Strengthen, Prepare, Detect, React to Mitigate the Insider Threat (DARPA)


The Strengthen, Prepare, Detect, React (SPDR) project is part of Phase II of DARPA's Self Regenerative Systems (SRS) program. The objective of the SPDR project is to develop a system for detecting, thwarting, and attributing attacks by malicious insiders, and to do this in a manner that enables individuals (even the malicious insiders) to still accomplish their authorized tasks. The expected benefit is increased security without loss of performance in both enterprise and tactical systems. The research addresses the challenges of mitigating the insider's access advantage by strategically placing sensors to minimize noise while detecting a broad set of attacks, even attacks based on the user's authorized accesses to the system. To accomplish this Adventium is integrating results from the SCOAP project with plan recognition technology and is also developing an innovative Detection and Response Embedded Device (DRED™) that insiders cannot disable or bypass from their host systems.