DocumentCode :
2210142
Title :
A scalable architecture for improving the timeliness and relevance of cyber incident notifications
Author :
Miller, James L. ; Mills, Robert F. ; Grimaila, Michael R. ; Haas, Michael W.
Author_Institution :
Dept. of Electr. & Comput. Eng., Air Force Inst. of Technol., Wright-Patterson AFB, OH, USA
fYear :
2011
fDate :
11-15 April 2011
Firstpage :
76
Lastpage :
83
Abstract :
The current mechanics of cyber incident notification within the United States Air Force rely on a broadcast “push” of incident information to the affected community of interest. This process is largely ineffective because when the notification arrives at each unit, someone has to make a decision as to who should be notified within their unit. Broadcasting the notification to all users creates noise for those who do not need the notification, increasing the likelihood of ignoring future notifications. Selectively sending notifications to specific people without a priori knowledge of who might be affected results in missing users who need to know. Neither of these approaches addresses the passing of notifications to downstream entities whose missions may be affected by the incident. In this paper, we propose a modular, scalable, cyber incident notification system concept that makes use of a “publish and subscribe” architecture to assure the timeliness and relevance of incident notification. Mission stakeholders subscribe to the status of mission critical information resources (external and internal) and publish their own mission capability allowing other units to maintain real-time awareness of their own dependencies. We contend that this architecture is a significant improvement over current methods by making direct connections between mission stakeholders and their dependencies and eliminating multiple levels of human processing, thereby reducing noise and ensuring relevant information gets to the right people.
Keywords :
information resources; message passing; middleware; military computing; security of data; United States Air Force; cyber incident notifications; mission critical information resources; publish and subscribe architecture; scalable architecture; Communities; Databases; Joints; Noise; Organizations; Personnel; Servers; CIMIA; cyber incident notification; mission assurance; situational awareness;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence in Cyber Security (CICS), 2011 IEEE Symposium on
Conference_Location :
Paris
Print_ISBN :
978-1-4244-9905-2
Type :
conf
DOI :
10.1109/CICYBS.2011.5949396
Filename :
5949396
Link To Document :
بازگشت