<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <abstract>
        <p>We are addressing the class of virtual organizations where an entrepreneurial or other activity acts as an interface between a number of existing remote services or applications and a number of customers that should interact with them in complex ways. For example, such activities include private e-Government middle services that specialize in carrying out complex tasks with many different state administration services, or commercial houses specializing in centralizing and organizing large complicated orders that involve a number of different vendors scattered around the electronic world. Because the integrated services/applications are remote and external to the middle entity responsible for the organization, the current practice is to manage the customer tasks mostly manually or in conventional ways, such as calling external entities and negotiating prices and delivery delays. The INFRAWEBS1 framework is being designed and developed with the vision to help business people build composite applications that tackle much of this interaction complexity as automatically as possible, with the role of human intervention not necessarily being fully dismissed. Such virtual organizations are characterized by operational and performance criteria that are independent and even sometimes incompatible with those of individual components (external services/applications) involved. This parallels the organization of multicellular biological organisms where the integrity of the organism as a whole is defined differently than for each of its constituent cells, and indeed many individually effective functionalities may be harmful from a systemic point of view, such as for example tumor cells, parasites etc. Because of this property, it is expected that an artificial immune system can be designed to treat integrity issues in the same way that a natural immune system does so within a multi-cellular organism. This setup assumes that individual security problems are tackled by the corresponding components themselves, so that at the composite (organismal) level only those attacks can be identified and tackled that have functional consequences for the overall system. For instance, a component may be unavailable, or it may reply with unusual information and so on. Such dysfunctions should be detected and handled at the application level, wherever possible. Because such distributed organizations are to be dynamic by nature, it makes sense to avoid as much as possible predefined “rigid” security schemes between components and allow plasticity, in the sense that some of the used components may later become obsolete and abandoned, or new ones will have to be included in the organization's repertoire, or the connection pathways through the virtual organization will change and so on. That is, much of the S&amp;P testing should be designed to happen at runtime. Furthermore, individual protection schemes of existing components will be bound to change without notice. Such virtual organizations should rely on this information as little as possible.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>In such a democratic framework, that uses external uncontrollable components in a
nonexclusive manner, some components may be occasionally busy or committed elsewhere.
Furthermore, some external components may be occasionally updated or adapted. In this
context, the exact relations between components, both structural and semantic, are dynamic
and thus sometimes unforeseen.</p>
      <p>As a consequence, it makes no sense to regard components as safe or unsafe, which is the
usual approach in classical ICT security research. Instead, the same component may behave
safely or unsafely for the overall organization (and even for itself) according to internal state,
specifics of the requests processed, timings etc. This means that the communication channel
between components cannot be assigned a unique forever-constant value of safe or unsafe;
instead, the specifics of a request or message in relation with the internals of the receiver
service may determine, sometimes not uniquely, whether the particular communication act is
safe or unsafe. The same message may be therefore considered safe in one context and unsafe
in another one. The security problem can be formulated now as a problem of managing
information about information, i.e. information about message from component to component
and is therefore declarative, in the sense of understanding abstract relations and flow.
Because of the above, our approach focuses on the detailed examination of exchanged
messages with components to identify potential threats and only a little if any explicit
component authentication is necessary. This approach sets itself in the trend of information
flow regulation at runtime.</p>
      <p>The artificial immune system is defined as a security “shell” that constitutes the control
system for the autonomous virtual organization and filters incoming and outcoming
information to external components or other types of active resources. This shell functions in
parallel with the regular activities of the virtual organization and is responsible for
recognizing hostile resources, i.e. resources that are malicious, malfunctioning or just slow.
