Leveraging the Multi-Stakeholder Nature of Cyber Security
利用网络安全的多利益相关者性质
基本信息
- 批准号:EP/P011918/1
- 负责人:
- 金额:$ 98.17万
- 依托单位:
- 依托单位国家:英国
- 项目类别:Research Grant
- 财政年份:2017
- 资助国家:英国
- 起止时间:2017 至 无数据
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Cyber Security (CyS) is a challenging, distributed, multi-stakeholder problem. It is distributed in the sense that the expertise to comprehensively assess the level of security of a given IT system is commonly not all available in one location; e.g. detail on the IT components within a company is available within that company, while detail on operating system software vulnerability may be available to the OS manufacturer and further expert insight may be available to public security agencies, such as CESG. It is a multi-stakeholder problem because a number of human stakeholders, from IT designers to users with varying levels of expertise, need to effectively communicate and work together in order to deliver systems with an appropriate level of CyS assurance.This interdisciplinary project brings together leading academic experts from the University of Nottingham, UK and Carnegie Mellon University, USA, with a strongly integrated project partner: CESG - the UK's National Technical Authority for Information Assurance. The project is designed to leverage the distributed, multiple human stakeholder nature of CyS by developing a novel framework with the necessary scientific underpinning to improve user access to user-tailored CyS information, operationalised as a cutting-edge, data-driven Online CYber Security decision support System (OCYSS). This approach id designed to directly address an acute shortage of availability and access to highly qualified CyS experts by both small-to-large scale users from government to industry. The role of OCYSS is to effectively and efficiently integrate expert and user inputs, capturing commonly uncertain vulnerability levels of individual components as well as vulnerabilities arising from the interaction/combination of these components, to efficiently deliver appropriate, balanced, informed and up-to-date threat analysis and CyS decision support to users. Importantly, the OCYSS framework:- Addresses the limited availability of CyS experts by comprehensively capturing and aggregating their insight and expertise to assess the vulnerability, including associated levels of uncertainty, of individual system components (e.g. intrusion detection, encryption) and their interactions (e.g. SSL 3.0 and weak password). This information is captured centrally by OCYSS and updated regularly. - Avoids delays in threat analysis and potential mitigation by providing a direct pathway for newly discovered component vulnerabilities & component interaction vulnerabilities (and associated uncertainty) to be rapidly put forward, incl. by manufacturers such as Oracle and third party organisations such as Symantec.- Is designed to deliver user-tailored, comprehensive and up-to-date threat analysis and decision support which is continuously updated as new information becomes available. OCYSS two-stage outputs capture uncertainty in A) the threat analysis inputs (e.g. uncertainty around a component vulnerability over time and by different experts) and B) in intuitive benefit-cost analysis on threat mitigation in response to asset ranking by users (e.g. a low value asset may not warrant a high investment to address a low threat).Going beyond the scope of a standard research project, this project is designed to not only deliver cutting-edge science, developing key advances in data science and HCI, but to also deliver a real-world, open source prototype of the OCYSS framework. This enables the project to conduct an exceptional level of evaluation and tailoring to real-world CyS challenges, including the deployment of OCYSS in real-world contexts such as government departments advised by CESG. Further, through this approach, the project is able to deliver both open source algorithms and a substantial open-source software platform prototype, facilitating the academic reproduction of results, as well as substantially boosting the potential of commercial up-take of the project outcomes.
网络安全(CYS)是一个具有挑战性的,分布式的,多利益相关者的问题。它是从某种意义上分发的,即全面评估给定系统的安全性水平的专业知识通常在一个位置不可用。例如该公司内的IT组件中有关IT组件的详细信息,而操作系统软件漏洞的详细信息可能可供操作系统制造商获得,并且可以向CESG等公共安全机构提供更多专家洞察力。这是一个多方利益相关者的问题,因为从设计师到具有不同专业知识水平的用户,需要有效地交流和合作,以提供适当水平的CYS保证的系统,跨学科项目培养了这一领先的诺丁汉大学和Carnegie Mellelloy Intorlion Introvion Antimpers Introlignation Introvie Introlignation Introvie Introlignation Introvie Introlignation Introvie Introvie Anouse Introlity Introvie Antim at USAG,该项目与美国的领先学术组成 - 美国技术人员合作:保证。该项目旨在通过开发具有必要科学基础的新型框架来利用CYS的分布式,多个人类利益相关者的性质,以改善用户访问用户计算的CYS信息,该信息是作为尖端,数据驱动的在线网络安全决策支持系统(OCYSS)运行的。此方法ID旨在直接解决从政府到工业的小型范围用户对高素质CYS专家的严重短缺和访问高度合格的CYS专家的访问。 OCYS的作用是有效,有效地整合专家和用户的输入,捕获单个组件的通常不确定的脆弱性水平以及由这些组件的相互作用/组合引起的脆弱性,以有效地提供适当,平衡,知情,知情和最新的威胁和最新威胁分析,并与用户提供了决策支持。重要的是,OCYSS框架: - 通过全面捕获和汇总其洞察力和专业知识来评估CYS专家的可用性有限,以评估脆弱性,包括相关的不确定性,单个系统组件(例如,侵入式检测,加密)及其交互(例如SSL 3.0和弱密码)。此信息由OCYS中心捕获并定期更新。 - 避免通过为新发现的组件漏洞和组件互动漏洞(以及相关的不确定性)提供直接途径,以避免威胁分析和潜在缓解措施的延迟。由Oracle和Symantec等第三方组织等制造商旨在提供用户量,全面和最新的威胁分析和决策支持,随着新信息的可用性,这些威胁分析和决策支持不断更新。 OCYSS两阶段输出捕获了a)a)威胁分析输入(例如,围绕成分脆弱性的不确定性,随着时间的流逝和不同的专家的不确定性)和b)b)b)b)b)响应减轻威胁的福利成本分析,以响应用户对资产排名的响应减轻资产排名(例如,低价值资产都无法为较低的项目而设计的范围。数据科学和HCI的进步,但还提供了OCYSS框架的实际开源原型。这使该项目能够针对现实世界中的CYS挑战进行特殊水平的评估和裁缝,包括在现实世界中的OCYS部署,例如CESG建议的政府部门。此外,通过这种方法,该项目能够提供开源算法和实质性的开源软件平台原型,从而促进了结果的学术复制,并大大提高了项目成果的商业化潜力。
项目成果
期刊论文数量(10)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Responsible research and innovation in practice: Driving both the 'How' and the 'What' to research
实践中负责任的研究和创新:推动研究“如何”和“什么”
- DOI:10.1016/j.jrt.2022.100042
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Chen J
- 通讯作者:Chen J
Do People Prefer to Give Interval-Valued or Point Estimates and Why?
人们更喜欢给出区间值估计还是点估计?为什么?
- DOI:10.1109/fuzz45933.2021.9494507
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Ellerby Z
- 通讯作者:Ellerby Z
Insights from interval-valued ratings of consumer products-a DECSYS appraisal
消费产品区间值评级的见解——DECSYS 评估
- DOI:10.1109/fuzz48607.2020.9177634
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Ellerby Z
- 通讯作者:Ellerby Z
Extension of Restricted Equivalence Functions and Similarity Measures for Type-2 Fuzzy Sets
- DOI:10.1109/tfuzz.2021.3136349
- 发表时间:2022-09
- 期刊:
- 影响因子:11.9
- 作者:Laura De Miguel;R. Santiago;Christian Wagner;J. Garibaldi;Z. Takác̆;A.F. Roldan Lopez de Hierro;H. Bustince
- 通讯作者:Laura De Miguel;R. Santiago;Christian Wagner;J. Garibaldi;Z. Takác̆;A.F. Roldan Lopez de Hierro;H. Bustince
Similarity between interval-valued fuzzy sets taking into account the width of the intervals and admissible orders
- DOI:10.1016/j.fss.2019.04.002
- 发表时间:2020-07
- 期刊:
- 影响因子:0
- 作者:H. Bustince;C. Marco-Detchart;Javier Fernández;Christian Wagner;J. Garibaldi;Z. Takác̆
- 通讯作者:H. Bustince;C. Marco-Detchart;Javier Fernández;Christian Wagner;J. Garibaldi;Z. Takác̆
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Christian Wagner其他文献
Towards data-driven environmental planning and policy design-leveraging fuzzy logic to operationalize a planning framework
迈向数据驱动的环境规划和政策设计——利用模糊逻辑来实施规划框架
- DOI:
10.1109/fuzz-ieee.2014.6891783 - 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Amir Pourabdollah;Christian Wagner;Simon Miller;Michael Smith;K. Wallace - 通讯作者:
K. Wallace
A Restricted Parametrized Model for Interval-Valued Regression
区间值回归的限制参数化模型
- DOI:
10.1109/fuzz52849.2023.10309686 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Jingda Ying;Shaily Kabir;Christian Wagner - 通讯作者:
Christian Wagner
Capturing Individuals' Uncertainties-On Establishing the Validity of an Interval-Valued Survey Response Mode
捕捉个体的不确定性——论建立区间值调查响应模式的有效性
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
Zack Ellerby;Christian Wagner;S. Broomell - 通讯作者:
S. Broomell
Expert systems and creativity
专家系统和创造力
- DOI:
10.1007/978-3-642-86679-1_10 - 发表时间:
1987 - 期刊:
- 影响因子:0
- 作者:
K. MacCrimmon;Christian Wagner - 通讯作者:
Christian Wagner
On Comparing and Selecting Approaches to Model Interval-Valued Data as Fuzzy Sets
区间值数据模糊集建模方法的比较和选择
- DOI:
10.1109/fuzz-ieee.2019.8858993 - 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Josie McCulloch;Zack Ellerby;Christian Wagner - 通讯作者:
Christian Wagner
Christian Wagner的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Christian Wagner', 18)}}的其他基金
SBE-UKRI:A Novel Theory of Ordered Judgment Processes
SBE-UKRI:有序判断过程的新颖理论
- 批准号:
ES/Z000084/1 - 财政年份:2024
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Digital Catapult Fellowship Programme
数字弹射器奖学金计划
- 批准号:
EP/M029263/1 - 财政年份:2015
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Towards managing risk from climate change through comprehensive, inclusive and resilient UK infrastructure planning
通过全面、包容和有弹性的英国基础设施规划来管理气候变化风险
- 批准号:
NE/M008401/1 - 财政年份:2014
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Towards Data-Driven Environmental Policy Design
迈向数据驱动的环境政策设计
- 批准号:
EP/K012479/1 - 财政年份:2013
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Automotive 2020 Scholarship Program
汽车2020年奖学金计划
- 批准号:
0220554 - 财政年份:2003
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
Improving Manufacturing with Artificial Intelligence Techniques
利用人工智能技术改进制造
- 批准号:
9251110 - 财政年份:1992
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
On the Development of Alternatives: A Human - Computer System
论替代方案的开发:人机系统
- 批准号:
9016305 - 财政年份:1991
- 资助金额:
$ 98.17万 - 项目类别:
Continuing Grant
相似国自然基金
新型血管微创介入智能碎溶栓系统设计与多物理效应下碎溶栓机理研究
- 批准号:82302400
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
二元金属原子团簇协同催化多硫化锂转化机制研究
- 批准号:22379001
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
温度作用下CA砂浆非线性老化蠕变性能的多尺度研究
- 批准号:12302265
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
面向肉羊生命特征精准辨识的可穿戴柔性无创多模态传感信号检测方法研究
- 批准号:62303471
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
全固态锂电池硫化物固体电解质的合成、调控及多尺度中子散射研究
- 批准号:12375301
- 批准年份:2023
- 资助金额:53 万元
- 项目类别:面上项目
相似海外基金
Integrated Supportive Care Policies to Improve Maternal Health Equity: Evaluating the Multi-level Effects and Implementation of Doula Programs for Medicaid-Eligible Birthing People in New York City
改善孕产妇健康公平的综合支持性护理政策:评估纽约市符合医疗补助资格的新生儿导乐计划的多层次影响和实施情况
- 批准号:
10833919 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
The HVIP+ Community Model: A Community Violence Prevention Program in a Southern State
HVIP 社区模式:南部各州的社区暴力预防计划
- 批准号:
10812074 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
Implementation Science to Understand and Design Stakeholder Informed Innovative Interventions to Improve Adolescent and Youth HIV Prevention and Care Continuums in Rural and Urban Uganda
实施科学以理解和设计利益相关者知情的创新干预措施,以改善乌干达农村和城市青少年艾滋病毒预防和护理的连续性
- 批准号:
10749472 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
Embracing diversity: a multi-phased project to advance the science of knowledge mobilization for Canada's culturally diverse groups
拥抱多样性:一个多阶段项目,旨在推动加拿大文化多元化群体的知识动员科学
- 批准号:
489584 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
Operating Grants
Multi-Stakeholder Determinants of Medicare Diabetes Prevention Program Implementation and Participation
医疗保险糖尿病预防计划实施和参与的多利益相关者决定因素
- 批准号:
10578862 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别: