Security in Large-Scale Open Distributed Multi-Agent Systems
Michel A. Oey, Martijn Warnier, Frances M.T. Brazier · InTech eBooks · 2010
Designing large-scale distributed multi-agent systems that operate in open environments, such as the Internet, creates new challenges, especially with respect to security issues.Agents are autonomous, pro-active, communicative, goal-directed, often capable of learning, and sometimes mobile (8).Mobile agents traverse the network to access services and resources they need to achieve the goals they pursue.The potential of mobile agent technology in sectors such as E-Commerce (17; 18), E-Health (29) and E-Governance (10; 52) is well recognized.In these sectors, security issues such as authentication, authorization, privacy, and copyright are of utmost importance.Data access control is mandatory: by moving agents to the location at which data is stored, data access and processing can be done locally and controlled.Many security requirements need to be addressed for large-scale distributed multi-agent systems in open environments.The focus of this chapter lies on security requirements specific for agent systems rather than security requirements for distributed computer systems in general.Section 2 identifies the most relevant security requirements for agent systems.This set of requirements is a minimum that needs to be fulfilled for secure agent systems in open environments.Sections 3 through 7 discuss the security requirements and possible solutions in detail.The solutions are illustrated within the context of the AgentScape (20) agent platform.This platform has been chosen as it has been specially designed to be used in a large-scale, distributed, open environment.However, similar implementations of these solutions are possible in other agent platforms.The chapter closes with an overview of a number of well-known agent platforms, such as AgentScape (20), Ajanta (23), SeMoA (41), and JADE (5) with its security extensions JADE-S (34) and S-Agent (16).The discussion focuses on what techniques these agent systems have used to solve some of the discussed security requirements. Security Issues in Agent SystemsAn agent system, a specific type of distributed computer system, needs to address not only security requirements related to distributed computer systems, but also multi-agent system specific security requirements.This section identifies a minimum set of security requirements specific to multi-agent systems that needs to be fulfilled for it to operate securely in an open environment.6 www.intechopen.com Autonomous Agents 108 Principals in an Agent SystemConceptually, multi-agent systems are distributed, networked, computer systems in which agent owners run communicating agents that access resources on hosts, each of which runs an agent platform (i.e., an instance of an agent middleware) that is under the control of a platform administrator. 1 The bold terms are the major principals in a multi-agent system.Each of these principals faces security threats.A secure agent system must protect these principals and their communication with other principals against security threats.For example, secure communication is needed to protect the communication between two agents, but also between two platforms and between an agent and a platform or the agent's owner.In a largescale, distributed system, such as the Internet, communication is usually over long distances and can be intercepted or monitored.In a closed environment, all principals in an agent system are known in advance and usually trusted, therefore, security measures are often implicit.However, in a more open environment, more explicit security measures are needed to guard against security threats.Traditionally, security threats are described using the terms confidentiality, integrity, and availability: the CIA-triad (46).Confidentiality refers to the ability to prevent access by those that are not authorized.Integrity refers to the ability to prevent any unauthorized modification.Availability refers to keeping resources accessible at all times to authorized parties.A prerequisite for guarding confidentiality, integrity, and availability is identity management (9), which encompasses naming and authentication.Naming is the ability to identify each individual principal in an agent system.Authentication is the ability to verify a principal's identity.For example, reliable authentication is needed as malicious parties may want to impersonate certain principals in order to gain access to that principal's privileges.The next sections look at security threats in an agent system from the viewpoint of the two most important stakeholders in an agent system: the agent owner and the agent platform's administrator. How to referenceIn order to correctly reference this scholarly work, feel free to copy and paste the following: