Top Banner
1 Impacts of Autonomous Cyber Defence Michael Docking, DST Group Redefining R&D Needs for Australian Cyber Security UNSW ACCS at ADFA, November 16 th 2015 UNCLASSIFIED Approved for Public Release
21

Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

Mar 11, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

1

Impacts of Autonomous Cyber Defence

Michael Docking, DST Group

Redefining R&D Needs for Australian Cyber Security

UNSW ACCS at ADFA, November 16th 2015

UNCLASSIFIED

Approved for

Public Release

Page 2: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

2

1. The drivers for Autonomous Cyber Defence

2. The disruptive impacts for Australia:

• Enterprise Security

• Military and Unmanned Systems

• Cyber Warfare

3. Overview of the HINDER project

UNCLASSIFIED

Broad research topics Partnerships & collaboration }

Page 3: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

3

1. The drivers for Autonomous Cyber Defence

2. The disruptive impacts for Australia:

• Enterprise Security

• Military and Unmanned Systems

• Cyber Warfare

3. Overview of the HINDER project

UNCLASSIFIED

Broad research topics Partnerships & collaboration }

Page 4: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

4

R&D plan developed in consultation with Defence, industry and academia.

Available at: www.dsto.defence.gov.au

UNCLASSIFIED

Page 5: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

5

UNCLASSIFIED

Scale

Pace

Isolation

Key Autonomy Drivers Dull, Dirty & Dangerous?

Page 6: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

6

UNCLASSIFIED

Scale

Pace

Isolation

Key Autonomy Drivers

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Passive

Centralised

Active

Distributed

Network Defence Dull, Dirty & Dangerous?

Au

tom

atio

n

Page 7: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

7

Scale

Pace

Isolation

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Passive

Centralised

Active

Distributed

Key Autonomy Drivers Network Defence Intrusion detection,

prevention & response

Timely

Run continually

Fault tolerant

Resist subversion

Minimal overhead

Configurable

Adaptable

Scalable

Graceful degradation

UNCLASSIFIED

Au

tom

atio

n

Dynamic reconfig.

Page 8: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

8

Au

tom

atio

n

Scale

Pace

Isolation

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Passive

Centralised

Active

Distributed

Key Autonomy Drivers Network Defence

Remote control

Autonomous control

Threat Actors

Defeat

Intrusion detection, prevention & response

Timely

Run continually

Fault tolerant

Resist subversion

Minimal overhead

Configurable

Adaptable

Scalable

Graceful degradation

UNCLASSIFIED

Dynamic reconfig.

Page 9: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

9

1. The drivers for Autonomous Cyber Defence

2. The disruptive impacts for Australia:

• Enterprise Security

• Military and Unmanned Systems

• Cyber Warfare

3. Overview of the HINDER project

UNCLASSIFIED

Broad research topics Partnerships & collaboration }

Page 10: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

10

1. The drivers for Autonomous Cyber Defence

2. The disruptive impacts for Australia:

• Enterprise Security

• Military and Unmanned Systems

• Cyber Warfare

3. Overview of the HINDER project

UNCLASSIFIED

Australia has a cyber defence that acts rapidly to minimise damage (fight through) - enabling networks to support operations whilst under sustained cyber attack.

Broad research topics Partnerships & collaboration }

Page 11: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

11

1. The drivers for Autonomous Cyber Defence

2. The disruptive impacts for Australia:

• Enterprise Security

• Military and Unmanned Systems

• Cyber Warfare

3. Overview of the HINDER project

UNCLASSIFIED

Australia can reliably deploy military and unmanned systems into remote and hostile environments - equipped

with active defences to resist cyber threats.

Broad research topics Partnerships & collaboration }

Page 12: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

12

1. The drivers for Autonomous Cyber Defence

2. The disruptive impacts for Australia:

• Enterprise Security

• Military and Unmanned Systems

• Cyber Warfare

3. Overview of the HINDER project

UNCLASSIFIED

Australia has a resilient cyber defence that significantly raises the bar - forcing adversaries to build and expose

increasingly sophisticated tools and limiting their impact.

Broad research topics Partnerships & collaboration }

Page 13: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

13

UNCLASSIFIED

Wide Area Network

Operations Network

Intrusion Analyst

Client Network

Mobile Devices

Military Systems

Unmanned Vehicles

Protect & defend our networks

Sensing Data

Decisions

Monitor

Automation Human

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Page 14: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

14

UNCLASSIFIED

Wide Area Network

Operations Network

Intrusion Analyst

Client Network

Mobile Devices

Military Systems

Unmanned Vehicles

Poor observability

Isolation

Disruption

Protect & defend our networks

Sensing Data

Decisions

Monitor

Automation Human

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Reaction time

Response…

Encryption, Covert

channels, Insiders,

Avoidance

Page 15: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

15

UNCLASSIFIED

Wide Area Network

Operations Network

Intrusion Analyst

Client Network

Mobile Devices

Military Systems

Unmanned Vehicles

Host-based monitoring

Isolation

Disruption

Protect & defend our networks

Sensing Data

Decisions

Monitor Monitor

Monitor Monitor

Bottleneck, Latency x 2

Automation Human

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Reaction time

Response…

Page 16: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

16

UNCLASSIFIED

Wide Area Network

Operations Network

Intrusion Analyst

Client Network

Mobile Devices

Military Systems

Unmanned Vehicles

Security Command

Remote control

Isolation

Disruption

Protect & defend our networks

Policy Rules of

engagement

Sensing

Effects

Data

Decisions

Remotes Remotes

Remotes Remotes

Bottleneck, Latency x 2

Automation Human

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Reaction time

Page 17: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

17

UNCLASSIFIED

Wide Area Network

Operations Network

Intrusion Analyst

Client Network

Mobile Devices

Military Systems

Unmanned Vehicles

Security Command

Remote control

Isolation

Disruption

Protect & defend our networks

Policy Rules of

engagement

Sensing

Effects

Data

Decisions

Remotes Remotes

Remotes Remotes

Bottleneck, Latency x 2

Automation Human

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Page 18: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

18

UNCLASSIFIED

Wide Area Network

Operations Network

Intrusion Analyst

Client Network

Mobile Devices

Military Systems

Unmanned Vehicles

Security Command

Fusion and reasoning under uncertainty

Autonomic & distributed computing

Distributed control

Isolation

Disruption

Protect & defend our networks

Policy Rules of

engagement

Sensing

Effects

Data

Decisions

Agents Agents

Agents Agents

Bottleneck, Latency x 2

Automation Human

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Page 19: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

19

UNCLASSIFIED

Wide Area Network

Operations Network

Intrusion Analyst

Client Network

Mobile Devices

Military Systems

Unmanned Vehicles

Security Command

Fusion and reasoning under uncertainty

Autonomic & distributed computing

Distributed control

Isolation

Disruption

Protect & defend our networks

Policy Rules of

engagement

Sensing

Effects

Data

Decisions

Agents Agents

Agents Agents

Bottleneck, Latency x 2

Automation Human

Gateway monitoring

Host-based monitoring

Remote control

Autonomous control

Autonomous red teaming

Enabling lower-skill operators Force multiplier

Isolated networks, military & unmanned systems

Continuous fixing & hardening Dynamic networks

& policy

Rapid quarantine & recovery

Self-protection & healing

Significantly raise the bar for adversary

Page 20: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

20

1. The drivers for Autonomous Cyber Defence

2. The disruptive impacts for Australia:

• Enterprise Security

• Military and Unmanned Systems

• Cyber Warfare

3. Overview of the HINDER project

UNCLASSIFIED

Broad research topics Partnerships & collaboration }

Page 21: Impacts of Autonomous Cyber Defence - UNSW Canberra · 2016-05-26 · 12 1. The drivers for Autonomous Cyber Defence 2. The disruptive impacts for Australia: •Enterprise Security

21

Demonstrate a feasible and effective new concept for cyber defence through researching and prototyping a

well-founded autonomous cyber security capability and demonstrating it within an operational environment.

UNCLASSIFIED

Research Themes

Reasoning & Fusion

Distributed Control

Autonomic Systems

Technologies

Influx

Reflex

Unison

Collaboration

TTCP

Academia TBD

Industry TBD

Impact

R&D

Policy

Capability

Demonstrator

HINDER Vision