Prevention, Detection and Recovery from Cyber-Attacks Using a Multilevel Agent Architecture

Dennis Edwards, Sharon Simmons, Norman Wilde · 2007

Intelligent software agents offer great potential for improving the operation and response of power grids. These agents are networked applications that could be vulnerable to cyber attacks. The goal of this research is to prevent known attacks, and to reduce or eliminate the consequences of successful attacks. A multilevel security architecture is presented that contains small, verifiable agents at each level with a well defined duty. Layers are designed to intercept dangerous or malformed information before it has a chance to damage the computational agents. Cross-monitoring ensures that any malfunctioning agent in the multilayer system is detected and the consequences of the attack are prevented or corrected. At the lowest level of the architecture are the computational agents. These agents are replicated to provide redundancy. Each replicate is mutated using a novel technique to prevent an attack from succeeding. Our mutation engine alters the program without changing the functionality.

Read the paper · More papers on PaperTik