Enhanced cyberspace defense with real-time distributed systems using covert channel publish-subscribe broker pattern communications

In this thesis, we propose a novel cyberspace defense solution to the growing sophistication of threats facing networks within the Department of Defense. Current network defense strategies, including traditional intrusion detection and firewall-based perimeter defenses, are ineffective against in...

Full description

Bibliographic Details
Main Author: Paxton, Steven G. B.
Other Authors: Michael, James B.
Published: Monterey California. Naval Postgraduate School 2012
Online Access:http://hdl.handle.net/10945/4049
id ndltd-nps.edu-oai-calhoun.nps.edu-10945-4049
record_format oai_dc
spelling ndltd-nps.edu-oai-calhoun.nps.edu-10945-40492014-11-27T16:05:03Z Enhanced cyberspace defense with real-time distributed systems using covert channel publish-subscribe broker pattern communications Paxton, Steven G. B. Michael, James B. Dinolt, George W. Naval Postgraduate School (U.S.) In this thesis, we propose a novel cyberspace defense solution to the growing sophistication of threats facing networks within the Department of Defense. Current network defense strategies, including traditional intrusion detection and firewall-based perimeter defenses, are ineffective against increasingly sophisticated social engineering attacks such as spear-phishing which exploit individuals with targeted information. These asymmetric attacks are able to bypass current network defense technologies allowing adversaries extended and often unrestricted access to portions of the enterprise. Network defense strategies are hampered by solutions favoring network-centric designs which disregard the security requirements of the specific data and information on the networks. Our solution leverages specific technology characteristics from traditional network defense systems and real-time distributed systems using publish-subscribe broker patterns to form the foundation of a full-spectrum cyber operations capability. Building on this foundation, we present the addition of covert channel communications within the distributed systems framework to protect sensitive Command and Control and Battle Management messaging from adversary intercept and exploitation. Through this combined approach, DoD and Service network defense professionals will be able to meet sophisticated cyberspace threats head-on while simultaneously protecting the data and information critical to warfighting Commands, Services and Agencies. 2012-03-14T17:40:12Z 2012-03-14T17:40:12Z 2008-06 Thesis http://hdl.handle.net/10945/4049 244584376 Approved for public release, distribution unlimited Monterey California. Naval Postgraduate School
collection NDLTD
sources NDLTD
description In this thesis, we propose a novel cyberspace defense solution to the growing sophistication of threats facing networks within the Department of Defense. Current network defense strategies, including traditional intrusion detection and firewall-based perimeter defenses, are ineffective against increasingly sophisticated social engineering attacks such as spear-phishing which exploit individuals with targeted information. These asymmetric attacks are able to bypass current network defense technologies allowing adversaries extended and often unrestricted access to portions of the enterprise. Network defense strategies are hampered by solutions favoring network-centric designs which disregard the security requirements of the specific data and information on the networks. Our solution leverages specific technology characteristics from traditional network defense systems and real-time distributed systems using publish-subscribe broker patterns to form the foundation of a full-spectrum cyber operations capability. Building on this foundation, we present the addition of covert channel communications within the distributed systems framework to protect sensitive Command and Control and Battle Management messaging from adversary intercept and exploitation. Through this combined approach, DoD and Service network defense professionals will be able to meet sophisticated cyberspace threats head-on while simultaneously protecting the data and information critical to warfighting Commands, Services and Agencies.
author2 Michael, James B.
author_facet Michael, James B.
Paxton, Steven G. B.
author Paxton, Steven G. B.
spellingShingle Paxton, Steven G. B.
Enhanced cyberspace defense with real-time distributed systems using covert channel publish-subscribe broker pattern communications
author_sort Paxton, Steven G. B.
title Enhanced cyberspace defense with real-time distributed systems using covert channel publish-subscribe broker pattern communications
title_short Enhanced cyberspace defense with real-time distributed systems using covert channel publish-subscribe broker pattern communications
title_full Enhanced cyberspace defense with real-time distributed systems using covert channel publish-subscribe broker pattern communications
title_fullStr Enhanced cyberspace defense with real-time distributed systems using covert channel publish-subscribe broker pattern communications
title_full_unstemmed Enhanced cyberspace defense with real-time distributed systems using covert channel publish-subscribe broker pattern communications
title_sort enhanced cyberspace defense with real-time distributed systems using covert channel publish-subscribe broker pattern communications
publisher Monterey California. Naval Postgraduate School
publishDate 2012
url http://hdl.handle.net/10945/4049
work_keys_str_mv AT paxtonstevengb enhancedcyberspacedefensewithrealtimedistributedsystemsusingcovertchannelpublishsubscribebrokerpatterncommunications
_version_ 1716720921228607488