Reasoning about Timeliness for Computer Security Reactions: CIRCA and AIA Experiment 001
نویسندگان
چکیده
DARPA’s Autonomic Information Assurance (AIA) program is exploring the use of automatic systems to detect and respond, at computer speeds, to high-speed computer security attacks. The first formal experiment of the AIA program, termed AIA Experiment 001, explored the relationship between the effectiveness of responses to scripted security attacks and the speed of those responses [5]. This paper discusses how the CIRCA system for automatic controller synthesis can reason about the problem explored in AIA Experiment 001, can automatically predict the results of the experiment, and can exploit those predictions itself. By modeling the individual steps of the attack and the potential response actions, CIRCA can explicitly compute the response-time threshold distinguishing effective responses from ineffective responses. In fact, CIRCA can use this knowledge to build a reactive security controller that guarantees to respond quickly enough to prevent the attacker from succeeding. To show how CIRCA does this reasoning, we begin with a brief review of Experiment 001 and its results, then provide a short review of how CIRCA works. We then illustrate how CIRCA models the experiment and builds a controller that will always defeat the attack. The intent is to clearly illustrate CIRCA’s reasoning processes that build guaranteed controllers, and how they relate to information assurance. This paper is not meant to be an introduction to CIRCA; instead, our goal is to describe how CIRCA can address the type of information security challenges explored in Experiment 001. Accordingly, we refer readers to other publications [3, 4, 1] for more comprehensive information on CIRCA, its planning algorithms, and related work.
منابع مشابه
Reasoning About Knowledge: A Survey
In this survey, I attempt to identify and describe some of the common threads that tie together work in reasoning about knowledge in such diverse elds as philosophy, economics, linguistics, artiicial intelligence, and theoretical computer science, with particular emphasis on work of the past ve years, particularly in computer science. It is a revised and updated version of a paper entitled \Rea...
متن کاملToward Decision-Theoretic CIRCA with Application to Real-Time Computer Security Control
We report our on-going work toward extending the CIRCA (Cooperative Intelligent Real-Time Control Architecture) with decision-theoretic reasoning capabilities. By explicitly modeling uncertainty using probabilities, and goals using utilities, the new CIRCA planner can now appeal to the powerful decision-theoretic paradigm of maximizing expected utility to find the best plan. We discuss represen...
متن کاملCirca: the Cooperative Intelligent Real-time Control Architecture Circa: the Cooperative Intelligent Real-time Control Architecture Table of Contents
CIRCA: THE COOPERATIVE INTELLIGENT REAL-TIME CONTROL ARCHITECTURE by David John Musliner Co-Chairs: Kang G. Shin and Edmund H. Durfee The Cooperative Intelligent Real-time Control Architecture (CIRCA) is a novel architecture for intelligent real-time control that can guarantee to meet hard deadlines while still using unpredictable, unrestricted AI methods. CIRCA includes a real-time subsystem u...
متن کاملمقایسه ی کیفیت مستندات پروندههای پزشکی بیماران بستری در بیمارستانهای عمومی دانشگاه علوم پزشکی ایران و تامین اجتماعی شهر تهران : 1386
Introduction: Quality of patients care is directly linked with medical documentation quality, because in all medical professions related to patient care, quality of decisions depends on information quality. Thus, in this study two main populations that offer medical care in country, Ministry of Health (MoH) and Social security Organization, were selected to measure access rate, and level of med...
متن کاملCIRCA: a cooperative intelligent real-time control architecture
Most research into applying AI techniques to real-time control problems has limited the power of AI methods or embedded \reactivity" in an AI system. We present an alternative, cooperative architecture that uses separate AI and real-time subsystems to address the problems for which each is designed; a structured interface allows the subsystems to communicate without compromising their respectiv...
متن کامل