CERT
 
Publications CatalogHistorical Documents Research Staff Biographies CMU Heinz College CMU School of Computer Science US-CERT CyLab
 

Network Situational Awareness (NetSA)

The CERT Network Situational Awareness group develops engineering solutions and research approaches for analyzing broad network activity. The goal is to quantitatively characterize threats and targeted intruder activity.

Publications

2008

2007

2006

2005

2004

2003

Conferences

FloCon
FloCon is an annual workshop providing a forum for researchers, operational analysts, and other parties in the DoD, DoE, federal civilian community, international response teams, and academia to discuss the analysis of flow from the perspective of security. For more information, visit the FloCon page.

Presentations at Conferences

Open Source Tools

Source code for the following tools is released under the GPL and LGPL licenses.

  • SiLK (System for Internet Level Knowledge)
    a collection of netflow tools that facilitates security analysis in large networks; enables analysts to rapidly query large sets of data traffic volumes

  • YAF (YAF Flow Sensor)
    a tool that processes packet data into bidirectional flow records that can be used as input to an IPFIX Collecting Process; the output can be used with the NetSA Aggregated Flow (NAF) toolchain and the SiLK tools

  • NAF (NetSA Aggregated Flow)
    tools that create and manipulate the IPFIX-based NAF file format, designed as a common format for aggregate network flow analysis

  • fixbuf
    a library that provides a set of functions for processing the IPFIX protocol message format; using fixbuf, developers can build IPFIX Collecting and Exporting Processes

  • RAVE (Retrospective Analysis and Visualization Engine)
    an extensible analysis middleware platform based on Python that simplifies the task of building analysis environments on top of a network monitoring and collection infrastructure

  • IPA
    a library that provides efficient data structures for manipulating labelings of IP addresses and IP address ranges

Current Projects

  • Port and Payload Agnostic Application Identification
    To properly understand the threats that a network faces, network administrators must access current, accurate information about the composition of their networks. However, the considerable expense of continuous traffic monitoring and deep packet examination raises the need for a method that can identify applications without relying on payload.

  • RAVE: Network Flow Visualization
    Fully automated analysis is a valuable tool for network situational awareness, but few techniques can discern subtle patterns in noisy data as well as human visual inspection. The CERT Network Situational Awareness Group has developed the Retrospective Analysis and Visualization Environment (RAVE), an operational environment for generating visualizations and making them available to presentation applications.

  • The Uncleanliness Vector: Histories of Hostile Activity
    In an operational network security analysis environment, there is little time for gathering context information on attackers. Analysts need tools that present background information in an easily digestible way. The Uncleanliness Vector (UV) project is an attempt to provide context information on external networks to security analysts that indicates whether the network in question has engaged in other malicious activity and, if so, what kind.


Last updated September 02, 2009