. Military Space News .
CYBER WARS
Researchers identify novel cybersecurity approach to protect Army systems
by Staff Writers
Adelphi MD (SPX) Mar 05, 2020

.

Researchers at the Army's corporate laboratory in collaboration with the University of California, Riverside have identified an approach to network security that will enhance the effectiveness and timeliness of protection against adversarial intrusion and evasion strategies.

Networked devices and infrastructure are becoming increasingly complex, making it nearly impossible to verify an entire system, and new attacks are continuously being developed.

To rapidly protect Army systems from attack in ways that don't require massive amounts of manual intervention, the researchers have developed and approach called SymTCP.

SymTCP is a proposed approach that can be used to identify previously unknown ways to bypass deep packet inspection, or DPI, checks in networked appliances, often what internet service providers use to prevent malicious attacks from being launched or to censor certain content.

"Identifying strategies that attackers use to evade DPI in networked systems has been generally a manual process," said Dr. Kevin Chan, researcher at the U.S. Army Combat Capabilities Development Command's Army Research Laboratory. "This research provides an automated method to identify potential vulnerabilities in the Transmission Control Protocol, or TCP, state machines of DPI implementation."

Chan stated that this research has found previously undiscovered vulnerabilities in TCP, which is what the internet is built on; most of internet traffic is TCP. However, it is very difficult to find vulnerabilities in the implementation of TCP, as some of these vulnerabilities are found in obscure parts of the code and require a specific sequence of packets to be sent in order to trigger the vulnerability.

"Our approach uses symbolic execution to explore the state of TCP implementation of an endhost to identify ways to reach critical points in the code," Chan said. "If such a point is found, then packets can be inserted and be undetected by DPI. This method is evaluated against several state-of-the-art DPI systems such as Zeek and Snort and identifies previously known evasion strategies in addition to new ones that were not previously documented."

The search space is enormous, and being able to make sense of the state and explore it efficiently is a great achievement, Chan said.

"This research will improve the security of Army networks in terms of being able to protect against future intrusion and evasion strategies," Chan said. "It has developed an efficient way to find and patch vulnerabilities in future Army network infrastructure."

According to the researchers, information must be securely transmitted between domains (i.e. air and land) and within domains (i.e. cyber domains) for various Army functions, making this research crucial to each of the Army Modernization Priorities in support of enabling Multi-Domain Operations, with direct applicability to the Army's Network Modernization Priority.

"This type of research helps focus cyber defense resources," said Dr. Tracy Braun, computer scientist at CCDC ARL. "It can reveal weaknesses and suggest more efficient deployments of network defenses. This helps protect networks against advanced attacks. It can also help guide the design of future Army network infrastructure and cyber defense strategies."

This collaborative research endeavor was made possible by ARL's Cyber Security Collaborative Research Alliance, which has the objective to develop a fundamental understanding of cyber phenomena, including aspects of human attackers, cyber defenders and end users, so that fundamental laws, theories, and theoretically grounded and empirically validated models can be applied to a broad range of Army domains, applications and environments.

CRAs are partnerships between Army laboratories and centers, private industry and academia that are focusing on the rapid transition of innovative science and technology for Army modernization.

"Collaboration by the teams of academic, industry and government researchers in the CRA, including students, builds enduring relationships and maintains a focus on cross-cutting foundational research addressing important Army challenges," said Dr. Michael Frame, Cyber Security CRA collaborative alliance manager.

The team's research was accepted to be presented at the Network and Distributed System Security Symposium 2020, which took place Feb. 23-26 in San Diego, California.

The Network and Distributed System Security Symposium fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy and advance the state of available security technologies.

According to Dr. Zhiyun Qian, Everett and Imogene Ross associate professor in the Computer Science and Engineering Department at the University of California Riverside, future research includes the continuous analysis of future generation of DPI boxes, as well as better designs of DPIs that can be made robust against evasion attempts.


Related Links
US Army Research Laboratory
Cyberwar - Internet Security News - Systems and Policy Issues


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


CYBER WARS
China hints at retaliation over US 'bullying' of state media
Beijing (AFP) March 3, 2020
China on Tuesday accused the United States of "bullying" and issued a veiled threat of retaliation after Washington cut the number of Chinese nationals allowed to work for Beijing's state-run media on American soil. The US move comes after China expelled three Wall Street Journal reporters late last month, although the US said its decision was based on levelling numbers between the countries rather than retaliating over content. Foreign ministry spokesman Zhao Lijian said China "strongly opposes ... read more

Comment using your Disqus, Facebook, Google or Twitter login.



Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

CYBER WARS
BAE wins $188.2M Navy contract for AEGIS system engineering, testing

Turkey says might receive US missiles over Syria threat

Raytheon completes first antenna array for anti-hypersonic sensor

Syrian air defence intercepts missile attack: state media

CYBER WARS
Lockheed Martin nabs $1.1B to provide GMLRS to Romania, South Korea

Raytheon awarded $90.4M for JMEWS warheads for Tomahawk missiles

Russia successfully test fires Tsirkon hypersonic cruise missile

Saudi intercepts Yemen rebel missiles targeting cities: coalition

CYBER WARS
Turkish drones kill 19 Syrian government soldiers as tensions soar

Navy installs ODIN laser weapon system to counter aerial drones

Ground-breaking solar powered unmanned aircraft makes first flight

UAV's Flight Control Solutions compatible with Trimble's UAS1

CYBER WARS
Lockheed Martin's Most Advanced Mobile Communications Satellite Launches

Space and Missile Systems Center awards Northrop Grumman $253.6 million for Protected Tactical SATCOM acquisition

AEHF-5 Satellite Control Authority Transferred to Space Operations Command

Improving 5G Network Security

CYBER WARS
This wearable device camouflages its wearer no matter the weather

Army to buy additional BONUS munitions for howitzers

Raytheon nets $15M to support small diameter bomb II

AFRL creates safer-than-steel synthetic winch cable for cargo aircraft

CYBER WARS
State department approves $325.5M arms deal to Tunisia

BAE Systems profits as governments splurge on military

German arrested for illegal military exports to Russia

World defence spending spikes as rivalries heat up

CYBER WARS
Turkey-Russia tensions soar after deadly Syria strike

Trump says US can avoid major epidemic as virus spreads

Last Soviet marshal and 1991 coup plotter Yazov dies

After US, Greece to sign defence deal with France: officials

CYBER WARS
New DNA origami motor breaks speed record for nano machines

Deep-sea osmolyte makes biomolecular machines heat-tolerant

Nanobubbles in nanodroplets

New production method for carbon nanotubes gets green light









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.