SaTC: CORE: Medium: Collaborative: RADAR: Real-time Advanced Detection and Attack Reconstruction

SaTC:核心:中等:协作:雷达:实时高级检测和攻击重建

基本信息

  • 批准号:
    1918542
  • 负责人:
  • 金额:
    $ 61.2万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2019
  • 资助国家:
    美国
  • 起止时间:
    2019-10-01 至 2024-09-30
  • 项目状态:
    已结题

项目摘要

There has been a rapid escalation of targeted cyber-attacks, called Advanced Persistent Threats (APTs), on high-profile enterprises. These skilled attacks routinely bypass widely deployed protection mechanisms. Existing second-line cyber defenses (e.g., intrusion detection systems) are helpful, but they often generate a flood of information that overwhelms cyber analysts. Moreover, analysts lack the tools to piece together attack fragments spanning multiple applications and/or hosts. This project will hence focus on developing the principles, techniques, and tools for accurate attack detection and real-time reconstruction of attacker activities across large enterprises.Many intellectual challenges arise in APT campaign reconstruction, including: (a) developing a wide range of policy-based, anomaly-based and signature-based attack detectors, (b) connecting the dots in the presence of unreliable detectors, (c) scaling to large enterprise networks, and (d) resisting adversarial manipulation. To overcome these challenges, this project will explore several novel directions, including (i) domain-specific languages for cyber attack detection and forensics, (ii) novel detection techniques that leverage natural language descriptions of recent attacks, (iii) alternative dependence propagation semantics that mitigate dependence explosion, and (iv) mapping attack steps to the high-level objectives ("kill-chain") of APT actors.Cyber technologies are inextricably woven into the fabric of today's society. Repeated cyber attacks undermine the society's trust in this fabric. Even in purely economic terms, worldwide cybercrime led to $600 billion in losses in 2017 (Source: McAfee). This project will help arrest these downward trends. It will also educate graduate, undergraduate and K-12 students through cybersecurity coursework, research, and outreach activities. Enhanced participation of women and minorities will be targeted through alliances with partners, including the National Center for Women & Information Technology, Governor's State University, and Chicago Public Schools. Project-related data, results, publications and tools will be made available through the web sites of the research laboratories collaborating on this project: http://seclab.cs.stonybrook.edu/ and http://sisl.lab.uic.edu/.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
针对知名企业的定向网络攻击(称为高级持续威胁 (APT))迅速升级。这些熟练的攻击通常会绕过广泛部署的保护机制。现有的二线网络防御(例如入侵检测系统)很有帮助,但它们通常会产生大量信息,让网络分析师不知所措。此外,分析人员缺乏将跨多个应用程序和/或主机的攻击片段拼凑在一起的工具。因此,该项目将重点开发用于准确检测攻击并实时重建跨大型企业的攻击者活动的原理、技术和工具。APT 活动重建过程中出现了许多智力挑战,包括: (a) 制定广泛的策略基于、基于异常和基于签名的攻击检测器,(b) 在存在不可靠检测器的情况下连接点,(c) 扩展到大型企业网络,以及 (d) 抵抗对抗性操纵。为了克服这些挑战,该项目将探索几个新的方向,包括(i)用于网络攻击检测和取证的特定领域语言,(ii)利用最近攻击的自然语言描述的新颖检测技术,(iii)替代依赖传播语义(iv) 将攻击步骤映射到 APT 参与者的高级目标(“杀伤链”)。网络技术已密不可分地融入当今社会的结构中。反复的网络攻击破坏了社会对这种结构的信任。即使从纯粹的经济角度来看,2017 年全球网络犯罪也造成了 6000 亿美元的损失(来源:McAfee)。该项目将有助于遏制这些下降趋势。它还将通过网络安全课程、研究和外展活动对研究生、本科生和 K-12 学生进行教育。将通过与国家妇女与信息技术中心、州长州立大学和芝加哥公立学校等合作伙伴的联盟来提高妇女和少数族裔的参与度。与项目相关的数据、结果、出版物和工具将通过参与该项目的研究实验室的网站提供:http://seclab.cs.stonybrook.edu/ 和 http://sisl.lab.uic。 edu/。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(3)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Extractor: Extracting Attack Behavior from Threat Reports
提取器:从威胁报告中提取攻击行为
OSTINATO: Cross-host Attack Correlation Through Attack Activity Similarity Detection
OSTINATO:通过攻击活动相似性检测进行跨主机攻击关联
POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting
POIROT:将攻击行为与网络威胁追踪的内核审计记录结合起来
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Venkat Venkatakrishnan其他文献

