Re: nipper studio experiences?

Gregg Dotoli <[email protected]> Thu, 24 Jul 2014 11:45:09 -0400
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
--===============0981500283==
Content-Type: multipart/alternative;
	boundary=Apple-Mail-770112C8-ABF9-477B-8C2E-23F637434CC3
Content-Transfer-Encoding: 7bit


--Apple-Mail-770112C8-ABF9-477B-8C2E-23F637434CC3
Content-Type: text/plain;
	charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Marcus,
Is this the  definition being discussed? If so, we have a long way to go.

encouraging a person to learn, discover, understand, or solve problems on hi=
s or her own, as by experimenting, evaluating possible answers or solutions,=
 or by trial and error: a heuristic teaching method.=20


Gregg Dotoli

Sent from my iPhone

> On Jul 20, 2014, at 12:00 PM, "Marcus J. Ranum" <[email protected]> wrote:
>=20
> Mike Lloyd wrote:
>> Simple rule-checking systems don't need a lot - they work, but they also j=
ust aren't all that "smart" about the intention or design of your network, i=
n much the same way that a spell checker can't tell whether a legal contract=
 is "good" or "bad" - it can just tell if it's got typos.
>=20
> Since you're posting from redsealnetworks.com may I infer that you are
> referring as "smart" to redseal's products? Because, as far as I can tell,=

> they are also rule-checking systems. Granted, the rules are much more
> complicated than they might otherwise be, but an expert system is an
> expert system; short of solving the hard AI problem (in which case we
> wouldn't call it an "expert system") they're all the same thing.
>=20
> An expert system takes a set of facts, applies a rules engine and a
> knowledge-base to them, and offers a set of conclusions.
>=20
> All of the inputs into the expert system are going to affect the quality
> and usefulness of its conclusions; this is important to understand because=

