PROCEEDINGS OF A WORKSHOP
FORUM ON |
|
Cyber |
|
WORKSHOP SERIES |
|
Recoverability as a |
THE NATIONAL ACADEMIES PRESS 500 Fifth Street, NW Washington, DC 20001
This project was supported by the National Science Foundation under award number CNS-14194917 and the National Institute of Standards and Technology under award number 60NANB16D311. Any opinions, findings, conclusions, or recommendations expressed in this publication do not necessarily reflect the views of any organization or agency that provided support for this project.
International Standard Book Number-13: 978-0-309-48370-4
International Standard Book Number-10: 0-309-48370-0
Digital Object Identifier: https://doi.org/10.17226/25240
Additional copies of this publication are available for sale from the National Academies Press, 500 Fifth Street, NW, Keck 360, Washington, DC 20001; (800) 624-6242 or (202) 334-3313; http://www.nap.edu.
Copyright 2018 by the National Academy of Sciences. All rights reserved.
Printed in the United States of America
National Academies of Sciences, Engineering, and Medicine. 2018. Recoverability as a First-Class Security Objective: Proceedings of a Workshop. Forum on Cyber Resilience Workshop Series. Washington, DC: The National Academies Press. https://doi.org/10.17226/25240.
Consensus Study Reports published by the National Academies of Sciences, Engineering, and Medicine document the evidence-based consensus on the study’s statement of task by an authoring committee of experts. Reports typically include findings, conclusions, and recommendations based on information gathered by the committee and the committee’s deliberations. Each report has been subjected to a rigorous and independent peer-review process and it represents the position of the National Academies on the statement of task.
Proceedings published by the National Academies of Sciences, Engineering, and Medicine chronicle the presentations and discussions at a workshop, symposium, or other event convened by the National Academies. The statements and opinions contained in proceedings are those of the participants and are not endorsed by other participants, the planning committee, or the National Academies.
For information about other products and activities of the National Academies, please visit www.nationalacademies.org/about/whatwedo.
FORUM ON |
|
Cyber |
|
WORKSHOP SERIES |
Recoverability as a
First-Class Security Objective
PROCEEDINGS OF A WORKSHOP
Anne Frances Johnson and Lynette I. Millett, Rapporteurs
THE NATIONAL ACADEMIES PRESS
Washington, DC
www.nap.edu
The National Academy of Sciences was established in 1863 by an Act of Congress, signed by President Lincoln, as a private, nongovernmental institution to advise the nation on issues related to science and technology. Members are elected by their peers for outstanding contributions to research. Dr. Marcia McNutt is president.
The National Academy of Engineering was established in 1964 under the charter of the National Academy of Sciences to bring the practices of engineering to advising the nation. Members are elected by their peers for extraordinary contributions to engineering. Dr. C. D. Mote, Jr., is president.
The National Academy of Medicine (formerly the Institute of Medicine) was established in 1970 under the charter of the National Academy of Sciences to advise the nation on medical and health issues. Members are elected by their peers for distinguished contributions to medicine and health. Dr. Victor J. Dzau is president.
The three Academies work together as the National Academies of Sciences, Engineering, and Medicine to provide independent, objective analysis and advice to the nation and conduct other activities to solve complex problems and inform public policy decisions. The National Academies also encourage education and research, recognize outstanding contributions to knowledge, and increase public understanding in matters of science, engineering, and medicine.
Learn more about the National Academies of Sciences, Engineering, and Medicine at www.nationalacademies.org.
