agile applied research for cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf ·...

27
Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL MaC Bishop, UC Davis Melissa Dark, Purdue Acknowledgements: DoE contract DE-AC05-00OR22725 to UT-BaCelle, LLC; NSF grant DGE-1303211 to UC Davis, DGE-1303048 to Purdue Universiy January 7, 2017 HICSS 50 1

Upload: others

Post on 30-Jul-2020

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

AgileAppliedResearchforCybersecurity

RickLinger,ORNLLuanneGoldrich,JHU/APLMaCBishop,UCDavisMelissaDark,Purdue

Acknowledgements:DoEcontractDE-AC05-00OR22725toUT-BaCelle,LLC;NSFgrantDGE-1303211toUCDavis,DGE-1303048toPurdueUniversiy

January7,2017 HICSS50 1

Page 2: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

DefiniZonofResearch

ResearchiswhatI’mdoingwhenIdon’tknowwhatI’mdoing.

—WernhervonBraun

January7,2017 HICSS50 2

Page 3: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

ResearchGap

•  TradiZonalresearchaimedatdeveloping,understanding,applyingfoundaZonalwork

•  ButsomeZmesproblemsrequire– Shorttermresearchleadinginto…– BeCerunderstandingoftheproblem– Resultsthatcanbeappliedquickly– Whatlong-termresearchwouldbemostusefulandinteresZngtodealwiththeproblemoverthelongterm

January7,2017 HICSS50 3

Page 4: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

AgileResearch

•  Exploratoryresearchwherespeedisoverarchingrequirement

•  ContribuZon:merge– Exploratorymethodsthatfocusonappliedresearch

– Academic,broadermethodsthatfocusonfoundaZonalresearch

January7,2017 HICSS50 4

Page 5: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

InnovaZon

•  InsZtuZonsproducetechnicalchangeviaresearchanddevelopment

•  InsZtuZonsareplacesandsocialroles•  InnovaZonschangebothsocialrolesoftheseplacesandsocialrulesbywhichtheyinteract– Example:Bayh-DoleAct(1980)

January7,2017 HICSS50 5

Page 6: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

AgileResearchBasis

•  SponsorsposeresearchquesZons•  Researcherscarryouttheresearchandproduceresults

•  DoneiteraZvely,andwithsponsorsabletoreframethedirecZonoftheresearchifneeded

January7,2017 HICSS50 6

Page 7: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

AgileResearchPrinciples

•  PredefinedInfrastructure:resources,logisZcsdefinedandallocatedbeforeresearchneedsemerge

•  IncrementalResearch:structuredintoiteraZve,short-term,accumulaZngincrementseachproducingsomethingofvaluetosponsor

January7,2017 HICSS50 7

Page 8: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

AgileResearchPrinciples

•  Incrementalmanagement:processprovidesbuilt-in,short-termcheckpointsforsponsorstounderstandresearch,redirectifneededbasedonincrementalresults

•  Transferability:onegroupmaycarryoutresearch,butmustdosoinawaythatallowsthecurrentstatetobetransferredtoanothergroupifnecessary

January7,2017 HICSS50 8

Page 9: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

AgileResearchProcess

January7,2017 HICSS50 9

Page 10: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

AgileResearchProperZes

•  Flexible•  AnZcipatory•  Staged•  Speedy

•  Visible•  EffecZve•  Impacgul•  Incremental

January7,2017 HICSS50 10

Page 11: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

Example:DataTagging•  Problem:usedatataggingtosupportaccessandretenZonpolicies

•  ResearchquesZonsfromQuickLookStudy:–  Examine current use of data tagging for ABAC, withpolicy-based aCributes and tags used for a largeenterprise

–  IdenZfy technologies that can be adapted to datataggingneeds

–  Researchhowtousedata tagging to supportaccess,retenZonpolicies

–  IdenZfyotherrelevantresearchobjecZves

January7,2017 HICSS50 11

Page 12: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

DataTaggingWayForward:RecommendaZons

•  Defineapathforwardinlightofthecomplexityoftheproblem–  Organizecomplexityofproblemusingstructured,divideandconquerrefinementofgoalsandrequirements

–  ExploreexisZngdatataggingsoluZonspaceforcost-effecZveapplicaZontotheproblemsettoaddresssponsorneeds

•  Conductincrementalresearchanddevelopment.–  ResearchtagrepresentaZonandmanagementasfoundaZonforinformaZonsharing

–  DevelopproofofconceptsystemtoexploreandevaluatepotenZalsoluZons

January7,2017 HICSS50 12

Page 13: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

DataTaggingSoluZonSpace:RecommendaZons

•  TherearepromisingexisZngcommercialsoluZons.–  RunpublicchallengefordatataggingtoelicitpotenZalsoluZons

–  ConductdatataggingproductevaluaZons•  SponsororganizaZonisbeginningtopilotsoluZonsforenterprisedatatagginginseveralareas–  StudydatataggingdesignpaCernsofsponsororganizaZon

•  OtherorganizaZonsbeginningtotackleenterprisedatatagging–  EvaluatedesignpaCernsusedinsponsororganizaZon–  InvesZgateanearliersponsororganizaZoninformaZondiscoveryandassuredaccessstudy

January7,2017 HICSS50 13

Page 14: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

DataTaggingRequirementsAnalysis:RecommendaZons

•  ProblemdomaintoocomplextotacklewithtradiZonalrequirementsspecificaZon–  Conductstructuredengineeringassessmenttodefineincrementaldevelopment,deploymentstages

