Cooperative Red Teaming of a Prototype Survivable Service-Oriented System

نویسندگان

  • Partha Pal
  • Michael Atighetchi
  • Andrew Gronosky
  • Joseph Loyall
  • Charles Payne
  • Asher Sinclair
  • Brandon Froberg
  • Robert Grant
چکیده

An increasing number of military systems are being developed using service orientation. Some of the features that make service orientation appealing, like loose coupling, dynamism and composition-oriented system construction, make securing service-based systems more complicated. We have been developing technologies for Advanced Protected Services (APS) to improve the resilience and survival of services under cyber attack. These technologies introduce a layer to absorb, contain, and adapt to cyber attacks before attacks reach critical services. This paper describes an evaluation of these advanced protection technologies using cooperative red teaming. In cooperative red teaming, an independent red team launches attacks on a protected enclave in order to evaluate the efficacy and efficiency of the protection technologies, but the red team is provided full knowledge of the system under test and its protections, and is given escalating levels of access to the system. The red team also operates within agreed upon rules of engagement designed to focus their effort on useful evaluation results. Apart from presenting the evaluation results, we also discuss cooperative red teaming as an effective means of evaluating cyber security. Keywords-component; Service-Oriented Architecture, Survivability, Adaptive Security, Red Team Evaluation

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Cyber Security and Trusted Computing

An increasing number of military systems are being developed using Service Oriented Architecture (SOA). Some of the features that make SOA appealing, like loose coupling, dynamism and composition-oriented system construction, make securing service-based systems more complicated. We have been developing Advanced Protected Services (APS) technologies for improving the resilience and survival of S...

متن کامل

Red Teaming Military Intel based on Neutrosophic Cognitive Mapping

One of the key methods of ensuring effectiveness and actionability of military intelligence is “Red Teaming”. Red Teaming involves questioning the conventional analyst-driven military intelligence constructs. This paper proposes a new Red teaming approach based on Neutrosophic Cognitive Mapping, that helps combine various multi-disciplinary intelligence inputs in a non-linear and complex manner...

متن کامل

Collaborative Red Teaming for Anonymity System Evaluation

This paper describes our experiences as researchers and developers during red teaming exercises of the SAFEST anonymity system. We argue that properly evaluating an anonymity system — particularly one that makes use of topological information and diverse relay selection strategies, as does SAFEST— presents unique challenges that are not addressed using traditional red teaming techniques. We pre...

متن کامل

Analysis of Key Installation Protection using Computerized Red Teaming

This paper describes the use of genetic algorithms (GAs) for computerized red teaming applications, to explore options for military plans in specific scenarios. A tool called Optimized Red Teaming (ORT) is developed and we illustrate how it may be utilized to assist the red teaming process in security organizations, such as military forces. The developed technique incorporates a genetic algorit...

متن کامل

Building Survivable Services Using Redundancy and Adaptation

Survivable systems—that is, systems that can continue to provide service despite failures, intrusions, and other threats—are increasingly needed in a wide variety of civilian and military application areas. As a step toward realizing such systems, this paper advocates the use of redundancy and adaptation to build survivable services that can provide core functionality for implementing survivabi...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014