Attacks and insecure cases such as unavailability, improper treatment, unacceptability of
communicated information, denial of service etc. can in principle be smoothly integrated in
this configuration.</p>
      <p>The operation of the artificial immune system mirrors exactly that of the natural immune
system of first order. The natural immune system recognizes and attacks alien bodies by not
allowing them to be metabolized by the body of the organism. In the same way, the security
shell recognizes and captures alien or suspect messages before they are processed by the
organization. A population of specialized artificial cells (that correspond to the antibodies),
are triggered by the presence of the alien message and proliferate very rapidly and only as
much as necessary to ensure clobbering of the alien population. Certainly, under certain
conditions, for example when the alien attack is extremely severe or when there are multiple
attacks concurrently, the immune system occupies a large amount of the resources of the
central organization and as a result the latter is hindered in its normal operation. In nature,
advanced organisms, such as vertebrates, possess also a second order level of operation, in
which the population of the antibodies records information from past experience, i.e. alien
body features or “templates” used for identification, so as to make resistance automatic the
next time the same threat appears.</p>
      <p>The immune systems approach proposed is in principle independent of the actual
implementation of the individual components and their potential security policies. Thus, in
principle, the immune algorithms are application-independent and relatively generic. But
since the exact details and parameters of the algorithms need to be identified and tuned based
on the case studies, it would be unrealistic to claim that the particular structure of the immune
security shell would be directly applicable (“pluggable”) to other frameworks or to other
types of organization. Instead, the solution sought should be thought of as one instance of the
class of solutions supported by this system in general.</p>
      <p>Because of these, and in accordance with the usual approach in complex systems research, we
have decided to study the properties of the immune system and the details of the algorithms in
simulation. We are in the process of developing special purpose tools that co-develop with the
simulations and the experimental design activity.</p>
      <p>The virtual organization (the body) is a highly connected network of representations or
“images” of external components (somatic cells), where for each link a “preference degree” or
“degree of trust” is present. This metric is continuously monitored and updated by the security
shell, according to the immune algorithm. While particular details are bound to be
casespecific, in general the immune algorithm has the following properties :
•
•
•
•
•
•</p>
      <p>The artificial immune network regulates input-output flow between component images.
The immune network consists of a number of nodes (“cells” or “antibodies”), each
responding to one type of component message. Types are to be defined within the scope
of particular applications, but as a general rule they use actual component properties or
metrics. Two general-purpose antibody classes are price-related ones (e.g. “price &gt; 100”
or “price between 80 and 120”) and delay-related ones (e.g. “delay &lt; 3h”).</p>
      <p>Many such different types have to be present and/or generated for the algorithm to work
properly. For example, in the above case many variants of the type “price &gt; X” have to be
present and/or generated for different values of X. The types correspond to the biological
notion of specificity.</p>
      <p>The algorithm relies on emergent population effects, hence a number of clones for each
antibody should be present at any moment.</p>
      <p>The antibodies (clones) compete with each other for message “consumption” that leads to
proliferation. The antibodies that dominate in the competition define which messages are
discarded. The competition corresponds to the biological notion of clonal selection.
The competition criterion is organization-specific and integrates both absolute global
properties (for example, an antibody that executes once, is faster next time) and
intercomponent properties (a message not confirmed by the recipient virtual node may be
weaker next time).</p>
      <p>Future research issues include stability study of the network, extension to a two-level
vertebrate-like memoriful immune system and hooking to real-world S&amp;P policies.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <surname>Bersini</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          (
          <year>1999</year>
          ).
          <article-title>The Endogenous Double Plasticity of the Immune Network and the Inspiration to be drawn for Engineering Artifacts</article-title>
          .
          <source>In “Artificial Immune Systems and Their Applications”</source>
          , Springer Verlag, pp.
          <fpage>22</fpage>
          -
          <lpage>44</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Dasgupta</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gonzalez</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          (
          <year>2005</year>
          ).
          <article-title>Artificial Immune Systems in Intrusion Detection, Chapter 7 in the book “Enhancing Computer Security with Smart Technology” by V. Rao Vemuri (Ed</article-title>
          .), pages
          <fpage>165</fpage>
          -
          <lpage>208</lpage>
          ,
          <string-name>
            <surname>Auerbach</surname>
            <given-names>Publications</given-names>
          </string-name>
          ,
          <year>November 2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <surname>Goldenberg</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shavitt</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shir</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Solomon</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          (
          <year>2005</year>
          ).
          <article-title>Distributive immunization of networks against viruses using the 'honey-pot' architecture,</article-title>
          <string-name>
            <surname>Nature</surname>
          </string-name>
          ,
          <year>December 2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <surname>Perelson</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Weisbuch</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          (
          <year>1997</year>
          ).
          <article-title>Immunology for physicists</article-title>
          ,
          <source>Review of Modern Physics</source>
          ,
          <volume>69</volume>
          (
          <issue>4</issue>
          ):
          <fpage>1219</fpage>
          -
          <lpage>1267</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>