Collaborative Research: SaTC: CORE: Small: Flanker: Automatically Detecting Lateral Movement in Organizations Using Heterogeneous Data and Graph Representation Learning
协作研究:SaTC:核心:小型:侧翼:使用异构数据和图表示学习自动检测组织中的横向运动
基本信息
- 批准号:2127232
- 负责人:
- 金额:$ 25万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-10-01 至 2024-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
In modern cyberattacks, adversaries do not target single computer systems. Instead, they first set an initial foothold into a company's network and later amplify their breach by compromising additional assets, until they reach their final target inside an organization. This process of advancing computer breaches is known as lateral movement. Detecting lateral movement is challenging, because attackers can use multiple vectors for infection (e.g., phishing emails) and computer systems in a network present a large degree of diversity (e.g., workstations, network equipment). For this reason, no comprehensive system to effectively detect lateral movement is currently available. Yet, detecting and stopping computer breaches as soon as possible is critical to ensure the safety and the prosperity of U.S. corporations and citizens. The aim of this project is to fill this gap by developing Flanker, a system able to automatically detect lateral movement in the network of an organization. Unlike existing approaches, the goal of Flanker is to operate on a variety of data sources (e.g., data coming from network and applications) to be able to detect cyberattacks as they span different online services and computers across the organization.This project consists of four phases. In the first phase the investigators collect heterogeneous datasets from a variety of sources and develop techniques to clean them from noise and anonymize them to protect the identity of users. In the second phase this data is used to build a graph that represents network activity, and graph representation learning approaches are used to build a model for this network activity. In the third phase this model is used to automatically detect lateral movement attacks, by either applying anomaly detection or supervised learning techniques. Finally, the investigators develop visualization techniques to enable a security analyst to properly understand the detection results and adopt appropriate countermeasures against the attack.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
在现代网络攻击中,对手并不针对单个计算机系统。 相反,他们首先在公司网络中建立了最初的立足点,然后通过损害额外的资产来扩大他们的破坏,直到他们在组织内部达到最终目标。这种推进计算机漏洞的过程称为横向移动。检测横向移动具有挑战性,因为攻击者可以使用多个载体进行感染(例如网络钓鱼电子邮件),并且网络中的计算机系统呈现出很大程度的多样性(例如工作站、网络设备)。因此,目前还没有有效检测横向运动的综合系统。然而,尽快检测和阻止计算机泄露对于确保美国企业和公民的安全和繁荣至关重要。该项目的目的是通过开发 Flanker 来填补这一空白,Flanker 是一个能够自动检测组织网络中横向移动的系统。与现有方法不同,Flanker 的目标是对各种数据源(例如来自网络和应用程序的数据)进行操作,以便能够检测跨组织不同在线服务和计算机的网络攻击。该项目由四个部分组成阶段。在第一阶段,研究人员从各种来源收集异构数据集,并开发技术来清除数据中的噪音并对其进行匿名化,以保护用户的身份。在第二阶段,这些数据用于构建表示网络活动的图,并使用图表示学习方法来构建该网络活动的模型。在第三阶段,该模型用于通过应用异常检测或监督学习技术来自动检测横向移动攻击。最后,调查人员开发可视化技术,使安全分析师能够正确理解检测结果并针对攻击采取适当的对策。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力价值和更广泛的影响审查进行评估,被认为值得支持标准。
项目成果
期刊论文数量(4)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Finding MNEMON: Reviving Memories of Node Embeddings
寻找 MNEMON:恢复节点嵌入的记忆
- DOI:10.1145/3548606.3559358
- 发表时间:2022-04-14
- 期刊:
- 影响因子:0
- 作者:Yun Shen;Yufei Han;Zhikun Zhang;Min Chen;Tingyue Yu;Michael Backes;Yang Zhang;G. Stringhini
- 通讯作者:G. Stringhini
Shedding Light on the Targeted Victim Profiles of Malicious Downloaders
揭示恶意下载者的目标受害者资料
- DOI:10.1145/3538969.3544435
- 发表时间:2022-08-23
- 期刊:
- 影响因子:0
- 作者:François Labrèche;Enrico Mariconti;G. Stringhini
- 通讯作者:G. Stringhini
Cerberus: Exploring Federated Prediction of Security Events
Cerberus:探索安全事件的联合预测
- DOI:10.1145/3548606.3560580
- 发表时间:2022-09-07
- 期刊:
- 影响因子:0
- 作者:Mohammad Naseri;Yufei Han;Enrico Mariconti;Yun Shen;G. Stringhini;Emiliano De Cristofaro
- 通讯作者:Emiliano De Cristofaro
FirmSolo: Enabling dynamic analysis of binary Linux-based IoT kernel modules
FirmSolo:启用基于 Linux 的二进制 IoT 内核模块的动态分析
- DOI:
- 发表时间:2023-01
- 期刊:
- 影响因子:0
- 作者:Angelakopoulos, Ioannis;Stringhini, Gianluca;Egele, Manuel
- 通讯作者:Egele, Manuel
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Gianluca Stringhini其他文献
A Data Donation Approach for Youth Online Safety
青少年在线安全的数据捐赠方法
- DOI:
10.2139/ssrn.4627341 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Afsaneh Razi;Ashwaq Alsoubai;J. Park;Xavier V. Caddle;Shiza Ali;Seunghyun Kim;Gianluca Stringhini;Munmun De Choudhury;Pamela J. Wisniewski - 通讯作者:
Pamela J. Wisniewski
Enabling Contextual Soft Moderation on Social Media through Contrastive Textual Deviation
通过对比文本偏差在社交媒体上实现上下文软审核
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
Pujan Paudel;Mohammad Hammas Saeed;Rebecca Auger;Chris Wells;Gianluca Stringhini - 通讯作者:
Gianluca Stringhini
Systemization of Knowledge (SoK): Creating a Research Agenda for Human-Centered Real-Time Risk Detection on Social Media Platforms
知识系统化(SoK):为社交媒体平台上以人为中心的实时风险检测制定研究议程
- DOI:
10.1145/3613904.3642315 - 发表时间:
2024-05-11 - 期刊:
- 影响因子:0
- 作者:
Ashwaq Alsoubai;J. Park;Sarvech Qadir;Gianluca Stringhini;Afsaneh Razi;Pamela J. Wisniewski - 通讯作者:
Pamela J. Wisniewski
Poster Paper: Efficient Navigation of Cloud Performance with ’nuffTrace
海报论文:使用 nuffTrace 有效导航云性能
- DOI:
- 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
S. Qasim;M. Toslali;Q. Clark;Srinivasan Parthasarathy;Fábio Oliveira;A. Liu;Gianluca Stringhini;Ayse K. Coskun - 通讯作者:
Ayse K. Coskun
Gianluca Stringhini的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Gianluca Stringhini', 18)}}的其他基金
Collaborative Research: SaTC: TTP: Medium: iDRAMA.cloud: A Platform for Measuring and Understanding Information Manipulation
协作研究:SaTC:TTP:中:iDRAMA.cloud:测量和理解信息操纵的平台
- 批准号:
2247868 - 财政年份:2023
- 资助金额:
$ 25万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Detecting Accounts Involved in Influence Campaigns on Social Media
协作研究:SaTC:核心:小型:检测参与社交媒体影响力活动的帐户
- 批准号:
2114407 - 财政年份:2021
- 资助金额:
$ 25万 - 项目类别:
Standard Grant
CAREER: Towards Data-Driven Methods to Counter Online Aggression
职业:寻找数据驱动的方法来对抗网络攻击
- 批准号:
1942610 - 财政年份:2020
- 资助金额:
$ 25万 - 项目类别:
Continuing Grant
Inferring the Purpose of Network Activities
推断网络活动的目的
- 批准号:
EP/N008448/1 - 财政年份:2015
- 资助金额:
$ 25万 - 项目类别:
Research Grant
相似国自然基金
IGF-1R调控HIF-1α促进Th17细胞分化在甲状腺眼病发病中的机制研究
- 批准号:82301258
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
CTCFL调控IL-10抑制CD4+CTL旁观者激活促口腔鳞状细胞癌新辅助免疫治疗抵抗机制研究
- 批准号:82373325
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
RNA剪接因子PRPF31突变导致人视网膜色素变性的机制研究
- 批准号:82301216
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
血管内皮细胞通过E2F1/NF-kB/IL-6轴调控巨噬细胞活化在眼眶静脉畸形中的作用及机制研究
- 批准号:82301257
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于多元原子间相互作用的铝合金基体团簇调控与强化机制研究
- 批准号:52371115
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 25万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 25万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 25万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330941 - 财政年份:2024
- 资助金额:
$ 25万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 25万 - 项目类别:
Continuing Grant