Cyber attacks presents a formidable threat to critical components of the national infrastructure. Modern industrial, military and government systems are run by dedicated computer networks. The end user accesses such a system not directly but through a special computer interface by defining required operational regimes, or data to be retrieved, or information to be recorded, or data to be transmitted, etc. Then it is up to the computer to provide the necessary set point values to process controllers, to sample sensors, to perform search, retrieval of the requested data, to operate printers or computer graphics, to locate available communication channels, code and transmit data, etc. Examples go far beyond power plants and rocket launchers. Banking industry, insurance, libraries, data depositories, hospitals utilize their own dedicated computer facilities operating in this fashion. “Dedicated” is the key word – it emphasizes that these computer facilities run only a few preapproved applications and are closed to general public. (In contrast, a university campus computer is open to general public and runs virtually any application.) Attacking dedicated computers offers a highly efficient way to render useless the processes they service and compromise stored information.

We will discuss a cyber security technology that is based on behavioral normalcy profiling and operates on the level of functionalities thus providing unambiguous representation of the goals of the particular applications. The approach reliably detects malware and non-malicious applications that are not approved for a particular computer system.  A fully operational system prototype enhanced by advanced visualization will be demonstrated. Several important applications of the approach will be discussed.


