Configurable immunity for evolving human-computer systems

  • Authors:
  • Mark Burgess

  • Affiliations:
  • Oslo University College, Cort Adelers Gate 30 Oslo N-0254, Norway

  • Venue:
  • Science of Computer Programming - Methods of software design: Techniques and applications
  • Year:
  • 2004

Quantified Score

Hi-index 0.02

Visualization

Abstract

The immunity model, as used in the GNU cfengine project, is a distributed framework for performing policy conformant system administration, used on hundreds of thousands of Unix-like and Windows systems. This paper describes the idealized approach to policy-guided maintenance, that is approximated by cfengine, building on the notion of 'convergent' operations, i.e. those that reach stable equilibrium. Agents gravitate towards a policy-determined configurations, through the repeated application of unintelligent 'anti-body' operations or discrete, coded counter-measures. The distributed agents turn passive discovery of state into active strategy for 'curing' systems of policy transgressions.