论文标题
网络弹性:通过设计还是干预?
Cyber Resilience: by Design or by Intervention?
论文作者
论文摘要
“通过设计的网络弹性”一词越来越受欢迎。在这里,通过网络弹性,我们指的是系统抵抗,最小化和减轻由于在系统或计算和通信设备网络上成功的网络攻击引起的退化的能力。当必须以可证明的任务保证方式设计和实施系统时,有些人使用“按设计”一词,并具有系统的内在属性,以确保网络传播者无法引起有意义的退化。其他人建议系统应包括一个内置的自主智能代理,负责思考和采取行动,以持续观察,检测,最小化和修复网络降解。在所有情况下,预选赛“设计”都表明弹性的来源是系统结构和操作中固有的。但是,其他弹性是什么,而不是设计呢?显然,必须有另一种弹性,否则“设计”预选赛的目的是什么?确实,尽管提到的频率较低,但存在一种替代形式的弹性,称为“干预弹性”。在本文中,我们通过干预探索了设计和弹性的差异和相互依赖。
The term "cyber resilience by design" is growing in popularity. Here, by cyber resilience we refer to the ability of the system to resist, minimize and mitigate a degradation caused by a successful cyber-attack on a system or network of computing and communicating devices. Some use the term "by design" when arguing that systems must be designed and implemented in a provable mission assurance fashion, with the system's intrinsic properties ensuring that a cyber-adversary is unable to cause a meaningful degradation. Others recommend that a system should include a built-in autonomous intelligent agent responsible for thinking and acting towards continuous observation, detection, minimization and remediation of a cyber degradation. In all cases, the qualifier "by design" indicates that the source of resilience is somehow inherent in the structure and operation of the system. But what, then, is the other resilience, not by design? Clearly, there has to be another type of resilience, otherwise what's the purpose of the qualifier "by design"? Indeed, while mentioned less frequently, there exists an alternative form of resilience called "resilience by intervention." In this article we explore differences and mutual reliance of resilience by design and resilience by intervention.