<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SCIT Labs</title>
	<atom:link href="http://scitlabs.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://scitlabs.com</link>
	<description></description>
	<lastBuildDate>Mon, 02 Jan 2012 22:23:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Products</title>
		<link>http://scitlabs.com/?p=347</link>
		<comments>http://scitlabs.com/?p=347#comments</comments>
		<pubDate>Tue, 06 Dec 2011 03:34:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Products]]></category>

		<guid isPermaLink="false">http://scitlabs.com/?p=347</guid>
		<description><![CDATA[Learn more about protecting your company with SCIT software appliances and SCIT services. SCIT Labs offers software appliances for the following: SCIT Web server (information only) SCIT E-Commerce server SCIT DNS server SCIT Labs also offers highly targeted courses to support in-house training of software developers, testers, and security system designers and operators.  Two sample courses are: Security Architecture – Reactive and proactive security ...]]></description>
			<content:encoded><![CDATA[<div>Learn more about protecting your company with SCIT software appliances and SCIT services.</div>
<div><img title="More..." src="http://scitlabs.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" alt="" /></div>
<div>SCIT Labs offers <strong>software appliances</strong> for the following:</div>
<div>
<ul>
<li>SCIT Web server (information only)</li>
<li>SCIT E-Commerce server</li>
<li>SCIT DNS server</li>
</ul>
</div>
<div>SCIT Labs also offers <strong>highly targeted courses</strong> to support in-house training of software developers, testers, and security system designers and operators.  Two sample courses are:</div>
<div>
<ul>
<li>Security Architecture – Reactive and proactive security subsystems and how to combine these for best results.</li>
<li>Software Assurance – How to write and test code to capture and fix problems early in the software development life cycle?</li>
</ul>
<p>Additionally, SCIT Labs provides <strong>consulting services</strong> for the design and evaluation of security system acquisition and operations.</p>
<h4>How SCIT Technology Works</h4>
<div>
<p>The variety and complexity of cyber attacks is increasing.  The attackers have a strong economic and political motivation thus leading to organized and targeted attacks.  We have concluded that intrusions are inevitable, and have focused on strategies to work through the attack while limiting the losses.  Our approach, called <strong>Self Cleansing Intrusion Tolerance (SCIT)</strong>, leads to the next generation of secure servers. <strong>SCIT </strong>shifts the focus from intrusion avoidance to reducing the losses resulting from an intrusion.  <strong>SCIT </strong>servers are available for pilot projects and incorporation into your production enterprise systems.</p>
<p>From reports of recent breaches, it has become clear that intruders were in the system for long periods.  Not only did the IDS/IPS fail to prevent the intrusion, these systems were not able to detect the presence of the intruder.  To illustrate this point, we refer to the following data breach reports:</p>
<ul>
<li>Verizon <a href="http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf" target="_blank">DBIR </a>focuses on 90 studies conducted in 2008. 285 million consumer records were compromised. The average Intruder Residence Time (time between system compromise and breach containment) was more than 28 days.</li>
</ul>
<ul>
<li>Network Solutions <a href="http://about.networksolutions.com/site/data-security-alert-problem-fix-and-customers-notified/" target="_blank">breach </a>was investigated in June &#8211; July 2009 resulted in 600,000 records compromised and the data loss took place between March 12, 2009 and June 8, 2009.</li>
</ul>
</div>
<div>
<ul>
<li>Wyndham Hotels <a href="http://www.wyndhamworldwide.com/customer_care/data-claim.cfm" target="_blank">breach</a> was detected in January 2010, with an estimated start date of October 2009.</li>
</ul>
<p>From these incidents, we conclude that the current cyber defenses cannot protect against customized malware and other zero day attacks and intruders are resident for many weeks. Any strategy that will mitigate the effects of the attack would be useful, and if the breach duration is reduced it would lead to reduced data loss. <strong>SCIT </strong>deliberately focuses on reducing the data loss and we dramatically reduce the  records ex-filtrated because of malicious activity.</p>
<h5>Here&#8217;s how:</h5>
<p><a href="http://www.scitlabs.com/home/scit_rotate.jpg?attredirects=0"><img src="http://www.scitlabs.com/_/rsrc/1274747453725/home/scit_rotate.jpg" alt="" border="0" /></a></p>
<p><strong><br />
