A New Paradigm For Network Security Through Experiences From - - PowerPoint PPT Presentation

a new paradigm for network security through experiences
SMART_READER_LITE
LIVE PREVIEW

A New Paradigm For Network Security Through Experiences From - - PowerPoint PPT Presentation

A New Paradigm For Network Security Through Experiences From Reality (ANPFNSTEFR) Mohit Lad, UCLA Mohit Lad, Outrageous 06 Structure of the talk Background and motivation Gibberish More Gibberish A slide with the text


slide-1
SLIDE 1

Mohit Lad, Outrageous 06

Mohit Lad, UCLA

(ANPFNSTEFR) A New Paradigm For Network Security Through Experiences From Reality

slide-2
SLIDE 2

Mohit Lad, Outrageous 06

Structure of the talk

  • Background and motivation
  • Gibberish
  • More Gibberish
  • A slide with the text “Questions?”

written in big font.

slide-3
SLIDE 3

Mohit Lad, Outrageous 06

Background

Alice, Do you want to have dinner? F

  • r

g e t a b

  • u

t A l i c e , h

  • w

a b

  • u

t b e e r ? S u r e t h i n g p a l !

Alice Bob Frank

1 2 3

slide-4
SLIDE 4

Mohit Lad, Outrageous 06

Motivation

  • Defense through defense
  • Defense through offense new
  • ANPFNSTEFR newer
slide-5
SLIDE 5

Mohit Lad, Outrageous 06

What is ANPFNSTEFR?

  • Security through passive non-violent non-

cooperation

– Influenced by seminal work by Gandhi in early part of 1900s.

  • If the attacker attacks one machine, then

give him another machine to attack.

  • Tell an attacker “I am protesting against your

attack, but through peaceful and non-violent means”

slide-6
SLIDE 6

Mohit Lad, Outrageous 06

Why it works better

Guilt

Attacker Good guy Attack

I know you are attacking machine A, here are the details of machine B What the !@#!@#$ ? Oh, You have opened my eyes, I want to travel to the peak of Himalayas and meditate for the rest

  • f my life
slide-7
SLIDE 7

Mohit Lad, Outrageous 06

Why it works better

Fear

Attacker Good guy Attack

I know you are attacking machine A, here are the details of machine B What the !@#!@#$ ? Seems like a trap, he must be a genius. Instead I am going to attack somebody willing to use offense

slide-8
SLIDE 8

Mohit Lad, Outrageous 06

Why it works better

Lack of challenge

Attacker Good guy Attack

I know you are attacking machine A, here are the details of machine B My fellow hackers will look down on me. Instead I am going to attack somebody willing to use offense

slide-9
SLIDE 9

Mohit Lad, Outrageous 06

Evaluation Setup

  • Our hypothesis “Attackers are

consciously unaware of their wrong doings”.

– Our goal: Make them realize they are doing wrong and see how they change

  • Pick 4 professors from our department
  • Tell them to run scripts that attack our

machines without their knowledge.

slide-10
SLIDE 10

Mohit Lad, Outrageous 06

Evaluation

  • Tell them “You just attacked our

machines, and we are protesting in a non-violent manner”

  • Give them a one page questionnaire

asking “Do you feel guilty?”

  • 75 % cases, answer was “yes”
  • 25 % cases, student lost funding and

had to go back to his country

slide-11
SLIDE 11

Mohit Lad, Outrageous 06

Evaluation Setup II

  • Our hypothesis “Defenders prefer non-

violence rather than offense”.

  • Pick 4 professors from our department
  • Attack their machines without their

knowledge.

slide-12
SLIDE 12

Mohit Lad, Outrageous 06

Evaluation II

  • Tell them “We just attacked your

machines”

  • Give them a one page questionnaire

asking “Would you use offense to respond?”

  • 25 % cases, answer was “no”
  • 75 % cases, student lost funding and

had to go back to his country

slide-13
SLIDE 13

Mohit Lad, Outrageous 06

Mathematical Evaluation Why it works?

slide-14
SLIDE 14

Mohit Lad, Outrageous 06

Conclusion

  • Breakthrough philosophy in security
  • Comprehensive evaluation

– 75% feel guilty after attacking – 25% want to use offense as defenders

  • Thus, our approach 3 times (or 300%) better

than using offense

  • Using our approach will reduce

– 75% of attackers in the Internet – 25% of students in grad schools

slide-15
SLIDE 15

Mohit Lad, Outrageous 06

Future Work

  • The role of CURRY in network

diagnosis

  • Spamming the Spammer to Shut the

Spam using Offense (SSSSO)

slide-16
SLIDE 16

Mohit Lad, Outrageous 06

Questions?