliency by providing ready and secure access to granular cyber event data available across a network. Gestalt's federated monitoring architecture is based on the principles of strong isolation, least-privilege policies, defense-in-depth, crypto-strong authentication and encryption, and self-regeneration. Remote monitoring functionality is achieved through an orchestrated workflow across a distributed set of components, linked via a specialized secure communication protocol, that together enable unified access to cyber observables in a secure and resilient way.
机译:今天在网络空间的活动比以往任何时候都更加联系,这是通过动态互动和与各种网络上的更改伙伴相互作用和分享信息的能力。为了支持动态共享,计算机系统和网络将以持续的方式站起来,以支持更改任务关键功能。然而,这些系统的配置仍然是手动活动,延长期间未检测到的误导性,在需要后保持不确定的系统,并且没有更新的系统,以包括对漏洞的最新保护。这种环境为目标网络攻击提供了丰富的环境,这些网络攻击仍未被未被发现到几个月,并提出了严重的国家安全威胁。为了抵消这种威胁,技术已经开始出现在任何网络连接装置中提供持续监控,以便通过识别,然后减轻目标攻击来提高弹性。对于这些技术有效,最重要的是避免受监控系统的攻击表面的任何无意的增加。本文介绍了GESTALT的安全架构,这是一个下一代网络信息管理平台,其旨在通过提供对网络可用的粒度网络事件数据的准备和安全访问来增加弹性。 GESTALT的联邦监测架构基于强孤立,最小特权政策,防御深度,密码强度认证和加密以及自我再生的原则基础。通过通过专用安全通信协议链接的分布式组件组的策划工作流程实现了远程监控功能,该协议将以安全且有弹性的方式实现对网络可观察的统一访问。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号