•  InformaZonarchitectureneededfordatatags– DevelopadatataggingConceptofOperaZons–  ConductanorganizaZonalinventoryofaCributedata– Assesstaxonomies,ontologiesforrepresenZngtags.–  Conductstudyoftrade-offsbetweentaggingdataatrestandonthefly

January7,2017 HICSS50 14

Page 15: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

DataTaggingRequirementsAnalysis:RecommendaZons

•  Taggingtechnologies,mechanismsmustbesecured.–  IdenZfypotenZalthreatsandvulnerabiliZes.– Developsecurityreferencearchitecturesfordatatagging

– AssessefficacyofIdenZty-BasedInternetProtocol(IBIP)tosecuredatataggingnetwork

LotsofgristforDeepLookStep!AlsosuggestsseveralfoundaZonalresearchquesZons

January7,2017 HICSS50 15

Page 16: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

AgileResearchStructure

January7,2017 HICSS50 16

Page 17: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

AgileResearchPorgolio

January7,2017 HICSS50 17

Page 18: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

INSuREProject

•  FocalacZvity:cybersecurityresearchclass–  INSuREstandsforINformaZonSecurityResearchandEducaZon

•  Sponsorsproposeproblems–  Ifselected,sponsorexpectedtoprovideguidance,feedbackstudentsinconjuncZonwithfaculty

–  Sponsormustagreethat,ifresultsmeritpublicaZon,theresearchcanbepublished•  Sofar,noproblemswithdoingthis

January7,2017 HICSS50 18

Page 19: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

OverviewofStructure

1.  Projectbid2.  Projectproposal3.  Literaturereview4.  ProgressreportandpresentaZon5.  Finalreport,presentaZonforschoolson

semestersystem– PenulZmatereport,presentaZonforquartersystem

6.  Finalreport,presentaZonforschoolsonquartersystem

January7,2017 HICSS50 19

Page 20: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

Set-Up

•  Facultysolicitresearchproposalsfrom(potenZal)sponsors– Typically,aparagraphdescribingproblemingeneralterms

– Examples•  IdenZfyingICScomponentsinanetwork•  CodevariaZonasadefenseagainstaCacks•  AnalysisofproposedTCPcryptprotocol

•  Sponsorsthen“pitch”theprojectstothestudentsinfirst1or2classmeeZngs

January7,2017 HICSS50 20

Page 21: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

Research

•  Studentsmeetweeklywithsponsor,facultytoreportprogress,challengesencounteredandovercome,nextweek’sgoals

•  Goalsmaychangebasedonchallengesfound– Allowsponsorstomodifyincrementalresearchgoals

– Sponsorscanapplyintermediateresultsasworkprogresses

– Studentsseetheirworkbeingused

January7,2017 HICSS50 21

Page 22: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

Reports

•  Weeklyprogressreports•  Midtermprogressreport– Deliveredasformalpaper,presentaZontoallparZcipaZngteams

•  Finalreport– Alsodeliveredtoallteams

•  CriZcalidea:documentresults,tools,datasetssothatanotherteamcanpickupwherethisteamlepoff–  TeachesdatacuraZon

January7,2017 HICSS50 22

Page 23: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

PuqngItTogether

January7,2017 HICSS50 23

Page 24: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

Mapping•  Bid,proposalèQuickLook– Difference:studentsdon’tidenZfysubjectmaCerexperts;instead,explainwhytheyshouldbeconsidered(orwillbecome)experts

•  ProposalpreparaZonèDeepLook–  Presentsgoals,whattheresearchplancanbeexpectedtoaccomplish

•  ResearchèIncrementalResearchStage– WeeklymeeZngsallowsponsortoadjustgoalsofresearchtomeetneeds,andbasedonweeklyoutcomes

January7,2017 HICSS50 24

Page 25: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

QuesZons

•  HowtodeterminewhentouseAgileResearchratherthan(orinaddiZonto)long-termresearch

•  Howtodevelopintermediategoalssothat:–  Incrementalresultsareuseful–  Incrementalresultswillenablethesponsortoprovidefurtherguidancetotheresearchgroup

–  IncrementalgoalswillprovideinsightintothefoundaZonalresearchnecessarytoprovidedeeperunderstandingoftheproblemand,possibly,long-termsoluZons(this,especiallyinanacademicseqng)

January7,2017 HICSS50 25

Page 26: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

Conclusion

•  Long-termresearchquesZonsarisefromAgileResearchprojects– AgileResearchisappliedresearchtowardsaparZcular,pressingend

–  Thus,idealforidenZfyinginteresZnglong-termresearchprojects

•  AgileResearchexhibitsproperZesthatarecriZcaltoresearchinvolvementinthefastpacedandunpredictableworldofcybersecurity

January7,2017 HICSS50 26

Page 27: Agile Applied Research for Cybersecuritynob.cs.ucdavis.edu/bishop/talks/2017-hicss/agile.pdf · Agile Applied Research for Cybersecurity Rick Linger, ORNL Luanne Goldrich, JHU/APL

ClosingThought

•  Tothoseaccustomedtotheprecise,structuredmethodsofconvenZonalsystemdevelopment,exploratorydevelopmenttechniquesmayseemmessy,inelegant,andunsaZsfying.Butit’saquesZonofcongruence:precisionandflexibilitymaybejustasdysfuncZonalinnovel,uncertainsituaZonsassloppinessandvacillaZonareinfamiliar,well-definedones.Thosewhoadmirethemassive,rigidbonestructuresofdinosaursshouldrememberthatjellyfishsZllenjoytheirverysecureecologicalniche. —BeauSheil,“PowerToolsforProgrammers”

January7,2017 HICSS50 27