The science of cybersecurity and a roadmap to research
Book information
Description
Information technology has become pervasive in every way, from our phones and other small devices to our enterprise networks to the infrastructure that runs our economy. As the critical infrastructures of the United States have become more and more dependent on public and private networks, the potential for widespread national impact resulting from disruption or failure of these networks has also increased. Securing the nation's critical infrastructures requires protecting not only their physical systems but, just as important, the cyber portions of the systems on which they rely. This book examines the cybersecurity research roadmap in order to define a national R&D agenda that is required to enable us to get ahead of our adversaries and produce the technologies that will protect our information systems and networks into the future. Library of Congress Cataloging-in-Publication Data Contents Preface Science of Cybersecurity Abstract 1. executive Summary 2. Problem Statement and Introduction 3. Cyber-Security as Science - An Overview 3.1. Attributes for Cyber-Security 3.2. Guidance from other Sciences 3.2.1. Economics 3.2.2. Meteorology 3.2.3. Medicine 3.2.4. Astronomy 3.2.5. Agriculture 3.3. Security Degrades Over Time 3.3.1. Unix passwords 3.3.2. Lock bumping 3.4. The Role of Secrecy 3.5. Aspects of the Science of Cyber-Security 3.6. Some Science 3.6.1. Trust 3.6.2. Cryptography 3.6.3. Game theory 3.6.4. Model checking 3.6.5. Obfuscation 3.6.6. Machine learning 3.6.7. Composition of components 3.7. Applying the Fruits of Science 3.8. Metrics 3.9. The Opportunities of New Technologies 3.10. Experiments and Data 4. Model Checking 4.1. Brief Introduction to Spin and Promela 4.2. Application to Security 4.2.1. The Needham-Schroeder Protocol 4.2.2. Promela model of the protocol 4.3. Scaling Issues 4.4. Extracting Models from Code 4.5. Relationship to Hyper-Properties 5. The Immune System Analogy 5.1. Basic Biology 5.2. Learning from the Analogy 5.2.1. The need for adaptive response 5.2.2. A mix of sensing modalities 5.2.3. The need for controlled experiments 5.2.4. Time scale differences 5.2.5. Responses to detection 5.2.6. Final points 6. Conclusions and Recommendations A. Appendix: Briefers References A Roadmap for Cybersecurity Research Executive Summary Introduction Historical Background Current Context Document Format Background Future Directions Acknowledgments Current Hard Problems in INFOSEC Research 1. Scalable Trustworthy Systems Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of the practice? What is the status of current research? Future Directions On what categories can we subdivide this topic? What are the major research gaps? Near term Medium term Long term What are the challenges that must be addressed? What approaches might be desirable? What R&D is evolutionary and what is more basic, higher risk, game changing? Resources Measures of success What needs to be in place for test and evaluation? To what extent can we test real systems? 2. Enterprise-Level Metrics (ELMs) Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of the practice? What is the status of current research? Future Directions On what categories can we subdivide this topic? Definition Collection Analysis Composition Adoption What are the major research gaps? What are some exemplary problems for R&D on this topic? What R&D is evolutionary, and what is more basic, higher risk, game changing? Resources Measures of success What needs to be in place for test and evaluation? To what extent can we test real systems? 3. System Evaluation Life Cycle Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of the practice? What is the status of current research? Future Directions On what categories can we subdivide this topic? Requirements Design Development and Implementation Testing Deployment and Operations Decommissioning What are the major research gaps? What are some exemplary problems for R&D on this topic? What R&D is evolutionary, and what is more basic, higher risk, game changing? Resources Measures of success What needs to be in place for test and evaluation? To what extent can we test real systems? 4. Combatting Insider Threats Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of the practice? What is the status of current research? Future Directions On what categories can we subdivide this topic? What are the major research gaps? What are some exemplary problems for R&D on this topic? Collect and Analyze Detect Deter Protect Predict React What are the near-term, midterm, long-term capabilities that need to be developed? Near Term Medium Term Long Term What R&D is evolutionary and what is more basic, higher risk, game changing? Resources Measures of success To what extent can we test real systems? 5. Combatting Malware and Botnets Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of the practice? What is the status of current research? Future Directions On what categories can we subdivide this topic? What are the major research gaps? What are some exemplary problems for R&D on this topic? What R&D is evolutionary, and what is more basic, higher risk, game changing? Measures of success What needs to be in place for test and evaluation? To what extent can we test real systems? 6. Global-Scale Identity Management Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of the practice? What is the status of current research? Future Directions On what categories can we subdivide the topic? What are the major research gaps? Resources Measures of success What needs to be in place for test and evaluation? To what extent can we test real systems? 7. Survivability of Time-Critical Systems Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of practice? What is the status of current research? Future Directions On what categories can we subdivide the topics? What are the major research gaps? Detect React What are the challenges that must be addressed? What R&D is evolutionary and what is more basic, higher risk, game changing? Near term Medium term Long term Resources Measures of success What needs to be in place for test and evaluation? To what extent can we test real systems? 8. Situational Understanding and Attack Attribution Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of the practice? What is the status of current research? Future Directions On what categories can we subdivide this topic? What are the major gaps? What are some exemplary problems for R&D on this topic? What R&D is evolutionary and what is more basic, higher risk, game changing? Resources Measures of success What needs to be in place for test and evaluation? To what extent can we test real systems? 9. Provenance Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of practice? What is the status of current research? Future Directions On what categories can we subdivide the topic? What are the major research gaps? What are some exemplary problem domains for R&D in this area? What R&D is evolutionary, and what is more basic, higher risk, game changing? Resources Measures of success What needs to be in place for test and evaluation? 10. Privacy-Aware Security Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of practice? What is the status of current research? Future Directions On what categories can we subdivide the topic? What are the major research gaps? Selective disclosure and privacy-aware access Specification frameworks Policy issues What are some exemplary problems for R&D on this topic? What R&D is evolutionary and what is more basic, higher risk, game changing? Near term Medium term Long term Game changing Resources Measures of success What needs to be in place for test and evaluation? 11. Usable Security Background What is the problem being addressed? What are the potential threats? Who are the potential beneficiaries? What are their respective needs? What is the current state of practice? What is the status of current research? Future Directions On what categories can we subdivide the topic? What are the major research gaps? Hard problems Other areas we might draw on What are some exemplary problems for R&D on this topic? What R&D is evolutionary and what is more basic, higher risk, game changing? Near term Medium term Resources Measures of success What needs to be in place for test and evaluation? To what extent can we test real systems? Appendix A. Interdependencies among Topics Topic 1. Scalable Trustworthy Systems Topic 2. Enterprise-Level Metrics (ELMs) Topic 3. System Evaluation Life Cycle Topic 4. Combatting Insider Threats Topic 5. Combatting Malware and Botnets Topic 6. Global-Scale Identity Management Topic 7. Survivability of Time Critical Systems Topic 8. Situational Understanding and Attack Attribution Topic 9. Provenance Topic 10. Privacy-Aware Security Topic 11. Usable Security Appendix B. Technology Transfer B.1. Introduction B.2. Fundamental Issues for Technology Transition What are likely effective ways to transfer the technology? B.3. Topic-Specific Considerations Topic 1: Scalable Trustworthy Systems Topic 2: Enterprise-Level Metrics (ELMs) B.4 Forcing Functions (Some Illustrative Examples) Government Academia Industry Appendix C. List of Participants in the Roadmap Development Appendix D. Acronyms References Chapter Sources Index
Similar books
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF
The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians
1809 · PDF
Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix
2008 · PDF