Venkat Venkatakrishnan的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Venkat Venkatakrishnan', 18)}}的其他基金

TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
  • 批准号:
    1514472
  • 财政年份:
    2015
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Standard Grant
SFS Scholarships in Cybersecurity and Information Assurance
SFS 网络安全和信息保障奖学金
  • 批准号:
    1241685
  • 财政年份:
    2012
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Continuing Grant
I-Corps: Automated Web Application Analysis
I-Corps:自动化 Web 应用程序分析
  • 批准号:
    1248717
  • 财政年份:
    2012
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Standard Grant
A Series of Workshops on Security in Emerging Areas
新兴地区安全系列研讨会
  • 批准号:
    1139947
  • 财政年份:
    2011
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
  • 批准号:
    1065537
  • 财政年份:
    2011
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Standard Grant
IGERT: Electronic Security and Privacy: Technological, Human, Enterprise and Legal Considerations
IGERT:电子安全和隐私:技术、人力、企业和法律考虑因素
  • 批准号:
    1069311
  • 财政年份:
    2011
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Continuing Grant
TC: A U.S.-France Collaborative Symposium of Young Engineering Scientists (YESS 2009)
TC:美国-法国青年工程科学家合作研讨会(YESS 2009)
  • 批准号:
    0946768
  • 财政年份:
    2009
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Standard Grant
TC: Small: Keeping Jack in the Box: Confining the Role of Untrusted Inputs in Web Scenarios
TC:小:将 Jack 留在盒子里:限制不可信输入在 Web 场景中的作用
  • 批准号:
    0917229
  • 财政年份:
    2009
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Standard Grant
CAREER: A Framework for Preventing Web-based Attacks
职业:防止基于 Web 的攻击的框架
  • 批准号:
    0845894
  • 财政年份:
    2009
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Standard Grant
CT-ER : Runtime Techniques for protecting confidential data in large scale software
CT-ER:保护大型软件中机密数据的运行时技术
  • 批准号:
    0716584
  • 财政年份:
    2007
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Continuing Grant

相似国自然基金

中等质量丰中子核区的新核结构模型方法
  • 批准号:
  • 批准年份:
    2020
  • 资助金额:
    18 万元
  • 项目类别:
    专项基金项目
伏隔核D1/D2共表达中等多棘神经元在孤独症小鼠社交奖赏障碍中的作用及机制研究
  • 批准号:
    81901381
  • 批准年份:
    2019
  • 资助金额:
    20.5 万元
  • 项目类别:
    青年科学基金项目
星系中心的中等质量黑洞研究
  • 批准号:
    11473062
  • 批准年份:
    2014
  • 资助金额:
    90.0 万元
  • 项目类别:
    面上项目
过渡区中等质量原子核结构的配对壳模型研究
  • 批准号:
    11305101
  • 批准年份:
    2013
  • 资助金额:
    22.0 万元
  • 项目类别:
    青年科学基金项目
中等和大质量黑洞的潮汐瓦解及其吸积与辐射
  • 批准号:
    10873015
  • 批准年份:
    2008
  • 资助金额:
    42.0 万元
  • 项目类别:
    面上项目

相似海外基金

Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Medium: Increasing user autonomy and advertiser and platform responsibility in online advertising
SaTC:核心:中:增加在线广告中的用户自主权以及广告商和平台责任
  • 批准号:
    2318290
  • 财政年份:
    2024
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330941
  • 财政年份:
    2024
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317233
  • 财政年份:
    2024
  • 资助金额:
    $ 61.2万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了