Publications

Refine Results

(Filters Applied) Clear All

An interactive attack graph cascade and reachability display

Published in:
VizSEC 2007, Proc. of the Workshop on Visualization for Computer Security, 29 October 2007, pp. 221-236.

Summary

Attack graphs for large enterprise networks improve security by revealing critical paths used by adversaries to capture network assets. Even with simplification, current attack graph displays are complex and difficult to relate to the underlying physical networks. We have developed a new interactive tool intended to provide a simplified and more intuitive understanding of key weaknesses discovered by attack graph analysis. Separate treemaps are used to display host groups in each subnet and hosts within each treemap are grouped based on reachability, attacker privilege level, and prerequisites. Users position subnets themselves to reflect their own intuitive grasp of network topology. Users can also single-step the attack graph to successively add edges that cascade to show how attackers progress through a network and learn what vulnerabilities or trust relationships allow critical steps. Finally, an integrated reachability display demonstrates how filtering devices affect host-to-host network reachability and influence attacker actions. This display scales to networks with thousands of hosts and many subnets. Rapid interactivity has been achieved because of an efficient C++ computation engine (a program named NetSPA) that performs attack graph and reachability computations, while a Java application manages the display and user interface.
READ LESS

Summary

Attack graphs for large enterprise networks improve security by revealing critical paths used by adversaries to capture network assets. Even with simplification, current attack graph displays are complex and difficult to relate to the underlying physical networks. We have developed a new interactive tool intended to provide a simplified and...

READ MORE

Tuning intrusion detection to work with a two encryption key version of IPsec

Published in:
IEEE MILCOM 2007, 29-31 October 2007, pp. 3977-3983.

Summary

Network-based intrusion detection systems (NIDSs) are one component of a comprehensive network security solution. The use of IPsec, which encrypts network traffic, renders network intrusion detection virtually useless unless traffic is decrypted at network gateways. Host-based intrusion detection systems (HIDSs) can provide some of the functionality of NIDSs but with limitations. HIDSs cannot perform a network-wide analysis and can be subverted if a host is compromised. We propose an approach to intrusion detection that combines HIDS, NIDS, and a version of IPsec that encrypts the header and the body of IP packets separately ("Two-Zone IPsec"). We show that all of the network events currently detectable by the Snort NIDS on unencrypted network traffic are also detectable on encrypted network traffic using this approach. The NIDS detects network-level events that HIDSs have trouble detecting and HIDSs detect application-level events that can't be detected by the NIDS.
READ LESS

Summary

Network-based intrusion detection systems (NIDSs) are one component of a comprehensive network security solution. The use of IPsec, which encrypts network traffic, renders network intrusion detection virtually useless unless traffic is decrypted at network gateways. Host-based intrusion detection systems (HIDSs) can provide some of the functionality of NIDSs but with...

READ MORE

Sinewave analysis/synthesis based on the fan-chirp transform

Published in:
Proc. IEEE Workshop on Applications of Signal Processing to Audio and Acoustics, WASPA, 21-24 October 2007, pp. 247-250.

Summary

There have been numerous recent strides at making sinewave analysis consistent with time-varying sinewave models. This is particularly important in high-frequency speech regions where harmonic frequency modulation (FM) can be significant. One notable approach is through the Fan Chirp transform that provides a set of FM-sinewave basis functions consistent with harmonic FM. In this paper, we develop a complete sinewave analysis/synthesis system using the Fan Chirp transform. With this system we are able to obtain more accurate sinewave frequencies and phases, thus creating more accurate frequency tracks, in contrast to a system derived from the short-time Fourier transform, particularly for high-frequency regions of large-bandwidth analysis. With synthesis, we show an improvement in segmental signal-to-noise ratio with respect to waveform matching with the largest gains during rapid pitch dynamics.
READ LESS

Summary

There have been numerous recent strides at making sinewave analysis consistent with time-varying sinewave models. This is particularly important in high-frequency speech regions where harmonic frequency modulation (FM) can be significant. One notable approach is through the Fan Chirp transform that provides a set of FM-sinewave basis functions consistent with...

