Visible to the public Cyber Situational Awareness Enhancement with Regular Expressions and an Evaluation Methodology

TitleCyber Situational Awareness Enhancement with Regular Expressions and an Evaluation Methodology
Publication TypeConference Paper
Year of Publication2017
AuthorsPark, H. K., Kim, M. S., Park, M., Lee, K.
Conference NameMILCOM 2017 - 2017 IEEE Military Communications Conference (MILCOM)
PublisherIEEE
ISBN Number978-1-5386-0595-0
Keywordscomposability, computer network security, computer security, Cyber Operations, cyber situational awareness, cyber situational awareness enhancement, cyber threats, cybersecurity, decision maker mission completeness, deep packet inspection, Handheld computers, Metrics, Pattern matching, PCRE, performance evaluation, pubcrawl, Regexbench, regular expression processing capability, regular expressions, Resiliency, security systems, situational awareness, Sniffles
Abstract

Cybersecurity is one of critical issues in modern military operations. In cyber operations, security professionals depend on various information and security systems to mitigate cyber threats through enhanced cyber situational awareness. Cyber situational awareness can give decision makers mission completeness and providing appropriate timely decision support for proactive response. The crucial information for cyber situational awareness can be collected at network boundaries through deep packet inspection with security systems. Regular expression is regarded as a practical method for deep packet inspection that is considering a next generation intrusion detection and prevention, however, it is not commonly used by the reason of its resource intensive characteristics. In this paper, we describe our effort and achievement on regular expression processing capability in real time and an evaluation method with experimental result.

URLhttp://ieeexplore.ieee.org/document/8170859/
DOI10.1109/MILCOM.2017.8170859
Citation Keypark_cyber_2017