</strong> Using virtualization technology, SCIT rotates pristine virtual servers and applications every sixty seconds or so.  In the graphic above, five online virtual servers (shown in red) are processing transactions while three offline servers are being cleaned and restored to a pristine state. Every minute a pristine “green” server is swapped out with a “red” server and the SCIT process begins again.</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://scitlabs.com/?feed=rss2&#038;p=347</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Awards, Publications, &amp; Patents</title>
		<link>http://scitlabs.com/?p=165</link>
		<comments>http://scitlabs.com/?p=165#comments</comments>
		<pubDate>Wed, 16 Nov 2011 03:37:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Awards & Publications]]></category>

		<guid isPermaLink="false">http://scitlabs.com/?p=165</guid>
		<description><![CDATA[Since launching, SCIT has won awards for its innovative security solutions. The people behind SCIT have had their work on security technology published in several peer-reviewed publications. Lorem ipsum dolor sit amet, consectetuer adipiscingelit, sed diam nonummy nibh euismod tincidunt ut laoreet dolore magna aliquam erat volutpat. Ut wisi enim ad minim veniam, quis nostrud exerci tation ullamcorper suscipit lobortis nisl ut aliquip ex ea commodo consequat. ]]></description>
			<content:encoded><![CDATA[<p id="sites-page-title-header" align="left">Since launching in 2007, SCIT has won awards for its innovative security solutions.  Here are SCIT&#8217;s awards, accolades in the media, publications, and patents. <span id="more-165"></span></p>
<h2 align="left"><strong>Awards</strong></h2>
<p align="left">June 2010<br />
SCIT Labs is the overall winner of the Global Security Challenge and CNI-Expo sponsored Security Technologies of Tomorrow Challenge. This competition for security start-ups was only open to finalists from previous GSC competitions.  &#8220;This competition brings together the best entrants from various challenges to compete against each other in a race to be crowned the Best Security Technology of Tomorrow.&#8221;</p>
<p>November 2009<br />
SCIT Labs was awarded 2nd place in the 2009 GSC Cyber Security Challenge at GSC Summit held at London Business School in November 2009. GSC = Global Security Challenge.</p>
<p>October 2008<br />
SCIT Labs was winner of the TIE-DC Elevator Pitch competition.</p>
<h2 align="left"><strong>Media Reports</strong></h2>
<ul>
<li>Kelly Jackson Higgins, &#8220;Dark Reading News Analysis: New Intrusion Tolerance Technology Treats Attacks as Inevitable&#8221;, http://www.darkreading.com/document.asp?doc_id=153621 12 May 2008</li>
<li>Kelly Jackson Higgins, &#8220;Dark Reading Port In A Storm: Are Security Breaches Inevitable?&#8221;, http://www.darkreading.com/document.asp?doc_id=154016 15 May 2008</li>
<li>Jennifer Edgerly, &#8220;New Intrusion Tolerance Software Fortifies Server Security&#8221;, http://gazette.gmu.edu/articles/12128/ , 18 June 2008 (abridged version at http://www.physorg.com/news132846874.html and http://www.sciencedaily.com/releases/2008/06/080616144905.htm )</li>
<li>&#8220;La tol鲡nce aux intrusions profite de la virtualisation&#8221;, http://www.atelier.fr/securite/10/18062008/tolerance-aux-intrusions-virtualisation-36715-.html 18 June 2008</li>
<li>Tim Greene, &#8220;Software makes virtual servers a moving target&#8221;, Network World, http://www.networkworld.com/news/2008/061908-scit.html?page=1 , 19 June 2008 (also in http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9101418&amp;source=rss_news50; http://www.pcworld.com/businesscenter/article/147406/limit_internet_attacks_with_virtual_servers.html)</li>
</ul>
<h2 align="left"><strong>Patents</strong></h2>
<ul>
<li>&#8220;Self-Cleaning System&#8221;, US 7549167. Issued 6/16/2009. Inventors: Yih Huang and Arun Sood</li>
<li>&#8220;SCIT-DNS: Critical Infrastructure Protection through Secure DNS Server Dynamic Updates&#8221;, US 7680955. Issued 03/16/2010. Inventors: David Arsenault, Yih Huang and Arun Sood.</li>
<li>&#8220;Single Use Server System&#8221;, US 7725531. Issued May 25, 2010 Inventors: David Arsenault, Yih Huang and Arun Sood.</li>
</ul>
<h2 align="left"><strong>Pending Patents</strong></h2>
<ul>
<li>Regular US Patent Application # 11,419,832, Data Alteration Prevention System, Filed 5/23/2006.</li>
<li>Regular US Patent Application # 12,695,710, Self-Cleansing Secure DNS Server</li>
<li>Regular US Patent Application # 12,695,686, Cache Validating SCIT DNS Server</li>
</ul>
<h2><strong>Publications</strong></h2>
<div>
<ul>
<li>Ajay Nagarajan, Quyen Nguyen, Robert Banks and Arun Sood, “Combining Intrusion Detection and Recovery for Enhancing System Dependability”, 5th Workshop on Recent Advances in Intrusion-Tolerant Systems, in conjunction with 41st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2011), Hong Kong, 28 June, 2011. [<a href="http://cs.gmu.edu/%7Easood/scit/WRAITS-2011.pdf">WRAITS-2011.pdf</a>]</li>
<li>Quyen Nguyen, Arun Sood, “Designing SCIT Architecture Pattern in a Cloud-based Environment”, The First International Workshop on Dependability of Clouds, Data Centers and Virtual Computing Environments (DCDV 2011) in conjunction with 41st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2011), Hong Kong, 28 June, 2011.[<a href="http://cs.gmu.edu/%7Easood/scit/DCDV-2011.pdf">DCDV-2011.pdf</a>]</li>
