<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NetQi</title>
	<atom:link href="http://www.netqi.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netqi.org</link>
	<description>Brings foresight to your world</description>
	<lastBuildDate>Sun, 26 Oct 2008 22:40:21 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Publication: Using Strategy Objectives for Network Security Analysis</title>
		<link>http://www.netqi.org/publication/</link>
		<comments>http://www.netqi.org/publication/#comments</comments>
		<pubDate>Sun, 26 Oct 2008 22:40:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Publication]]></category>
		<category><![CDATA[article]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[paper]]></category>

		<guid isPermaLink="false">http://www.netqi.org/?p=39</guid>
		<description><![CDATA[Paper accepted at the 4th International Conferences on Information Security and Cryptology (INSCRYPT 2008). Beijing China.
Abstract
The anticipation game framework is an extension of attack graphs based on game theory. It is used to anticipate and analyze intruder and administrator concurrent interactions with the network.
As attack graph based on model checking, the goal on an anticipation [...]]]></description>
			<content:encoded><![CDATA[<p>Paper accepted at the<a href="http://www.inscrypt.cn/inscrypt/" target="_blank"> 4th International Conferences on Information Security and Cryptology</a> (INSCRYPT 2008). Beijing China.</p>
<h5>Abstract</h5>
<p>The anticipation game framework is an extension of attack graphs based on game theory. It is used to anticipate and analyze intruder and administrator concurrent interactions with the network.</p>
<p>As attack graph based on model checking, the goal on an anticipation game is to prove that a safety property hold. However using this kind of goal is tedious and error prone on large networks because it assume that the analyst have a prior and complete knowledge of the network critical services.</p>
<p>In this paper we address this issue by introducing a new kind of goal called strategy objectives which is more usable for network security analysis purpose.</p>
<p>To do so we have extended the anticipation games framework with cost and reward. Additionally this extension allows to take into account the financial dimension of attack during the analysis.</p>
<p>We prove that finding the optimal strategy is decidable and only requires a linear memory space. Finally we show that anticipation game with strategy can be used in practice even on large networks by evaluating the performance of our prototype.</p>
<h5>file</h5>
<h5><a href="http://www.netqi.org/wp-content/uploads/2008/10/strat.pdf">Using Strategy Objectives for Network Security Analysis (PDF preliminary version)</a></h5>
<h5>Bibtex</h5>
]]></content:encoded>
			<wfw:commentRss>http://www.netqi.org/publication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Publication: NetQi: A Model checker for Anticipation Game</title>
		<link>http://www.netqi.org/publication/</link>
		<comments>http://www.netqi.org/publication/#comments</comments>
		<pubDate>Fri, 10 Oct 2008 22:08:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Publication]]></category>
		<category><![CDATA[article]]></category>
		<category><![CDATA[implementation]]></category>
		<category><![CDATA[paper]]></category>