> sometimes the knowledge-base doesn't need much to reach a
> conclusion. For example, if the query you asked is "give me a list of
> SMB servers" the usefulness of the query results is going to depend more
> on the available facts about the network than the difficulty of
> identifying an SMB server - there are degrees of accuracy that can
> be achieved in identifying SMB servers but, since they tend to announce
> themselves, it's more a matter of having the right facts in your data
> than performing complex analysis. If you had a further set of rules in
> your engine that caused it to try to offer conclusions about the purpose
> of the SMB servers, it's not "smart" it's "further rules that give more
> results."
>=20
> it always drives me a bit battier when someone refers to a hunk of
> software - no matter how cleverly programmed - as "smart" because
> that's one thing that, for now, software isn't. The people who coded
> the rules engine and its knowledge-base are "smart" but the system is
> the antithesis of "smart" in that it lacks the key elements of intelligenc=
e,
> namely:
> - creativity
> - curiousity
>=20
> I'm sure your system has a more exhaustive knowledge-base than
> whatever, and a cleverly programmed rules engine. But you are
> mis-speaking if you characterize one expert system as smarter
> than another.
>=20
> In a talk I gave in 2005 or so, I characterized all security products
> in terms of fact collection, application of a knowledge-base through
> a rules engine, and controlled output based on the conclusions
> that are offered.
> Firewall: packets in -> rules engine + knowledge about state and policy ->=
 output
> Anti-virus: execution attempt -> rules engine + knowledge about behavior a=
nd a blacklist -> execution decision
> Intrusion detection: facts about network and behavior -> rules engine + in=
dicators of compromise -> alert
> etc.
>=20
> The reason this is a consistent thread through computer security is
> because knowledge-bases offer one very valuable thing: diagnosis.
> An expert system such as RedSeal's value is that the smart people
> who built its rules encoded those rules so as to carry their expertise
> to customers' networks in the abstract. The value of such tools is that
> they can turn a bunch of packets into a conclusion, i.e.:
> "x.x.x.x is an SMB server!"
> If you imagine a hypothetical system that was "smart" and able to
> form new conclusions that had never been seen before - if they
> had never been seen before, it would have to be _creative_ in order
> to generate a human-comprehensible description of its state.
> Suppose you had a rule fire that produced an alert similar to:
> "the ratio of syn/fin packets is 2 standard deviations from normal!"
> that's not as human-comprehensible as "syn flood attack!" but even
> my example is a cheat because it encodes my expert knowledge that
> the ratio of syn/fin packets is interesting.  An actual "smart" network
> analysis product, if such a thing existed, would probably say:
> "Daddy, I'm worried about the network."
>=20
> mjr.
> --=20
> Marcus J. Ranum, CSO, Tenable Network Security, inc. http://www.tenable.co=
m
> _______________________________________________
> firewall-wizards mailing list
> [email protected]
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--Apple-Mail-770112C8-ABF9-477B-8C2E-23F637434CC3
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div style=3D"-webkit-text-size-adjust: aut=
o;">Marcus,</div><div style=3D"-webkit-text-size-adjust: auto;">Is this the &=
nbsp;definition being discussed? If so, we have a long way to go.</div><div s=
tyle=3D"-webkit-text-size-adjust: auto;"><br></div><div><span style=3D"-webk=
it-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);">encour=
aging a person to learn, discover, understand, or solve problems on his or h=
er own, as by experimenting, evaluating possible answers or solutions, or by=
 trial and error:&nbsp;<i>a heuristic teaching method.</i>&nbsp;</span></div=
><div style=3D"-webkit-text-size-adjust: auto;"><br></div><div style=3D"-web=
kit-text-size-adjust: auto;"><br></div><div style=3D"-webkit-text-size-adjus=
t: auto;">Gregg Dotoli<br><br>Sent from my iPhone</div><div style=3D"-webkit=
-text-size-adjust: auto;"><br>On Jul 20, 2014, at 12:00 PM, "Marcus J. Ranum=
" &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<br><br><=
/div><blockquote type=3D"cite" style=3D"-webkit-text-size-adjust: auto;"><di=
v><span>Mike Lloyd wrote:</span><br><blockquote type=3D"cite"><span>Simple r=
ule-checking systems don't need a lot - they work, but they also just aren't=
 all that "smart" about the intention or design of your network, in much the=
 same way that a spell checker can't tell whether a legal contract is "good"=
 or "bad" - it can just tell if it's got typos.</span><br></blockquote><span=
></span><br><span>Since you're posting from <a href=3D"http://redsealnetwork=
s.com">redsealnetworks.com</a> may I infer that you are</span><br><span>refe=
rring as "smart" to redseal's products? Because, as far as I can tell,</span=
><br><span>they are also rule-checking systems. Granted, the rules are much m=
ore</span><br><span>complicated than they might otherwise be, but an expert s=
