DocumentCode :
3393181
Title :
A lightweight software control system for cyber awareness and security
Author :
Co, Michele ; Coleman, Clark L. ; Davidson, Jack W. ; Ghosh, Sudeep ; Hiser, Jason D. ; Knight, John C. ; Nguyen-Tuong, Anh
Author_Institution :
Dept. of Comput. Sci., Univ. of Virginia, Charlottesville, VA, USA
fYear :
2009
fDate :
11-13 Aug. 2009
Firstpage :
19
Lastpage :
24
Abstract :
Designing and building software that is free of defects that can be exploited by malicious adversaries is a difficult task. Despite extensive efforts via the application of formal methods, use of automated software engineering tools, and performing extensive pre-deployment testing, exploitable errors still appear in software. The problem of cyber resilience is further compounded by the growing sophistication of adversaries who can marshal substantial resources to compromise systems. This paper describes a novel, promising approach to improving the resilience of software. The approach is to impose a process-level software control system that continuously monitors an application for signs of attack or failure and responds accordingly. The system uses software dynamic translation to seamlessly insert arbitrary sensors and actuators into an executing binary. The control system employs the sensors to detect attacks and the actuators to effect an appropriate response. Using this approach, several novel monitoring and response systems have been developed. The paper describes our light-weight process-level software control system, our experience using it to increase the resilience of systems, and discusses future research directions for extending and enhancing this powerful approach to achieving cyber awareness and resilience.
Keywords :
formal verification; program testing; security of data; software tools; automated software engineering tools; cyber awareness; cyber security; extensive predeployment testing; formal methods; lightweight software control system; process-level software control system; software dynamic translation; Actuators; Application software; Automatic control; Computer security; Control systems; Lighting control; Process control; Resilience; Sensor systems; Software systems; Cyber Awareness; Cyber Security; Diversity; Randomization; Software Dynamic Translation; Virtual Execution;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Resilient Control Systems, 2009. ISRCS '09. 2nd International Symposium on
Conference_Location :
Idaho Falls, ID
Print_ISBN :
978-1-4244-4853-1
Electronic_ISBN :
978-1-4244-4854-8
Type :
conf
DOI :
10.1109/ISRCS.2009.5251353
Filename :
5251353
Link To Document :
بازگشت