Optimal response through policy and state-based modeling
Marcus Tylutki, Karl Levitt · 2005
It has long been realized within the field of computer security that perfect attack protection is impossible. Current response systems have incorporated many types of responses, but are generally limited in scope by the policies with which they can comply, the responses they can initiate, and the expressiveness of alerts and state information they represent. Additionally; current response systems generally assume that their responses will be completely effective. The goal of this work is to present a response model that incorporates: several types of responses, expressive and dynamic policies, a feedback control loop to account for partially effective responses, and a model for representing alert and state based information. We present an abstract response model that incorporates all of these properties, compare it to related work, and discuss new aspects to response, such as response fusion and responses where backoff is possible. We also present a low-level response model and implementation that highlight the usefulness of control theory in low-level response agents. Responses can be used to reconfigure intrusion detection sensors. These are useful for dynamic policies that frequently change. A sensor reconfiguration model is presented that relates the sensor configuration detection capabilities and policy constraints to event classes within a model. This enables the model to produce sensor configurations that satisfy a policy with respect to the current system state. An implementation that combines the high-level response model and the sensor reconfiguration model is presented, along with experiments that highlight the usefulness of both models. The implementation provides a modular XML-based framework, incorporating host-based agents, a correlation agent, and a response agent, so that alternative real intrusion detection systems or response agents can be incorporated. Using these models, we show how to assess the relative global and local security of a system with respect to its capability to detect and respond to specific types of events.