ystem is an</span><br><span>expert system; short of solving the hard AI prob=
lem (in which case we</span><br><span>wouldn't call it an "expert system") t=
hey're all the same thing.</span><br><span></span><br><span>An expert system=
 takes a set of facts, applies a rules engine and a</span><br><span>knowledg=
e-base to them, and offers a set of conclusions.</span><br><span></span><br>=
<span>All of the inputs into the expert system are going to affect the quali=
ty</span><br><span>and usefulness of its conclusions; this is important to u=
nderstand because</span><br><span>sometimes the knowledge-base doesn't need m=
uch to reach a</span><br><span>conclusion. For example, if the query you ask=
ed is "give me a list of</span><br><span>SMB servers" the usefulness of the q=
uery results is going to depend more</span><br><span>on the available facts a=
bout the network than the difficulty of</span><br><span>identifying an SMB s=
erver - there are degrees of accuracy that can</span><br><span>be achieved i=
n identifying SMB servers but, since they tend to announce</span><br><span>t=
hemselves, it's more a matter of having the right facts in your data</span><=
br><span>than performing complex analysis. If you had a further set of rules=
 in</span><br><span>your engine that caused it to try to offer conclusions a=
bout the purpose</span><br><span>of the SMB servers, it's not "smart" it's "=
further rules that give more</span><br><span>results."</span><br><span></spa=
n><br><span>it always drives me a bit battier when someone refers to a hunk o=
f</span><br><span>software - no matter how cleverly programmed - as "smart" b=
ecause</span><br><span>that's one thing that, for now, software isn't. The p=
eople who coded</span><br><span>the rules engine and its knowledge-base are "=
smart" but the system is</span><br><span>the antithesis of "smart" in that i=
t lacks the key elements of intelligence,</span><br><span>namely:</span><br>=
<span>- creativity</span><br><span>- curiousity</span><br><span></span><br><=
span>I'm sure your system has a more exhaustive knowledge-base than</span><b=
r><span>whatever, and a cleverly programmed rules engine. But you are</span>=
<br><span>mis-speaking if you characterize one expert system as smarter</spa=
n><br><span>than another.</span><br><span></span><br><span>In a talk I gave i=
n 2005 or so, I characterized all security products</span><br><span>in terms=
 of fact collection, application of a knowledge-base through</span><br><span=
>a rules engine, and controlled output based on the conclusions</span><br><s=
pan>that are offered.</span><br><span>Firewall: packets in -&gt; rules engin=
e + knowledge about state and policy -&gt; output</span><br><span>Anti-virus=
: execution attempt -&gt; rules engine + knowledge about behavior and a blac=
klist -&gt; execution decision</span><br><span>Intrusion detection: facts ab=
out network and behavior -&gt; rules engine + indicators of compromise -&gt;=
 alert</span><br><span>etc.</span><br><span></span><br><span>The reason this=
 is a consistent thread through computer security is</span><br><span>because=
 knowledge-bases offer one very valuable thing: diagnosis.</span><br><span>A=
n expert system such as RedSeal's value is that the smart people</span><br><=
span>who built its rules encoded those rules so as to carry their expertise<=
/span><br><span>to customers' networks in the abstract. The value of such to=
ols is that</span><br><span>they can turn a bunch of packets into a conclusi=
on, i.e.:</span><br><span>"x.x.x.x is an SMB server!"</span><br><span>If you=
 imagine a hypothetical system that was "smart" and able to</span><br><span>=
form new conclusions that had never been seen before - if they</span><br><sp=
an>had never been seen before, it would have to be _creative_ in order</span=
><br><span>to generate a human-comprehensible description of its state.</spa=
n><br><span>Suppose you had a rule fire that produced an alert similar to:</=
span><br><span>"the ratio of syn/fin packets is 2 standard deviations from n=
ormal!"</span><br><span>that's not as human-comprehensible as "syn flood att=
ack!" but even</span><br><span>my example is a cheat because it encodes my e=
xpert knowledge that</span><br><span>the ratio of syn/fin packets is interes=
ting. &nbsp;An actual "smart" network</span><br><span>analysis product, if s=
uch a thing existed, would probably say:</span><br><span>"Daddy, I'm worried=
 about the network."</span><br><span></span><br><span>mjr.</span><br><span>-=
- </span><br><span>Marcus J. Ranum, CSO, Tenable Network Security, inc. <a h=
ref=3D"http://www.tenable.com">http://www.tenable.com</a></span><br><span>__=
_____________________________________________</span><br><span>firewall-wizar=
ds mailing list</span><br><span><a href=3D"mailto:firewall-wizards@listserv.=
icsalabs.com">[email protected]</a></span><br><span><a h=
ref=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards">http=
s://listserv.icsalabs.com/mailman/listinfo/firewall-wizards</a></span><br></=
div></blockquote></body></html>=

--Apple-Mail-770112C8-ABF9-477B-8C2E-23F637434CC3--

--===============0981500283==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--===============0981500283==--