Trust Management Considerations For the Cooperative Infrastructure Defense Framework: Trust Relationships, Evidence, and Decisions
Cooperative Infrastructure Defense (CID) is a hierarchical, agent-based, adaptive, cyber-security framework designed to collaboratively protect multiple enclaves or organizations participating in a complex infrastructure. CID employs a swarm of lightweight, mobile agents called Sensors designed to roam hosts throughout a security enclave to find indications of anomalies and report them to host-based Sentinels. The Sensors’ findings become pieces of a larger puzzle, which the Sentinel puts together to determine the problem and respond per policy as given by the enclave-level Sergeant agent. Horizontally across multiple enclaves and vertically within each enclave, authentication and access control technologies are necessary but insufficient authorization mechanisms to ensure that CID agents continue to fulfill their roles in a trustworthy manner. Trust management fills the gap, providing mechanisms to detect malicious agents and offering more robust mechanisms for authorization. This paper identifies the trust relationships throughout the CID hierarchy, the types of trust evidence that could be gathered, and the actions that the CID system could take if an entity is determined to be untrustworthy.
- Research Organization:
- Pacific Northwest National Laboratory (PNNL), Richland, WA (US)
- Sponsoring Organization:
- USDOE
- DOE Contract Number:
- AC05-76RL01830
- OSTI ID:
- 975421
- Report Number(s):
- PNNL-19117
- Country of Publication:
- United States
- Language:
- English
Similar Records
Ant-Based Cyber Defense
DualTrust: A Distributed Trust Model for Swarm-Based Autonomic Computing Systems
Trust Management in Swarm-Based Autonomic Computing Systems
Software
·
Mon Sep 28 20:00:00 EDT 2015
·
OSTI ID:code-76601
DualTrust: A Distributed Trust Model for Swarm-Based Autonomic Computing Systems
Conference
·
Mon Jan 31 23:00:00 EST 2011
·
OSTI ID:1008240
Trust Management in Swarm-Based Autonomic Computing Systems
Conference
·
Tue Jul 07 00:00:00 EDT 2009
·
OSTI ID:973734