50
Innovate Shit Happens! Robert Ghanea-Hercock Chief Researcher in Centre for Information & Security Systems Research, BT Innovate 2009

Shit Happens!

  • Upload
    bunny

  • View
    87

  • Download
    0

Embed Size (px)

DESCRIPTION

Shit Happens!. Robert Ghanea-Hercock Chief Researcher in Centre for Information & Security Systems Research, BT Innovate 2009. A D A S T R A L P A R K. EXCHANGE IN GREENOCK WITH OPERATORS CIRCA 1908. Unleashing open innovation. Customers. BT FON. BT Vision. Future services. - PowerPoint PPT Presentation

Citation preview

Page 1: Shit Happens!

Innovate

Shit Happens!Robert Ghanea-HercockChief Researcher in Centre for Information & Security Systems Research, BT Innovate2009

Page 2: Shit Happens!

© British Telecommunications plc

A D A S T R A L P A R K

Page 3: Shit Happens!

© British Telecommunications plc

EXCHANGE IN GREENOCK WITH OPERATORS CIRCA 1908

Page 4: Shit Happens!

© British Telecommunications plc

Unleashing open innovation

Future services

BT Snap&Send

BT FON

Customers

BT Vision

Page 5: Shit Happens!

© British Telecommunications plc

• Motivation– Autonomous Cyber Defence Solutions

• Where we are– In trouble!

• Research– Biology & Artificial Immune Systems– Self* systems– Complex Networks, Dynamics and Topology

• Conclusions

Page 6: Shit Happens!

© British Telecommunications plc

• Next Generation Web Research

– Semantic Business Intelligence

• ICT Infrastructure Virtualisation

– Policy based management

• Service Management Research

– Adaptive ICT

• Automated management of network, storage and computing

• Information Security Research

– Security Architectures Research

– Enterprise Risk Research

Overview of Centre for Information & Security Systems Research

Page 7: Shit Happens!

© British Telecommunications plc

Page 8: Shit Happens!

© British Telecommunications plc

BT Pervasive ICT Centre

Page 9: Shit Happens!

© British Telecommunications plc

Real-time performance & risk intelligence

Page 10: Shit Happens!

© British Telecommunications plc

Motivation

• Static network security techniques are failing

• Cyber Defence must become Adaptive & Autonomous

• Goal: Resilient and self-healing Enterprise systems

Page 11: Shit Happens!

© British Telecommunications plc

Biological Defence as a model

• Artificial Immune Systems (Forrest et al)• Biological defence examples

– External (teeth, claws etc)– Internal (lymphatic network & immune system)– Social networks in animal groups (Soldier Ants,

herding, swarms..)

Page 12: Shit Happens!

© British Telecommunications plc

Page 13: Shit Happens!

© British Telecommunications plc

Page 14: Shit Happens!

© British Telecommunications plc

The Problem

• Attacks occur at machine speed 10-6 sec• Responses at human speed 103 sec• Economics trades cost of response with risk• Information Assurance boring• Business Continuity, dull and expensive• Humans are very, very, bad at risk assessment

Page 15: Shit Happens!

© British Telecommunications plc

15

Page 16: Shit Happens!

© British Telecommunications plc

Network Dynamics & Topology

• Topology impacts spread of viral/self-replicating processes (Satorras & Vespignani 2001)

• “Error and attack tolerance in complex networks”, Albert R., Jeong H., and Barabási A., Nature 406 , 378 (2000).

• In a Small-World: Topology counts

Page 17: Shit Happens!

© British Telecommunications plc

Past & Future Defence

Page 18: Shit Happens!

© British Telecommunications plc

Simulated tactical network under attack

Page 19: Shit Happens!

© British Telecommunications plc

With adaptive link allocation

Page 20: Shit Happens!

© British Telecommunications plc

NetStress Topology Analysis Toolkit

Page 21: Shit Happens!

© British Telecommunications plc

BT Pervasive ICT Centre

BT Exact - Agent Immunology ModelAgent-based Modelling of Anti-viral systems

• Two-dimensional discrete spatial world model, in which a population of artificial agents interact, move, and infect each other: based on the Sugarscape model (Epstein and Axtell 1996).

• Cooperative exchange of simulated antibodies, used to create group immunity

• Built on the REPAST agent toolkit from the University of Chicago

(http://repast.sourceforge.net/).

Page 22: Shit Happens!

© British Telecommunications plc

Page 23: Shit Happens!

© British Telecommunications plc

0 200 400 600 800 10000

100

200

300

400

No. of iterations i.

Ave

rage

age

nt i

nfec

tion

lev

el

xi

zi

i

Graph showing decrease in average viral infection level without, and with shared antibodies between agents.

Page 24: Shit Happens!

© British Telecommunications plc

Nexus Middleware

• Smart middleware for resilient & agile ICT Services

• Enables flexible applications composed of services + sensors in dynamic and unreliable networks

• Emphasis on– Robustness – Adaptivity – Runtime flexibility/re-configurable– Rapid deployment– Low cost

Page 25: Shit Happens!

© British Telecommunications plc

25

Page 26: Shit Happens!

© British Telecommunications plc

Rules of Resilience

• Engineer the Network to fail gracefully– Incorporate multiple-layers of defence (Defence

in Depth)• Use robust response mechanisms• Design out human options: choices = threats

• Resilience not Optimality

Page 27: Shit Happens!

