Re: nipper studio experiences?
Gregg Dotoli <[email protected]> Thu, 24 Jul 2014 11:45:09 -0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
--===============0981500283== Content-Type: multipart/alternative; boundary=Apple-Mail-770112C8-ABF9-477B-8C2E-23F637434CC3 Content-Transfer-Encoding: 7bit --Apple-Mail-770112C8-ABF9-477B-8C2E-23F637434CC3 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: quoted-printable Marcus, Is this the definition being discussed? If so, we have a long way to go. encouraging a person to learn, discover, understand, or solve problems on hi= s or her own, as by experimenting, evaluating possible answers or solutions,= or by trial and error: a heuristic teaching method.=20 Gregg Dotoli Sent from my iPhone > On Jul 20, 2014, at 12:00 PM, "Marcus J. Ranum" <[email protected]> wrote: >=20 > Mike Lloyd wrote: >> Simple rule-checking systems don't need a lot - they work, but they also j= ust aren't all that "smart" about the intention or design of your network, i= n much the same way that a spell checker can't tell whether a legal contract= is "good" or "bad" - it can just tell if it's got typos. >=20 > Since you're posting from redsealnetworks.com may I infer that you are > referring as "smart" to redseal's products? Because, as far as I can tell,= > they are also rule-checking systems. Granted, the rules are much more > complicated than they might otherwise be, but an expert system is an > expert system; short of solving the hard AI problem (in which case we > wouldn't call it an "expert system") they're all the same thing. >=20 > An expert system takes a set of facts, applies a rules engine and a > knowledge-base to them, and offers a set of conclusions. >=20 > All of the inputs into the expert system are going to affect the quality > and usefulness of its conclusions; this is important to understand because= > sometimes the knowledge-base doesn't need much to reach a > conclusion. For example, if the query you asked is "give me a list of > SMB servers" the usefulness of the query results is going to depend more > on the available facts about the network than the difficulty of > identifying an SMB server - there are degrees of accuracy that can > be achieved in identifying SMB servers but, since they tend to announce > themselves, it's more a matter of having the right facts in your data > than performing complex analysis. If you had a further set of rules in > your engine that caused it to try to offer conclusions about the purpose > of the SMB servers, it's not "smart" it's "further rules that give more > results." >=20 > it always drives me a bit battier when someone refers to a hunk of > software - no matter how cleverly programmed - as "smart" because > that's one thing that, for now, software isn't. The people who coded > the rules engine and its knowledge-base are "smart" but the system is > the antithesis of "smart" in that it lacks the key elements of intelligenc= e, > namely: > - creativity > - curiousity >=20 > I'm sure your system has a more exhaustive knowledge-base than > whatever, and a cleverly programmed rules engine. But you are > mis-speaking if you characterize one expert system as smarter > than another. >=20 > In a talk I gave in 2005 or so, I characterized all security products > in terms of fact collection, application of a knowledge-base through > a rules engine, and controlled output based on the conclusions > that are offered. > Firewall: packets in -> rules engine + knowledge about state and policy ->= output > Anti-virus: execution attempt -> rules engine + knowledge about behavior a= nd a blacklist -> execution decision > Intrusion detection: facts about network and behavior -> rules engine + in= dicators of compromise -> alert > etc. >=20 > The reason this is a consistent thread through computer security is > because knowledge-bases offer one very valuable thing: diagnosis. > An expert system such as RedSeal's value is that the smart people > who built its rules encoded those rules so as to carry their expertise > to customers' networks in the abstract. The value of such tools is that > they can turn a bunch of packets into a conclusion, i.e.: > "x.x.x.x is an SMB server!" > If you imagine a hypothetical system that was "smart" and able to > form new conclusions that had never been seen before - if they > had never been seen before, it would have to be _creative_ in order > to generate a human-comprehensible description of its state. > Suppose you had a rule fire that produced an alert similar to: > "the ratio of syn/fin packets is 2 standard deviations from normal!" > that's not as human-comprehensible as "syn flood attack!" but even > my example is a cheat because it encodes my expert knowledge that > the ratio of syn/fin packets is interesting. An actual "smart" network > analysis product, if such a thing existed, would probably say: > "Daddy, I'm worried about the network." >=20 > mjr. > --=20 > Marcus J. Ranum, CSO, Tenable Network Security, inc. http://www.tenable.co= m > _______________________________________________ > firewall-wizards mailing list > [email protected] > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --Apple-Mail-770112C8-ABF9-477B-8C2E-23F637434CC3 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto"><div style=3D"-webkit-text-size-adjust: aut= o;">Marcus,</div><div style=3D"-webkit-text-size-adjust: auto;">Is this the &= nbsp;definition being discussed? If so, we have a long way to go.</div><div s= tyle=3D"-webkit-text-size-adjust: auto;"><br></div><div><span style=3D"-webk= it-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);">encour= aging a person to learn, discover, understand, or solve problems on his or h= er own, as by experimenting, evaluating possible answers or solutions, or by= trial and error: <i>a heuristic teaching method.</i> </span></div= ><div style=3D"-webkit-text-size-adjust: auto;"><br></div><div style=3D"-web= kit-text-size-adjust: auto;"><br></div><div style=3D"-webkit-text-size-adjus= t: auto;">Gregg Dotoli<br><br>Sent from my iPhone</div><div style=3D"-webkit= -text-size-adjust: auto;"><br>On Jul 20, 2014, at 12:00 PM, "Marcus J. Ranum= " <<a href=3D"mailto:[email protected]">[email protected]</a>> wrote:<br><br><= /div><blockquote type=3D"cite" style=3D"-webkit-text-size-adjust: auto;"><di= v><span>Mike Lloyd wrote:</span><br><blockquote type=3D"cite"><span>Simple r= ule-checking systems don't need a lot - they work, but they also just aren't= all that "smart" about the intention or design of your network, in much the= same way that a spell checker can't tell whether a legal contract is "good"= or "bad" - it can just tell if it's got typos.</span><br></blockquote><span= ></span><br><span>Since you're posting from <a href=3D"http://redsealnetwork= s.com">redsealnetworks.com</a> may I infer that you are</span><br><span>refe= rring as "smart" to redseal's products? Because, as far as I can tell,</span= ><br><span>they are also rule-checking systems. Granted, the rules are much m= ore</span><br><span>complicated than they might otherwise be, but an expert s= ystem is an</span><br><span>expert system; short of solving the hard AI prob= lem (in which case we</span><br><span>wouldn't call it an "expert system") t= hey're all the same thing.</span><br><span></span><br><span>An expert system= takes a set of facts, applies a rules engine and a</span><br><span>knowledg= e-base to them, and offers a set of conclusions.</span><br><span></span><br>= <span>All of the inputs into the expert system are going to affect the quali= ty</span><br><span>and usefulness of its conclusions; this is important to u= nderstand because</span><br><span>sometimes the knowledge-base doesn't need m= uch to reach a</span><br><span>conclusion. For example, if the query you ask= ed is "give me a list of</span><br><span>SMB servers" the usefulness of the q= uery results is going to depend more</span><br><span>on the available facts a= bout the network than the difficulty of</span><br><span>identifying an SMB s= erver - there are degrees of accuracy that can</span><br><span>be achieved i= n identifying SMB servers but, since they tend to announce</span><br><span>t= hemselves, it's more a matter of having the right facts in your data</span><= br><span>than performing complex analysis. If you had a further set of rules= in</span><br><span>your engine that caused it to try to offer conclusions a= bout the purpose</span><br><span>of the SMB servers, it's not "smart" it's "= further rules that give more</span><br><span>results."</span><br><span></spa= n><br><span>it always drives me a bit battier when someone refers to a hunk o= f</span><br><span>software - no matter how cleverly programmed - as "smart" b= ecause</span><br><span>that's one thing that, for now, software isn't. The p= eople who coded</span><br><span>the rules engine and its knowledge-base are "= smart" but the system is</span><br><span>the antithesis of "smart" in that i= t lacks the key elements of intelligence,</span><br><span>namely:</span><br>= <span>- creativity</span><br><span>- curiousity</span><br><span></span><br><= span>I'm sure your system has a more exhaustive knowledge-base than</span><b= r><span>whatever, and a cleverly programmed rules engine. But you are</span>= <br><span>mis-speaking if you characterize one expert system as smarter</spa= n><br><span>than another.</span><br><span></span><br><span>In a talk I gave i= n 2005 or so, I characterized all security products</span><br><span>in terms= of fact collection, application of a knowledge-base through</span><br><span= >a rules engine, and controlled output based on the conclusions</span><br><s= pan>that are offered.</span><br><span>Firewall: packets in -> rules engin= e + knowledge about state and policy -> output</span><br><span>Anti-virus= : execution attempt -> rules engine + knowledge about behavior and a blac= klist -> execution decision</span><br><span>Intrusion detection: facts ab= out network and behavior -> rules engine + indicators of compromise ->= alert</span><br><span>etc.</span><br><span></span><br><span>The reason this= is a consistent thread through computer security is</span><br><span>because= knowledge-bases offer one very valuable thing: diagnosis.</span><br><span>A= n expert system such as RedSeal's value is that the smart people</span><br><= span>who built its rules encoded those rules so as to carry their expertise<= /span><br><span>to customers' networks in the abstract. The value of such to= ols is that</span><br><span>they can turn a bunch of packets into a conclusi= on, i.e.:</span><br><span>"x.x.x.x is an SMB server!"</span><br><span>If you= imagine a hypothetical system that was "smart" and able to</span><br><span>= form new conclusions that had never been seen before - if they</span><br><sp= an>had never been seen before, it would have to be _creative_ in order</span= ><br><span>to generate a human-comprehensible description of its state.</spa= n><br><span>Suppose you had a rule fire that produced an alert similar to:</= span><br><span>"the ratio of syn/fin packets is 2 standard deviations from n= ormal!"</span><br><span>that's not as human-comprehensible as "syn flood att= ack!" but even</span><br><span>my example is a cheat because it encodes my e= xpert knowledge that</span><br><span>the ratio of syn/fin packets is interes= ting. An actual "smart" network</span><br><span>analysis product, if s= uch a thing existed, would probably say:</span><br><span>"Daddy, I'm worried= about the network."</span><br><span></span><br><span>mjr.</span><br><span>-= - </span><br><span>Marcus J. Ranum, CSO, Tenable Network Security, inc. <a h= ref=3D"http://www.tenable.com">http://www.tenable.com</a></span><br><span>__= _____________________________________________</span><br><span>firewall-wizar= ds mailing list</span><br><span><a href=3D"mailto:firewall-wizards@listserv.= icsalabs.com">[email protected]</a></span><br><span><a h= ref=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards">http= s://listserv.icsalabs.com/mailman/listinfo/firewall-wizards</a></span><br></= div></blockquote></body></html>= --Apple-Mail-770112C8-ABF9-477B-8C2E-23F637434CC3-- --===============0981500283== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============0981500283==--