CERT

 
Publications CatalogHistorical Documents
 


Our research in cyber security engineering involves analyzing how susceptible systems are to sophisticated attacks and proposing better designs for such systems. We also develop techniques that enable us to predict future threats to the internet. The results of our research contribute to our work with network situational awareness. As part of this "operational" component, we are developing tools and techniques that will improve the ability for network administrators to identify what is happening on their networks. These tools and techniques include engineering solutions and research approaches for analyzing broad network activity. The goal is to quantitatively characterize threats and targeted intruder activity.

Cyber Security Engineering

The field of cyber security engineering explores the current state of systems to identify problems and propose engineering solutions.

Popular Destinations

Overview
Includes a list of areas of work.

CERT Research Report
Describes current CERT research projects: problems addressed, research approaches, expected benefits, accomplishments, and plans


Research Projects

SQUARE
Security Quality Requirements Engineering (SQUARE) is a nine-step process to help organizations build security into the early stages of the production life cycle.

Software Assurance Curriculum
Substantial effort by curriculum development and subject matter experts has resulted in a comprehensive body of foundational knowledge and a course structure for software assurance education at the graduate level.

Network Situational Awareness (NetSA)

The Network Situational Awareness group develops engineering solutions and research approaches for analyzing broad network activity. The goal is to quantitatively characterize threats and targeted intruder activity.

Publications and presentations

Finding Peer-to-Peer File-sharing Using Coarse Network Behaviors - Collins and Reiter (pdf)
A Model for Opportunistic Network Exploits: The Case of P2P Worms - Collins, Gates, and Kataria (pdf)

Tools & Components

offsite SiLK
A collection of netflow tools developed by the NetSA Team to facilitate security analysis in large networks.
offsite AirCERT
Automated Incident Reporting (AirCERT) is a scalable distributed system for sharing security event data among administrative domains.