DERBI: Diagnosis, Explanation and Recovery from Break-Ins

Mabry Tyson
Douglas B. Moran
Pauline Berry
David Blei
Jim Carpenter
Ruth Lang

Artificial Intelligence Center
SRI International
333 Ravenswood Avenue
Menlo Park, CA 94025
http://www.ai.sri.com/~derbi/


Contrast: Traditional Intrusion Detection Systems


Adaptive Reaction to Threat


Project Rationale


DERBI Architecture

Diagram (40K)


Diagnosis: Reasoning from a Model of Intrusion


Benefits of Model


General Model of Intrusion:
Components


Camouflage as
Indirect Evidence


Camouflage:
Examples of Evidence


Camouflage:
Examples of Evidence


Reasoning from the
Available Evidence


Chain of Reasoning


DERBI