SDCI Sec: SESv3 (Security Event System - Version 3)

SDCI Sec:SESv3(安全事件系统 - 版本 3)

基本信息

  • 批准号:
    1127425
  • 负责人:
  • 金额:
    $ 79.93万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2011
  • 资助国家:
    美国
  • 起止时间:
    2011-08-01 至 2015-05-31
  • 项目状态:
    已结题

项目摘要

Activities undertaken in the SESv3 Federated Security Intelligence project will develop significant new capabilities supporting the collection and sharing of cybersecurity threat data and intelligence, and a rich analytic knowledge of the reputation and forensic history of Internet elements. Work will be based on the existing open source REN-ISAC Security Event System (SES) and sister system, the Collective Intelligence Framework (CIF). Developed capabilities will be transitioned to operational practice in the REN-ISAC community, supporting security protection and response in the higher education and research communities, and will support the sharing of security event and incident intelligence among other discrete trust federations.In 2008-9, REN-ISAC developed SESv1 with funding from the US Department of Justice through Internet2. A production service in the REN-ISAC community, SESv1 collects aggregated security event information from participating sites and information sharing partners, correlates the data to develop confidence in the identification of bad actors, and provides resulting high-confidence threat intelligence back to participating sites for use in local protections. SESv2, to be deployed summer 2011, advances SES with the addition of the "Collective Intelligence Framework". CIF integrates a vast array of data from private partners, public sources, and mining, to provide intelligence supporting reputational knowledge and forensic history of Internet elements, including IP address, URL, domain name, CIDR, AS, and email addresses.SDCI Sec: SESv3 will substantially increase the reputational knowledgebase and forensic history by incorporating additional data types, such as BGP and passive DNS. These data types will permit analytic identification of miscreant cyber infrastructures. Free form data types such as e-mail, IRC, tweets, etc. will be incorporated to enrich threat understanding by correlating human conversations with the structured security event information. The underlying repository and system architectures will be redesigned in order to support massive scaling required by the additional data types and historical record. Leveraging the flexible SES/CIF v2 RESTful API, access and submission to SES and CIF will be incorporated into common incident analyst and responder tools. And importantly, methods will be implemented permitting unique and discrete information sharing trust communities to share event and incident intelligence, mediated by policy. SESv3 will be transitioned to operational status in the REN-ISAC community, providing direct support to the higher education and research communities, will be open source published, and the SESv3 team will continue with their strong advocacy for standards-based security information interchange, and SES/CIF technologies in the security community at-large.Intellectual Merit: SDCI Sec: SESv3 will lead development and deployment of inter-community security event and incident information sharing (addressing technical and policy issues), will significantly reduce human interrupt in the discovery, analysis, and protect cycle, and will develop advanced correlations among threat data types. SESv3 will provide novel integration of federation-based intelligence and data collection into the workflow of the security incident responder and analyst, and novel correlation of human conversations to structured data regarding Internet elements.Broader Impact: SDCI Sec: SESv3 will provide fundamental improvement to national and international capabilities concerning the protection of critical cyberinfrastructure. Intelligence developed and shared in SES is actionable, and is a resource for understanding threat and criminal operations. Advanced new capabilities and information sharing relationships with industry, government, and law enforcement will be established in REN-ISAC, supporting the research and education sector. Outside R&E, national capabilities and information sharing practice will be stimulated by SESv3 concepts, open source code, data standards advocacy, and the technical and policy information sharing frameworks.
在SESV3联合安全情报项目中开展的活动将开发出重要的新功能,支持收集和共享网络安全威胁数据和情报,以及对互联网元素的声誉和法医历史的丰富分析知识。工作将基于现有的开源Ren-ISAC安全事件系统(SES)和姊妹系统,集体智能框架(CIF)。开发的能力将过渡到Ren-ISAC社区的运营实践,支持高等教育和研究社区的安全保护和反应,并将支持其他离散信任联合会以及其他离散信任联合会的共享安全事件和事件情报的共享。 SESV1在Ren-ISAC社区的生产服务中,从参与的站点和信息共享合作伙伴收集了汇总的安全事件信息,将数据关联以发展对不良行为者的识别的信心,并提供了高信任威胁情报返回到参与的网站,以便在本地保护中使用。 SESV2将于2011年夏季部署,并加入了“集体情报框架”。 CIF集成了来自私人合作伙伴,公共资源和采矿的大量数据,以提供支持互联网元素的知识和法医历史的情报,包括IP地址,URL,域名,CIDR,CIDR,AS和电子邮件地址。SDCISEC:SESV3通过将声誉知识群和遗留类型纳入其他数据类型,例如,SESV3大大增加了bg secv3。这些数据类型将允许分析错误的网络基础架构。将合并免费表格数据类型,例如电子邮件,IRC,推文等,以通过将人类的对话与结构化安全事件信息相关联,以丰富威胁理解。为了支持其他数据类型和历史记录所需的大规模缩放,将重新设计基础存储库和系统体系结构。利用灵活的SES/CIF V2 RESTFUL API,将访问和提交SES和CIF的访问和提交将被纳入常见的事件分析师和响应器工具中。重要的是,将实施方法,允许允许独特的和离散的信息共享信托社区共享事件和事件情报,并由政策介导。 SESv3 will be transitioned to operational status in the REN-ISAC community, providing direct support to the higher education and research communities, will be open source published, and the SESv3 team will continue with their strong advocacy for standards-based security information interchange, and SES/CIF technologies in the security community at-large.Intellectual Merit: SDCI Sec: SESv3 will lead development and deployment of inter-community security event and incident信息共享(解决技术和政策问题)将大大减少人类在发现,分析和保护周期中的中断,并将在威胁数据类型之间发展高级相关性。 SESV3将提供基于联邦的智能和数据收集的新型整合到安全事件响应者和分析师的工作流程中,以及人类对话与有关互联网元素的结构化数据的新型相关性。BOADER的影响:SDCI SEC:SESV3:SESV3将对保护关键网络素养构造的保护的国家和国际能力的基本改进。在SES中开发和共享的情报是可行的,并且是理解威胁和犯罪行动的资源。先进的新功能和信息共享与行业,政府和执法部门的关系将在Ren-ISAC建立,并支持研究和教育部门。 SESV3概念,开源代码,数据标准倡导以及技术和政策信息共享框架将刺激R&E,国家能力和信息共享实践。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Douglas Pearson其他文献

