Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

DOE's Federated Model aims to identify security threats

Argonne National Laboratory, a division of the Department of Energy (DOE) operated out of the University of Chicago, is spearheading an effort to collect information about cyber security events that is beginning to gain steam.

Called The Federated Model, this information-sharing initiative among government, universities, and research labs began last September and currently has about half a dozen active members, says Scott Pinkerton, manager of network services for the lab in DuPage County, Ill.

The initiative is open to any organization wanting to share details, or even just view information, regarding attempts by different IP addresses to access networks and how organizations have responded to these attempts, in an effort to spot patterns of malicious behavior and proactively block security threats, says Pinkerton.

For example, if one member of the Federated Model suffers an attack from a certain IP address, another member may be able to block that IP address from accessing its network and thwart a second attack, he says.

"We're reinforcing the idea that we could be smarter, and more prepared," Pinkerton says. While the number of members is growing, Pinkerton says The Federated Model hasn't yet hit critical mass.

Pinkerton discussed The Federated Model's progress at Network World's IT Roadmap conference held in Chicago late last month during a session on security. He stressed the importance of monitoring NetFlow data to search for zero-day attack traffic patterns, a practice his department engages in. NetFlow is a Cisco technology for storing traffic flow histories on routers and switches.

Argonne has taken on the development of The Federated Model's repository and laid out specifications to be used for submitting and accessing information. Following IETF standards, data is submitted in XML format that is encrypted. The lab is working on adding features, such as an RSS feed that would tell members when new information has been added to the repository, Pinkerton says.

What's valuable about this data is not only learning what IP addresses are doing, but what organizations are doing in response to potential threats, says Tami Martin, intrusion detection systems engineer with Argonne. "You're learning the reactive measures other sites are taking," she says. "Also of intrinsic value is [learning] the severity of the action taken."

Eventually, members could get to the point where they can completely thwart an attack by following the actions of a trusted member, says Pinkerton.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Cisco, HIS Limited, IETF, Pinkerton

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • HTML5 and security on the new web
    There are lots of changes happening to the key technologies that power the web. The new version of HTML, the dominant web language, offers impressive enhancements for rich web applications. But as HTML5 comes into greater use we’ll see new security issues arise. It’s typical for a new technology to have defects and pitfalls. And although the standard is still being defined, it's already being implemented. So how does HTML5 stand up to security scrutiny?
    Learn more »
  • 10 Essential Steps to Email Security
    Modern business is reliant on email. All organisations using email need to answer the following questions: How do we control spam volumes without the risk of trapping a business email? How do we prevent infections from email-borne viruses? How do we stop leakage of confidential information? Can we detect and stop exploitation from phishing attacks? How do we control brand damage from occurring due to employee misuse? How do we prevent inappropriate content from being circulated?
    Learn more »
  • The State of Data Security
    Recognize how your data can become vulnerable, including the latest issues stemming from unprotected data on mobile devices and social media sites. Understand the compliance issues involved, and identify data protection strategies you can use to keep your company’s information both safe and compliant.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments