DocumentCode :
547498
Title :
Using a novel behavioral stimuli-response framework to Defend against Adversarial Cyberspace Participants
Author :
Bilar, Daniel ; Saltaformaggio, Brendan
Author_Institution :
Dept. of Comput. Sci., Univ. of New Orleans, New Orleans, LA, USA
fYear :
2011
fDate :
7-10 June 2011
Firstpage :
1
Lastpage :
16
Abstract :
Autonomous Baiting, Control and Deception of Adversarial Cyberspace Participants (ABCD-ACP) is an experimental defensive framework against potentially adversarial cyberspace participants, such as malicious software and subversive insiders. By deploying fake targets (called baits/stimuli) onto a virtualized environment, the framework seeks to probabilistically identify suspicious participants through aggregate suspicious behavior, subvert their decision structure and goad them into a position favorable to the defense. Baits include simulating insertion of readable and writable drives with weak or no password, marked doc/pdf/txt/exe/cad/xls/dat files, processes with popular target names and processes that detect thread injections. This approach bears some similarities to the concept of subverting an enemy´s OODA (Observe, Orient, Decide, and Act) loop, an information warfare strategy which seeks to proactively influence and change enemy behavior. By controlling perception of the environment, this approach similarly seeks to influence adversarial participants´ decision complexity, noise levels, effectiveness and ultimately their ability to fulfill their mission. This is a work in progress: The conceptual framework is described, and implemented baits and preliminary empirical results are presented. The long term project end vision is an autonomic framework playing a repeated, dynamic, imperfect information, non-cooperative stimuli-response game which probabilistically identifies, then impedes, quarantines, subverts, possibly attributes and possibly inoculates against suspected adversarial cyberspace participants.
Keywords :
computer viruses; virtualisation; work in progress; adversarial cyberspace participants; autonomous baiting-control-deception; behavioral stimuli-response framework; decision structure; doc-pdf-txt-exe-cad-xls-dat files; enemy behavior; fake targets; information warfare strategy; noncooperative stimuli-response game; observe-orient-decide-act loop; readable-writable drives; suspicious behavior; suspicious participants; thread injections; virtualized environment; work in progress:; Aggregates; Complexity theory; Cyberspace; Games; Malware; Probabilistic logic; Software; behavior; dynamic game; malware; stimuli; virtualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cyber Conflict (ICCC), 2011 3rd International Conference on
Conference_Location :
Tallinn
Print_ISBN :
978-1-61284-245-5
Electronic_ISBN :
978-9949-9040-3-7
Type :
conf
Filename :
5954708
Link To Document :
بازگشت