READ MORE

The MIT-LL/AFRL IWSLT-2007 MT System

Published in:
Int. Workshop on Spoken Language Translation, IWSLT, 15-16 October 2007.

Summary

The MIT-LL/AFRL MT system implements a standard phrase-based, statistical translation model. It incorporates a number of extensions that improve performance for speech-based translation. During this evaluation our efforts focused on the rapid porting of our SMT system to a new language (Arabic) and novel approaches to translation from speech input. This paper discusses the architecture of the MIT-LL/AFRL MT system, improvements over our 2007 system, and experiments we ran during the IWSLT-2007 evaluation. Specifically, we focus on 1) experiments comparing the performance of confusion network decoding and direct lattice decoding techniques for speech machine translation, 2) the application of lightweight morphology for Arabic MT pre-processing and 3) improved confusion network decoding.
READ LESS

Summary

The MIT-LL/AFRL MT system implements a standard phrase-based, statistical translation model. It incorporates a number of extensions that improve performance for speech-based translation. During this evaluation our efforts focused on the rapid porting of our SMT system to a new language (Arabic) and novel approaches to translation from speech input...

READ MORE

Design of an optical photon counting array receiver system for deep-space communications

Summary

Demand for increased capacity in deep-space to Earth communications systems continues to rise as sensor data rates climb and mission requirements expand. Optical freespace laser communications systems offer the potential for operating at data rates 10 to 1000 times that of current radiofrequency systems. A key element in an optical communications system is the Earth receiver. This paper reviews the design of a distributed photon-counting receiver array composed of four meter-class telescopes, developed as a part of the Mars Laser Communications Demonstration (MLCD) project. This design offers a cost-effective and adaptable alternative approach to traditional large, single-aperture receive elements while preserving the expected improvement in data rates enabled by free-space laser communications systems. Key challenges in developing distributed receivers and details of the MLCD design are discussed.
READ LESS

Summary

Demand for increased capacity in deep-space to Earth communications systems continues to rise as sensor data rates climb and mission requirements expand. Optical freespace laser communications systems offer the potential for operating at data rates 10 to 1000 times that of current radiofrequency systems. A key element in an optical...

READ MORE

Scaling three-dimensional SOI integrated-circuit technology

Published in:
2007 IEEE Int. SOI Conf. Proc., 1-4 October 2007, pp. 87-88.

Summary

Introduction At Lincoln Laboratory, we have established a three dimensional (3D) integrated circuit (IC) technology that has been developed and demonstrated over seven designs, bonding two or three active circuit layers or tiers to form monolithically integrated 3D circuits. Key features of our 3DIC technology include fully depleted SOI (FDSOI) circuit fabrication, low-temperature wafer-scale oxide-to-oxide bonding, precision wafer-to-wafer alignment, and dense unrestricted 3D vias interconnecting stacked circuit layers, successfully demonstrated in a large area 8 x 8 mm2 high-3D-via-count 1024 x 1024 visible imager. In this paper, we describe details of our bonding protocol for 150-mm diameter wafers, leading to a 50% increase in oxide-oxide bond strength and demonstration of +--0.5 am wafer-to-wafer alignment accuracy. We have established design rules for our 3DIC technology, have quantified process factors limiting our design-rule 3D via pitch, and have demonstrated next generation 3D vias with a 2x size reduction, stacked 3D vias, a backmetal interconnect process to reduce 2D circuit exclusion zones, and buried oxide (BOX) vias to allow both electrical and thermal substrate connections. All of these improvements will allow us to continue to reduce minimum 3D via pitch and reduce 2D layout limitations, making our 3DIC technology more attractive to a broader range of applications.
READ LESS

Summary

Introduction At Lincoln Laboratory, we have established a three dimensional (3D) integrated circuit (IC) technology that has been developed and demonstrated over seven designs, bonding two or three active circuit layers or tiers to form monolithically integrated 3D circuits. Key features of our 3DIC technology include fully depleted SOI (FDSOI)...

READ MORE

An approach to verify a model for translating convective weather information to air traffic management impact

Published in:
7th AIAA Aviation Technology, Integration, and Operations (ATIO) Conf., 18-20 September 2007.

