Showing posts with label computer. Show all posts
Showing posts with label computer. Show all posts

Monday, April 19, 2010

The Future of High-Technology Crime: A Parallel Delphi Study

This study conducted by Larry E. Coutorie in 1995 is a follow-up to a 1980s study using the Delphi Technique to forecast the future of high-technology crimes. One of the purposes of this study is to give law enforcement a forecast of where high-tech crimes are headed, since most other techniques only allow reactionary responses.

The Experiment:
The study was conducted using two panels. One was comprised of “traditional” experts, or people already in the high-tech law enforcement field, and “nontraditional” experts, member of hacker and cracker groups recommended by other experts. Two groups on experts were sent three rounds of questionnaires with the following questions, refined each time by the groups’ responses to the previous questionnaire.
  1. In your opinion, what area(s) of high technology will be the focus of criminal activity in the next ten years?
  2. What form(s) do you believe this activity will take?
  3. What steps should be taken now to prepare the police to combat this criminal activity?
  4. Do you believe the responsibility for criminal investigation of high-technology crimes will be primarily that of government or private businesses? Why?
  5. Do you believe the responsibility for crime prevention activities regarding high-technology crimes will be primarily that of government or private businesses? Why?
Findings:
Each groups’ perspective diverged significantly from the first round of questioning onward. However, at the end of the three questionnaires, a consensus on several issues was identified.
  • Likely high-tech future crime areas include computer system attacks via telecommunications, a growing increase in computer-assisted fraud, and computer assisted data manipulation or theft.
  • Crime will take the form of software piracy, increased incidents of computer assisted counterfeiting, increased incidents of financial fraud, and increased attacks on computer systems via advanced technologies.
  • Preventative steps recommended include recruitment of individual with computer knowledge, increased public/private partnership, more training for law enforcement officers earlier in their career, and legislation that better defines jurisdiction.
  • At the time of this study experts forecasted private business would conduct the initial investigation and have an active participatory role in government investigations.
  • They also forecasted that private businesses would be responsible for protecting their own assets, with government assistance in identifying potential threats.

Saturday, April 3, 2010

Modeling Behavior of the Cyber Terrorist

According to the article “Modeling Behavior of the Cyber Terrorist” by Gregg Schundel and Bradley Wood, it is not clear whether the Cyber-Terrorist is real or simply a theoretical class of adversary. However, this work is based on the assumption that the Cyber-Terrorist is a very real potential threat to modern information systems.

The Experiment
In order to red team an unknown, potential adversary, a set of parameters are set for the red team to follow based on the Defense Advanced Research Project’s Agency’s (DARPA) understanding of terrorist behavior:
  • The cyber-terrorist is believed to have a level of sophistication somewhere between that of a sophisticated hacker and a foreign intelligence organization.
  • This adversary is assumed to be able to raise funds on the order of hundreds of thousands to a few million dollars, and he is willing to spend these funds to accomplish his mission.
  • This adversary is assumed to be able to acquire all design information on a system of interest.
  • This adversary is assumed to be very risk averse. Premature detection is a serious negative consequence for the cyber-terrorist.
  • This adversary has specific targets or goals in mind when they attack a given system.
  • The adversary will also expend only the minimum amount of resources needed to accomplish their mission.
  • The cyber-terrorist is assumed to be professional, creative, and very clever. They will seek unorthodox and original methods to accomplish their goals.

Findings
The Information Design Assurance Red Team (IDART) spent most of its time gathering intelligence on the target system. Their results were only considered successful if the team met their objectives and preserved stealth. In this study the red team followed the same basic process repeatedly, and gave up before mounting an attack with a risk threshold that was too high.

Conclusion
DARPA’s experience suggests some improvements to the process that they are using to model the cyber-terrorist adversary including the use of additional red teams, improving the scientific method used to record and test red team behavior, incorporating verified terrorist behavior, war-gaming cyber terrorist scenarios, and improving the library of possible approaches to difficult threats.

Red Teaming Experiments with Deception Technologies

With their study “Red Teaming Experiments with Deception Technologies,” Fred Cohen, et.al., conducted a series of 30 experimental assessments on the use of specific deceptive methods against human attackers in order to understand the role of deception in information processes.