<li>Quyen L. Nguyen and Arun Sood, &#8220;Comparative Analysis of Intrusion-Tolerant System Architectures&#8221;, IEEE Security and Privacy. Preprint. Accepted for publication August 2010. [<a href="http://cs.gmu.edu/%7Easood/scit/SP-PrePrint.pdf">SP-PrePrint.pdf</a>]</li>
<li>Quyen L. Nguyen and Arun Sood, &#8220;Multiclass S-Reliability for Services in SOA&#8221;, accepted for The Fifth International Conference on Software Engineering Advances, ICSEA 2010, Nice, France, August 22-27, 2010.</li>
<li>David Pham and Arun K Sood, &#8220;An Intrusion Tolerance Approach to Enhance Single Sign On Server Protection&#8221;, Proc The Third International Conference on Dependability (DEPEND 2010)July 18-25, 2010 &#8211; Venice/Mestre, Italy..[<a href="http://cs.gmu.edu/%7Easood/scit/DEPEND2010_SSO.pdf">DEPEND2010_SSO.pdf</a>]</li>
<li>Ajay Nagarajan and Arun Sood, &#8220;SCIT and IDS Architectures for Reduced Data Ex-filtration&#8221; 4th Workshop on Recent Advances in Intrusion-Tolerant Systems, Chicago,IL, USA, June 28 2010[<a href="http://cs.gmu.edu/%7Easood/scit/WRAITS2010_Des_Trees.pdf">WRAITS2010_Des_Trees.pdf</a>]</li>
<li>Quyen L. Nguyen and Arun Sood, &#8220;Realizing S-Reliability for Services via Recovery-driven Intrusion Tolerance Mechanism&#8221;, 4th Workshop on Recent Advances in Intrusion-Tolerant Systems, Chicago,IL, USA, June 28 2010. [<a href="http://cs.gmu.edu/%7Easood/scit/WRAITS2010_sreliability.pdf">WRAITS2010_sreliability.pdf</a>]</li>
<li>Quyen Nguyen and Arun Sood, Quantitative Approach to Tuning of a Time-Based Intrusion-Tolerant System Architecture, 3rd Workshop on Recent Advances in Intrusion Tolerant Systems, Portugal, June 29, 2009.[<a href="http://cs.gmu.edu/%7Easood/scit/WRAITS2009.pdf">WRAITS2009.pdf</a>]</li>
<li>Anantha K. Bangalore and Arun K Sood, Securing Web Servers Using Self Cleansing Intrusion Tolerance (SCIT), Proc The Second International Conference on Dependability (DEPEND 2009)June 18-23, 2009 &#8211; Athens/Vouliagmeni, Greece. [<a href="http://cs.gmu.edu/%7Easood/scit/depend_2009_submitted_version-2.pdf">DEPEND2009.pdf</a>]</li>
<li>Arsenault, D., and Sood, A.(2007). &#8220;Resilience: A Systems Design Imperative.&#8221; CIPP Working Paper 02-07.Arlington, VA: George Mason University. [<a href="http://cs.gmu.edu/%7Easood/scit/CIPP%20Resilience%20Series%20Sood%20Arsenault.pdf">CIPP2007.pdf</a>]</li>
<li>David Arsenault, Arun Sood, and Yih Huang, &#8220;Secure, Resilient Computing Clusters: Self-Cleansing Intrusion Tolerance with Hardware Enforced Security (SCIT/HES)&#8221; Proceedings Second International Conference on Availability, Reliability and Security (ARES 2007), Vienna, Austria, April 2007. [<a href="http://cs.gmu.edu/%7Easood/scit/SCIT-HES2-IEEE-ARES2007-FINAL.pdf">ARES2007.pdf</a>]</li>
<li>Yih Huang, David Arsenault, and Arun Sood, &#8220;Incorruptible Self-Cleansing Intrusion Tolerance and Its Application to DNS Security&#8221; Journal of Networks, Academy Press, vol 1 No 5, pp 21 &#8211; 30, September/October 2006. [<a href="http://cs.gmu.edu/%7Easood/scit/Network06.pdf">Network06.pdf</a>]</li>
<li>Yih Huang, David Arsenault, and Arun Sood, &#8220;Closing Cluster Attack Windows through Server Redundancy and Rotations&#8221; Proceedings of the Second International Workshop on Cluster Security (Cluster-Sec06),Singapore, May 2006.[<a href="http://cs.gmu.edu/%7Easood/scit/CSEC06.pdf">CSEC06.pdf</a>]</li>
<li>Yih Huang, David Arsenault, and Arun Sood, &#8220;SCIT-DNS: Critical Infrastructure Protection through Secure DNS Server Dynamic Updates&#8221;, Journal of High Speed Networking, vol 15 No 1, pp 5 19, 2006.</li>
<li>Yih Huang, David Arsenault, and Arun Sood, &#8220;Securing DNS Services through System Self Cleansing and Hardware Enhancements&#8221;, Proceedings First International Conference on Availability, Reliability and Security (ARES 2006), Vienna, Austria, April 2006. [<a href="http://cs.gmu.edu/%7Easood/scit/ARES06.pdf">ARES06.pdf</a>]</li>
<li>Yih Huang, David Arsenault, and Arun Sood, ?Incorruptible System Self-Cleansing for Intrusion Tolerance&#8221;, Proceedings Workshop on Information Assurance (WIA 2006), Phoenix, AZ, April 2006 (in press). [<a href="http://cs.gmu.edu/%7Easood/scit/WIA2006.pdf">WIA2006.pdf</a>]</li>
<li>Yih Huang, David Arsenault, and Arun Sood, &#8220;SCIT-DNS: Critical Infrastructure Protection through Secure DNS Server Dynamic Updates&#8221;, Proceedings of 3rd International Trusted Internet Workshop (TIW), /Bangalore,INDIA, December 2004. [<a href="http://cs.gmu.edu/%7Easood/scit/SCIT-DNS-TIW04.pdf">SCIT-DNS-TIW04.pdf</a>]</li>
<li>Yih Huang, Arun Sood, and Ravi K. Bhaskar, ?Countering Web Defacing Attacks with System Self-Cleansing ,? /Proceedings of 7^th Word Multiconference on Systemics, Cybernetics and Informatics/, pp. 12?16, Orlando,Florida, July 2003. [<a href="http://cs.gmu.edu/%7Easood/scit/defacing.pdf">defacing.pdf</a>]</li>