Summary

This paper describes a method to determine the accuracy of the Convective Weather Avoidance Model which predicts the likelihood that pilots will deviate away from specific areas of convective activity. Visual inspection with a reduced data set helped refine the algorithms used in the verification and offered some preliminary results of the model's accuracy in today's airspace. This model has some explanatory power in predicting regions of airspace where pilots are willing to deviate or fly through. In some instances, pilots appeared not to make an early decision to deviate around convective weather and continued on course as the region appeared more passable when they reached it. In other instances, pilots skirted the edges of regions where the model expected pilots avoid. This behavior suggests edge areas of those model regions were more passable and the convection in that region was not uniform in intensity.
READ LESS

Summary

This paper describes a method to determine the accuracy of the Convective Weather Avoidance Model which predicts the likelihood that pilots will deviate away from specific areas of convective activity. Visual inspection with a reduced data set helped refine the algorithms used in the verification and offered some preliminary results...

READ MORE

Model estimates of traffic reduction in storm impacted en route airspace

Author:
Published in:
7th AIAA Aviation Technology, Integration, and Operations (ATIO) Conf., 18-20 September 2007.

Summary

An understanding of convective weather impacts on en route airspace capacity is a first step toward development of predictive tools to support both tactical and strategic routing decisions in storm-impacted airspace. This study presents a model for traffic reductions in en route sectors that result from convective weather impacts. A model to predict the impact of convective weather on en route traffic, Traffic Normalized Fractional Route Availability (TNFRA), combines Weather Avoidance Fields (WAF) from the Convective Weather Avoidance Model (CWAM) with a model for route usage in air traffic control (ATC) sectors. The model estimates the number of flights that will be able to pass through convective weather in a given sector. Results show that TNFRA provides a relatively unbiased estimate of sector traffic when compared to actual operations during high impact - convective weather events.
READ LESS

Summary

An understanding of convective weather impacts on en route airspace capacity is a first step toward development of predictive tools to support both tactical and strategic routing decisions in storm-impacted airspace. This study presents a model for traffic reductions in en route sectors that result from convective weather impacts. A...

READ MORE

Evaluation of potential NEXRAD dual polarization products

Published in:
MIT Lincoln Laboratory Report ATC-336

Summary

The NEXRAD program will begin fielding a dual polarization capability in 2009. Three additional base data parameters and two additional derived parameters from the dual polarization capability will be produced to complement the traditional three radar moments. The initial use of the added data is to provide a dual-polarization-based quantitative precipitation estimate (QPE) algorithm. Other NEXRAD algorithms will have access to the new dual polarization parameters as well as the derived products. The National Severe Storms Laboratory coordinated a dual polarization product evaluation to solicit NEXRAD agency participant feedback regarding potential dual polarization products. The evaluation consisted of analyzing dual polarization data from seven weather cases. MIT Lincoln Laboratory participated in the evaluation. The evaluation opportunity was used to have early access to prototypical dual polarization data to consider the potential benefit to FAA weather systems. This report introduces the new dual polarization pararmeters, presents some of the relevant weather cases, and provides recommendations regarding use of the dual polarization parameters.
READ LESS

Summary

The NEXRAD program will begin fielding a dual polarization capability in 2009. Three additional base data parameters and two additional derived parameters from the dual polarization capability will be produced to complement the traditional three radar moments. The initial use of the added data is to provide a dual-polarization-based quantitative...

READ MORE

Classification methods for speaker recognition

Published in:
Chapter in Springer Lecture Notes in Artificial Intelligence, 2007.

Summary

Automatic speaker recognition systems have a foundation built on ideas and techniques from the areas of speech science for speaker characterization, pattern recognition and engineering. In this chapter we provide an overview of the features, models, and classifiers derived from these areas that are the basis for modern automatic speaker recognition systems. We describe the components of state-of-the-art automatic speaker recognition systems, discuss application considerations and provide a brief survey of accuracy for different tasks.
READ LESS

Summary

Automatic speaker recognition systems have a foundation built on ideas and techniques from the areas of speech science for speaker characterization, pattern recognition and engineering. In this chapter we provide an overview of the features, models, and classifiers derived from these areas that are the basis for modern automatic speaker...

READ MORE