Seminars and Events
CRADLE: A Language for Cyber Event Reproduction and System-Wide Analysis
Event Details
Abstract:
Advanced cyber threats pose significant challenges for cyber event analysis, investigation, and prevention. These challenges are further amplified by the limited and fragmented availability of information about real-world incidents. One effective approach is to reproduce cyber incidents in isolated testbeds, enabling systematic observation, comprehensive telemetry collection, and rigorous validation of defenses.
To address the challenges of cyber experimentation, we propose CRADLE, a language that encodes cyber experimentation as code and establishes a foundation for a broad range of cyber analysis applications. CRADLE provides representations for describing detailed cyber environments and events. As a high-level language, CRADLE specifications integrate components from multiple sources and can be “compiled” into different types of testbed environments. CRADLE drives the reproduction of cyber events from attack descriptions, enabling interactive investigation and the generation of datasets suitable for data-driven cyber analysis. Furthermore, CRADLE enables system-wide analysis via statically reasoning about the environment, such as exploitability and risk analysis.
In this talk, we will present the design and case studies of CRADLE and discuss our roadmap for follow-up research.
Speaker Bio
Zhenkai Liang is an Associate Professor in the Department of Computer Science, School of Computing, National University of Singapore. He is also a co-Lead Principal Investigator of National Security R&D Lab of Singapore. His research interests are in systems and security, including binary program analysis, system provenance analysis, cyber security experimentation, security in emerging platforms, such as Web, mobile, and Internet-of-things (IoT), and AI platforms. He also investigates security problems beyond the system boundary from the angle of economics, finance, and risk management. He has been publishing high-impact papers in top security and software engineering conferences, and won ten best/distinguished paper awards, as well as seven Teaching Excellence Awards from NUS and School of Computing. He is a member of the Steering Committee of ACM CCS and has served as a member of the Steering Group of NDSS. He has served as technical committee members and editorial board members of top security conferences and journals, including ACM Conference on Computer and Communications Security (CCS), USENIX Security Symposium, Network and Distributed System Security Symposium (NDSS), IEEE Transactions on Dependable and Secure Computing (TDSC), and ACM Transactions on Privacy and Security (TOPS). He received his Ph.D. degree in Computer Science from Stony Brook University in 2006 and B.S. degree in Computer Science and B.S. degree in Economics (CCER) from Peking University in 1999.
Speaker Host: David Balenson, Interim Director of the Networking and Cybersecurity Division, ISI
POC: Matt Binkley, Executive Assistant of the Networking and Cybersecurity Division, ISI