<li>Yih Huang and Arun Sood, &#8220;Self-Cleansing Systems for Intrusion Containment&#8221;, Proceedings of Workshop on Self-Healing, Adaptive, and Self-Managed Systems (SHAMAN), New York City, June 2002. [<a href="http://cs.gmu.edu/%7Easood/scit/shaman02.pdf">shaman02.pdf</a>]</li>
</ul>
<h2 align="left"><strong>Online Articles</strong></h2>
<ul>
<li>Arun Sood, &#8221; Exposure Time &#8211; A Metric For Proactive Security Risk Management&#8221;, http://www.riskbloggers.com/arunsood/2007/07/exposure-time-a-metric-for-proactive-security-risk-management/ , 23 July 2007.</li>
<li>Naresh Verma, Yih Huang, and Arun Sood, &#8220;Proactively Managing Security Risk&#8221;, http://www.securityfocus.com/infocus/1896 , 07 November 2007.</li>
</ul>
<h2 align="left">White Papers (for download)</h2>
<p><a href="http://scitlabs.com/wp-content/uploads/2011/11/SCIT-Datasheet-3.pdf">SCIT Datasheet</a></p>
<p><a href="http://scitlabs.com/wp-content/uploads/2011/12/CONOP-for-SCIT.pdf">SCIT Concept of Operations</a></p>
<p><a href="http://scitlabs.com/wp-content/uploads/2011/11/CCF-CaseStudy.pdf">Case Study: Continuous Monitoring, Compromised Server Handling and Forensics</a></p>
<p><a href="http://scitlabs.com/wp-content/uploads/2011/11/SCIT_ClearSky-Integration2.pdf">SCIT and Lockheed Clear Sky Integration</a></p>
<p>Please <a href="mailto:info@scitlabs.com">contact us</a> for additional application targeted  SCIT  white papers.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://scitlabs.com/?feed=rss2&#038;p=165</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Partners</title>
		<link>http://scitlabs.com/?p=154</link>
		<comments>http://scitlabs.com/?p=154#comments</comments>
		<pubDate>Wed, 16 Nov 2011 03:10:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Partners]]></category>

		<guid isPermaLink="false">http://scitlabs.com/?p=154</guid>
		<description><![CDATA[Partners]]></description>
			<content:encoded><![CDATA[<p>SCIT Labs has partnered with system integrators and other organizations with specialized knowledge base to develop joint proposals submitted to federal agencies. We have also developed a network of national and international of sales and marketing efforts. <span id="more-154"></span></p>
<h5>SCIT has submitted joint proposals with:<span class="Apple-style-span" style="font-size: 13px; font-weight: normal;"> </span></h5>
<p>&nbsp;</p>
<h4></h4>
<h4>                         <a href="http://scitlabs.com/wp-content/uploads/2011/11/lockheed.gif"><img class="alignnone size-full wp-image-230" title="lockheed" src="http://scitlabs.com/wp-content/uploads/2011/11/lockheed-e1322597005115.gif" alt="" width="281" height="70" /></a>                     <a style="font-weight: normal;" href="http://www.six3systems.com"><img class="alignnone" title="Six3 Systems" src="http://www.six3systems.com/res/images/brand/six3logo.png" alt="Six3 Systems" width="130" height="41" /></a></h4>
<p style="padding-left: 90px;"><a href="http://www.landisgyr.com/"><img class="alignnone" title="Landis Gyr" src="http://style.landisgyr.com/siteimg/logo/LG_logo.gif" alt="Landis Gyr" width="220" height="84" /></a>           <a href="http://scitlabs.com/wp-content/uploads/2011/11/Screen-shot-2011-11-29-at-3.27.35-PM.png"><img title="J.O.T Enterprises" src="http://scitlabs.com/wp-content/uploads/2011/11/Screen-shot-2011-11-29-at-3.27.35-PM.png" alt="J.O.T Enterprises" width="256" height="44" /></a></p>
<h5></h5>
<h5>SCIT&#8217;s partners in systems integration, sales, and marketing are:<span class="Apple-style-span" style="font-size: 13px; font-weight: normal;"> </span></h5>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p style="padding-left: 150px;"><img class="alignnone size-full wp-image-231" title="ibc" src="http://scitlabs.com/wp-content/uploads/2011/11/ibc.png" alt="" width="160" height="64" />                            <img class="alignnone" style="border-style: initial; border-color: initial;" title="Blackstone Technology Group" src="http://www.bizthink.com/images/partners/blackstone_logo.gif" alt="Blackstone Technology Group" width="210" height="55" /></p>
<div>      <img class="alignnone size-full wp-image-229" title="Camphora Consulting" src="http://scitlabs.com/wp-content/uploads/2011/11/camphora.png" alt="Camphora Consulting" width="198" height="87" />           <strong><strong><a href="http://scitlabs.com/wp-content/uploads/2011/11/Screen-shot-2011-11-29-at-3.12.02-PM.png"><img class="alignnone size-full wp-image-232" style="border-style: initial; border-color: initial;" title="Screen shot 2011-11-29 at 3.12.02 PM" src="http://scitlabs.com/wp-content/uploads/2011/11/Screen-shot-2011-11-29-at-3.12.02-PM.png" alt="" width="185" height="75" /></a></strong></strong><strong><strong>            </strong></strong><strong><strong><a href="http://www.coronadogroup.com"><img style="border-style: initial; border-color: initial;" title="Coronado Group" src="http://www.coronadogroup.com/images/360_Coronado_Logo2.jpg" alt="Coronado Group" width="200" height="35" /></a>    </strong></strong></div>
