The increasing complexity of attacks has given rise to varied security applications tackling profound tasks, ranging from alert triage to attack reconstruction. Yet, security products, such as Endpoint Detection and Response, bring together applications that are developed in isolation, trigger many false positives, miss actual attacks, and produce limited labels useful in supervised learning schemes. To address these challenges, we propose DrSec-a system employing self-supervised learning to pre-train foundation language models (LMs) that ingest event-sequence data and emit distributed representations for processes. Once pre-trained, the LMs can be adapted to solve different downstream tasks with limited to no supervision, helping unify the currently fractured application ecosystem. We trained DrSec with two LM types on a real-world dataset containing similar to 91M processes and similar to 2.55B events, and tested it in three application domains. We found that DrSec enables accurate, unsupervised process identification; outperforms leading methods on alert triage to reduce alert fatigue (e.g., 75.11% vs. similar to 64.31% precision-recall area under curve); and accurately learns expert-developed rules, allowing tuning incident detectors to control false positives and negatives.
—Given the importance of cryptography to modern security and privacy solutions, it is surprising how little attention has been given to the problem of cryptographic agility , or frameworks enabling the transition from one cryptographic algorithm or implementation to another. In this paper, we argue that traditional notions of cryptographic agility fail to capture the challenges facing modern enterprises that will soon be forced to implement a disruptive migration from today’s public key algorithms (e.g., RSA, ECDH) to quantum-safe alternatives (e.g., CRYSTALS-KYBER). After discussing the challenge of real-world cryptographic transition at scale, we describe our work on enterprise-level cryptographic agility for secure communications based on orchestrated cryptographic providers . Our policy-driven approach, prototyped in service mesh, provides a much-needed re-envisioning for cryptographic agility and highlights what’s missing today to enable disruptive cryptographic change at scale.
Gaps facing the industry as quantum safe algorithms move closer to standardization.
Quantum computing advances threaten the security of today's public key infrastructure, and have led to the pending standardization of alternative, quantum-resistant key encapsulation and digital signature cryptography schemes. Unfortunately, authentication algorithms based on the new post-quantum (PQ) cryptography create significant performance bottlenecks for TLS due to larger certificate chains which introduce additional packets and round-trips. The TLS handshake slowdown will be unacceptable to many applications, and detrimental to the broader adoption of quantum safe cryptography standards. In this paper, we propose a novel framework for Intermediate Certificate Authority (ICA) certificate suppression in TLS that reduces the authentication message size and prevents excessive round-trip delays. Our approach utilizes an approximate membership query (AMQ) data structure (probabilistic filter) to advertise known ICA certs to remote TLS endpoints so that unnecessary ICA certificates are omitted from the TLS handshake exchange. We showcase the extend of the PQ authentication overhead challenge in TLS, and evaluate the feasibility of AMQ filters for ICA suppression in terms of space and computational overhead. Finally, we experimentally evaluate the potential gains form our approach and showcase a 70% reduction in exchanged ICA cert data that translates to 15--50 MB of savings in PQ TLS and for certain Web-based application scenarios.
: As the prospects for scaled quantum computing steadily improve, there is an important disruption emerging in response within the world of security: post-quantum cryptography, or PQC. In the 1990s, Peter Shor showed that if scaled quantum computers were to exist, they could be used to efficiently break trap door functions underlying our widely used public key cryptography algorithms (RSA, DSA, ECDSA, ECDH). Various US government agencies have issued reports on this concern, including NIST which embarked on a standardization effort to select new algorithms with the help of the cryptography community as of 2016. But while NIST will address the problem of new algorithms, many organizations feel puzzled at the uncertain timeline for PQC and the lack of guidance on the path forward with migration. In this paper, we discuss the problem of PQC readiness from an organization’s point of view, providing recommendations on how to understand the landscape and guidance on what can and should be done in a phased manner. While scaled quantum computing may seem a distant concern, we believe there are good reasons for an organization to start now in developing its understanding of the situation and creating a phased action plan toward PQC readiness.
Michael Devetsikiotis合作论文数Department of Electrical and Computer Engineering ;;North Carolina State University;Operations Research Program1