Doers, not Watchers: Intelligent Autonomous Agents are a Path to Cyber Resilience

01/26/2022
by   Alexander Kott, et al.
0

Today's cyber defense tools are mostly watchers. They are not active doers. To be sure, watching too is a demanding affair. These tools monitor the traffic and events; they detect malicious signatures, patterns and anomalies; they might classify and characterize what they observe; they issue alerts, and they might even learn while doing all this. But they don't act. They do little to plan and execute responses to attacks, and they don't plan and execute recovery activities. Response and recovery - core elements of cyber resilience are left to the human cyber analysts, incident responders and system administrators. We believe things should change. Cyber defense tools should not be merely watchers. They need to become doers - active fighters in maintaining a system's resilience against cyber threats. This means that their capabilities should include a significant degree of autonomy and intelligence for the purposes of rapid response to a compromise - either incipient or already successful - and rapid recovery that aids the resilience of the overall system. Often, the response and recovery efforts need to be undertaken in absence of any human involvement, and with an intelligent consideration of risks and ramifications of such efforts. Recently an international team published a report that proposes a vision of an autonomous intelligent cyber defense agent (AICA) and offers a high-level reference architecture of such an agent. In this paper we explore this vision.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/28/2018

Initial Reference Architecture of an Intelligent Autonomous Agent for Cyber Defense

This report describes an initial reference architecture for intelligent ...
research
06/07/2018

Towards an Active, Autonomous and Intelligent Cyber Defense of Military Systems: the NATO AICA Reference Architecture

Within the future Global Information Grid, complex massively interconnec...
research
11/25/2019

When Autonomous Intelligent Goodware will Fight Autonomous Intelligent Malware: A Possible Future of Cyber Defense

In the coming years, the future of military combat will include, on one ...
research
04/24/2023

Autonomous Intelligent Cyber-defense Agent: Introduction and Overview

This chapter introduces the concept of Autonomous Intelligent Cyber-defe...
research
08/20/2021

A Quantitative Framework for Network Resilience Evaluation using Dynamic Bayesian Network

Measuring and evaluating network resilience has become an important aspe...

Please sign up or login with your details

Forgot password? Click here to reset