		<guid isPermaLink="false">http://www.netqi.org/?p=38</guid>
		<description><![CDATA[The paper has been accepted to  the 6th International Symposium on Automated   Technology for Verification and Analysis (ATVA&#8217;08). Held at Seoul, Korea in  October 2008
Abstract
NetQi is a freely available model-checker designed to analyze network incidents such as intrusion. This tool is an implementation of the anticipation game framework, a variant of timed [...]]]></description>
			<content:encoded><![CDATA[<p>The paper has been accepted to <a class="DOIinentry" href="http://dx.doi.org/10.1007/978-3-540-88387-6_22"><span class="booktitle"> the 6th International Symposium on Automated   Technology for Verification and Analysis (ATVA&#8217;08).</span></a> Held at Seoul, Korea in  October 2008</p>
<h5>Abstract</h5>
<p>NetQi is a freely available model-checker designed to analyze network incidents such as intrusion. This tool is an implementation of the anticipation game framework, a variant of timed game tailored for network analysis. The main purpose of NetQi is to find, given a network initial state and a set of rules, the best strategy that fulfills player objectives by model-checking the anticipation game and comparing the outcome of each play that fulfills strategy constraints. For instance, it can be used to find the best patching strategy. NetQi has been successfully used to analyze service failure due to hardware, network intrusion, worms and multiple-site intrusion defense cooperation.</p>
<h5>Bibtex</h5>
<table border="0" width="80%" align="center">
<tbody>
<tr>
<td colspan="3"><tt>@<span style="color: #bb2222;">inproceedings</span>{Bur-atva08,</tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">address</span> =</tt></td>
<td valign="baseline"><tt> {Seoul, Korea}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">author</span> =</tt></td>
<td valign="baseline"><tt> {Bursztein, Elie}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">booktitle</span> =</tt></td>
<td valign="baseline"><tt> {{P}roceedings of the 6th {I}nternational {S}ymposium on {A}utomated   {T}echnology for {V}erification and {A}nalysis ({ATVA}'08)}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">DOI</span> =</tt></td>
<td valign="baseline"><tt> {10.1007/978-3-540-88387-6_22}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">editor</span> =</tt></td>
<td valign="baseline"><tt> {Cha, Sungdeok and Choi, Jin-Young and Kim, Moonzoo and Lee, Insup and   Viswanathan, Mahesh}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">month</span> =</tt></td>
<td valign="baseline"><tt> oct, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">pages</span> =</tt></td>
<td valign="baseline"><tt> {246-251}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">publisher</span> =</tt></td>
<td valign="baseline"><tt> {Springer}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">series</span> =</tt></td>
<td valign="baseline"><tt> {Lecture Notes in Computer Science}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">title</span> =</tt></td>
<td valign="baseline"><tt> {Net{Q}i: A~Model checker for Anticipation Game}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">url</span> =</tt></td>
<td valign="baseline"><tt> {http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/Bur-atva08.pdf}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">volume</span> =</tt></td>
<td valign="baseline"><tt> {5311}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">year</span> =</tt></td>
<td valign="baseline"><tt> {2008}, </tt></td>
</tr>
<tr>
<td colspan="3"><tt>}</tt></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.netqi.org/publication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Publication: Extending Anticipation Games with Location, Penalty and Timeline.</title>
		<link>http://www.netqi.org/publication/</link>
		<comments>http://www.netqi.org/publication/#comments</comments>
		<pubDate>Mon, 15 Sep 2008 21:34:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Publication]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[paper]]></category>

		<guid isPermaLink="false">http://www.netqi.org/?p=36</guid>
		<description><![CDATA[Paper accepted at FAST&#8217;08, Malaga, Spain,
Abstract
Over the last few years, attack graphs have became a well   recognized tool to analyze and model complex network attack. The most   advanced evolution of attack graphs, called anticipation games, is based on   game theory. However even if anticipation games allow to model time, [...]]]></description>
			<content:encoded><![CDATA[<p>Paper accepted at <span class="booktitle">FAST&#8217;08, Malaga, Spain,</span></p>
<h5>Abstract</h5>
<p>Over the last few years, attack graphs have became a well   recognized tool to analyze and model complex network attack. The most   advanced evolution of attack graphs, called anticipation games, is based on   game theory. However even if anticipation games allow to model time,   collateral effects and player interactions with the network, there is still   key aspects of the network security that cannot be modeled in this framework.   Theses aspects are network cooperation to fight unknown attack, the cost of   attack based on its duration and the introduction of new attack over the   time. In this paper we address these needs, by introducing a three-fold   extension to anticipation games. We prove that this extension does not change   the complexity of the framework. We illustrate the usefulness of this   extension by presenting how it can be used to find a defense strategy against   0 days that use an honey net. Finally, we have implemented this extension   into a prototype, to show that it can be used to analyze large networks   security.</p>
<h5>File</h5>
<p><a href="http://www.netqi.org/wp-content/uploads/2008/10/eb-fast08.pdf">The paper in PDF</a></p>
<h5>BibTex</h5>
<table border="0" width="80%" align="center">
<tbody>
<tr>
<td colspan="3"><tt>@<span style="color: #bb2222;">inproceedings</span>{EB-fast08,</tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">address</span> =</tt></td>
<td valign="baseline"><tt> {Malaga, Spain}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">author</span> =</tt></td>
<td valign="baseline"><tt> {Bursztein, Elie}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">booktitle</span> =</tt></td>
<td valign="baseline"><tt> {{P}roceedings of the 5th {I}nternational {W}orkshop on {F}ormal {A}spects in   {S}ecurity and {T}rust ({FAST}'08)}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">editor</span> =</tt></td>
<td valign="baseline"><tt> {Degano, Pierpaolo and Guttman, Joshua and Martinelli, Fabio}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">month</span> =</tt></td>
<td valign="baseline"><tt> oct, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">note</span> =</tt></td>
<td valign="baseline"><tt> {To   appear}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">publisher</span> =</tt></td>
<td valign="baseline"><tt> {Springer}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">series</span> =</tt></td>
<td valign="baseline"><tt> {Lecture Notes in Computer Science}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">title</span> =</tt></td>
<td valign="baseline"><tt> {Extending Anticipation Games with Location, Penalty and Timeline}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">url</span> =</tt></td>
<td valign="baseline"><tt> {http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/eb-fast08.pdf}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">year</span> =</tt></td>
<td valign="baseline"><tt> {2008}, </tt></td>
</tr>
<tr>
<td colspan="3"><tt>}</tt></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.netqi.org/publication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Presentation: NetQi presented at MITACS</title>
		<link>http://www.netqi.org/presentation/</link>
		<comments>http://www.netqi.org/presentation/#comments</comments>
		<pubDate>Tue, 10 Jun 2008 21:33:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Presentation]]></category>
		<category><![CDATA[communication]]></category>

