Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Situational Awareness of Network System Roles (SANSR)

Software ·
DOI:https://doi.org/10.11578/dc.20221116.3· OSTI ID:code-96817 · Code ID:96817
 [1];  [1]
  1. Oak Ridge National Lab. (ORNL), Oak Ridge, TN (United States)

In a large enterprise it is difficult for cyber security analysts to know what services and roles every machine on the network is performing (e.g. file server, domain name server, email server). Understanding the roles of the systems in the network provides analysts with a situational awareness that will allow them to detect consequential changes in the network, initiate an incident response plan, and optimize their security posture. Using the network flow data, already collected by most enterprises, we developed a tool that enables analysts to automatically detect/classify services and roles of every machine that’s operating on a network (e.g. file server, domain name server, email server) for better situational awareness of potential threats to the network. his tool queries Elasticsearch for network flow data, creates a temporal behavior model of each system, uses unsupervised machine learning to cluster the models with a set of labeled temporal behavior models, and the resulting information can be printed to the console or programmatically accessed. The results include the likelihood that a machine has a labeled role and lists other machines that are most similar in behavior.

Short Name / Acronym:
SANSR
Project Type:
Closed Source
Site Accession Number:
8101
Software Type:
Scientific
Programming Language(s):
Go 1.11.1
Research Organization:
Oak Ridge National Laboratory (ORNL), Oak Ridge, TN (United States)
Sponsoring Organization:
USDOE

Primary Award/Contract Number:
AC05-00OR22725
DOE Contract Number:
AC05-00OR22725
Code ID:
96817
OSTI ID:
code-96817
Country of Origin:
United States

Similar Records

Situational Awareness of Network System Roles (SANSR)
Conference · Sat Dec 31 23:00:00 EST 2016 · OSTI ID:1356923

CyberPetri at CDX 2016: Real-time Network Situation Awareness
Conference · Mon Oct 24 00:00:00 EDT 2016 · OSTI ID:1346299

Real-Time Visualization of Network Behaviors for Situational Awareness
Conference · Tue Sep 14 00:00:00 EDT 2010 · OSTI ID:988662

Related Subjects