This report - a major revision of its previous release - describes a reference architecture for intelligent software agents performing active, largely autonomous cyber-defense actions on military networks of computing and communicating devices. The report is produced by the North Atlantic Treaty Organization (NATO) Research Task Group (RTG) IST-152 "Intelligent Autonomous Agents for Cyber Defense and Resilience". In a conflict with a technically sophisticated adversary, NATO military tactical networks will operate in a heavily contested battlefield. Enemy software cyber agents - malware - will infiltrate friendly networks and attack friendly command, control, communications, computers, intelligence, surveillance, and reconnaissance and computerized weapon systems. To fight them, NATO needs artificial cyber hunters - intelligent, autonomous, mobile agents specialized in active cyber defense. With this in mind, in 2016, NATO initiated RTG IST-152. Its objective has been to help accelerate the development and transition to practice of such software agents by producing a reference architecture and technical roadmap. This report presents the concept and architecture of an Autonomous Intelligent Cyber-defense Agent (AICA). We describe the rationale of the AICA concept, explain the methodology and purpose that drive the definition of the AICA Reference Architecture, and review some of the main features and challenges of AICAs.
翻译:本报告是对之前版本的重大修订,描述了在计算和通信设备的军事网络上执行活动、大部分自主进行网络防御行动的智能软件代理人的参考架构。本报告由北约研究任务组(RTG)IST-152“智能自主代理人用于网络防御和适应性”的成员制作。在与技术复杂的敌人进行冲突时,北约军事战术网络将在一个极为激烈的战场上运作。敌方软件网络代理人——恶意软件——将渗透到友方网络中并攻击友方指挥、控制、通信、计算机、情报、监视和侦察以及计算机化武器系统。为了对抗它们,北约需要人工智能网络猎手——专注于主动网络防御的智能、自主、移动代理人。鉴于此,北约于2016年启动了RTG IST-152。它的目标是通过制定参考架构和技术路线图来帮助加速这类软件代理人的开发和应用。本报告介绍了自主智能网络防御代理人(AICA)的概念和架构。我们描述了AICA概念的基础,并解释了定义AICA参考架构的方法和目的,并回顾了AICAs的一些主要特点和挑战。