Predicting User Behavior to Improve Security
CitizenC writes "New computer-monitoring software designed to second-guess the intentions of individual system users could be close to perfect at preventing security breaches, say researchers. Read more." The paper (pdf) is online as well.
Does sound promising though.
Meow meow meow meow, meow meow meow meow...
-Note to Self-
Keep doors locked at my house to prevent other people from coming in.
NO! NO! Please don't mod me, I'm too young to die a troll. *click* Oh the pain, the pain...
the first action you take breaches security?
Jon Bardin
Surely this will just prompt crackers to stealth their actions in commands that are similar to how the system is used normally?
if they had any clue about real-world users, they'd know they're absolutely unpredictable. A user's creativeness to mess things up never ceases to amaze.
Oh wait. That wouldn't be unusual. DAMMIT!
Wouldn't it be relatively easy to get around this by aliasing shell scripts to frequently used commands? Sure, the admin might be able to find the shell scripts lying around, but if an intruder was trying to do a one-off attack, it might be viable.
Brandon
How is the system used by credit card and phone companies different than the one proposed by this paper?
The law of excluded middle : Either I'm foo or I'm foobar
This would encourage users not to experiment and find new ways of doing tasks, if everytime you tried something new a sysad came round to ask you what you were doing.
Never trust a man in a blue trench coat, Never drive a car when you're dead
The user could "poison" the information by slowly changing his working habits. If done properly, the AI would probably think this was no different than the user just learning to do things in a different way. When the habits are close enough to the infringing behaviour, the user can probably do anything without setting off alarms.
In addition, if this is the only line of security, the user can then gradually return his patterns to normal. The logs from this system won't show anything. The PHBs may well decide that, when using something as smart as this, traditional logs won't be needed.
I can't say that I don't give a fuck. I've just run out of fuck to give.
And how long will it be before users start losing privileges for things that they "potentially might do" (with a 94% accuracy rate). About one in 20 of us is really going to suffer for this one.
"Can't you see that everyone is buying station wagons?"
..are what we need. If someone could come up with a box that could filter pages based on the amount of pink within the images I could delete 80% of my outgoing firewall rules at work!
Trolling is a art,
Um, that's Godel's Theorem.
> Wish I was a Physics Genius
I think that just about sums it up. ;-)
--
If you moderate this, then your children will be next.
The average user may be adept at breaking his PC, but he's much less likely to, say, flood the network with bad packets.
Would you to start the IIS hacking wizard?
Would you like to view a list of the top 1,000 exploits?
Never show this prompt again, its already too easy to hack IIS.
You could go even further and log a typing rate jump or dip of 30 WPM.
I took a brief look at the paper and sincerly the idea is not bad at all. However that 94% is pure hype.
The biggest problem in computer security, in what is related to users, is not anomalies, but the usual practice. Remember that experts say that 90% of flaws is due to insiders and not outsiders. And why? Because 99% of these insiders don't care a nail for security. Most of them keep using the wife's name for password and sharing C: to everyone. And no matter the efforts, policies, orders and instructions keep gaining dust. If you try to enforce them then you get a crowd in front of the boss with a rope for your neck.And if even the boss comes up to defend your work, everyone start to mine all your job. All they want is Internet, passing documents and hoping that you finally get out and Microsoft comes in to solve all the problems. That's what the lamers think about security. And in this mess, no matter the expert you are, no matter the tools you have, no matter the hours you loose on the net, you always get trouble every week.
Besides I noted that if someone is going for the break-in, he will mostly go from start. It starts up with this guy "playing" with the computer, then it goes up to the net. Later he thinks he's smart enough to break the server and show that the security admin is a LaMeR.And it ends up with you looking at his desktop and writing the final document to fire or put him into court. You may ask why this guy could go so far. Because he's smart, because no matter the lamerness he is good on something. So the boss will think twice before firing him. If you are in a corporation, then the boss will hang you up with this "unreplaceble" expert because in the city where he lives there's no one else to do his job. Besides, the corporation lost too much money on training him and doesn't want to start from zero on this. So you continue to see the bastard for a few monthes more before you catch him on the red spot.
I saw this and I know that this is a problem on many companies and state institutions around the world. So how this system will help you in such cases? It will, with a large margin of error as the main anomaly, the user, is there from the very start..
Sounds like profiling terrorists. It'll work great, and everyone will feel secure and all, until somone flies a plane into their "secure" server.
The REAL jabber has the user id: 13196
What you do today will cost you a day of your life
$ r00t machine
Ush: command not found: r00t
*meanwhile, in the Secret Command Centre*
#QUEER#COMMAND##INVESTIGATE##
$ owNz0rz machine
owNz0rz: unknown parameter machine
*SCC*
###THERE#MIGHT#BE#SOMETHING#GOING#ON##
$ owNz0rz r00t
Ush: j00 owNz0r d4 r00t!
*SCC*
#####ALARM#ALARM#####
$
Ush: Someone trying to use 'alarm()', authorize? n0
Ush: Killing alarming process.
$ 1337
Marxist evolution is just N generations away!
Any time someone mentions a "success rate" without also mentioning the false positive rate, they're feeding you garbage
.001% false alarm rate means that an innocent worker is going to be interrupted THREE TIMES A YEAR by burly security people at the cube doorway shouting "Hands off that keyboard RIGHT NOW!"
I'd be much more impressed by a claim of an 0.001% false alarm rate than I am by a 94% success rate.
Yet, on a per-line basis, if you assume that a user averages, say, three typed lines per minute, that's 180 lines per hour = 360000 lines per working year.
A
"How to Do Nothing," kids activities, back in print!
it'd be like...
:;do for IP in `cat /var/log/httpd/access_log|awk '{print $2}'`; do /usr/sbin/iptables -t filter -A INPUT -p tcp -s $IP/32 -j DROP;done;done or something like that. Yeah. I got your AI right here. I can sell you a tarball with a digitally signed dignature- I'm quite digil when it comes to being a digilante.
while
slashdot: where everyone yells sarcastic metaphors to themselves to understand the issue