SDCI Sec: SESv3 (Security Event System - Version 3)
SDCI Sec: SESv3 (Security Event System - Version 3)
批准号:
1127425
负责人:
Douglas Pearson
金额:
$79.93万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-08-01 至 2015-05-31
中文摘要
SESv 3联合安全情报项目中开展的活动将开发重要的新能力,支持收集和共享网络安全威胁数据和情报,以及丰富的互联网元素声誉和取证历史分析知识。工作将基于现有的开源REN-ISAC安全事件系统(SES)和姐妹系统,集体智能框架(CIF)。开发的功能将在REN-ISAC社区中过渡到操作实践,支持高等教育和研究社区的安全保护和响应,并将支持其他离散信任联盟之间的安全事件和事件情报共享。SESv 1是REN-ISAC社区中的一项生产服务,它从参与站点和信息共享合作伙伴处收集汇总的安全事件信息,将这些数据关联起来,以增强识别不良行为者的信心,并将由此产生的高置信度威胁情报提供给参与站点,用于本地保护。SESv 2将于2011年夏季部署,通过增加“集体智能框架”来推进SES。CIF集成了来自私人合作伙伴、公共来源和挖掘的大量数据,以提供支持互联网元素(包括IP地址、URL、域名、CIDR、AS和电子邮件地址)的声誉知识和取证历史的情报。SDCI Sec:SESv 3将通过纳入其他数据类型(如BGP和被动DNS)来大幅增加声誉知识库和取证历史。这些数据类型将允许分析识别恶意网络基础设施。自由形式的数据类型(如电子邮件、IRC、推文等)将被纳入,通过将人类对话与结构化的安全事件信息相关联来丰富对威胁的理解。将重新设计基础储存库和系统架构,以支持新增数据类型和历史记录所需的大规模扩展。利用灵活的SES/CIF v2 RESTful API,SES和CIF的访问和提交将被纳入常见的事件分析和响应工具。重要的是,将实施方法,允许独特和离散的信息共享信任社区共享事件和事件情报,由政策调解。SESv 3将在REN-ISAC社区中过渡到运行状态,为高等教育和研究社区提供直接支持,并将以开源方式发布,SESv 3团队将继续大力倡导基于标准的安全信息交换,并在整个安全社区中推广SES/CIF技术。SESv 3将领导社区间安全事件和事件信息共享(解决技术和政策问题)的开发和部署,将大大减少发现、分析和保护周期中的人为干扰,并将开发威胁数据类型之间的高级关联。SESv 3将为安全事件响应者和分析人员的工作流程提供基于联邦的情报和数据收集的新颖集成,以及人类对话与有关互联网元素的结构化数据的新颖关联。更广泛的影响:SDCI Sec:SESv 3将从根本上提高国家和国际保护关键网络基础设施的能力。SES开发和共享的情报是可操作的,是了解威胁和犯罪活动的资源。REN-ISAC将建立先进的新能力和与工业、政府和执法部门的信息共享关系,支持研究和教育部门。在R E之外,SESv 3概念、开放源代码、数据标准倡导以及技术和政策信息共享框架将激发国家能力和信息共享实践。
英文摘要
Activities undertaken in the SESv3 Federated Security Intelligence project will develop significant new capabilities supporting the collection and sharing of cybersecurity threat data and intelligence, and a rich analytic knowledge of the reputation and forensic history of Internet elements. Work will be based on the existing open source REN-ISAC Security Event System (SES) and sister system, the Collective Intelligence Framework (CIF). Developed capabilities will be transitioned to operational practice in the REN-ISAC community, supporting security protection and response in the higher education and research communities, and will support the sharing of security event and incident intelligence among other discrete trust federations.In 2008-9, REN-ISAC developed SESv1 with funding from the US Department of Justice through Internet2. A production service in the REN-ISAC community, SESv1 collects aggregated security event information from participating sites and information sharing partners, correlates the data to develop confidence in the identification of bad actors, and provides resulting high-confidence threat intelligence back to participating sites for use in local protections. SESv2, to be deployed summer 2011, advances SES with the addition of the "Collective Intelligence Framework". CIF integrates a vast array of data from private partners, public sources, and mining, to provide intelligence supporting reputational knowledge and forensic history of Internet elements, including IP address, URL, domain name, CIDR, AS, and email addresses.SDCI Sec: SESv3 will substantially increase the reputational knowledgebase and forensic history by incorporating additional data types, such as BGP and passive DNS. These data types will permit analytic identification of miscreant cyber infrastructures. Free form data types such as e-mail, IRC, tweets, etc. will be incorporated to enrich threat understanding by correlating human conversations with the structured security event information. The