{"72599":{"#nid":"72599","#data":{"type":"news","title":"Georgia Tech Helps to Develop System That Will Detect Insider Threats from Massive Data Sets","body":[{"value":"\u003Cp\u003EWhen a soldier in good mental health becomes homicidal or a government employee abuses access privileges to share classified information, we often wonder why no one saw it coming. When looking through the evidence after the fact, a trail often exists that, had it been noticed, could have possibly provided enough time to intervene and prevent an incident.\u003C\/p\u003E\u003Cp\u003EWith support from the Defense Advanced Research Projects Agency (DARPA) and the Army Research Office, researchers at the Georgia Institute of Technology are collaborating with scientists from four other organizations to develop new approaches for identifying these \u0022insider threats\u0022 before an incident occurs. The two-year, $9 million project will create a suite of algorithms that can detect multiple types of insider threats by analyzing massive amounts of data -- including email, text messages and file transfers -- for unusual activity.\u003C\/p\u003E\u003Cp\u003EThe project is being led by Science Applications International Corporation (SAIC) and also includes researchers from Oregon State University, the University of Massachusetts and Carnegie Mellon University.\u003C\/p\u003E\u003Cp\u003E\u0022Analysts looking at the electronically recorded activities of employees within government or defense contracting organizations for anomalous behaviors may now have the bandwidth to investigate five anomalies per day out of thousands of possibilities. Our goal is to develop a system that will provide analysts for the first time a very short, ranked list of unexplained events that should be further investigated,\u0022 said project co-principal investigator David A. Bader, a professor with a joint appointment in the Georgia Tech School of Computational Science and Engineering and the Georgia Tech Research Institute (GTRI).\u003C\/p\u003E\u003Cp\u003EUnder the contract, the researchers will leverage a combination of massively scalable graph-processing algorithms, advanced statistical anomaly detection methods and knowledge-based relational machine learning algorithms to create a prototype Anomaly Detection at Multiple Scales (ADAMS) system. The system could revolutionize the capabilities of counter-intelligence community operators to identify and prioritize potential malicious insider threats against a background of everyday cyber network activity.\u003C\/p\u003E\u003Cp\u003EThe research team will have access to massive data sets collected from operational environments where individuals have explicitly agreed to be monitored. The information will include electronically recorded activities, such as computer logins, emails, instant messages and file transfers. The ADAMS system will be capable of pulling these terabytes of data together and using novel algorithms to quickly analyze the information to discover anomalies.\u003C\/p\u003E\u003Cp\u003E\u0022We need to bring together high-performance computing, algorithms and systems on an unprecedented scale because we\u0027re collecting a massive amount of information in real time for a long period of time,\u0022 explained Bader. \u0022We are further challenged because we are capturing the information at different rates -- keystroke information is collected at very rapid rates and other information, such as file transfers, is collected at slower rates.\u0022\u003C\/p\u003E\u003Cp\u003EIn addition to Bader, other Georgia Tech researchers supporting key components of this program include School of Interactive Computing professor Irfan Essa, School of Computational Science and Engineering associate professor Edmond Chow, GTRI principal research engineers Lora Weiss and Fred Wright, GTRI senior research scientist Richard Boyd, and GTRI research scientists Joshua L. Davis and Erica Briscoe.