Leveraging the Multi-Stakeholder Nature of Cyber Security
利用网络安全的多利益相关者性质
基本信息
- 批准号:EP/P011918/1
- 负责人:
- 金额:$ 98.17万
- 依托单位:
- 依托单位国家:英国
- 项目类别:Research Grant
- 财政年份:2017
- 资助国家:英国
- 起止时间:2017 至 无数据
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Cyber Security (CyS) is a challenging, distributed, multi-stakeholder problem. It is distributed in the sense that the expertise to comprehensively assess the level of security of a given IT system is commonly not all available in one location; e.g. detail on the IT components within a company is available within that company, while detail on operating system software vulnerability may be available to the OS manufacturer and further expert insight may be available to public security agencies, such as CESG. It is a multi-stakeholder problem because a number of human stakeholders, from IT designers to users with varying levels of expertise, need to effectively communicate and work together in order to deliver systems with an appropriate level of CyS assurance.This interdisciplinary project brings together leading academic experts from the University of Nottingham, UK and Carnegie Mellon University, USA, with a strongly integrated project partner: CESG - the UK's National Technical Authority for Information Assurance. The project is designed to leverage the distributed, multiple human stakeholder nature of CyS by developing a novel framework with the necessary scientific underpinning to improve user access to user-tailored CyS information, operationalised as a cutting-edge, data-driven Online CYber Security decision support System (OCYSS). This approach id designed to directly address an acute shortage of availability and access to highly qualified CyS experts by both small-to-large scale users from government to industry. The role of OCYSS is to effectively and efficiently integrate expert and user inputs, capturing commonly uncertain vulnerability levels of individual components as well as vulnerabilities arising from the interaction/combination of these components, to efficiently deliver appropriate, balanced, informed and up-to-date threat analysis and CyS decision support to users. Importantly, the OCYSS framework:- Addresses the limited availability of CyS experts by comprehensively capturing and aggregating their insight and expertise to assess the vulnerability, including associated levels of uncertainty, of individual system components (e.g. intrusion detection, encryption) and their interactions (e.g. SSL 3.0 and weak password). This information is captured centrally by OCYSS and updated regularly. - Avoids delays in threat analysis and potential mitigation by providing a direct pathway for newly discovered component vulnerabilities & component interaction vulnerabilities (and associated uncertainty) to be rapidly put forward, incl. by manufacturers such as Oracle and third party organisations such as Symantec.- Is designed to deliver user-tailored, comprehensive and up-to-date threat analysis and decision support which is continuously updated as new information becomes available. OCYSS two-stage outputs capture uncertainty in A) the threat analysis inputs (e.g. uncertainty around a component vulnerability over time and by different experts) and B) in intuitive benefit-cost analysis on threat mitigation in response to asset ranking by users (e.g. a low value asset may not warrant a high investment to address a low threat).Going beyond the scope of a standard research project, this project is designed to not only deliver cutting-edge science, developing key advances in data science and HCI, but to also deliver a real-world, open source prototype of the OCYSS framework. This enables the project to conduct an exceptional level of evaluation and tailoring to real-world CyS challenges, including the deployment of OCYSS in real-world contexts such as government departments advised by CESG. Further, through this approach, the project is able to deliver both open source algorithms and a substantial open-source software platform prototype, facilitating the academic reproduction of results, as well as substantially boosting the potential of commercial up-take of the project outcomes.
网络安全(CyS)是一个具有挑战性的、分布式的、多利益相关者的问题。从某种意义上说,它是分布式的,即全面评估给定 IT 系统安全级别的专业知识通常无法在一个地点获得。例如有关公司内部 IT 组件的详细信息可在该公司内部获得,而有关操作系统软件漏洞的详细信息可提供给操作系统制造商,并且进一步的专家见解可提供给公共安全机构,例如 CESG。这是一个多利益相关者的问题,因为许多人类利益相关者,从 IT 设计师到具有不同专业水平的用户,需要有效地沟通和合作,以便交付具有适当水平的 CyS 保证的系统。这个跨学科项目汇集了来自英国诺丁汉大学和美国卡内基梅隆大学的顶尖学术专家,以及强大的综合项目合作伙伴:CESG - 英国国家信息保障技术局。该项目旨在通过开发具有必要科学基础的新颖框架来利用 CyS 的分布式、多个人类利益相关者的性质,以改善用户对用户定制的 CyS 信息的访问,并将其作为尖端的、数据驱动的在线网络安全决策进行操作支持系统(OCYSS)。这种方法旨在直接解决从政府到行业的小型到大型用户的可用性和高素质 CyS 专家的严重短缺问题。 OCYSS 的作用是有效且高效地整合专家和用户的输入,捕获各个组件通常不确定的漏洞级别以及这些组件交互/组合所产生的漏洞,以有效地提供适当、平衡、知情和最新的信息。为用户提供数据威胁分析和 CyS 决策支持。重要的是,OCYSS 框架: - 通过全面捕获和汇总 CyS 专家的见解和专业知识来评估各个系统组件(例如入侵检测、加密)及其交互(例如网络安全)的漏洞,包括相关的不确定性级别,从而解决 CyS 专家的可用性有限的问题。 SSL 3.0 和弱密码)。该信息由 OCYSS 集中捕获并定期更新。 - 通过为新发现的组件漏洞和组件交互漏洞(以及相关的不确定性)提供快速提出的直接途径,避免威胁分析和潜在缓解的延迟,包括。由 Oracle 等制造商和 Symantec 等第三方组织提供。- 旨在提供用户定制的、全面的、最新的威胁分析和决策支持,并随着新信息的出现而不断更新。 OCYSS 两阶段输出捕获以下方面的不确定性:A) 威胁分析输入(例如,随着时间的推移,不同专家对组件漏洞的不确定性);B) 根据用户的资产排名,对威胁缓解进行直观的收益-成本分析(例如,低价值资产可能无法保证高投资来解决低威胁)。该项目超出了标准研究项目的范围,旨在不仅提供尖端科学,开发数据科学和人机交互方面的关键进展,而且还提供了一个真实的世界, OCYSS 框架的开源原型。这使得该项目能够针对现实世界的 CyS 挑战进行卓越水平的评估和定制,包括在现实世界环境中部署 OCYSS,例如 CESG 建议的政府部门。此外,通过这种方法,该项目能够提供开源算法和实质性的开源软件平台原型,促进结果的学术复制,并大大提高项目成果的商业应用潜力。
项目成果
期刊论文数量(10)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Responsible research and innovation in practice: Driving both the 'How' and the 'What' to research
实践中负责任的研究和创新:推动研究“如何”和“什么”
- DOI:10.1016/j.jrt.2022.100042
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Chen J
- 通讯作者:Chen J
Do People Prefer to Give Interval-Valued or Point Estimates and Why?
人们更喜欢给出区间值估计还是点估计?为什么?
- DOI:10.1109/fuzz45933.2021.9494507
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Ellerby Z
- 通讯作者:Ellerby Z
Insights from interval-valued ratings of consumer products-a DECSYS appraisal
消费产品区间值评级的见解——DECSYS 评估
- DOI:10.1109/fuzz48607.2020.9177634
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Ellerby Z
- 通讯作者:Ellerby Z
Extension of Restricted Equivalence Functions and Similarity Measures for Type-2 Fuzzy Sets
- DOI:10.1109/tfuzz.2021.3136349
- 发表时间:2022-09
- 期刊:
- 影响因子:11.9
- 作者:Laura De Miguel;R. Santiago;Christian Wagner;J. Garibaldi;Z. Takác̆;A.F. Roldan Lopez de Hierro;H. Bustince
- 通讯作者:Laura De Miguel;R. Santiago;Christian Wagner;J. Garibaldi;Z. Takác̆;A.F. Roldan Lopez de Hierro;H. Bustince
Capturing richer information: On establishing the validity of an interval-valued survey response mode.
- DOI:10.3758/s13428-021-01635-0
- 发表时间:2022-06
- 期刊:
- 影响因子:5.4
- 作者:Ellerby, Zack;Wagner, Christian;Broomell, Stephen B.
- 通讯作者:Broomell, Stephen B.
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Christian Wagner其他文献
Towards data-driven environmental planning and policy design-leveraging fuzzy logic to operationalize a planning framework
迈向数据驱动的环境规划和政策设计——利用模糊逻辑来实施规划框架
- DOI:
10.1109/fuzz-ieee.2014.6891783 - 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Amir Pourabdollah;Christian Wagner;Simon Miller;Michael Smith;K. Wallace - 通讯作者:
K. Wallace
A Restricted Parametrized Model for Interval-Valued Regression
区间值回归的限制参数化模型
- DOI:
10.1109/fuzz52849.2023.10309686 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Jingda Ying;Shaily Kabir;Christian Wagner - 通讯作者:
Christian Wagner
Expert systems and creativity
专家系统和创造力
- DOI:
10.1007/978-3-642-86679-1_10 - 发表时间:
1987 - 期刊:
- 影响因子:0
- 作者:
K. MacCrimmon;Christian Wagner - 通讯作者:
Christian Wagner
On Comparing and Selecting Approaches to Model Interval-Valued Data as Fuzzy Sets
区间值数据模糊集建模方法的比较和选择
- DOI:
10.1109/fuzz-ieee.2019.8858993 - 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Josie McCulloch;Zack Ellerby;Christian Wagner - 通讯作者:
Christian Wagner
The WHO-5 well-being questionnaire in type 1 diabetes: screening for depression in pediatric and young adult subjects
WHO-5 1 型糖尿病健康问卷:儿科和青年受试者抑郁症筛查
- DOI:
- 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
S. Tittel;B. Kulzer;P. Warschburger;Ulrich Merz;A. Galler;Christian Wagner;M. Plaumann;E. Siegel;R. Holl - 通讯作者:
R. Holl
Christian Wagner的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Christian Wagner', 18)}}的其他基金
SBE-UKRI:A Novel Theory of Ordered Judgment Processes
SBE-UKRI:有序判断过程的新颖理论
- 批准号:
ES/Z000084/1 - 财政年份:2024
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Digital Catapult Fellowship Programme
数字弹射器奖学金计划
- 批准号:
EP/M029263/1 - 财政年份:2015
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Towards managing risk from climate change through comprehensive, inclusive and resilient UK infrastructure planning
通过全面、包容和有弹性的英国基础设施规划来管理气候变化风险
- 批准号:
NE/M008401/1 - 财政年份:2014
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Towards Data-Driven Environmental Policy Design
迈向数据驱动的环境政策设计
- 批准号:
EP/K012479/1 - 财政年份:2013
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Automotive 2020 Scholarship Program
汽车2020年奖学金计划
- 批准号:
0220554 - 财政年份:2003
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
Improving Manufacturing with Artificial Intelligence Techniques
利用人工智能技术改进制造
- 批准号:
9251110 - 财政年份:1992
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
On the Development of Alternatives: A Human - Computer System
论替代方案的开发:人机系统
- 批准号:
9016305 - 财政年份:1991
- 资助金额:
$ 98.17万 - 项目类别:
Continuing Grant
相似国自然基金
脂质多聚复合物mRNA纳米疫苗的构筑及抗肿瘤治疗研究
- 批准号:52373161
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
膝关节软骨退变多模态磁共振成像与软骨及滑膜相关生物标记物表达关系的实验研究
- 批准号:82360339
- 批准年份:2023
- 资助金额:32 万元
- 项目类别:地区科学基金项目
基于脑电信号多域特征和深度学习的驾驶行为识别研究
- 批准号:62366028
- 批准年份:2023
- 资助金额:33 万元
- 项目类别:地区科学基金项目
多因素耦合作用下的高原寒旱区动车组关键部件剩余寿命自适应预测方法研究
- 批准号:72361019
- 批准年份:2023
- 资助金额:29 万元
- 项目类别:地区科学基金项目
生物质/含氮废弃物可控热裂解-定向催化重整过程调控与多还原组分分解炉脱硝机制研究
- 批准号:52372024
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
相似海外基金
Integrated Supportive Care Policies to Improve Maternal Health Equity: Evaluating the Multi-level Effects and Implementation of Doula Programs for Medicaid-Eligible Birthing People in New York City
改善孕产妇健康公平的综合支持性护理政策:评估纽约市符合医疗补助资格的新生儿导乐计划的多层次影响和实施情况
- 批准号:
10833919 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
The HVIP+ Community Model: A Community Violence Prevention Program in a Southern State
HVIP 社区模式:南部各州的社区暴力预防计划
- 批准号:
10812074 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
Implementation Science to Understand and Design Stakeholder Informed Innovative Interventions to Improve Adolescent and Youth HIV Prevention and Care Continuums in Rural and Urban Uganda
实施科学以理解和设计利益相关者知情的创新干预措施,以改善乌干达农村和城市青少年艾滋病毒预防和护理的连续性
- 批准号:
10749472 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
Embracing diversity: a multi-phased project to advance the science of knowledge mobilization for Canada's culturally diverse groups
拥抱多样性:一个多阶段项目,旨在推动加拿大文化多元化群体的知识动员科学
- 批准号:
489584 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
Operating Grants
A smoke-free home intervention in federally subsidized housing
对联邦补贴住房进行无烟家庭干预
- 批准号:
10585905 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别: