Presentation is loading. Please wait.

Presentation is loading. Please wait.

Integrating information towards Digital ATM Cyber Situational Awareness Presented By: David M. Petrovich Date:August 28, 2013.

Similar presentations


Presentation on theme: "Integrating information towards Digital ATM Cyber Situational Awareness Presented By: David M. Petrovich Date:August 28, 2013."— Presentation transcript:

1 Integrating information towards Digital ATM Cyber Situational Awareness Presented By: David M. Petrovich Date:August 28, 2013

2 1 What will be presented: A “lessons learned” case study involving a Mission Driven, Semantically Enabled and User Defined Cyber Situational Awareness Framework & Implementation.  The Why  The Approach  The What  The Lessons  Conclusion The Presentation

3 2 The Why – Within a Complex Cyber Domain We need to:  Understand - capture our understanding of the domain  Be aware of - what is occurring at that point in time  Communicate - share, collaborate and disseminate  Anticipate - plan and prepare  React - command & control, mitigate, affect. We base this on:  Information, data and derived data – this is a given  Obvious relationships – easy but critical Non-obvious relationships – this is hard  Non-obvious relationships – this is hard   Obvious consequences – common sense  Unintended consequences – this is really hard

4 3 The Approach Incremental  Plan, Design, Develop and Deploy “Status Demos”  “Status Demos” – Challenge and validate assumptions and designs.  Socialize and listen – “What do you think ?” “All-Hazards” perspective – It’s all related Integrated models  Integrated models: Physical, Logical, and Social type themes. Standards - Adherence to and awareness of  Comm. protocols, Exchange formats, Enumerations, Controls, etc. Flexible threats  Understanding the evolving missions, threats and domains. Allow the user to define their own needs

5 4 The What Cyber The Cyber Information System (CIS) is Mission Driven, Semantically Enabled and User Defined. The CIS integrates advanced visualizations, provides automated data ingest from “Data contributors”, includes multi-tool logic, supports complex visual analytics and a “drag and drop” media wall implementation.

6 5 The What - Cont’d Mission Driven  Multiple visualizations support specific missions Inter-related schema(s) / model(s)  Inter-related schema(s) / model(s) support the execution of complex mission threads. Semantically Enabled  Mission schemas are represented within a Resource Description Framework (RDF) - easily redefined and managed.  Inferred visualizations  Inferred visualizations are linked to specific mission capability needs User Defined  The User Interface (UI) contains tabs or panels that can be “popped- out” and dragged onto an unlimited number of monitors.  An unlimited UI landscape accommodates multiple visualizations that user defined perspectives support user defined perspectives – filter and view data in multiple ways

7 6 The Lessons “All-Hazards” ingest & structuring mechanism Standards An “All-Hazards” approach requires multiple “Data Contributors” to populate the repository. - The ingest & structuring mechanism should align and leverage, as best as possible, with the available Standards in order to normalize the data and minimize “stove piping”. really context and user dependent commonality is leveraged, Situational Awareness (SA) is context and user dependent - Cyber SA is really context and user dependent, so designing the CIS to be mission neutral and generic seems to be working. Missions that require SA have shared common capabilities, features and data. The commonality is leveraged, which is making for more effective SA. “Linked Data” - “Linked Data” (Semantic Technology) - is extremely powerful. Comparing “Apples to Oranges” can mitigate risk. Identifying non- obvious relationships can more easily uncover the real threats faster.

8 7 The Lessons - Cont’d Filtering Filtering data – The ability to easily filter and visualize the results effectively and in multiple ways is critical. The means to visualize the filtered data from a users perspective, removes the constraint on who can use the system and how they are going to use it. socializing the concepts vetted Continually socializing the concepts – Rolling vetted concepts into the engineering process improves performance by reducing false starts. Periodic “Status Demos” Periodic “Status Demos” - are excellent for managing expectations. “Linked Data” - “Linked Data” (Semantic Technology) - is extremely powerful. Comparing “Apples to Oranges” can mitigate risk. Identifying non- obvious relationships can more easily uncover the real threats faster.

9 8 Conclusion The deployed Cyber Information System prototype is intended to support the following sectors: commercial, industrial, institutional and defense. The Cyber Information System enhancements and refinements are continuing. For example, near real-time mission capabilities are currently being added.

10 Questions 9

11 Contact Information 10 David M. Petrovich Principal Investigator & Integrated Product Team Lead Cyber Situational Awareness - Cyber Defense, Research & Development. Phone (727) 252-9231 David_M_Petrovich@raytheon.com


Download ppt "Integrating information towards Digital ATM Cyber Situational Awareness Presented By: David M. Petrovich Date:August 28, 2013."

Similar presentations


Ads by Google