Generating automated cyber resilience policies for real-world settings is a challenging research problem that must account for uncertainties in system state over time and dynamics between attackers and defenders. In addition to understanding attacker and defender motives and tools, and identifying “relevant” system and attack data, it is also critical to develop rigorous mathematical formulations representing the defender's decision-support problem under uncertainty. Game-theoretic approaches involving cyber resource allocation optimization with Markov decision processes (MDP) have been previously proposed in the literature. However, as is the case in strategic card games such as poker, research challenges using game-theoretic approaches for practical cyber defense applications include equilibrium solvability, existence, and possible multiplicity. Moreover, mixed uncertainties associated with player payoffs also need to be accounted for within game settings. This paper proposes an agent-centric approach for cybersecurity decision-support with partial system state observability. Multiple partially observable MDP (POMDP) problems are formulated and solved from a cyber defender's perspective, against a fixed attacker type, using synthetic (notional) system and attack parameters estimated from a Monte Carlo based sampling scheme. The agent-centric problem formulation helps address equilibrium related research challenges and represents a step toward automated and dynamic cyber resilience policy generation and implementation.
Prior practices such as waterfall software development, project management, and IT process frameworks are being questioned, and workforce requirements changing in response. IT education must keep current with these digital trends. Present programs and curricula do not adequately meet the rapidly emerging demand for digitally-skilled professionals. To address this urgent need, the lightening talk discusses needs for digital transformation, Agile and DevOps skills. This lightening talk presents the first version of an IT curriculum reference guide recently developed for use in the Minnesota State Colleges and Universities system. The audience will be able to use this guide to embed digital and DevOps skills into new IT curriculum, modify existing IT curriculum, or develop new courses/programs for IT.
Changes in data generation sources such as social networks, mobile devices, and process automation, along with an increase in the number of instruments generating observational data have pushed beyond the boundaries of current day data analysis systems. New algorithms, specialized hardware systems, and computing paradigms are designed to solve problems exhibited by large datasets, but at the same time there is a dearth of flexible and easy to use tools to assess the effectiveness of these proposed solutions. Benchmarking tools are required to compare the performance and the cost associated with any Big Data system. This research focuses on a user-centric approach of building such tools and proposes a flexible, extensible, and easy to use framework to support performance analysis of Big Data systems. Finally, case studies from two different domains are presented to validate the framework.
As cyber attacks on enterprise systems and critical infrastructure increase in prevalence and severity, persistent presence of adversaries in these systems is a common theme. While there are many efforts and tools focused on locating and removing adversaries from cyber systems, there is an increasing need for automated, steerable response that happens in attack-relevant time scales-an active cyber defense. The research presented here describes design and implementation of a system (SEQUESTOR) to achieve a form of active defense at the network layer by using the output of multiple behavior models to drive differential routing of traffic through a core network. This approach is based on two assertions: 1) methods for detecting behavior that are inconsistent with a user's past are a proxy for compromised systems or credentials, but are subject to high rate of false positives; and 2) automatically changing the logical route taken by future traffic emanating from the potentially compromised system provides a means for graded response that makes is possible to balance the cost of false positive with the risk of allowing the behavior to continue. The presented system is a framework that combines behavior models in a modular way and allows for future models and responses to be incorporated. Ultimately, this is a model for how real-time situational awareness technologies can be coupled to automated responses as well as supporting steerable responses that provide decision support to human operators.
This report outlines techniques for extending benchmark generation products so they support uncertainty quantification by benchmarked systems. We describe how uncertainty quantification requirements can be presented to candidate analytical tools supporting SPARQL. We describe benchmark data sets for evaluating uncertainty quantification, as well as an approach for using our benchmark generator to produce data sets for generating benchmark data sets.
Mathematical concepts of order and ordering relations play multiple roles in semantic technologies. Discrete totally ordered data characterize both input streams and top-k rank-ordered recommendations and query output, while temporal attributes establish numerical total orders, either over time points or in the more complex case of start-end temporal intervals. But also of note are the fully partially ordered data, including both lattices and non-lattices, which actually dominate the semantic strcuture of ontological systems. Scalar semantic similarities over partially-ordered semantic data are traditionally used to return rank-ordered recommendations, but these require complementation with true metrics available over partially ordered sets. In this paper we report on our work in the foundations of order measurement in ontologies, with application to top-k semantic recommendation in workflows. We conclude that true ordered set metrics are strongly preferable to traditional semantic similarities.
research-article Share on A predictive defense system for the smart grid Authors: Ning Lu View Profile , Pengwei Du View Profile , Patrick Paulson View Profile , Frank Greitzer View Profile , Xinxin Guo View Profile , Mark Hadley View Profile Authors Info & Claims CSIIRW '11: Proceedings of the Seventh Annual Workshop on Cyber Security and Information Intelligence ResearchOctober 2011Article No.: 29Pages 1https://doi.org/10.1145/2179298.2179330Published:12 October 2011Publication History 0citation163DownloadsMetricsTotal Citations0Total Downloads163Last 12 Months0Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
This paper presents a smart distribution grid testbed to test or compare designs of integrated information management systems (I2MSs). An I2MS extracts and synthesizes information from a wide range of data sources to detect abnormal system behaviors, identify possible causes, assess the system status, and provide grid operators with response suggestions. The objective of the testbed is to provide a modeling environment with sufficient data sources for the I2MS design. The testbed includes five information layers and a physical layer; it generates multi-layer chronological data based on actual measurement playbacks or simulated data sets produced by the physical layer. The testbed models random hardware failures, human errors, extreme weather events, and deliberate tampering attempts to allow users to evaluate the performance of different I2MS designs. Initial results of I2MS performance tests showed that the testbed created a close-to-real-world environment that allowed key performance metrics of the I2MS to be evaluated.
This paper presents the modeling approach, methodologies, and initial results of setting up a multi-layer, hierarchical information management system (IMS) for the smart grid. The IMS allows its users to analyze the data collected by multiple control and communication networks to characterize the states of the smart grid. Abnormal, corrupted, or erroneous measurement data and outliers are detected and analyzed to identify whether they are caused by random equipment failures, human error, or tampering. Data collected from different information networks are crosschecked for data integrity based on redundancy, dependency, correlation, or cross-correlations, which reveal the interdependency between data sets. A hierarchically structured reasoning mechanism is used to rank possible causes of an event to enable system operators to proactively respond or provide mitigation recommendations to remove or neutralize the threats. The model satisfactorily identifies the cause of an event and significantly reduces the need to process myriads of data.
In this paper we contribute two methods that simplify the demands of knowledge elicitation for particular types of Bayesian networks. The first method simplify the task of providing probabilities when the states that a random variable takes can be described by a new, fully ordered state set in which a state implies all the preceding states. The second method leverages Dempster-Shafer theory of evidence to provide a way for the expert to express the degree of ignorance that they feel about the estimates being provided.
We describe a methodology and architecture to support the development of games in a predictive analytics context. These games serve as part of an overall family of systems designed to gather input knowledge, calculate results of complex predictive technical and social models, and explore those results in an engaging fashion. The games provide an environment shaped and driven in part by the outputs of the models, allowing users to exert influence over a limited set of parameters, and displaying the results when those actions cause changes in the underlying model. We have crafted a prototype system in which we are implementing test versions of games driven by models in such a fashion, using a flexible architecture to allow for future continuation and expansion of this work.
We present a method to measure the amount of structural distortion carried by an alignment between two taxonomic cores of ontologies represented as semantic hierarchies. We present our formalism based in metric order theory. We then illustrate the results of such an analysis on the Anatomy track of the 2008 Ontology Alignment Evaluation Initiative (OAEI).
DISCLAIMER This report was prepared as an account of work sponsored by an agency of the United States Government. Neither the United States Government nor any agency thereof, nor Battelle Memorial Institute, nor any of their employees, makes any warranty, express or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, apparatus, product, or process disclosed, or represents that its use would not infringe privately owned rights. Reference herein to any specific commercial product, process, or service by trade name, trademark, manufacturer, or otherwise does not necessarily constitute or imply its endorsement, recommendation, or favoring by the United States Government or any agency thereof, or Battelle Memorial Institute. The views and opinions of authors expressed herein do not necessarily state or reflect those of the United States Government or any agency thereof.
Initial delivery for mathematical analysis of the Omega Ontology. We provide an analysis of the hierarchical structure of a version of the Omega Ontology currently in use within the US Government. After providing an initial statistical analysis of the distribution of all link types in the ontology, we then provide a detailed order theoretical analysis of each of the four main hierarchical links present. This order theoretical analysis includes the distribution of components and their properties, their parent/child and multiple inheritance structure, and the distribution of their vertical ranks.
Semantic typing systems for ontological databases are dominated by structures characterized as semantic hierarchies: collections of linguistic concepts which are taxonomically organized in subsumption (“is-a”) and compositional (“has-part”) relations. The most prominent examples are perhaps the Gene Ontology (GO, www.geneontology.org [6]) and WordNet (wordnet.princeton.edu [4]), but most real-world ontologies have a similar structure: two large, interacting generalization and meronomic hierarchies, together with a collection of smaller, domain-specific, possibly nonhierarchical semantic relations. Our position is: