

The MulVAL project aims at providing automated tools to aid in security administration of enterprise networks. It builds upon a logic-based attack graph generator, leverages existing standard security information databases, and conducts comprehensive and quantitative analysis to help system administrators to harden the security of an enterprise network in a cost-effective manner.

Automated intrusion analysis

This project focuses on the problem of how to automatically identify high-confident attack traces from large amounts of system monitoring data, through a simple logic with the capability of reasoning about uncertainty which is inherent in real-time security analysis.