<div></div>
<div></div>
<div></div>
<div></div>
<div></div>
<div></div>
<div></div>
<div></div>
]]></content:encoded>
			<wfw:commentRss>http://scitlabs.com/?feed=rss2&#038;p=154</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About Us</title>
		<link>http://scitlabs.com/?p=116</link>
		<comments>http://scitlabs.com/?p=116#comments</comments>
		<pubDate>Wed, 16 Nov 2011 02:48:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[About Us]]></category>

		<guid isPermaLink="false">http://scitlabs.com/?p=116</guid>
		<description><![CDATA[SCIT Labs, Inc was incorporated in 2007.  SCIT is a university spin off, licensing the technology from GMIP - the IP licensing affiliate of George Mason University.  Our initial effort was in defining and building servers that demonstrate the effectiveness of the SCIT technology.]]></description>
			<content:encoded><![CDATA[<p>SCIT Labs, Inc was incorporated in 2007.  SCIT is a university spin off, licensing the technology from GMIP &#8211; the IP licensing affiliate of George Mason University.  Our initial effort was in defining and building servers that demonstrate the effectiveness of the SCIT technology.</p>
<h3 align="left">Staff</h3>
<p><strong>Arun Sood<br />
</strong>Dr. Sood is CEO of SCIT Labs Inc, a startup that is licensing SCIT technology from George Mason University. He has published more than 150 papers and edited two books. Three SCIT patents have been issued, and three patent applications are pending. A list of his publications and detailed resume can be found at <a href="http://cs.gmu.edu/~asood" rel="nofollow">http://cs.gmu.edu/~asood</a>. He has a BTech (1966) from the Indian Institute of Technology, Delhi, and an MS (1967) and PhD (1971) from Carnegie Mellon University. All of his degrees are in electrical engineering.<span class="Apple-style-span" style="font-size: x-small;"> </span></p>
<p><strong>Arleen Zank<br />
</strong>Arleen Malley Zank is Program Director and Solutions Architect with over 25 years of experience in technology commercialization and product development and designing, developing and delivering complex large-scale enterprise solutions.  Ms Zank has extensive experience integrating new and emerging technology to solve mission critical information infrastructure challenges and the scientific and technical challenges of integrating new technology into existing standards-based IT environments.  In particular, she has experience developing and deploying FISMA, NIST and Classified secure systems. Ms. Zank is Co-Founder and President of Coronado Group, Ltd. a specialized systems integration and technology advisory firm focused on emerging and disruptive technology, technology strategy, intellectual property, and commercialization.   Prior to founding Coronado Group, Ltd. in 1991, Ms. Zank served as a Program Director responsible for program capture and management, pricing strategies, and product development for a Fortune 200 information technology company.<br />
<strong><br />
Anantha Bangalore<br />
</strong>Mr. Bangalore is Chief Systems Architect. Anantha has a proven 18-year track record of leading, managing and developing on time and quality solutions in Health Information, Security, E-Commerce and Financial domains. He has published many papers in national and international conferences.<br />
<strong><br />
Lee Mericle</strong><br />
Ms. Mericle is Chief Software Engineer.  Lee has broad experience in software design and development and in formal Government testing management. She has worked with systems ranging from large computer-based training (CBT) systems to a cellular telephone antenna system. She works on various research projects for the National Library of Medicine’s (NLM) Lister Hill National Center for Biomedical Communications (LHNCBC) and served as Aquilent’s program manager for NLM projects.</p>
]]></content:encoded>
			<wfw:commentRss>http://scitlabs.com/?feed=rss2&#038;p=116</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protect Yourself with SCIT</title>
		<link>http://scitlabs.com/?p=22</link>
		<comments>http://scitlabs.com/?p=22#comments</comments>
		<pubDate>Mon, 14 Nov 2011 23:41:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[The Software]]></category>

		<guid isPermaLink="false">http://scitlabs.com/?p=22</guid>
		<description><![CDATA[Protect Yourself with SCIT]]></description>
