NASA Logo

NTRS

NTRS - NASA Technical Reports Server

Back to Results
Security Data Warehouse ApplicationThe Security Data Warehouse (SDW) is used to aggregate and correlate all JSC IT security data. This includes IT asset inventory such as operating systems and patch levels, users, user logins, remote access dial-in and VPN, and vulnerability tracking and reporting. The correlation of this data allows for an integrated understanding of current security issues and systems by providing this data in a format that associates it to an individual host. The cornerstone of the SDW is its unique host-mapping algorithm that has undergone extensive field tests, and provides a high degree of accuracy. The algorithm comprises two parts. The first part employs fuzzy logic to derive a best-guess host assignment using incomplete sensor data. The second part is logic to identify and correct errors in the database, based on subsequent, more complete data. Host records are automatically split or merged, as appropriate. The process had to be refined and thoroughly tested before the SDW deployment was feasible. Complexity was increased by adding the dimension of time. The SDW correlates all data with its relationship to time. This lends support to forensic investigations, audits, and overall situational awareness. Another important feature of the SDW architecture is that all of the underlying complexities of the data model and host-mapping algorithm are encapsulated in an easy-to-use and understandable Perl language Application Programming Interface (API). This allows the SDW to be quickly augmented with additional sensors using minimal coding and testing. It also supports rapid generation of ad hoc reports and integration with other information systems.
Document ID
20120010434
Acquisition Source
Johnson Space Center
Document Type
Other - NASA Tech Brief
Authors
Vernon, Lynn R.
(NASA Johnson Space Center Houston, TX, United States)
Hennan, Robert
(NASA Johnson Space Center Houston, TX, United States)
Ortiz, Chris
(NASA Johnson Space Center Houston, TX, United States)
Gonzalez, Steve
(NASA Johnson Space Center Houston, TX, United States)
Roane, John
(MEI Technologies, Inc. Houston, TX, United States)
Date Acquired
August 26, 2013
Publication Date
June 1, 2012
Publication Information
Publication: NASA Tech Briefs, June 2012
Subject Category
Man/System Technology And Life Support
Report/Patent Number
MSC-24148-1
Distribution Limits
Public
Copyright
Public Use Permitted.
No Preview Available