Explaining and Recovering from Computer Intrusions: Progress 7/97




Douglas B. Moran
Pauline M. Berry

Artificial Intelligence Center
SRI International
333 Ravenswood Avenue
Menlo Park CA 94025

1/18/96

Overview/Review

Status

The Role of PRS in DERBI

DERBI Analysis

DERBI Design



PRS - (history slide)



Shared Principles

What is PRS?

PRS Agent



Architecture in DERBI



Execution Cycle

  1. New information arrives that updates facts and goals
  2. Acts are triggered by new facts or goals
  3. A triggered Act is intended
  4. An intended Act is selected
  5. That intention is Activated
  6. An Action is performed, usually a call to an external function
  7. New Facts or Goals are posted
  8. Intentions are updated

DERBI Design Issues

Rootkit Scenario

Anomaly Leads to Hypothesis



Trace Anomaly: Slow




Back to Security Project Home Page
Back to AI Center Home Page
Back to SRI International Home Page
Pauline M. Berry berry@ai.sri.com