Autonomous Intelligent Cyber-Defense Agent (AICA) Reference Architecture, Release 2.0

Abstract

This report--a major revision of its previous release--describes a reference architecture for intelligent software agents performing active, largely autonomous cyber-defense actions on military networks of computing and communicating devices. The report is produced by the North Atlantic Treaty Organization (NATO) Research Task Group (RTG) IST-152 "Intelligent Autonomous Agents for Cyber Defense and Resilience". In a conflict with a technically sophisticated adversary, NATO military tactical networks will operate in a heavily contested battlefield. Enemy software cyber agents--malware--will infiltrate friendly networks and attack friendly command, control, communications, computers, intelligence, surveillance, and reconnaissance and computerized weapon systems. To fight them, NATO needs artificial cyber hunters--intelligent, autonomous, mobile agents specialized in active cyber defense. With this in mind, in 2016, NATO initiated RTG IST-152. Its objective has been to help accelerate the development and transition to practice of such software agents by producing a reference architecture and technical roadmap. This report presents the concept and architecture of an Autonomous Intelligent Cyber-defense Agent (AICA). We describe the rationale of the AICA concept, explain the methodology and purpose that drive the definition of the AICA Reference Architecture, and review some of the main features and challenges of AICAs.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Sep 01, 2019
Accession Number
AD1080471

Entities

People

  • Agostino Panico
  • Alessandro Guarino
  • Alexander S. Kott
  • Benoit Leblanc
  • Edlira Dushku
  • Fabio De Gaspari
  • Krzysztof Rzadca
  • Luigi V. Mancini
  • Martin Drasar
  • Mauno Pihelgas
  • Paul Losiewicz
  • Paul Theron

Organizations

  • United States Army Research Laboratory

Tags

Communities of Interest

  • Autonomy
  • C4I
  • Cyber
  • Engineered Resilient Systems
  • Materials and Manufacturing Processes

DTIC Thesaurus Topics

  • Active Defense
  • Application Protocols
  • Artificial Intelligence
  • Cognition
  • Cognitive Science
  • Communication Channels
  • Computer Languages
  • Computer Networks
  • Computer Programming
  • Computers
  • Cyber Defense Techniques
  • Cyberattacks
  • Cybersecurity
  • Information Science
  • Information Systems
  • Intrusion Detectors
  • Multiagent Systems
  • Network Science
  • Neural Networks
  • Ontologies
  • Self Organizing Systems

Fields of Study

  • Computer science

Readers

  • Agent-Based Social Robotics and Mobile-Assisted Learning in Virtual Environments.
  • International Relations and European Studies
  • Irregular Warfare and Special Operations Cyberspace Operations against Adversarial Threats.

Technology Areas

  • Cyber
  • Fully Networked C3
  • Fully Networked C3 - Command and Control