LOGIN
|
REGISTER NOW
|
SUBSCRIBE
AS OF 6/18/2013 12:59AM EST
HOME
ALL STORIES
LATEST NEWS
COLUMNS
OPINIONS
GUEST VIEWS
SHORT TAKES
LINKAPALOOZA
NEWSWIRE
SPECIAL REPORTS
ZEICHICK'S TAKE
SD TIMES 100
BE A NEWSHOUND
IPHONE APP
IPAD APP
RSS FEEDS
FACEBOOK
TWITTER
WHITE PAPERS
SPONSORED PROFILES
JOB BOARD
WEBINAR CENTER
FREE SOFTWARE
ANDROID NEWSLETTER
BIG DATA TECHREPORT
ALM
SHAREPOINT
EVENTS CALENDAR
PRINT/PDF EDITION
PRINT/PDF BACK ISSUES
SUBSCRIBE TODAY
CUSTOMER SERVICE
EDITORIAL BEATS
GUEST VIEW GUIDE
SD TIMES 100 GUIDE
EVENTS CALENDAR
ADVERTISING
ARTICLE REPRINTS
REPORT A BUG
SITE MAP
ABOUT US
BZ MEDIA NEWS
NEWS ON MONDAY
SPTECHREPORT
SPTECHWEB
SPTECHCON
IPHONE/IPAD DEVCON
ANDROID DEVCON
PRIVACY POLICY
CONTACT US
HOME
>>
ZEICHICK'S TAKE
Zeichick’s Take: Is that really you, Dave?
By
Alan Zeichick
Tweet
June 22, 2012 —
Bet you never thought that AI would have tremendous applications to the field of computer security. AI's challenge: Someone logs into your network or multi-user system using Dave's userid and password. Can your computer be sure that it's Dave logging in, and not someone who's borrowed his password or cracked the system’s security measures? Can your computer be sure that Dave is not preparing to perform malicious activities?
First let's verify that it's really Dave who logged in. Over the past several years, computer-security researchers at SRI, Mitre, and other organizations (including the U.S. government) have learned that individuals have distinctive system-usage signatures. Data that can make up that signature include the name (or type) of programs executed, the method of changing system directories, the login time, and session length. Let's say that Dave normally uses the mainframe during business hours to read e-mail. One Saturday night around 2:00 a.m., he logs in, scans the system read-only directories, and then attempts to rewrite the master password file. There's a good chance your system's been infiltrated.
That's a simple scenario, of course. Programmers, who perform a wide variety of computer activities at all hours of the day and night, are more difficult to validate than 9-to-5 data-entry clerks. On an academic network, you'll frequently need to recalculate your baseline models for each user as his or her expertise grows. The computer is vulnerable if hackers break into a new user's account before there's enough data to train the neural net properly or construct the model. Still, studies show that if the operating system is gathering the proper data, AI techniques can be applied in this area.
Expert systems can be applied to the second problem, trying to detect if Dave (or the intruder using Dave's account) is misbehaving. A network-monitoring tool can see what commands Dave is issuing (like changing other user's files, or altering permission flags for various files). If the knowledgebase contains data on known ways of hacking superuser privileges or crashing the system, it can watch for that type of activity. If Dave issues the first two commands in a dangerous three-command sequence, the expert system could alert the systems operator, flash a warning on Dave's screen ("What are you doing, Dave?"), or even lock his account out of the system.
Perhaps you're thinking that Big Brother is watching. You're right. Instead of Orwellian thought police monitoring your private conversations, you might soon have AI software watching your every keystroke. Given today's business realities, we might as well get used to that unpleasant idea.
I wrote the above essay in June 1994 and recently stumbled across it. Eighteen years later, it’s still relevant.
Alan Zeichick is editorial director of SD Times. Read his blog at
ztrek.blogspot.com
.
Related Search Term(s):
AI
,
security
Share this link:
http://sdt.bz/36747
Technorati
Digg
Reddit
Slashdot
Facebook
Friendfeed
Twitter
del.icio.us
Related Articles
Cigital Develops Ready-to-Use Tools for Securing the Smart Grid
Cigital Inc. announced the release of the Guide to Developing a Cyber Security and Risk Mitigation Plan.
Department of Homeland Security lays down security suggestions
Common Weakness Enumeration version 2.0 highlights flaws in software development practices
Metadata Security for SharePoint Adds Security Permissions
Titus Metadata Security for SharePoint allows permissions to be assigned based on the recipient's Active Directory properties
NEXT ARTICLE
Cigital Develops Ready-to-Use Tools for Securing the Smart Grid
Cigital Inc. announced the release of the Guide to Developing a Cyber Security and Risk Mitigation Plan
Read More...
 
LOADING...
News on Monday
more>>
Android Developer News
more>>
SharePoint Tech Report
more>>
Big Data TechReport
more>>
Download Current Issue
JUNE 2013 PDF ISSUE
Need Back Issues?
DOWNLOAD HERE
Want to subscribe?
Velocity Conf.
6/18/2013 to 6/20/2013
Santa Clara, Calif.
O'Reilly Media
Structure
6/19/2013 to 6/20/2013
San Francisco
GigaOM
Mobile Commerce World
6/24/2013 to 6/26/2013
San Francisco
UBM TechWeb
USENIX Federated Conference
6/24/2013 to 6/28/2013
San Jose, Calif.
USENIX
Microsoft Build
6/26/2013 to 6/28/2013
San Francisco
Microsoft
More