COMMITTEE ON CYBER RESILIENCE WORKSHOP SERIES
FRED B. SCHNEIDER, NAE,1 Cornell University, Chair
ANITA ALLEN, NAM,2 University of Pennsylvania
ERIC GROSSE, Independent Consultant
BUTLER W. LAMPSON, NAS3/NAE, Microsoft Corporation
SUSAN LANDAU, Worcester Polytechnic Institute
Staff
LYNETTE I. MILLETT, Director, Forum on Cyber Resilience
EMILY GRUMBLING, Program Officer
SHENAE BRADLEY, Senior Program Assistant
FORUM ON CYBER RESILIENCE
FRED B. SCHNEIDER, NAE, Cornell University, Chair
ANITA ALLEN, NAM, University of Pennsylvania
ROBERT BLAKLEY, Citigroup
FRED CATE, Indiana University
DAVID D. CLARK, NAE, Massachusetts Institute of Technology
RICHARD DANZIG, Johns Hopkins University
ERIC GROSSE, Independent Consultant
DAVID HOFFMAN, Intel Corporation
PAUL KOCHER, Independent Researcher
TADAYOSHI KOHNO, University of Washington
BUTLER W. LAMPSON, NAS/NAE, Microsoft Corporation
SUSAN LANDAU, Tufts University
STEVEN B. LIPNER, NAE, SAFECode
JOHN MANFERDELLI, Northeastern University
DEIRDRE K. MULLIGAN, University of California, Berkeley
TONY SAGER, Center for Internet Security
WILLIAM SANDERS, University of Illinois at Urbana-Champaign
PETER SWIRE, Georgia Institute of Technology
DAVID VLADECK, Georgetown University
MARY ELLEN ZURKO, MIT Lincoln Laboratory
Ex Officio
DONNA DODSON, National Institute for Standards and Technology
JEREMY EPSTEIN, National Science Foundation
WILLIAM MARTIN, National Security Agency
Staff
LYNETTE I. MILLETT, Director
EMILY GRUMBLING, Program Officer
KATIRIA ORTIZ, Associate Program Officer
SHENAE BRADLEY, Administrative Assistant
For more information about the Forum, see its website at http://www.cyber-forum.org, or e-mail the Forum at cyberforum@nas.edu.
COMPUTER SCIENCE AND TELECOMMUNICATIONS BOARD
FARNAM JAHANIAN, Carnegie Mellon University, Chair
LUIZ ANDRE BARROSO, Google, Inc.
STEVEN M. BELLOVIN, NAE, Columbia University
ROBERT F. BRAMMER, Brammer Technology, LLC
EDWARD FRANK, Cloud Parity, Inc.
LAURA HAAS, NAE, University of Massachusetts, Amherst
MARK HOROWITZ, NAE, Stanford University
ERIC HORVITZ, NAE, Microsoft Research
VIJAY KUMAR, NAE, Univ. of Pennsylvania
BETH MYNATT, Georgia Institute of Technology
CRAIG PARTRIDGE, Raytheon BBN Technologies
DANIELA RUS, NAE, Massachusetts Institute of Technology
FRED B. SCHNEIDER, NAE, Cornell University
MARGO SELTZER, Harvard University
MOSHE VARDI, NAS/NAE, Rice University
KATHERINE YELICK, University of California, Berkeley
Staff
JON EISENBERG, Senior Director
LYNETTE I. MILLETT, Associate Director
SHENAE BRADLEY, Administrative Assistant
EMILY GRUMBLING, Program Officer
RENEE HAWKINS, Financial and Administrative Manager
KATIRIA ORTIZ, Associate Program Officer
JANKI PATEL, Senior Program Assistant
For more information on CSTB, see its website at http://www.cstb.org, write to CSTB, National Research Council, 500 Fifth Street, NW, Washington, DC 20001, call (202) 334-2605, or email the CSTB at cstb@nas.edu.
ACKNOWLEDGMENT OF REVIEWERS
This Proceedings of a Workshop was reviewed in draft form by individuals chosen for their diverse perspectives and technical expertise. The purpose of this independent review is to provide candid and critical comments that will assist the National Academies of Sciences, Engineering, and Medicine in making each published proceedings as sound as possible and to ensure that it meets the institutional standards for quality, objectivity, evidence, and responsiveness to the charge. The review comments and draft manuscript remain confidential to protect the integrity of the process. We thank the following individuals for their review of this proceedings:
Robert Blakley, Citigroup, Inc.,
Steven B. Lipner, NAE,1 SAFECode,
Peter G. Neumann, SRI International, and
Tony W. Sager, Center for Internet Security.
Although the reviewers listed above provided many constructive comments and suggestions, they were not asked to endorse the content of the proceedings nor did they see the final draft before its release. The review of this proceedings was overseen by Steven M. Bellovin, NAE, Columbia University. He was responsible for making certain that an independent examination of this proceedings was carried out in accordance with standards of the National Academies and that all review comments were carefully considered. Responsibility for the final content rests entirely with the rapporteurs and the National Academies.
___________________
1 National Academy of Engineering.
Preface
The Forum on Cyber Resilience—a roundtable established in 2015 by the National Academies of Sciences, Engineering, and Medicine—facilitates and enhances the exchange of ideas among scientists, practitioners, and policy makers who are concerned with urgent and important issues related to the resilience of the nation’s computing and communications systems, including the Internet, other critical infrastructures, and commercial systems. Forum activities help inform and engage a broad range of stakeholders around issues involving technology and policy related to cyber resilience, cybersecurity, privacy, and related emerging issues. A key role for the forum is to surface and explore topics that advance the national conversation.
In 2016, the forum held a workshop to explore the topic of mitigating harms from data breach. That workshop was summarized in Data Breach Aftermath and Recovery for Individuals and Institutions: Proceedings of a Workshop. Discussions during and subsequent to that workshop highlighted how cyberattacks and breaches can also compromise availability and/or integrity of critical systems. The abilities to mitigate the effects of a successful attack and to reliably recover—either to full functionality or to a well-understood set of critical functionalities—are important; in some circumstances, recovering to full functionality is more important than protecting confidentiality.
To explore recoverability as a first-class security objective—at different granularities (from documents to data centers) and from both research and operational perspectives—the forum decided to host a workshop. The workshop featured invited speakers from the
government, private sector, and academia. This proceedings summarizes presentations made by invited speakers and other remarks by workshop participants. In keeping with the workshop’s exploratory purpose, the proceedings does not contain findings or recommendations. Nor, in keeping with National Academies guidelines for workshop proceedings, does it necessarily report consensus views of the workshop participants or organizing committee. The planning group appointed to oversee all forum workshops was limited to planning the workshop, and this workshop proceedings was prepared by the workshop rapporteurs and forum staff as a factual summary of what occurred at the workshop. The document draws on prepared remarks of workshop speakers, comments made by workshop participants, and ensuing discussions.
The first chapter summarizes the introduction to the workshop, reproduces background material provided to all participants, and summarizes the introductory keynote by Butler Lampson. Chapter 2 summarizes speaker presentations. Chapter 3 describes the content of the final plenary discussion, highlighting some of the broader themes that emerged throughout the workshop. The agenda of the workshop is in Appendix A, and short biosketches of the planning group and speakers appear in Appendixes B and C, respectively.
My sincere thanks to the planning group, forum members, and staff who helped organize the workshop, as well as to the invited speakers for their thoughtful remarks and enthusiastic participation in the discussions that ensued. Writing support was provided by Anne Frances Johnson and Kathleen Pierce, Creative Science Writing. I also extend our appreciation to the National Science Foundation and the National Security Agency and the Special Cyber Operations Research and Engineering Working Group, and the National Institute of Standards and Technology for their support and encouragement of forum activities.
Fred B. Schneider, Chair
Forum on Cyber Resilience
Contents
Framing Keynote: A Broad View of Recovery
2 SUMMARY OF WORKSHOP PRESENTATIONS
The Role of Trust in Breach Recovery
Resilience in the U.S. Financial Sector
Resilience and Recovery in the Electric Grid
Community Resilience and the Framework for Improving Critical Infrastructure for Cybersecurity
3 CLOSING OBSERVATIONS AND DISCUSSION
A Workshop Agenda and Participants List
This page intentionally left blank.