Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence

用于可扩展生成网络威胁情报的指纹识别和大数据安全分析

基本信息

  • 批准号:
    RGPIN-2017-06650
  • 负责人:
  • 金额:
    $ 3.64万
  • 依托单位:
  • 依托单位国家:
    加拿大
  • 项目类别:
    Discovery Grants Program - Individual
  • 财政年份:
    2020
  • 资助国家:
    加拿大
  • 起止时间:
    2020-01-01 至 2021-12-31
  • 项目状态:
    已结题

项目摘要

Everyday, a deluge of cyber attacks is launched against the cyber infrastructure of corporations, governmental agencies and individuals, with unprecedented sophistication, speed, intensity, volume, damage and audacity. Besides, the threat landscape is shifting towards more stealthy, mercurial and targeted advanced persistent threats against: (a) industrial control systems, (b) IoT devices, (c) social networks, (d) SDN and cloud infrastructure, and (e) mobile devices, which exacerbates even more the security challenge. These attacks emanate from a wide spectrum of perpetrators such as criminals, cyber-terrorists, terrorists, and foreign intelligence/military services. The damage can be even more potent when the target involves critical infrastructure. Organizations deploy an arsenal of security apparatus such as firewalls, intrusion detection and prevention systems, and network security monitoring, which generates various alerts, events, code and logs that are generally voluminous, unavailable in real-time, and underused. In this context, there is an acute desideratum that consists of harnessing big data technologies in order to subject the aforementioned security logs, data feeds and streams to real-time aggregation, analysis, mining and correlation to derive timely and relevant cyber threat intelligence that will enable detection, prevention, mitigation and attribution of cyber threats. In the short term, we will focus on the most prominent OS platforms, namely those based on Android operating system. Indeed, Android holds nearly 87.6% of the market share in the mobile world. Moreover, it is rapidly expanding to various consumer electronics and Internet of Things (IoT) devices through the Google's Brillo platform. In this regard, the long-term goal of this research proposal is to elaborate a practical framework for the generation of timely, relevant, and actionable intelligence to counter cyber threats. In the short term, we will focus on the analysis of Android threats. In this respect, our short and mid-term goals are as follows: (i) elaborate a suite of highly scalable techniques for the automatic analysis of large influx of Android malware and target applications. Typical analyses include: classification and clustering of malicious targets, new malware family detection and isolation of malicious behaviours; (ii) devise scalable algorithms to characterize, track and aggregate network footprints of Android threats by analyzing various network information such as passive DNS streams, malware network flows collected via dynamic analysis, as well as darknet traffic streams; (iii) design and implement a framework for the generation of cyber threat intelligence that leverages the aforementioned innovative, near-real-time, highly-scalable and streamlined techniques for the analysis of the malware feeds, applications and related network information streams.
每天,针对企业、政府机构和个人的网络基础设施发起大量网络攻击,其复杂程度、速度、强度、数量、损害和胆量都是前所未有的。此外,威胁格局正在转向更加隐蔽、多变和有针对性的高级持续威胁,针对:(a) 工业控制系统、(b) 物联网设备、(c) 社交网络、(d) SDN 和云基础设施,以及 (e)移动设备,这进一步加剧了安全挑战。这些攻击的肇事者范围广泛,例如犯罪分子、网络恐怖分子、恐怖分子和外国情报/军事部门。当目标涉及关键基础设施时,损害可能会更加严重。组织部署了一系列安全设备,例如防火墙、入侵检测和防御系统以及网络安全监控,这些设备会生成各种警报、事件、代码和日志,这些警报、事件、代码和日志通常数量庞大、实时不可用且未得到充分利用。在这种背景下,迫切需要利用大数据技术对上述安全日志、数据源和流进行实时聚合、分析、挖掘和关联,以获得及时且相关的网络威胁情报,从而实现网络威胁的检测、预防、缓解和归因。短期内,我们将重点关注最著名的操作系统平台,即基于Android操作系统的平台。事实上,Android 占据了移动领域近 87.6% 的市场份额。此外,它还通过谷歌的Brillo平台迅速扩展到各种消费电子和物联网(IoT)设备。在这方面,本研究计划的长期目标是制定一个实用的框架,以生成及时、相关且可操作的情报来应对网络威胁。短期内我们将重点分析Android威胁。在这方面,我们的短期和中期目标如下:(i)制定一套高度可扩展的技术,用于自动分析大量涌入的 Android 恶意软件和目标应用程序。典型的分析包括:恶意目标的分类和聚类、新恶意软件家族的检测和恶意行为的隔离; (ii) 通过分析各种网络信息(例如被动 DNS 流、通过动态分析收集的恶意软件网络流以及暗网流量流),设计可扩展的算法来表征、跟踪和聚合 Android 威胁的网络足迹; (iii) 设计和实施一个网络威胁情报生成框架,利用上述创新、近实时、高度可扩展和简化的技术来分析恶意软件源、应用程序和相关网络信息流。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Debbabi, Mourad其他文献

CASeS: Concurrent Contingency Analysis-Based Security Metric Deployment for the Smart Grid
  • DOI:
    10.1109/tsg.2019.2959937
  • 发表时间:
    2020-05-01
  • 期刊:
  • 影响因子:
    9.6
  • 作者:
    Akaber, Parisa;Moussa, Bassam;Debbabi, Mourad
  • 通讯作者:
    Debbabi, Mourad
A Detection and Mitigation Model for PTP Delay Attack in an IEC 61850 Substation
  • DOI:
    10.1109/tsg.2016.2644618
  • 发表时间:
    2018-09-01
  • 期刊:
  • 影响因子:
    9.6
  • 作者:
    Moussa, Bassani;Debbabi, Mourad;Assi, Chadi
  • 通讯作者:
    Assi, Chadi
Fingerprinting Android packaging: Generating DNAs for malware detection
  • DOI:
    10.1016/j.diin.2016.04.013
  • 发表时间:
    2016-08-07
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Karbab, ElMouatez Billah;Debbabi, Mourad;Mouheb, Djedjiga
  • 通讯作者:
    Mouheb, Djedjiga
Cyber Scanning: A Comprehensive Survey
  • DOI:
    10.1109/surv.2013.102913.00020
  • 发表时间:
    2014-01-01
  • 期刊:
  • 影响因子:
    35.6
  • 作者:
    Bou-Harb, Elias;Debbabi, Mourad;Assi, Chadi
  • 通讯作者:
    Assi, Chadi
Detection of Malicious Payload Distribution Channels in DNS

Debbabi, Mourad的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Debbabi, Mourad', 18)}}的其他基金

Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
  • 批准号:
    RGPIN-2017-06650
  • 财政年份:
    2022
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Discovery Grants Program - Individual
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
  • 批准号:
    RGPIN-2017-06650
  • 财政年份:
    2021
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Discovery Grants Program - Individual
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
NSERC/Hydro-Québec/Thales 智能电网安全工业研究主席:网络物理攻击的检测、预防、缓解和恢复
  • 批准号:
    501621-2015
  • 财政年份:
    2020
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Industrial Research Chairs
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
  • 批准号:
    DGDND-2017-00016
  • 财政年份:
    2019
  • 资助金额:
    $ 3.64万
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
  • 批准号:
    RGPIN-2017-06650
  • 财政年份:
    2019
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Discovery Grants Program - Individual
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
NSERC/Hydro-Québec/Thales 智能电网安全工业研究主席:网络物理攻击的检测、预防、缓解和恢复
  • 批准号:
    501621-2015
  • 财政年份:
    2019
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Industrial Research Chairs
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
  • 批准号:
    DGDND-2017-00016
  • 财政年份:
    2018
  • 资助金额:
    $ 3.64万
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
  • 批准号:
    RGPIN-2017-06650
  • 财政年份:
    2018
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Discovery Grants Program - Individual
Connect Internet of Things Research
连接物联网研究
  • 批准号:
    534119-2018
  • 财政年份:
    2018
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Connect Grants Level 2
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
NSERC/Hydro-Québec/Thales 智能电网安全工业研究主席:网络物理攻击的检测、预防、缓解和恢复
  • 批准号:
    501621-2015
  • 财政年份:
    2018
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Industrial Research Chairs

相似国自然基金

多源数据约束下的大尺度河道形状建模方法研究
  • 批准号:
    42371481
  • 批准年份:
    2023
  • 资助金额:
    46 万元
  • 项目类别:
    面上项目
员工算法规避行为的内涵结构、量表开发及多层次影响机制:基于大(小)数据研究方法整合视角
  • 批准号:
    72372021
  • 批准年份:
    2023
  • 资助金额:
    40 万元
  • 项目类别:
    面上项目
数据与知识联合驱动的可通用视觉基础大模型研究
  • 批准号:
    62336004
  • 批准年份:
    2023
  • 资助金额:
    239 万元
  • 项目类别:
    重点项目
基于神经功能影像数据的抑郁症大尺度脑网络动力学建模及调控研究
  • 批准号:
    12305051
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
时序工况下模块化数据生成的大机车轴齿轮箱在线剩余寿命预测研究
  • 批准号:
    52305140
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

Longitudinal neural fingerprinting of opioid-use trajectories
阿片类药物使用轨迹的纵向神经指纹图谱
  • 批准号:
    10805031
  • 财政年份:
    2023
  • 资助金额:
    $ 3.64万
  • 项目类别:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
  • 批准号:
    RGPIN-2017-06650
  • 财政年份:
    2022
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Discovery Grants Program - Individual
Chemical Fingerprints of Cognitive Impairment-related alpha-Synuclein Strains using 3D Small Molecule Microarray and Related Therapeutic Application
使用 3D 小分子微阵列的认知障碍相关 α-突触核蛋白菌株的化学指纹及相关治疗应用
  • 批准号:
    10360139
  • 财政年份:
    2022
  • 资助金额:
    $ 3.64万
  • 项目类别:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
  • 批准号:
    RGPIN-2017-06650
  • 财政年份:
    2021
  • 资助金额:
    $ 3.64万
  • 项目类别:
    Discovery Grants Program - Individual
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
  • 批准号:
    DGDND-2017-00016
  • 财政年份:
    2019
  • 资助金额:
    $ 3.64万
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了