Raytheon chosen by DARPA for cybersecurity programme
Raytheon Company has been selected to support an insider threat research programme led by the Defense Advanced Research Projects Agency (DARPA).
The goal of the DARPA Anomaly Detection at Multiple Scales (ADAMS) programme is to create, adapt and apply technology to the problem of anomaly characterization and detection in large data sets.
In order to build algorithms to better detect anomalous behaviors, the ADAMS project will use data collected by Raytheon's endpoint audit and investigation solution known as SureView(TM). The specific goal of ADAMS researchers is to detect anomalous behaviors shortly after a trusted insider "turns" and begins committing malicious acts. Unlike previous insider threat research programmes that were limited in size and scope, ADAMS will leverage massive data sets from large computer end-user populations observed in live, operational environments. DARPA has stated it wants the technology developed by ADAMS researchers to bolster the capabilities of existing sensor suites currently employed by cybersecurity analysts and operators.
"This project will provide unprecedented understanding of the insider threat at a time when the US government is mandating that agencies implement automated insider threat detection capabilities to protect their classified information systems," said Steve Hawkins, vice president of Raytheon's Intelligence and Information Systems' Information Security Solutions business. "The ADAMS programme will ensure that operationally proven tools such as SureView can be further enhanced to keep pace with the ever-evolving nature of the insider threat and allow analysts to better identify precursor behaviors before damaging incidents occur."
SureView captures malicious activity by proactively auditing end-user behavior on computer endpoints for policy violations and high-risk activity, such as accessing classified or proprietary data and trying to send it outside the firewall. Whether an incident is accidental or deliberate, SureView provides customers visibility and context to discern benign and malicious behavior all while adhering to an organization's privacy policies.
SureView agents are able to collect data associated with a multitude of applications, processes and behaviors, including Web browsing, removable media, MS Office applications, file activity, email, MS Windows registry, peer-to-peer applications, log on/log off activity, keystroke logging and clipboard functions, use of printers, use of Windows terminal services, instant messaging, command line operations and use of encryption.
Source: Raytheon
More from Digital Battlespace
-
Wave Relay devices cleared for security use on commercial systems in industry trend
Persistent Systems has been cleared by National Security Agency (NSA) to transmit sensitive data on commercial networks. The devices are added to the NSA’s Commercial Solutions for Classified (CSfC) component list which also includes other companies’ products providing the same security.
-
UK teases cyber spending boost in Strategic Defence Review ahead of “imminent” release
The release of the UK’s Strategic Defence Review (SDR) has been long promised as mid-year. It is possible it could be as early as 2 June although the UK Ministry of Defence (MoD) continues to play its cards close to its chest.
-
Intelsat emphasises SATCOM resilience for SOF in contested domains (video)
Intelsat outlines how its multi-orbit SATCOM architecture is enhancing connectivity and resilience for special operations forces operating in degraded and contested environments.
-
US Space Force’s next-generation missile warning system moves forward with $500 million in new contracts
Next-Generation Overhead Persistent Infrared (Next-Gen OPIR) satellites are intended to provide early warning of missile launches from any location worldwide and new ground stations will result in expanded coverage of critical missile warning.
-
Airbus launches final CSO observation satellite for French Armed Forces
Airbus was awarded the Composante Spatiale Optique (CSO) contract at the end of 2010. This included an option for a third satellite, which was activated after Germany joined the programme in 2015.
-
Intelligence advantage: How real-time GEOINT is reshaping military decision-making (Studio)
In today’s contested operational environment, adaptability is key. The new Geospatial-Intelligence as a Service (GEO IaaS) solution from Fujitsu and MAIAR empowers militaries by enabling intelligence advantage, combining advanced technology with human expertise to deliver actionable insights.