首页> 外文会议>IEEE Security and Privacy Workshops >A Case Study in Tailoring a Bio-Inspired Cyber-Security Algorithm: Designing Anomaly Detection for Multilayer Networks
【24h】

A Case Study in Tailoring a Bio-Inspired Cyber-Security Algorithm: Designing Anomaly Detection for Multilayer Networks

机译:量身定制生物启发式网络安全算法的案例研究:设计多层网络的异常检测

获取原文

摘要

Although bio-inspired designs for cybersecurity have yielded many elegant solutions to challenging problems, the vast majority of these efforts have been ad hoc analogies between the natural and human-designed systems. We propose to improve on the current approach of searching through the vast diversity of existing natural algorithms for one most closely resembling each new cybersecurity challenge, and then trying to replicate it in a designed cyber setting. Instead, we suggest that researchers should follow a protocol of functional abstraction, considering which features of the natural algorithm provide the efficiency/effectiveness in the real world, and then use those abstracted features as design components to build purposeful, tailored (perhaps even optimized) solutions. Here, we demonstrate how this can work by considering a case study employing this method. We design an extension of an existing (and ad hoc-created) algorithm, DIAMoND, for application beyond its originally intended solution space (detection of Distributed Denial of Service attacks in simple networks) to function on multilayer networks. We show how this protocol provides insights that might be harder or take longer to discover by direct analogy-building alone; in this case, we see that differential weighting of shared information by the providing network layer is likely to be effective.
机译:尽管以生物为灵感的网络安全设计为应对挑战性问题提供了许多优雅的解决方案,但这些努力中的绝大部分都是自然与人为设计的系统之间的临时类比。我们建议改进当前的方法,即搜索现有的自然算法的多样性,以找到与每个新的网络安全挑战最相似的一种,然后尝试在设计的网络环境中进行复制。相反,我们建议研究人员应遵循功能抽象的协议,考虑自然算法的哪些功能可提供现实世界中的效率/效果,然后将这些抽象功能用作设计组件来构建有目的的,量身定制的(也许甚至是经过优化的)解决方案。在这里,我们通过考虑采用此方法的案例研究来演示这是如何工作的。我们设计了现有算法(即临时创建的算法)DIAMoND的扩展,以便将其应用超出其最初预期的解决方案空间(在简单网络中检测到分布式拒绝服务攻击)以在多层网络上运行。我们将展示此协议如何提供仅通过直接类比构建可能难以发现或需要更长时间的见解;在这种情况下,我们看到提供网络层对共享信息进行差分加权可能是有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号