			<content:encoded><![CDATA[<p><a title="Small Businesses Hacked" href="http://www.huffingtonpost.com/2011/10/24/small-business-hackers_n_1028781.html" target="_blank"><img class="alignnone size-thumbnail wp-image-198" title="Small Businesses Hacked" src="http://scitlabs.com/wp-content/uploads/2011/11/higher-res-huffpo1-e1323639995555-150x133.jpg" alt="" width="150" height="133" /></a>        <a title="Facebook Security Breach" href="http://www.washingtonpost.com/business/economy/facebook-hack-raises-security-concerns/2011/11/15/gIQAqCyYPN_story.html" target="_blank"><img class="alignnone size-thumbnail wp-image-281" title="Protect Yourself with SCIT" src="http://scitlabs.com/wp-content/uploads/2011/08/dont-get-hacked-e1323019029824-150x150.jpg" alt="Protect Yourself with SCIT" width="150" height="150" /></a>        <a title="Hacker Rattles Security Circles" href="http://www.nytimes.com/2011/09/12/technology/hacker-rattles-internet-security-circles.html?pagewanted=all" target="_blank"><img class="alignnone size-thumbnail wp-image-266" title="Hacker Rattles Security Circles" src="http://scitlabs.com/wp-content/uploads/2011/11/Screen-shot-2011-11-29-at-4.15.29-PM1-e1323639138368-150x132.png" alt="Hacker Rattles Security Circles" width="150" height="132" /></a>        <a title="Sony Hacked Again" href="http://www.wired.com/gamelife/2011/05/sony-online-entertainment-hack/" target="_blank"><img class="alignnone size-thumbnail wp-image-328" title="Sony Hacked Again" src="http://scitlabs.com/wp-content/uploads/2011/06/dc-universe-e1323639220520-150x142.png" alt="Sony Hacked Again" width="150" height="142" /></a></p>
<p>Businesses are increasingly vulnerable to security breaches.</p>
<p>The current reactive systems lead to many alerts and require extensive alert (incident) management costs. Furthermore, many of the alerts are false positives, and thus an extensive amount of effort is wasted.</p>
<p>SCIT technology is threat independent.  It reduces the impact of zero day attacks, thus providing protection while the manufacturer develops and distributes a patch.  In this way even the small retailer is protected – there maybe undetected intrusions but the losses are contained.  Further, SCIT servers do not generate alerts and this reduces the need for alert processing.  Without SCIT, effective alert processing is essential, to avoid the long term (days, weeks and months) residency of the bad guys in the system.  For this reason, SCIT servers reduce the cost of operations.</p>
<h2 id="sites-page-title-header" align="left">SCIT Benefits</h2>
<div>Current servers are online for very long times.  This gives the attacker ample time to scan the server and understand the server vulnerabilities, thus increasing the likelihood of a successful attack.  On the other hand, SCIT servers are online for short periods (a few minutes), thereby reducing the time an attacker has to do damage.In effect SCIT strategy converts static servers into dynamic servers. In this way, the temporal dimension of security is emphasized. This has the added advantage of enabling the use of diversity principles.  Randomization of address space, application or operating system will increase the attacker difficulty.</div>
<div>
<p>The SCIT servers have the following advantages:</p>
<ul>
<li>SCIT removes malware every minute without detection.</li>
<li>SCIT reduces data ex-filtration.</li>
<li>SCIT does not rely on signatures and is threat independent.</li>
<li>SCIT automatically recovers from defacement or software deletion attacks.</li>
<li>SCIT addition enhances the value of investment in legacy systems.</li>
<li>SCIT hot patches do not require online server reboot.</li>
<li>SCIT increases the security of virtualized systems.</li>
</ul>
<div>
<h2>SCIT&#8217;s ECommerce Demo Video</h2>
<p>Video is available for download in .wmv formats and can be viewed in streaming video mode.</p>
<p><a href="http://cs.gmu.edu/~asood/scit/SCIT-ECommerce-Demo.wmv">ECommerce SCIT demo video in wmv format </a>is about 280 MB and can be downloaded from http://cs.gmu.edu/~asood/scit/SCIT-ECommerce-Demo.wmv.</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://scitlabs.com/?feed=rss2&#038;p=22</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://cs.gmu.edu/~asood/scit/SCIT-ECommerce-Demo.wmv" length="287783619" type="video/asf" />
		</item>
		<item>
		<title>The Digital Vaccine</title>
		<link>http://scitlabs.com/?p=51</link>
		<comments>http://scitlabs.com/?p=51#comments</comments>
		<pubDate>Sun, 13 Nov 2011 05:34:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[The Software]]></category>

		<guid isPermaLink="false">http://scitlabs.com/?p=51</guid>
		<description><![CDATA[The Digital Vaccine]]></description>
			<content:encoded><![CDATA[<h4></h4>
<h4>How does SCIT work like a vaccine?</h4>
<p>Vaccines have been successfully used to significantly reduce the risk of certain diseases.  For example, the small pox vaccine has eliminated small pox.  Polio vaccine is another success story.  In both cases the vaccines, with requisite boosters, immunize the patient for life and are very successful.</p>
<p>On the other hand there are vaccines that have limited goals but are still very useful. The flu vaccine provides immunity against three specific strains and has to be applied every year.  From among the many strains, the vaccine manufacturer research estimates the three strains that will be most prevalent and develops protection against these strains. In general the flu vaccine reduces infections and speeds recovery.</p>