		<guid isPermaLink="false">http://www.netqi.org/?p=35</guid>
		<description><![CDATA[Elie Bursztein gave a talk about NetQI and how it can be use by network administrators to improve their security at the 1st Canada-France MITACS Workshop on Foundations &#38; Practice of Security Montréal, Québéc May 31 &#8211; June 2, 2008. A quick demo of the new GUI, was also presented at the end of the [...]]]></description>
			<content:encoded><![CDATA[<p>Elie Bursztein gave a talk about NetQI and how it can be use by network administrators to improve their security at the <a href="http://www.mitacs.ca/conferences/site/index.php?site_id=10006&amp;menu_id=43&amp;page_id=39">1st Canada-France MITACS Workshop on Foundations &amp; Practice of Security</a> Montréal, Québéc May 31 &#8211; June 2, 2008. A quick demo of the new GUI, was also presented at the end of the talk.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netqi.org/presentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Code release: version 1.1</title>
		<link>http://www.netqi.org/release/</link>
		<comments>http://www.netqi.org/release/#comments</comments>
		<pubDate>Thu, 05 Jun 2008 14:57:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Release]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[implementation]]></category>

		<guid isPermaLink="false">http://www.netqi.org/release/</guid>
		<description><![CDATA[We are please to release NetQi v1.1.
This version mainly offers significant speed and memory usage improvements. This release also include the new version of the GUI (v0.8), that improves the ergonomy. Please note that the GUI realase is an early release and that the GUI is still under heavy developpement.
As always you can find the [...]]]></description>
			<content:encoded><![CDATA[<p>We are please to release NetQi v1.1.</p>
<p>This version mainly offers significant speed and memory usage improvements. This release also include the new version of the GUI (v0.8), that improves the ergonomy. Please note that the GUI realase is an early release and that the GUI is still under heavy developpement.</p>
<p>As always you can find the <a title="full changelog" href="http://www.netqi.org/wiki/index.php/Changelog">full changelog here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netqi.org/release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Code release: version 1.0</title>
		<link>http://www.netqi.org/release/</link>
		<comments>http://www.netqi.org/release/#comments</comments>
		<pubDate>Sat, 23 Feb 2008 21:32:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Release]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[implementation]]></category>

