Combining Trust and Behavioral Analysis to Detect Security Threats in Open Environments

Owen McCusker, Joel Glanfield, Scott Brunza, Carrie E. Gates, John McHugh, Diana Paterson · 2010

Open computing environments are under a deluge of network attacks from complex threats. These threats are distributed, decentralized, dynamic, and operate over multiple timescales. Trusted Computing environments provide a means to manage cryptographic identity and authentication operations in the form of static assertions, but were not developed to provide complete end-to-end security for heterogeneous environments such as the NATO Architecture Framework (NAF). There is a gap in the contextual understanding of trust that reaches beyond identity to the behavior of that identity. The challenge in deriving trust, and ultimately risk, from network behavior is that it is inherently subjective compared to identity. Trust is defined in the Webster dictionary as the “assured reliance on the character, ability, strength, or truth of someone or something ” 1. When we trust a person there is the notion of identity; e.g., family, and the implied context of trust. Structural identity alone cannot be used to define the overall measure of an entity’s trust; the notion of behavior must be taken into account. Trust then becomes a layered concept that can be realized by a number of perspectives including an object’s identity along with the behavior of that object. In assessing the trustworthiness of an entity; e.g., host, within a complex enterprise, a cyber defense strategy should take into account various signals regarding identity and behavior that promote an attestation of a digital “self and

Read the paper · More papers on PaperTik