NS12 è PMI Innovativa
+39 0689178001

H.A.P.S. "Holistic Attack Prevention System"

H.A.P.S. was created as a project carried out by an association of companies, including NS12, Whitehall Reply, Expleo, and CNR as the Research Organization associated with the project. The project’s goal is to conduct industrial research and experimental development activities aimed at creating a Cyber Defense solution capable of predicting possible vulnerabilities in critical applications and cyber attacks, seeking to improve the effectiveness of current practices.

The Solution

The solution aims to collect and correlate various types of information, such as data generated from static code analysis, system logs, and application logs, to monitor in real-time any signals (alerts) that may indicate ongoing cyber attacks.

Using Machine Learning (ML) techniques and Semantic Web methods, leveraging Big Data technologies, the solution will be able to classify and predict different types of attacks and vulnerabilities, providing timely alerts in various forms. The results will be validated with a use case conducted at a pilot Public Administration entity.

NS12’s Commitment

In this project, the NS12 team developed functions for acquiring information flows from systems feeding HAPS (particularly from QMAP and system status monitoring systems), as well as functions for preparing data sets for system training according to ML algorithms. Technologies such as Hadoop, Spark, Yarn, Kafka, and the Scala programming language were used to call ML algorithms from Spark.ml.

NS12 also proposed some extensions to the logical model of the HAPS architecture, introducing a new information flow related to potential attacks from an Intrusion Detection system (SNORT), and developed a prototype of a “Scenario Analysis” system using the rule-based system Drools Expert. This system aims to verify the significance of attack alerts by jointly analyzing various alerts from different sources, even at different times.

Finally, NS12 contributed to the system validation test by conducting a series of targeted cyber attacks – Penetration Tests – which produced new (and important) use cases for an additional step of system training.

The project was completed as planned in July 2019.

Conclusion

  • The project was completed in July 2019.
This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).