		<guid isPermaLink="false">http://www.netqi.org/release/</guid>
		<description><![CDATA[After an extensive testing periode, we are proud to announce that NetQi version 1.0 is finally available.  This version have been tested against large examples and is considered as stable.
For installation or upgrade, please read the documentation. If you found a bug or still have problem with NetQi , you are welcome to contact us.
The [...]]]></description>
			<content:encoded><![CDATA[<p>After an extensive testing periode, we are proud to announce that NetQi version 1.0 is finally available.  This version have been tested against large examples and is considered as stable.</p>
<p>For installation or upgrade, please read the documentation. If you found a bug or still have problem with NetQi , you are welcome to contact us.</p>
<p>The next release will be focus on providing a stable a more intuitive Gui.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netqi.org/release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Publication: A Logical Framework for Evaluating Network Resilience Against Faults and Attacks</title>
		<link>http://www.netqi.org/publication/</link>
		<comments>http://www.netqi.org/publication/#comments</comments>
		<pubDate>Mon, 05 Nov 2007 17:47:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Publication]]></category>
		<category><![CDATA[asian 07]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[paper]]></category>

		<guid isPermaLink="false">http://www.netqi.org/publication/</guid>
		<description><![CDATA[Accepted paper at ASIAN 2007 at Carnegie Mellon University in Qatar.
Abstract
We present a logic-based framework to evaluate the resilience of computer networks in the face of incidents, i.e., attacks from malicious intruders as well as random faults. Our model uses a two-layered presentation of dependencies between files and services, and of timed games to represent [...]]]></description>
			<content:encoded><![CDATA[<p>Accepted paper at <a title="asian 2007" href="http://www.qatar.cmu.edu/asian07/" target="_blank">ASIAN 2007</a> at Carnegie Mellon University in Qatar.</p>
<h5>Abstract</h5>
<p>We present a logic-based framework to evaluate the resilience of computer networks in the face of incidents, i.e., attacks from malicious intruders as well as random faults. Our model uses a two-layered presentation of dependencies between files and services, and of timed games to represent not just incidents, but also the dynamic responses from administrators and their respective delays. We demonstrate that a variant TATL$\Diamond$ of timed alternating-time temporal logic is a convenient language to express several desirable properties of networks, including several forms of survivability. We illustrate this on a simple redundant Web service architecture, and show that checking such timed games against the so-called TATL$\Diamond$ variant of the timed alternating time temporal logic TATL is EXPTIME-complete.</p>
<h5>Files</h5>
<p><a title="Direct link to file" onclick="return false;" href="http://www.netqi.org/wp-content/uploads/2007/11/incidentlogic.pdf">Paper Author version (pdf)</a></p>
<h5>Bibtex</h5>
<table border="0" width="80%" align="center">
<tbody>
<tr>
<td colspan="3"><tt>@<span style="color: #bb2222;">inproceedings</span>{BG-asian07,</tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">address</span> =</tt></td>
<td valign="baseline"><tt> {Doha, Qatar}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">author</span> =</tt></td>
<td valign="baseline"><tt> {Bursztein, Elie and Goubault{-}Larrecq, Jean}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">booktitle</span> =</tt></td>
<td valign="baseline"><tt> {{P}roceedings of the 12th {A}sian {C}omputing {S}cience {C}onference   ({ASIAN}'07)}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">DOI</span> =</tt></td>
<td valign="baseline"><tt> {10.1007/978-3-540-76929-3_20}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">editor</span> =</tt></td>
<td valign="baseline"><tt> {Cervesato, Iliano}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">month</span> =</tt></td>
<td valign="baseline"><tt> dec, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">pages</span> =</tt></td>
<td valign="baseline"><tt> {212-227}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">publisher</span> =</tt></td>
<td valign="baseline"><tt> {Springer}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">series</span> =</tt></td>
<td valign="baseline"><tt> {Lecture Notes in Computer Science}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">title</span> =</tt></td>
<td valign="baseline"><tt> {A   Logical Framework for Evaluating Network Resilience Against Faults and   Attacks}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">url</span> =</tt></td>
<td valign="baseline"><tt> {http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/BGL-asian07.pdf}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">volume</span> =</tt></td>
<td valign="baseline"><tt> {4846}, </tt></td>
</tr>
<tr>
<td></td>
<td valign="baseline"><tt> <span style="color: #117711;">y</span></tt></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.netqi.org/publication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
