Download No Slide Title

Survey
yes no Was this document useful for you?
   Thank you for your participation!

* Your assessment is very important for improving the workof artificial intelligence, which forms the content of this project

Document related concepts

Distributed firewall wikipedia , lookup

Cryptanalysis wikipedia , lookup

Signals intelligence wikipedia , lookup

Disaster recovery plan wikipedia , lookup

Computer security wikipedia , lookup

Cyberattack wikipedia , lookup

Computer and network surveillance wikipedia , lookup

Transcript
Explaining & Recovering from Computer Break-ins
New Ideas
•
Forensic analysis of intrusions uses
database of current vulnerabilities and
exploits
•
Analysis drives explanation-based
recommendation of steps for recovery
and prevention
•
Automated reporting from sites
updates database used in analyzing
subsequent attacks
Impact
•
•
•
•
DoD Information Security improved by
DERBI providing expertise to widely
distributed, minimally trained System
Administrators
Crisis response improved by current
information distributed via database
Downtime and exposure minimized by
nullifying current attacks
Situation awareness raised by
reporting coverage and accuracy
Schedule
FY98
Exploit database
Intrusion indicators
knowledge base
Evidential correlations
among indicators
Explanation and
reporting
Recovery and repair
Artificial Intelligence Center, SRI International: Mabry Tyson
FY99 FY00