The Experiment
In total, 5 experimental runs of duration 4 hours each were run on each of 6 exercises. This represents 30 runs, including deception "on" and deception "off" control groups (6 each) and random "on" "off" mixes (18).

Each run was preceded by a standard briefing and a run-specific briefing and followed by filling out of standard assessment forms, both individually by all team members and as a group. The exercises were of increasing intensity and difficulty so as to keep the participants challenged. Feedback was provided and varying amounts of information were disclosed to teams during the course of the experiment.

The participants, in this case, were students ranging in age from 16 to 38, all in computer-related fields, all with excellent grade point averages, all US citizens, and all interested in information protection, and all participating in an intensive program of study and research in this area.

Findings
The use of red teams in simulating the effectiveness of deception methods on human network attackers revealed several interesting results:
  • Teams which were not aware they were not working in a deceptive environment engaged in self-deception which hindered their progress. The study concluded that the threat of deception offers some protection against attackers.
  • Teams unknowingly operating under deceptive conditions who followed a deception to its logical end gave up on the problem earlier than the time allotted because they believed they had finished correctly.
  • For teams operating in a deceptive environment, even after being educated on the deceptive techniques that were being employed, were rarely able to move more rapidly past the deceptions, and often followed the same deceptive route they had learned in previous experiments.
  • Teams continually subjected to deception became disheartened and only 3 of the original 15 participants under deception finished the study, while 8 of 12 participants not working under deceptive conditions finished the study.

Conclusion
The net objective of combined deceptions is that attackers spend more time going down deception paths rather than real paths, that the deception paths are increasingly indifferentiable to the attackers, and that the defenders can gain time, insight, data, and control over the attackers while reducing defensive costs and improving outcomes. Content-oriented deception can be an effective deterrent against network attackers, and deception capabilities should be improved to combat highly skilled, long term network threats.

Wednesday, March 25, 2009

Enhancing Deliberation Through Computer Supported Argument Mapping

Tim van Gelder
Department of Philosophy, University of Melbourne, Australia; and Austhink



Summary
Tim van Gelder defines deliberation as "a form of thinking in which we decide where we stand on some claim in light of the relevant arguments." Although this is a common and important process, it is complicated and often conducted poorly. Gelder contends that deliberation can be improved by mapping out arguments, especially when the methodology utilizes the new computer tools available. An argument map is a presentation of reasoning in which the evidential relationships among claims are made wholly explicit using graphical or other non-verbal techniques. Argument mapping is producing such maps.

This fairly minimal or broad definition recommended by Gelder allows for enormous variety in argument maps. The point of an argument map is to present complex reasoning in a clear and unambiguous way, and mappers should use whatever resources work best. Currently, argument maps are mostly comprised of "box and arrow" diagrams. With technology expanding, other presentations are likely to count as argument mapping. For example, somebody may develop a way to present arguments in virtual 3D or through a virtual reality environment.

According to Gelder, at least four main factors explain the superiority of argument maps. These points concern the limitations of prose which are partly or wholly overcome by argument maps. 1) In prose, the reader has to figure out what the relationships among the claims are. In an argument diagram, in contrast, all relationships are made completely explicit using simple visual conventions. In practice, this relieves a huge burden. Readers can devote their mental energy to thinking about the argument itself rather than trying to figure out what the argument is. 2) Prose is a monochrome stream of words, sentences, and paragraphs. Prose does not use any color, shape, line, or position in space to convey information about the structure of the argument. We know, however, that our brains can process huge amounts of color, shape, and space information very quickly. In an argument map, color can be used to indicate in a matter of milliseconds whether a claim is being presented as reason or an objection. 3) Prose is sequential in nature. However, arguments are fundamentally not sequential. Arguments are more than just one thing after another; they are more complicated. 4) Using diagrams, we can to some extent take advantage of the way humans learn and understand. "We can place all the reasons over here and all the objections over there, or we can make stronger reasons bigger, or place them underneath (supporting) the conclusion."

Until now, argument maps have not really taken off as a practical tool for argument deliberation. Creating these diagrams by hand can be quite difficult. However, new computer software (both free and commercial) is making this method easier. New argument mapping pieces of software include Araucaria, Athena, and Reason!Able.




Reblog this post [with Zemanta]