Proteus


Proteus aims to improve security solutions for enterprise networks. The majority of security breaches inside enterprise networks today occur when laptops (nodes at the mobile perimeter) leave, get infected, and then re-enter the enterprise. We consider it imperative to make laptops smarter so they can do a better job of protecting themselves against a broad range of security threats, and thereby protecting the enterprise as well. We believe that today's solutions that configure security mechanisms for laptops are fundamentally flawed in that all laptops are configured the same way. Since anomaly detection relies upon finding outliers based upon some description of ``normal patterns of usage'', it is essential to define ``normal'' correctly. Our premise is that normal behavior should be defined with respect to each end host individually. Since end host behavior differs substantially across people, what is normal for one person may be out of range for another. We thus propose to develop and use individual profiles of end host behavior that can in term be used to allow the security solutions at each machine to be personalized. These profiles will also enable novel security solutions to be developed.


Researchers