Behavioral effects of moderate lead exposure in children and animal models: part 1, clinical studies.
中度铅暴露对儿童和动物模型的行为影响:第 1 部分,临床研究。
  • DOI:
    10.3109/10408448009037491
  • 发表时间:
    1980
  • 期刊:
  • 影响因子:
    5.9
  • 作者:
    R. Bornschein;Douglas Pearson;Lawrence W. Reiter;Lester D. Grant
  • 通讯作者:
    Lester D. Grant
Generalized imitative affection: relationship to prior kinds of imitation training.
广义模仿情感:与先前的模仿训练的关系。
  • DOI:
    10.1016/0022-0965(73)90067-2
  • 发表时间:
    1973
  • 期刊:
  • 影响因子:
    2.6
  • 作者:
    L. E. Acker;Margaret A Acker;Douglas Pearson
  • 通讯作者:
    Douglas Pearson

Douglas Pearson的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

相似国自然基金

飞秒激光调控阿秒电荷迁移的机理研究及其在卤代乙炔中的应用
  • 批准号:
    12374267
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目
硫系聚合物基相位型中红外微光学元件的飞秒激光直写方法研究
  • 批准号:
    62375224
  • 批准年份:
    2023
  • 资助金额:
    48 万元
  • 项目类别:
    面上项目
树脂糖苷类Sec61α抑制剂的发现及其潜在抗冠状病毒活性研究
  • 批准号:
    32370419
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目
一种50飞秒抖动的毫米波小数分频全数字锁相环
  • 批准号:
    62374156
  • 批准年份:
    2023
  • 资助金额:
    55 万元
  • 项目类别:
    面上项目
高功率纳秒脉冲单纵模金刚石拉曼激光技术研究
  • 批准号:
    62375107
  • 批准年份:
    2023
  • 资助金额:
    47 万元
  • 项目类别:
    面上项目

相似海外基金

レーザー駆動円偏光フェムト秒軟X線パルスの時間分解X線磁気円二色性測定への展開
开发激光驱动圆偏振飞秒软 X 射线脉冲到时间分辨 X 射线磁圆二色性测量
  • 批准号:
    23K22468
  • 财政年份:
    2024
  • 资助金额:
    $ 79.93万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
ゼプト秒原子・分子・素粒子物理学のための中赤外レーザー駆動X線分光システムの開発
开发用于泽秒原子、分子和粒子物理的中红外激光驱动 X 射线光谱系统
  • 批准号:
    23K26570
  • 财政年份:
    2024
  • 资助金额:
    $ 79.93万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
フェムト秒パルスと物質の相互作用における緩和メカニズムの第一原理計算による解明
使用第一性原理计算阐明飞秒脉冲与物质相互作用的弛豫机制
  • 批准号:
    24K08277
  • 财政年份:
    2024
  • 资助金额:
    $ 79.93万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
SiCインバータサージ絶縁の高度化:高繰り返しナノ秒パルス電圧下の部分放電の解明
SiC逆变器浪涌绝缘的进步:阐明高重复纳秒脉冲电压下的局部放电
  • 批准号:
    24K00874
  • 财政年份:
    2024
  • 资助金额:
    $ 79.93万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
ナノ秒パルス電場溶融方式による新たな3Dプリンティング技術の開拓
利用纳秒脉冲电场熔化法开发新型3D打印技术
  • 批准号:
    24KJ1175
  • 财政年份:
    2024
  • 资助金额:
    $ 79.93万
  • 项目类别:
    Grant-in-Aid for JSPS Fellows
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了