Most Popular Stories
- EU official says identity management must be based on multiple biometrics
- Clapper sounds alarm on cyber capabilities of Iran, China and Russia
- FAA reauthorization would create NextGen czar UPDATED
- NARA, agencies revisit millions of pages to ensure proper declassification
- Agencies not sharing enough information, says Karen Evans
- Malware targets smart ID cards, say researchers
- Top FAA execs lack institutional knowledge, says official; agency must be prepared for cuts
- Air traffic control training gaps will be exacerbated by NextGen, says OIG
- Agencies plan for governmentwide FOIA portal
- FDA issues draft social-media marketing guidelines
- Obama administration announces immigrant visa waiver change
Events
- TECHEXPO Top Secret Career Fair
February 29, 2012 — Colorado Springs, CO 10am - 3pm - TECHEXPO Top Secret POLYGRAPH ONLY Hiring Event
February 9, 2012 — Baltimore, MD 10am - 3pm - TECHEXPO Top Secret Career Fair
February 7, 2012 — Arlington, VA 10am - 3pm - Learn With Your Peers at the Federal Senior Management Conference
April 15-18 — Cambridge, MD
Sponsored Links
HOT TOPICS >> Cloud computing | Cybersecurity | Gov 2.0 | Fiscal 2012 | Mobile | Transparency | GAO reports
AGENCY NEWS >> Defense | NASA | Homeland Security | NIST | OMB | Veterans Affairs | NARA | GSA
Latest News
Free Newsletter
About | View Sample | Privacy
Popular Topics
Whitepapers
- Business Intelligence: It's All in the Data
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
- Innovative Solutions for Database and DBA Management
- Storage Consolidation: Best of Both Worlds
- The E-discovery Toolbox: What you should look for in a unified e-discovery solution
- Migrating enterprise digital communication to the Cloud
DARPA in pursuit of insider threats
Just as constantly looking over your shoulder might betray nefarious intent, the Defense Advanced Research Projects Agency says certain system and network activities could indicate the presence of an insider threat.
Insiders granted legitimate access to sensitive networks are notoriously difficult to catch--witness the saga of Bradley Manning, the Army intelligence analyst who allegedly sent a large cache of documents to Wikileaks after downloading them onto a CD labeled "Lady Gaga." As a DARPA broad agency announcement for a new program to detect insiders through their behavior notes, insider threats to date have largely been identified only through perpetrators' incompetence or by accident.
The DARPA program is Cyber Insider Threat, which the agency, through the miracle of selective acronym selection, dubs CINDER. At its head is Peiter Zatko, aka Mudge, a former hacker hired by DARPA earlier this year. CINDER will fund insider detection capabilities in three phases, starting with identifying the types of "missions" an insider might undertake and techniques to identify them.
For example, a malicious insider might take an unusual interest in log files, make frequent queries of who is logged into a particular system, or might repeat non-standard queries to databases, the announcement states. But the goal of CINDER isn't to identify inside actors per se, since a system that would examine isolated activities would run the risk being inundated with false positives. What's needed is a context--hence, identification of insider threat missions that might be performed by an individual or a group of people, the announcement states.
One such mission could "remain persistent within an environment and continuously identify and exfiltrate actionable intelligence as it is discovered."
Previous attempts to model the behavior of legitimate users have been problematic, the announcement says.
Later phases will develop a system utilizing information from Phase I to create a system capable of identifying multiple insider threat missions and demonstrate that system "at scale on real world environments," the announcement states.
For more:
- see the FBO webpage for the DARPA CINDER broad agency announcement or directly download the BAA (.docx)
Related Articles:
IARPA looks to the future
Hacker 'Mudge' will help DARPA to deal with cybersecurity attacks
Lynn: Cyber deterrence rests mostly on denial, not retaliation
Related Stories
- Cybersecurity runs deep in fiscal 2012 budget request
- Amazon backs off Wikileaks hosting while White House says 'structural reforms' are underway
- Army warns personnel away from Wikileaks
- WikiLeaks inspires new White House cybersecurity policy
- NIST preps guidance for mitigating insider threats
- Leaked Wikileaks cables finger Chinese government for Google hack
- Hacker 'Mudge' will help DARPA to deal with cybersecurity attacks
- Congress authorizes offensive cyberspace military operations
- Paper: Congress should focus on intent when investigating leaks
- Wikileaks hasn't stifled information sharing, has increased security
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |


