Flexible Transform U.S. DEPARTMENT OF ENERGY Semantic Translation for Cyber Threat Indicators.

Slides:



Advertisements
Similar presentations
Websydian Anne-Marie Arnvig Manager, Websydian Communications & Relations.
Advertisements

XML-based Network Management Rob Enns
Portable Data and Modeling for Electromagnetic Transient Analysis programs Jean Mahseredjian Ecole Polytechnique de Montreal 1.
The Online Library Environment Projects and Challenges at The University of Alabama Libraries Jason J. Battles Head, Web Services Department.
DataFoundry: An Approach to Scientific Data Integration Terence Critchlow Ron Musick Ida Lozares Center for Applied Scientific Computing Tom SlezakKrzystof.
Web Mapping Using XML and SVG SHEA Yu-kai Geoffrey Senior Lecturer Department of Land Surveying & Geo-Informatics The Hong Kong Polytechnic University.
Infomaster: An information Integration Tool O. M. Duschka and M. R. Genesereth Presentation by Cui Tao.
Nov Copyright Galdos Systems Inc. November 2001 Impact of GML on Data Development.
An Integrated Solution for Web-based Mathematical Expression Inputting Wei Su Department of Computer Science, Lanzhou University, PRC Department of Computer.
The information integration wizard (Iwiz) project Report on work in progress Joachim Hammer Presented by Muhammed Al-Muhammed.
Client-Server Processing and Distributed Databases
Technical Track Session XML Techie Tools Tim Bornholt.
Enterprise Workflow CPSC 476 Lightening Talk Brenda Griffith/Katie Soto.
XP New Perspectives on Microsoft Access 2002 Tutorial 71 Microsoft Access 2002 Tutorial 7 – Integrating Access With the Web and With Other Programs.
Presented by Brian Griffin On behalf of Manu Goel Mohit Goel Nov 12 th, 2014 Building a dynamic GUI, configurable at runtime by backend tool.
Copyright , Synchrony Systems, Inc. Enterprise Application Modernizations Slavik Zorin Phone: (415)
Aurora: A Conceptual Model for Web-content Adaptation to Support the Universal Accessibility of Web-based Services Anita W. Huang, Neel Sundaresan Presented.
Adapting Legacy Computational Software for XMSF 1 © 2003 White & Pullen, GMU03F-SIW-112 Adapting Legacy Computational Software for XMSF Elizabeth L. White.
JDF in the Inter-Enterprise Workflow Achieving JDF workflow automation.
 Copyright 2005 Digital Enterprise Research Institute. All rights reserved. Towards Translating between XML and WSML based on mappings between.
Pervasive e-commerce with XML Babak Esfandiari Carleton University Ottawa, Canada.
How to connect non IP devices into the UPnP™v1 fabric Vijay Dhingra Director of Standards Echelon Corp.
December 15, 2011 Use of Semantic Adapter in caCIS Architecture.
Publishing and Visualizing Large-Scale Semantically-enabled Earth Science Resources on the Web Benno Lee 1 Sumit Purohit 2
Esri UC 2015 | Technical Workshop | Land Records Maps and Apps for State and Local Governments Chris Buscaglia Scott Oppmann.
Peer-to-Peer Data Integration Using Distributed Bridges Neal Arthorne B. Eng. Computer Systems (2002) Supervisor: Babak Esfandiari April 12, 2005 Candidate.
GCMD/IDN STATUS AND PLANS Stephen Wharton CWIC Meeting February19, 2015.
Personalizing the web for multilingual web sources Anil Goud V Lalith Krishna L Dinesh Kumar D.R.
The INTERNET how it works. the internet: defined So, what is it?
SWETO: Large-Scale Semantic Web Test-bed Ontology In Action Workshop (Banff Alberta, Canada June 21 st 2004) Boanerges Aleman-MezaBoanerges Aleman-Meza,
1 Use of XML in LDR's Integrated Tax System Louisiana Department of Revenue Technology Conference San Antonio, TX August , 2000.
Scalable Metadata Definition Frameworks Raymond Plante NCSA/NVO Toward an International Virtual Observatory How do we encourage a smooth evolution of metadata.
Metadata and Geographical Information Systems Adrian Moss KINDS project, Manchester Metropolitan University, UK
Ontologies and Lexical Semantic Networks, Their Editing and Browsing Pavel Smrž and Martin Povolný Faculty of Informatics,
10/18/20151 Business Process Management and Semantic Technologies B. Ramamurthy.
1 Global Address Verification Overview Bud Walker, Admound Chou.
Using a LDAP Directory Server for Environmental Data Discovery Donald Denbo NOAA-PMEL/UW-JISAO Presented by Eugene Burger NOAA-PMEL/UW-JISAO
Automatic Report Generation for WLCG/EGEE D. D. Sonvane (Gridview Team) B.A.R.C.
From Objects to Assets: The Fungibility of Knowledge Christopher W. Higgins, Esq.
Problems/Disc. Adoption of standards Should there be standards? (not a big problem – responsibility lies with data centre – onus not on scientist) (peer.
A Context Model based on Ontological Languages: a Proposal for Information Visualization School of Informatics Castilla-La Mancha University Ramón Hervás.
Informed decisions for Selection Support in Libraries 20th Pan-helenic Conference of Academic Libraries Thessaloniki, 14/11/2011 Núria Sauri Electronic.
Grid Computing & Semantic Web. Grid Computing Proposed with the idea of electric power grid; Aims at integrating large-scale (global scale) computing.
Efficient RDF Storage and Retrieval in Jena2 Written by: Kevin Wilkinson, Craig Sayers, Harumi Kuno, Dave Reynolds Presented by: Umer Fareed 파리드.
Scaling Heterogeneous Databases and Design of DISCO Anthony Tomasic Louiqa Raschid Patrick Valduriez Presented by: Nazia Khatir Texas A&M University.
Building a Topic Map Repository Xia Lin Drexel University Philadelphia, PA Jian Qin Syracuse University Syracuse, NY * Presented at Knowledge Technologies.
March 2004 At A Glance NASA’s GSFC GMSEC architecture provides a scalable, extensible ground and flight system approach for future missions. Benefits Simplifies.
The Semistructured-Data Model Programming Languages for XML Spring 2011 Instructor: Hassan Khosravi.
Celluloid An interactive media sequencing language.
User Profiling using Semantic Web Group members: Ashwin Somaiah Asha Stephen Charlie Sudharshan Reddy.
Issues in Ontology-based Information integration By Zhan Cui, Dean Jones and Paul O’Brien.
August 2003 At A Glance The IRC is a platform independent, extensible, and adaptive framework that provides robust, interactive, and distributed control.
Universal fuzzy system representation with XML Authors : Chris Tseng, Wafa Khamisy, Toan Vu Source : Computer Standards & Interfaces, Volume 28, Issue.
©Silberschatz, Korth and Sudarshan10.1Database System Concepts W3C - The World Wide Web Consortium W3C - The World Wide Web Consortium.
1 Open Ontology Repository initiative - Planning Meeting - Thu Co-conveners: PeterYim, LeoObrst & MikeDean ref.:
DANIELA KOLAROVA INSTITUTE OF INFORMATION TECHNOLOGIES, BAS Multimedia Semantics and the Semantic Web.
The Semantic Web. What is the Semantic Web? The Semantic Web is an extension of the current Web in which information is given well-defined meaning, enabling.
A Portrait of the Semantic Web in Action Jeff Heflin and James Hendler IEEE Intelligent Systems December 6, 2010 Hyewon Lim.
Prizms for Data Publication and Management Katie Chastain May 9, 2014.
Copyright 2007, Information Builders. Slide 1 iWay Web Services and WebFOCUS Consumption Michael Florkowski Information Builders.
Semantic Web unleashes your data! The Semantic Web will transform the use of content. Semantic Web – is an extension of the current web. Semantic Web.
CHAPTER NINE Accessing Data Using XML. McGraw Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved Introduction The eXtensible.
Esri UC 2014 | Technical Workshop | Address Maps and Apps for State and Local Government Allison Muise Nikki Golding Scott Oppmann.
A Semi-Automated Digital Preservation System based on Semantic Web Services Jane Hunter Sharmin Choudhury DSTC PTY LTD, Brisbane, Australia Slides by Ananta.
Lawrence Livermore National Laboratory
Web Ontology Language for Service (OWL-S)
RichAnnotator: Annotating rich (XML-like) documents
Presents: Rally To Java Conversion Suite
Business Process Management and Semantic Technologies
1999 ACM SIGMOD: Data Management Issues in Electronic Commerce
Presentation transcript:

Flexible Transform U.S. DEPARTMENT OF ENERGY Semantic Translation for Cyber Threat Indicators

Who We Are June 2014 FIRST Annual Conference Andrew Hoying National Renewable Energy Laboratory Chris Strasburg Ames National Laboratory Dan Harkness Argonne National Laboratory Scott Pinkerton Argonne National Laboratory

Agenda  Motivation  Background  Flexible Transform (FT) Approach  Extended Example  Conclusions June 2014 FIRST Annual Conference

Motivation Why transformation? It is needed to:  Facilitate migration to a common language (STIX) … without having to wait on entire customer base to adopt the language natively  Adapt data to multiple tool chains dynamically within a single site Why must it be flexible?  Point–point translation is not scalable, O(n 2 )  A semantic representation minimizes data loss  Deals with inherent ambiguities in legacy data –Shared Internet Protocol (IP) address – source or target (or resource or pivot point or …)? June 2014 FIRST Annual Conference

Motivating Example June 2014 FIRST Annual Conference

Translation Scalability June 2014 FIRST Annual Conference O(N 2 ) New Syntax / Schema / Semantics CSV = comma-separated value; XML = extensible markup language.

Background  Sharing data is hard when everyone does not speak a common language  Methods exist for parsing data from systems you do not control –Dynamic or static mapping of field names and types –Post-ingestion data recognition –Predefined parsers We want a richer ontology so that data are not lost in translation. June 2014 FIRST Annual Conference

U.S. Department of Energy Cyber Fed Model (CFM) – GUWYG Background  [2004–2010] – Single Input Format Supported  [2010–2013] – Give Us What You’ve Got (GUWYG) v1  [2013–Present] – GUWYG v2 –Added XML and Key/Value formats for input –CFM supports multiple input/output formats and functions as a bridge between Enhanced Shared Situational Awareness (ESSA) initiative and thousands of Energy Sector utilities June 2014 FIRST Annual Conference

Ontology June 2014 FIRST Annual Conference

Ontology June 2014 FIRST Annual Conference

Flexible Transform Approach June 2014 FIRST Annual Conference

Approach/Design – Process Detail June 2014 FIRST Annual Conference

Approach/Design – Process Detail (cont.) June 2014 FIRST Annual Conference

Approach/Design – Process Detail (cont.) June 2014 FIRST Annual Conference

Approach/Design – Process Detail (cont.) June 2014 FIRST Annual Conference

Approach/Design – Process Detail (cont.) June 2014 FIRST Annual Conference

Approach/Design – Process Detail (cont.) June 2014 FIRST Annual Conference

Approach/Design – Process Detail (cont.) June 2014 FIRST Annual Conference

Flexible Transform Scalability June 2014 FIRST Annual Conference O(N)

Approach/Design – Semantic Structure June 2014 FIRST Annual Conference

Extended Example – Perfect Semantic Match June 2014 FIRST Annual Conference

Extended Example – Generalization Mismatch June 2014 FIRST Annual Conference

Extended Example – Specialization Mismatch June 2014 FIRST Annual Conference

Extended Example – Missing Data 1 June 2014 FIRST Annual Conference

Extended Example – Missing Data 2 June 2014 FIRST Annual Conference

Conclusions/Limitations  Using flexible transform, we act as an automated translator, enabling communities to share data regardless of the native tools/languages  FT carries a performance impact – additional processing ‘on-the-fly’  Current definition of new syntaxes, schemas is manual – we are working on an RDF language to automate this function  It requires fully structured data – we are examining the feasibility of parsing semi- structured data  Reduces, but does not eliminate, the problems of sharing ambiguous data June 2014 FIRST Annual Conference

Preparing for Tomorrow’s Cyber Threat  Cyber threats are global – sharing is key: –Are you ready to consume? –Are you ready to produce?  Examine your data / workflow: –Let us know what schemas/ languages are in use –Provide/ask for schema specifications when needed  Add structure to your data! June 2014 FIRST Annual Conference

Future Needs  A cross platform, or web-based, graphical user interface (GUI) for building indicators, other data types, and relationships using known semantic values –Visualize large data sets –List known semantics; provide user with a list of target formats –Built-in definitions of field types help analysts choose the appropriate field for the indicator or relationship  Syntax parser and dynamic schema for semi- structured data June 2014 FIRST Annual Conference

Questions?  Questions Now? –Ask away!  Questions Later? –federated- June 2014 FIRST Annual Conference