ATD: Collaborative Research: Extremal Dependence and Change-Point Detection Methods for High-Dimensional Data Streams with Applications to Network Cybersecurity
ATD:协作研究:高维数据流的极端依赖性和变点检测方法及其在网络网络安全中的应用
基本信息
- 批准号:1830293
- 负责人:
- 金额:$ 18.7万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-08-01 至 2021-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The project is motivated by the need to develop advanced network monitoring tools coupled with automated statistical methods for the quick detection of Internet traffic anomalies due to ongoing attacks or impending cybersecurity threats. Emphasis is placed on detecting cybersecurity threats such as highly distributed malware infections, which can launch coordinated and crippling distributed denial of service attacks on the nation's Internet infrastructure. This will be achieved through a study of the so-called darknet traffic data. Malicious actors in the network systematically probe the Internet space for vulnerable or misconfigured devices. In doing so, they automatically send data to the entire Internet address space, which includes the space of unused Internet addresses. This destined-to-nowhere traffic is indicative of malware infection attempts or stealthy vulnerability scanning. The investigators aim to develop and deploy specialized tools that allow cyber-security analysts to efficiently analyze darknet traffic data. The research involves a team of computer engineers and statisticians, who will work closely together to implement a prototype system for detecting as well as mapping and identifying world-wide malicious activity in the Internet. The project will create and communicate to the public a set of simple-to-interpret risk indices that summarize the current darknet threat activity. This effort will potentially enable the prevention and mitigation of cybersecurity network traffic threats.Understanding Internet threats, which continue to evolve due to the dynamic nature of Internet actors and the rapid expansion of the Internet of Things ecosystem, requires adequate data at fine-grained spatial and temporal scales. The project team has access to unique cyber-security data collected at Merit Network, Inc. that capture Internet-wide activity including network scanning, malware propagation, denial of service attacks, and network outages. This data consists of unsolicited Internet traffic destined to a routed but unused Internet address space, referred to as a darknet. This project will develop algorithmic and software infrastructure to collect and organize darknet data into high-dimensional, multivariate data streams, and will study statistical methods based on (i) extremal dependence, (ii) change-point detection, and/or (iii) high-dimensional sparse signal detection and recovery to inform the construction of Internet threat indices that quantify the risk of malicious scanning, degree of network vulnerability, risk of denial of service attacks, etc. Statistics of extremes in high-dimensional setting is a challenging problem since it requires the