论文标题
行动者,而不是观察者:智能自主代理是网络弹性的途径
Doers, not Watchers: Intelligent Autonomous Agents are a Path to Cyber Resilience
论文作者
论文摘要
当今的网络防御工具主要是观察者。他们不是活跃的行动。可以肯定的是,观看也是一件苛刻的事情。这些工具监视流量和事件;他们发现恶意的签名,模式和异常。他们可能会对观察到的内容进行分类和特征。他们发出警报,甚至在完成所有这些方面也可能会学习。但是他们不采取行动。他们几乎没有计划和执行对攻击的回应,也不会计划和执行恢复活动。响应和恢复 - 网络弹性的核心要素留给人类网络分析师,事件响应者和系统管理员。我们相信事情应该改变。网络防御工具不应仅仅是观察者。他们需要成为行动者 - 积极的战斗机,以保持系统对网络威胁的韧性。这意味着他们的能力应包括对妥协的快速响应(初期或已经成功)的快速响应,以及有助于整体系统弹性的迅速恢复。通常,在没有任何人类参与的情况下,需要进行反应和恢复工作,并明智地考虑了这种努力的风险和后果。最近,一支国际团队发布了一份报告,该报告提出了自主智能网络防御代理(AICA)的愿景,并提供了这种代理商的高级参考架构。在本文中,我们探讨了这一愿景。
Today's cyber defense tools are mostly watchers. They are not active doers. To be sure, watching too is a demanding affair. These tools monitor the traffic and events; they detect malicious signatures, patterns and anomalies; they might classify and characterize what they observe; they issue alerts, and they might even learn while doing all this. But they don't act. They do little to plan and execute responses to attacks, and they don't plan and execute recovery activities. Response and recovery - core elements of cyber resilience are left to the human cyber analysts, incident responders and system administrators. We believe things should change. Cyber defense tools should not be merely watchers. They need to become doers - active fighters in maintaining a system's resilience against cyber threats. This means that their capabilities should include a significant degree of autonomy and intelligence for the purposes of rapid response to a compromise - either incipient or already successful - and rapid recovery that aids the resilience of the overall system. Often, the response and recovery efforts need to be undertaken in absence of any human involvement, and with an intelligent consideration of risks and ramifications of such efforts. Recently an international team published a report that proposes a vision of an autonomous intelligent cyber defense agent (AICA) and offers a high-level reference architecture of such an agent. In this paper we explore this vision.