Although information security seems to be a factor more concerning to the practitioners to the extent that many papers including white papers have been written about it, academia have long indicated an interest in the subject matter as well. Many academic papers provide a perspective which is slightly deeper than the practitioner’s view in that the discussion also details the requirements for the design of the adaptive security tools.
In their paper, ‘Enterprise security architecture in business convergence environments” Sangkyun K et al. (2015) says that managements are facing difficult problems and confusions when trying to plan or implement information security systems in business convergence environments. They say that the more adaptive the enterprise firm, the greater its ability to improve its fitness as its market, industry, or technology changes. An article “Why can’t I do that?”: Tracing Adaptive Security Decision by Nhlabatsi et al. (2015), the authors take a look at adaptive systems on cloud whereby they say that users should understand how and why the behaviour of the system changes at runtime. This take of decision making capability by the system is shared by Evesti et al. (2014)in their paper Security Measuring for Self-adaptive Security when they say that self-adaptive security requires means for monitoring a security level and decision making capability to improve the current level.
In short, Evesti et al. (2014), define a self-adaptive security system as having the following capabilities:
1. System is capable to monitor its internal security state and external threat landscape in order to reveal security violations
2. System is capable to react to possible security violations and ongoing attacks by selecting alternative security mechanisms and parameters to keep the system on a secure state or move it back to the secure state.
In this paper by Evesti et al (2014), described two architectural requirements for a measurement based security adaptation as a collection of requirements for security measuring and identification of requirements from self-adaptive security perspective.
The paper, A System-Aware Cyber Security Architecture written by Jones and Harowitz and also published on-line in February 2012, says that the rising threat of successful attacks warrants the consideration of a top-down systems engineering approach that develops solution strategies regarding cyber security that go beyond the perimeter model. The authors advocate the use of a System-Aware Cyber Security that they say it provides the means to hypnotize specific threats in relation to specific application functions.
I have also noted from the article, Comparison of adaptive Information Security Approaches by Evesti & Ovaska, 2013 that in order to achieve a coherent security adaptation approach, the cooperation between autonomous computing, security and software development experts will be needed. As a result of collaboration, approach which is secure, easy to utilise, and contains necessary adaptation aspects in the same time can be achieved.
As mentioned earlier, academic papers extend the focus on in-depth mechanisms required by the adaptive security architecture tools. Although these are being addressed through different connotation, like EDAS (Event-Driven Adaptive Security) and some uses Self-Adaptive Security Architecture, the advocacy is on the continuous autonomic control loop.
EDAS (Event Driven Architecture Security)
Its platform consists of a set of methods and tools that are necessary to continuously monitor and analyze events in a context-aware manner to investigate any potential security threats and associated risks. It is constituted of three layers:
1. Monitoring Agent – It is tasked to remove any redundant events and shapes them into a universal format for risk analysis and adaptation.
2. Risk Analyzer – It investigates potential threats and risks associated with the events using a correlation engine such that false alarms are avoided.
3. Risk Adaptor – It is where adaptation engine selects a mitigation action from a pool of possible actions to reduce the risk impact. The selected action is then sent to the local adaptor process where the new security settings are received and applied.
The effects of the adapted changes are recorded, monitored and analyzed again. All this security monitoring, analysis and adaptation happens in a continuous control loop fashion.
ESAS is described in the article: Aman W, and Snekenes E (2015), EDAS: An Evaluation Prototype for Autonomic Event-Driven Adaptive Security in the Internet of Things, 225-256.
Self-Adaptive Security
It is considered as an adaptive security solution that is able to change and modify the used security mechanisms autonomously at runtime. This solution reference the model called MAPE-K (Monitor, Analyze, Plan and Execute), where K stands for knowledge. This platform concentrates on architecture, knowledge and access control. Architecture for security-adaptation loop is mapped to the MAPE model.
1. Monitor – It collects information that is analyzed to recognize adaptation needs.
2. Analyzer – It analyses the consequences of the changes based on knowledge retrieved from the ontologies at runtime.
3. Plan – This phase creates an adaptation plan for execution.
The four phases, MAPE, constitute an adaptation loop supported by knowledge and the adaptation approach combines solutions from different interoperability levels.
The Self-Adaptive Security is described in the article: Evesti, A., Suomalainen, J and Ovaska, E. (2013). Architecture and Knowledge-Driven Self-Adaptive Security in Smart Space, (2), 34-66.
What I have found from some academic papers is that academia supports the notion of going beyond traditional security mechanisms by advocating the development of architectures and tools that are threat intelligent to deal with sophisticated cyber attacks.