© British Telecommunications plc

P2P Networks

• A virtual overlay network • Very resilient • Highly adaptive• Low cost deployment

• Automatic load balancing (e.g. Bittorrent)• BBC iPlayer = 5% UK traffic, 1 Million shows/week• But• Challenges: security and management e.g. Marine One

Page 28: Shit Happens!

© British Telecommunications plc

BT Pervasive ICT Centre

PHOBOS P2P Agent Authentication

Java TransceiverNode

Java TransceiverNode

Sockets and HTTP / SSL

Plugin Adapter Plugin Adapter

PhobosAgent

PhobosAgentMessage DB

Message Loggingand Forwarding

Module

Agent-based user authentication model

Page 29: Shit Happens!

© British Telecommunications plc

Technology Stack

Resource Management

Layer

Process Management Layer

Communication Layer

Interaction Layer

SOA P2P Semantic Web Information Integration

MonitoringMonitoringDiscoveryDiscovery SubstitutionSubstitution Selection/AllocationSelection/Allocation

CompositionCompositionExecutionExecution Querying/RetrievalQuerying/Retrieval

Publish/SubscribePublish/

SubscribeRPC/RMIRPC/RMI StreamingStreaming MulticastMulticast

KnowledgeManipulationKnowledge

ManipulationGoal

CreationGoal

CreationService

InteractionService

InteractionUser

AssistanceUser

Assistance

MonitoringMonitoringDiscoveryDiscovery SubstitutionSubstitution Selection/AllocationSelection/Allocation

CompositionCompositionExecutionExecution Querying/RetrievalQuerying/Retrieval

Publish/SubscribePublish/

SubscribeRPC/RMIRPC/RMI StreamingStreaming MulticastMulticast

KnowledgeManipulationKnowledge

ManipulationGoal

CreationGoal

CreationService

InteractionService

InteractionUser

AssistanceUser

Assistance

Agents & AC

Page 30: Shit Happens!

© British Telecommunications plc

Neural Adaptive Network Algorithm (SCAN)

• Algorithms for resilience in P2P middleware

– Frequency Rule

– Feedback rule

– Decay rule

– Dynamic Growth Rule

– Constrained virtual connection Rule

BT Pervasive ICT Centre

Page 31: Shit Happens!

© British Telecommunications plc

0 2000 4000 6000 8000 1 104

0

0.5

1

No. of iterations i.

Avg

. nod

e co

nnec

tions

as

a pe

rcen

tage

SCAN network resistance to a targeted attack (i.e. nodes with high degree k)

Page 32: Shit Happens!

© British Telecommunications plc

Nexus Architecture

Page 33: Shit Happens!

© British Telecommunications plc

Page 34: Shit Happens!

© British Telecommunications plc

Page 35: Shit Happens!

© British Telecommunications plc

• Visual Data Mining– Not just data visualisation

• Mixed-initiative operation– Automatic clustering & User feedback

• Learning to cluster better & auto-categorise– Artificial neural network

• Minimising cognitive load / Maximising tag quality– Tag suggestion

Cyclone

Page 36: Shit Happens!

© British Telecommunications plc

Cyclone

• Categorisation of unstructured information

Page 37: Shit Happens!

© British Telecommunications plc

MoD CWID 2008

Page 38: Shit Happens!

© British Telecommunications plc

The Cyclone Framework

2009 IEEE International Symposium on Intelligent Agents (IA 2009), Nashville, Tennessee, USA - 30th March 2009

Categorization Process

Page 39: Shit Happens!

© British Telecommunications plc

2009 IEEE International Symposium on Intelligent Agents (IA 2009), Nashville, Tennessee, USA - 30th March 2009

The Cyclone Framework Force-based Visual Clustering

Page 40: Shit Happens!

© British Telecommunications plc

• Simulated Physical Forces– Attracting and Repelling Forces

– Cosine Similarity to determine Force weights

2009 IEEE International Symposium on Intelligent Agents (IA 2009), Nashville, Tennessee, USA - 30th March 2009

The Cyclone Framework Force-based Visual Clustering

Page 41: Shit Happens!

© British Telecommunications plc

2009 IEEE International Symposium on Intelligent Agents (IA 2009), Nashville, Tennessee, USA - 30th March 2009

The Cyclone Framework

Page 42: Shit Happens!

© British Telecommunications plc

Page 43: Shit Happens!

© British Telecommunications plc

Human factors

43

Page 44: Shit Happens!

© British Telecommunications plc

44

Page 45: Shit Happens!

© British Telecommunications plc

Conclusion

• Cyber Defence must become autonomous– Self*, P2P, Topology design, Dynamics

• Autonomy vs. Control debate– More research required

• Resilience as a design principal– Pagodas

• Dependability needs sophisticated risk analysis• Human Factors

– Simpson's

Page 46: Shit Happens!

© British Telecommunications plc

Questions

• How autonomous should Cyber Security become?

• Is there any alternative?

• Will AI become a threat?

46

Page 47: Shit Happens!

© British Telecommunications plc

Links

• BT Security Solutions– http://www.counterpane.com/

• UK Cyber Security KTN – http://www.ktn.qinetiq-tim.net/

• Santa Fe Institute– www.arcs-workshop.org

Page 48: Shit Happens!

© British Telecommunications plc

Contact

Dr Robert Ghanea-Hercock

[email protected]

48

Page 49: Shit Happens!

© British Telecommunications plc

BT Pervasive ICT Centre

Page 50: Shit Happens!

© British Telecommunications plc