\u003C\/p\u003E\u003Cp\u003E\u0022We look forward to working with DARPA and our academic partners to develop a prototype ADAMS system that can detect anomalies in massive data sets that can translate to significant, often critical, actionable insider threat information across a wide variety of application domains,\u0022 said John Fratamico, SAIC senior vice president and business unit general manager.\u003C\/p\u003E\u003Cp\u003E\u003Cstrong\u003EResearch News \u0026amp; Publications Office\u003Cbr \/\u003E Georgia Institute of Technology\u003Cbr \/\u003E 75 Fifth Street, N.W., Suite 314\u003Cbr \/\u003E Atlanta, Georgia 30308 USA\u003C\/strong\u003E\u003C\/p\u003E\u003Cp\u003E\u003Cstrong\u003EMedia Relations Contacts:\u003C\/strong\u003E Abby Robinson (abby@innovate.gatech.edu; 404-385-3364) or John Toon (jtoon@gatech.edu; 404-894-6986)\u003C\/p\u003E\u003Cp\u003E\u003Cstrong\u003EWriter:\u003C\/strong\u003E Abby Robinson\u003C\/p\u003E","summary":null,"format":"limited_html"}],"field_subtitle":"","field_summary":[{"value":"\u003Cp\u003EResearchers at Georgia Tech are developing new approaches for identifying \u0022insider threats\u0022 before an incident occurs. They are creating a suite of algorithms that can detect threats by analyzing massive amounts of computer data for unusual activity.\u003C\/p\u003E","format":"limited_html"}],"field_summary_sentence":[{"value":"Researchers will analyze massive amounts of data for unusual activity."}],"uid":"27206","created_gmt":"2011-11-10 01:00:00","changed_gmt":"2016-10-08 03:10:38","author":"Abby Vogel Robinson","boilerplate_text":"","field_publication":"","field_article_url":"","dateline":{"date":"2011-11-10T00:00:00-05:00","iso_date":"2011-11-10T00:00:00-05:00","tz":"America\/New_York"},"extras":[],"hg_media":{"72600":{"id":"72600","type":"image","title":"Georgia Tech DARPA ADAMS team","body":null,"created":"1449177942","gmt_created":"2015-12-03 21:25:42","changed":"1475894661","gmt_changed":"2016-10-08 02:44:21"},"72601":{"id":"72601","type":"image","title":"Data collection environment","body":null,"created":"1449177942","gmt_created":"2015-12-03 21:25:42","changed":"1475894661","gmt_changed":"2016-10-08 02:44:21"},"72602":{"id":"72602","type":"image","title":"Georgia Tech DARPA ADAMS leaders","body":null,"created":"1449177942","gmt_created":"2015-12-03 21:25:42","changed":"1475894661","gmt_changed":"2016-10-08 02:44:21"}},"media_ids":["72600","72601","72602"],"related_links":[{"url":"http:\/\/www.cse.gatech.edu\/people\/david-bader","title":"David Bader"},{"url":"http:\/\/www.cse.gatech.edu\/","title":"School of Computational Science and Engineering"},{"url":"http:\/\/www.gtri.gatech.edu\/","title":"Georgia Tech Research Institute"},{"url":"http:\/\/sc11.gatech.edu\/","title":"Georgia Tech at SC11"}],"groups":[{"id":"1183","name":"Home"}],"categories":[{"id":"153","name":"Computer Science\/Information Technology and Security"},{"id":"147","name":"Military Technology"},{"id":"135","name":"Research"}],"keywords":[{"id":"15027","name":"Adams"},{"id":"5660","name":"algorithms"},{"id":"15025","name":"Anomalies"},{"id":"15026","name":"Anomaly Detection at Multiple Scales"}],"core_research_areas":[],"news_room_topics":[],"event_categories":[],"invited_audience":[],"affiliations":[],"classification":[],"areas_of_expertise":[],"news_and_recent_appearances":[],"phone":[],"contact":[{"value":"\u003Cp\u003E\u003Cstrong\u003EAbby Robinson\u003C\/strong\u003E\u003Cbr \/\u003EResearch News and Publications\u003Cbr \/\u003E\u003Ca href=\u0022http:\/\/www.gatech.edu\/contact\/index.html?id=avogel6\u0022\u003EContact Abby Robinson\u003C\/a\u003E\u003Cbr \/\u003E\u003Cstrong\u003E404-385-3364\u003C\/strong\u003E\u003C\/p\u003E","format":"limited_html"}],"email":["abby@innovate.gatech.edu"],"slides":[],"orientation":[],"userdata":""}}}