Search NASA⌕ Search

Engineering topics

Nichols, Jeff

Publications and source records attributed to Nichols, Jeff.

AI ATAC 1: An Evaluation of Prominent Commercial Malware Detectors

This work presents an evaluation of six prominent commercial endpoint malware detectors, a network malware detector, and a file-conviction algorithm from a cyber technology vendor. The evaluation was administered as the first of the Artificial I ntelligence Applications t o Autonomous Cybersecurity (AI ATAC) prize challenges, funded by / completed in service of the US Navy. The experiment employed 100K files (50/50% benign/malicious) with a stratified distribution of file types, including ~1K zero-day program executables (increasing experiment size two orders of magnitude over previous work). We present an evaluation process of delivering a file to a fresh virtual machine donning the detection technology, waiting 90s to allow static detection, then executing the file and waiting another period for dynamic detection; this allows greater fidelity in the observational data than previous experiments, in particular, resource and time-to-detection statistics. To execute all 800K trials (100K files × 8 tools), a software framework is designed to choreograph the experiment into an automated, time-synced, and reproducible workflow with substantial parallelization. Software with base classes for this framework are provided. A cost-benefit model was configured to integrate the tools’ detection statistics into a comparable quantity by simulating costs of use. This provides a ranking methodology for cyber competitions and a lens for reasoning about the varied statistical results. The results provide insights on state of commercial malware detection.

Bridges, Robert↗

Assembling a Cyber Range to Evaluate Artificial Intelligence / Machine Learning (AI/ML) Security Tools

In this case study, we will describe the design and assembly of a cyber security test range we have built at Oak Ridge National Laboratory in Oak Ridge, TN, USA. The range is designed to provide a flexible environment to evaluate cyber security tools—particularly those involving AI/ML—in a way that provides realistic environments and where we can control the experiments to determine the strengths and weaknesses of the tools. We have designed in the ability to repeat the evaluations, so additional tools can be evaluated and compared at a later time. The system is one that can be scaled up or down for experiment sizes. At the time of the conference we will have completed two full-scale, national, government challenges on this range. These challenges are evaluating the performance and operating costs for AI/ML-based cyber security tools for application into large, government-sized environments. These evaluations will be described, in order to provide motivation and context for various design decisions and adaptations we have made. The first challenge measured end-point security tools against 100K malware samples chosen across a range of types. The second is network detection of attempted penetration and exploitations with varying levels of covertness in a high-volume, business network. The scale of each of these challenges is requiring us to create automation systems to repeat the experiments identically for each tool. Preventing there being easy signs of malicious activity for the AI/ML tools to focus on has been a particularly interesting and challenging aspect of designing and executing these challenge events. After the events, the range continues to be used for other research such as adversarial machine learning where the repeatability, scale, and automation required for the national challenge events become essential elements for research.

Nichols, Jeff↗