underlying repository and system architectures will be redesigned in order to support massive scaling required by the additional data types and historical record. Leveraging the flexible SES/CIF v2 RESTful API, access and submission to SES and CIF will be incorporated into common incident analyst and responder tools. And importantly, methods will be implemented permitting unique and discrete information sharing trust communities to share event and incident intelligence, mediated by policy. SESv3 will be transitioned to operational status in the REN-ISAC community, providing direct support to the higher education and research communities, will be open source published, and the SESv3 team will continue with their strong advocacy for standards-based security information interchange, and SES/CIF technologies in the security community at-large.Intellectual Merit: SDCI Sec: SESv3 will lead development and deployment of inter-community security event and incident information sharing (addressing technical and policy issues), will significantly reduce human interrupt in the discovery, analysis, and protect cycle, and will develop advanced correlations among threat data types. SESv3 will provide novel integration of federation-based intelligence and data collection into the workflow of the security incident responder and analyst, and novel correlation of human conversations to structured data regarding Internet elements.Broader Impact: SDCI Sec: SESv3 will provide fundamental improvement to national and international capabilities concerning the protection of critical cyberinfrastructure. Intelligence developed and shared in SES is actionable, and is a resource for understanding threat and criminal operations. Advanced new capabilities and information sharing relationships with industry, government, and law enforcement will be established in REN-ISAC, supporting the research and education sector. Outside R&E, national capabilities and information sharing practice will be stimulated by SESv3 concepts, open source code, data standards advocacy, and the technical and policy information sharing frameworks.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
登录
查看更多内容
工业大麻内生菌SEC-024A高效抑菌VOCs的合成调控、诱变选育及其增效分子机制研究
-
批准号:2026JJ81271
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2026
-
负责人:王吐虹
-
依托单位:
蟾毒灵通过SEC13/HMGB1/TLR4/NF-κB轴调控转移生态位抑制乳腺癌骨转移的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:殷佩浩
-
依托单位:
SEC61A2调控EMT影响肺腺癌细胞侵袭和转移的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:徐磊
-
依托单位:
膀胱癌细胞中TEAD4激活SEC61G通过糖酵解促进M2巨噬细胞极化的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:李朋
-
依托单位:
金葡菌肠毒素SEC 激活内皮细胞 PDK/AKT/mTOR 信号轴介导血管新生的分子
机制研究
-
批准号:24ZR1448300
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:易磊
-
依托单位:
SEC14L3 通过 CCN1调控心肌细胞凋亡在脓毒症诱导的
心功能障碍中的作用及机制研究
-
批准号:2024JJ3038
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:张伟志
-
依托单位:
毕赤酵母中Sec16p蛋白介导的膜泡出芽机制解析及运输系统重塑
研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:吕雪芹
-
依托单位:
Circ-SEC23B通过ceRNA机制调控CD24/Siglec10表达介导巨噬细胞M1极化参与Graves病免疫炎症的机制研究
-
批准号:2024Y9411
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:白雪凤
-
依托单位:
全基因组CRISPR筛选鉴定SEC23A驱动胃黏膜肠化生的作用和机制研究
-
批准号:2024Y9191
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:魏旭劲
-
依托单位:
基于胶质瘤类器官模型探讨SEC16B/TRIM56/HMGA1信号轴通过调控DNA损伤修复介导胶质母细胞瘤对替莫唑胺治疗耐药的分子机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:黄广龙
-
依托单位: