Simulating adversarial interactions between intruders and system administrators using OODA-RR

  • Authors:
  • T. J. Grant;H. S. Venter;J. H. P. Eloff

  • Affiliations:
  • Netherlands Defence Academy, PA Breda, Netherlands;University of Pretoria, Pretoria, South Africa;University of Pretoria, Pretoria, South Africa

  • Venue:
  • Proceedings of the 2007 annual research conference of the South African institute of computer scientists and information technologists on IT research in developing countries
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Intrusion in information systems is a major problem in security management. Present-day intrusion detection systems detect attacks too late to counter them in real-time. Several authors in the digital forensics literature have proposed using Boyd's Observe-Orient-Decide-Act (OODA) model for intrusion protection, but none have taken these proposals further. This paper reports on hand-simulation of the adversarial interaction between an intruder and a system administrator intended to demonstrate the feasibility of implementing a rationally reconstructed OODA (OODA-RR) model. An OODA-RR test-bed is currently being implemented.