<p>Typically, vaccines are effective for a time period and often booster shots are needed.  Further, the vaccination not only protects the individual and also the community.  For example, the flu vaccine is recommended by the CDC not only to protect individuals, but also to prevent the spread of the flu (fewer people getting the flu = fewer people spreading the flu) each season.  In addition to the vaccine, everyone is encouraged to obey simple rules (wash your hands often) so as to frequently restore the system to a clean state, thus prevent spread of infection.</p>
<p>SCIT is a digital vaccine that removes the malware and viruses every cycle.  Like the flu, new variants of the malware continuously appear, and restoring systems to a clean state (like washing hands) reduces the chance of infection.  The cycle duration is chosen by the user – one minute cycles have been achieved. SCIT servers are protected from long presence of the malware or virus on the servers – thus making it difficult to infect other servers in the system. SCIT server damage is limited by the duration of exposure time of the server to the internet, and the automatic recovery to a pristine state is included in the SCIT server cycle. SCIT technology complements the current reactive systems like firewalls, IDS and IPS; and leads to further reduction in malicious data ex-filtration.</p>
<div>
<div>
<p>&nbsp;</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://scitlabs.com/?feed=rss2&#038;p=51</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>$6,000,000</title>
		<link>http://scitlabs.com/?p=5</link>
		<comments>http://scitlabs.com/?p=5#comments</comments>
		<pubDate>Wed, 09 Nov 2011 01:46:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[The Software]]></category>

		<guid isPermaLink="false">http://scitlabs.com/?p=5</guid>
		<description><![CDATA[$6,000,000]]></description>
			<content:encoded><![CDATA[<p><strong>The Ponemon Institute <a href="http://www.ponemon.org/blog/post/cost-of-a-data-breach-climbs-higher">reports</a> that in the large breaches, the cost of handling a security breach is $6.4 million, and the average cost per customer record maliciously ex-filtrated is $214. </strong></p>
<p><strong>SCIT&#8217;s virtual servers are killed every cycle, thus forcibly breaking the connection from the server to the bad guys every cycle – maybe every minute.  This implies that the attacker has to make repeated attempts to download large files.  Repeated attempts increase the attacker exposure. By restoring the SCIT servers to a pristine state, the number of records lost per breach is reduced by several orders of magnitude.  When the SCIT technology is integrated with current reactive approaches the data ex-filtration per cycle is further reduced.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://scitlabs.com/?feed=rss2&#038;p=5</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protect Yourself with SCIT</title>
		<link>http://scitlabs.com/?p=276</link>
		<comments>http://scitlabs.com/?p=276#comments</comments>
		<pubDate>Tue, 01 Nov 2011 16:56:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[The Software]]></category>

		<guid isPermaLink="false">http://scitlabs.com/?p=276</guid>
		<description><![CDATA[Protect Yourself with SCIT]]></description>
			<content:encoded><![CDATA[<p><a title="Small Businesses Hacked" href="http://www.huffingtonpost.com/2011/10/24/small-business-hackers_n_1028781.html" target="_blank"><img title="Small Businesses Hacked" src="http://scitlabs.com/wp-content/uploads/2011/11/higher-res-huffpo1-e1323639995555-150x133.jpg" alt="" width="150" height="133" /></a>        <a title="Facebook Security Breach" href="http://www.washingtonpost.com/business/economy/facebook-hack-raises-security-concerns/2011/11/15/gIQAqCyYPN_story.html" target="_blank"><img title="Protect Yourself with SCIT" src="http://scitlabs.com/wp-content/uploads/2011/08/dont-get-hacked-e1323019029824-150x150.jpg" alt="Protect Yourself with SCIT" width="150" height="150" /></a>        <a title="Hacker Rattles Security Circles" href="http://www.nytimes.com/2011/09/12/technology/hacker-rattles-internet-security-circles.html?pagewanted=all" target="_blank"><img title="Hacker Rattles Security Circles" src="http://scitlabs.com/wp-content/uploads/2011/11/Screen-shot-2011-11-29-at-4.15.29-PM1-e1323639138368-150x132.png" alt="Hacker Rattles Security Circles" width="150" height="132" /></a>        <a title="Sony Hacked Again" href="http://www.wired.com/gamelife/2011/05/sony-online-entertainment-hack/" target="_blank"><img title="Sony Hacked Again" src="http://scitlabs.com/wp-content/uploads/2011/06/dc-universe-e1323639220520-150x142.png" alt="Sony Hacked Again" width="150" height="142" /></a></p>
<p>Businesses are increasingly vulnerable to security breaches.</p>
<p>The current reactive systems lead to many alerts and require extensive alert (incident) management costs. Furthermore, many of the alerts are false positives, and thus an extensive amount of effort is wasted.</p>
<p>SCIT technology is threat independent.  It reduces the impact of zero day attacks, thus providing protection while the manufacturer develops and distributes a patch.  In this way even the small retailer is protected – there maybe undetected intrusions but the losses are contained.  Further, SCIT servers do not generate alerts and this reduces the need for alert processing.  Without SCIT, effective alert processing is essential, to avoid the long term (days, weeks and months) residency of the bad guys in the system.  For this reason, SCIT servers reduce the cost of operations.</p>
<h2 id="sites-page-title-header" align="left">SCIT Benefits</h2>
<div>Current servers are online for very long times.  This gives the attacker ample time to scan the server and understand the server vulnerabilities, thus increasing the likelihood of a successful attack.  On the other hand, SCIT servers are online for short periods (a few minutes), thereby reducing the time an attacker has to do damage.In effect SCIT strategy converts static servers into dynamic servers. In this way, the temporal dimension of security is emphasized. This has the added advantage of enabling the use of diversity principles.  Randomization of address space, application or operating system will increase the attacker difficulty.</div>
<div>
<p>The SCIT servers have the following advantages:</p>
<ul>
<li>SCIT removes malware every minute without detection.</li>
<li>SCIT reduces data ex-filtration.</li>
<li>SCIT does not rely on signatures and is threat independent.</li>
<li>SCIT automatically recovers from defacement or software deletion attacks.</li>
<li>SCIT addition enhances the value of investment in legacy systems.</li>
<li>SCIT hot patches do not require online server reboot.</li>
<li>SCIT increases the security of virtualized systems.</li>
</ul>
<div>
<h2>SCIT&#8217;s ECommerce Demo Video</h2>
<p>Video is available for download in .wmv formats and can be viewed in streaming video mode.</p>
<p><a href="http://cs.gmu.edu/~asood/scit/SCIT-ECommerce-Demo.wmv">ECommerce SCIT demo video in wmv format </a>is about 280 MB and can be downloaded from http://cs.gmu.edu/~asood/scit/SCIT-ECommerce-Demo.wmv.</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://scitlabs.com/?feed=rss2&#038;p=276</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://cs.gmu.edu/~asood/scit/SCIT-ECommerce-Demo.wmv" length="287783619" type="video/asf" />
		</item>
		<item>
		<title>The Digital Vaccine</title>
		<link>http://scitlabs.com/?p=181</link>
		<comments>http://scitlabs.com/?p=181#comments</comments>
		<pubDate>Sat, 10 Sep 2011 22:17:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[The Software]]></category>

		<guid isPermaLink="false">http://scitlabs.com/?p=181</guid>
		<description><![CDATA[The Digital Vaccine]]></description>
			<content:encoded><![CDATA[<h4>How does SCIT work like a vaccine?</h4>
<p>Vaccines have been used to significantly reduce the risk of certain diseases. The small pox vaccine has eliminated small pox. The polio vaccine is another success story. Both these cases the vaccines immunize the patient for life and are very successful.</p>
<p>Other vaccines have limited goals but are still very useful. The flu vaccine provides immunity against three specific strains and must be applied every year. In general, the flu vaccine reduces infections and speeds recovery. In Fall 2011, there have been <a href="http://www.cnn.com/2011/10/18/health/trial-malaria-vaccine-africa/index.html">reports of success</a> with the malaria vaccine. The developers, GlaxoSmithKline and the PATH Malaria Vaccine Initiative, which receives funding from the Bill and Melinda Gates Foundation, said it showed roughly a 50% reduction in malaria cases in a 12 month period following vaccination. “Such a vaccine would not replace proven malaria control interventions such as insecticide-treated bed nets,&#8221; the CDC&#8217;s Hamel <a href="http://www.cnn.com/2011/10/18/health/trial-malaria-vaccine-africa/index.html">said</a>, &#8220;but could be an important addition to those interventions.&#8221;</p>
<p>SCIT is a digital vaccine that removes the malware and viruses every cycle.  The cycle duration is chosen by the user – one minute cycles have been achieved. SCIT servers are protected from long presence of the malware or virus on the servers – thus making it difficult to infect other servers in the system. SCIT server damage is limited by the duration of exposure time of the server to the internet, and the automatic recovery to a pristine state is included in the SCIT server cycle. SCIT technology complements the current reactive systems like firewalls, IDS and IPS; and leads to further reduction in malicious data ex-filtration.</p>
<div>
<div>
<p>&nbsp;</p>
</div>
</div>
<p>[[[EMBEDED SCIT VIDEO ?????? ]]]</p>
]]></content:encoded>
			<wfw:commentRss>http://scitlabs.com/?feed=rss2&#038;p=181</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

