SLIDE 4 4
Cyber Situational Awareness
Multiple Processes λ1 = router failure λ2 = worm λ3 = scan Events …….
Time
An Environment
consists of that produce
Unlabelled Sensor Reports …….
Time
that are seen as
Track 1 Track 2 Track 3
Hypothesis 1
Track 1 Track 2 Track 3
Hypothesis 2
that PQS resolves into that detect complex attacks and anticipate the next steps
129.170.46.3 is at high risk 129.170.46.33 is a stepping stone ......
that are used for control
1 2 3 4 5 6 Indicators and Warnings
Real World Process Detection (PQS)
Hypotheses Track Scores Sample Console
0.2 0.4 0.6 0.8 1 100 200 Track Score Service Degradation
FORWARD PROBLEM INVERSE PROBLEM