modeling/estimation of an infinite-dimensional parameter---the spectral measure. Using multivariate regular variation, this project will study novel hyper-graphical models that quantify and provide interpretable abstractions for the simultaneous occurrence of extremes in high-dimensions. Using limit theory for maxima of dependent variables, the project team will address open theoretical problems on the characterization of extremal dependence hyper-graphs and sparse signal detection in high-dimension. This analysis will lead to the development of novel threat indices that exhibit spatial dependence that will be analyzed with fast, scalable change-point detection algorithms. The new change-point methodology is designed to achieve large computational gains vis-a-vis standard approaches without compromising statistical accuracy and would be a significant contribution to the analysis of large data streams.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该项目的激励是由于需要开发高级网络监控工具以及自动统计方法,以快速检测由于持续攻击或即将发生的网络安全威胁而引起的互联网流量异常。重点是检测网络安全威胁,例如高度分布的恶意软件感染,这些威胁可能会引发对国家互联网基础架构的协调和残酷的分布拒绝服务攻击。 这将通过对所谓的暗网流量数据进行研究来实现。网络中的恶意参与者系统地探索了脆弱或错误配置的设备的Internet空间。在此过程中,他们会自动将数据发送到整个Internet地址空间,其中包括未使用的Internet地址的空间。这一注定的到处流量表明了恶意软件感染的尝试或隐身脆弱性扫描。 研究人员旨在开发和部署专业工具,以使网络安全分析师有效地分析DarkNet交通数据。这项研究涉及一个计算机工程师和统计学家团队,他们将紧密合作,以实施一个原型系统来检测以及在互联网中绘制和识别全球恶意活动。该项目将与公众建立并沟通一组简单截止的风险指数,以总结当前的DarkNet威胁活动。 这项努力有可能使网络安全网络交通威胁的预防和缓解。理解互联网威胁,由于互联网参与者的动态性质和物联网生态系统的快速扩展,这种威胁继续发展,需要在细粒度的空间上进行足够的数据和时间尺度。该项目团队可以访问在Merit Network,Inc。收集的独特网络安全数据,该数据捕获了网络范围的活动,包括网络扫描,恶意软件传播,拒绝服务攻击和网络中断。该数据由原定于路由但未使用的Internet地址空间(称为DarkNet)的未经请求的Internet流量组成。该项目将开发算法和软件基础架构,以将DarkNet数据收集和组织到高维的多元数据流中,并将基于(i)极端依赖性,(ii)变更点检测和/或(iii)研究统计方法。高维的稀疏信号检测和恢复,以告知量化恶意扫描风险,网络脆弱程度,拒绝服务攻击的风险等互联网威胁指标的构建。高维环境中极端的统计数据是一个具有挑战性的问题由于它需要对无限维参数的建模/估计 - 光谱度量。使用多元规则变化,该项目将研究新型的超图模型,这些模型可以量化并为高度极端发生的同时出现可解释的抽象。使用限制理论,对于因变量的最大值,项目团队将解决有关极端依赖性超图表和高维度中稀疏信号检测的开放理论问题。该分析将导致新的威胁指数的发展,这些威胁指标表现出空间依赖性,这些依赖性将通过快速,可扩展的更改点检测算法进行分析。新的更改点方法旨在实现相对于标准方法的大量计算收益,而不会损害统计准确性,这将是对大型数据流的分析的重要贡献。这项奖项反映了NSF的法定任务,并被认为值得一提通过基金会的智力优点和更广泛的影响评估标准通过评估来支持。
项目成果
期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Fundamental limits of exact support recovery in high dimensions
- DOI:10.3150/20-bej1197
- 发表时间:2018-11
- 期刊:
- 影响因子:1.5
- 作者:Zhengyuan Gao;Stilian A. Stoev
- 通讯作者:Zhengyuan Gao;Stilian A. Stoev
Data-adaptive trimming of the Hill estimator and detection of outliers in the extremes of heavy-tailed data
- DOI:10.1214/19-ejs1561
- 发表时间:2019-01-01
- 期刊:
- 影响因子:1.1
- 作者:Bhattacharya, Shrijita;Kallitsis, Michael;Stoev, Stilian
- 通讯作者:Stoev, Stilian
Exchangeable random partitions from max-infinitely-divisible distributions
最大无限可分分布的可交换随机分区
- DOI:10.1016/j.spl.2018.11.008
- 发表时间:2019
- 期刊:
- 影响因子:0.8
- 作者:Stoev, Stilian;Wang, Yizao
- 通讯作者:Wang, Yizao
On the rate of concentration of maxima in Gaussian arrays
关于高斯阵列中最大值的集中率
- DOI:10.1007/s10687-020-00399-8
- 发表时间:2021
- 期刊:
- 影响因子:1.3
- 作者:Kartsioukas, Rafail;Gao, Zheng;Stoev, Stilian
- 通讯作者:Stoev, Stilian
Concentration of Maxima and Fundamental Limits in High-Dimensional Testing and Inference
高维测试和推理中最大值和基本极限的集中
- DOI:10.1007/978-3-030-80964-5
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Gao, Zheng;Stoev, Stilian
- 通讯作者:Stoev, Stilian
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Stilian Stoev其他文献
Stilian Stoev的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Stilian Stoev', 18)}}的其他基金
Collaborative Research: IMR: MM-1A: Scalable Statistical Methodology for Performance Monitoring, Anomaly Identification, and Mapping Network Accessibility from Active Measurements
合作研究:IMR:MM-1A:用于性能监控、异常识别和主动测量映射网络可访问性的可扩展统计方法
- 批准号:
2319592 - 财政年份:2023
- 资助金额:
$ 18.7万 - 项目类别:
Continuing Grant
FRG: Collaborative Research: Extreme value theory for spatially indexed functional data
FRG:协作研究:空间索引函数数据的极值理论
- 批准号:
1462368 - 财政年份:2015
- 资助金额:
$ 18.7万 - 项目类别:
Continuing Grant
EVA 2015: The 9th International Conference on Extreme Value Analysis
EVA 2015:第九届国际极值分析会议
- 批准号:
1512982 - 财政年份:2015
- 资助金额:
$ 18.7万 - 项目类别:
Standard Grant
Conference on Long-Range Dependence, Self-Similarity, and Heavy Tails
长程依赖、自相似性和重尾会议
- 批准号:
1208965 - 财政年份:2012
- 资助金额:
$ 18.7万 - 项目类别:
Standard Grant
Spatio-Temporal Dependence and Extremes with Applications to Networking and the Environment
时空依赖性和极端情况及其在网络和环境中的应用
- 批准号:
1106695 - 财政年份:2011
- 资助金额:
$ 18.7万 - 项目类别:
Continuing Grant
Extremes: Short and Long-Range Dependence; Modeling and Inference with Applications to Computer Networks and Risk Analysis
极端情况:短期和长期依赖性;
- 批准号:
0806094 - 财政年份:2008
- 资助金额:
$ 18.7万 - 项目类别:
Continuing Grant
相似国自然基金
数智背景下的团队人力资本层级结构类型、团队协作过程与团队效能结果之间关系的研究
- 批准号:72372084
- 批准年份:2023
- 资助金额:40 万元
- 项目类别:面上项目
颅颌面手术机器人辅助半面短小牵张成骨术的智能规划与交互协作研究
- 批准号:
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:
面向自主认知与群智协作的多智能体制造系统关键技术研究
- 批准号:52305539
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
大规模物联网多协作绿色信息感知和智慧响应决策一体化方法研究
- 批准号:62371149
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
多UAV协作的大规模传感网并发充电模型及其服务机制研究
- 批准号:62362017
- 批准年份:2023
- 资助金额:32 万元
- 项目类别:地区科学基金项目
相似海外基金
Collaborative Research: ATD: Fast Algorithms and Novel Continuous-depth Graph Neural Networks for Threat Detection
合作研究:ATD:用于威胁检测的快速算法和新颖的连续深度图神经网络
- 批准号:
2219956 - 财政年份:2023
- 资助金额:
$ 18.7万 - 项目类别:
Standard Grant
Collaborative Research: ATD: a-DMIT: a novel Distributed, MultI-channel, Topology-aware online monitoring framework of massive spatiotemporal data
合作研究:ATD:a-DMIT:一种新颖的分布式、多通道、拓扑感知的海量时空数据在线监测框架
- 批准号:
2220495 - 财政年份:2023
- 资助金额:
$ 18.7万 - 项目类别:
Standard Grant
Collaborative Research: ATD: Rapid Structure Recovery and Outlier Detection in Multidimensional Data
合作研究:ATD:多维数据中的快速结构恢复和异常值检测
- 批准号:
2319370 - 财政年份:2023
- 资助金额:
$ 18.7万 - 项目类别:
Standard Grant
Collaborative Research: ATD: Geospatial Modeling and Risk Mitigation for Human Movement Dynamics under Hurricane Threats
合作研究:ATD:飓风威胁下人类运动动力学的地理空间建模和风险缓解
- 批准号:
2319552 - 财政年份:2023
- 资助金额:
$ 18.7万 - 项目类别:
Standard Grant
Collaborative Research: ATD: Fast Algorithms and Novel Continuous-depth Graph Neural Networks for Threat Detection
合作研究:ATD:用于威胁检测的快速算法和新颖的连续深度图神经网络
- 批准号:
2219904 - 财政年份:2023
- 资助金额:
$ 18.7万 - 项目类别:
Standard Grant