TWC: Medium: Collaborative: Data is Social: Exploiting Data Relationships to Detect Insider Attacks
TWC: Medium: Collaborative: Data is Social: Exploiting Data Relationships to Detect Insider Attacks
批准号:
1409303
负责人:
Xuanlong Nguyen
金额:
$24.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-10-01 至 2018-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Insider attacks present an extremely serious, pervasive and costly security problem under critical domains such as national defense and financial and banking sector. Accurate insider threat detection has proved to be a very challenging problem. This project explores detecting insider threats in a banking environment by analyzing database searches. This research addresses the challenge by formulating and devising machine learning-based solutions to the insider attack problem on relational database management systems (RDBMS), which are ubiquitous and are highly susceptible to insider attacks. In particular, the research uses a new general model for database provenance, which captures both the data values accessed or modified by a user's activity and summarizes the computational path and the underlying relationship between those data values. The provenance model leads naturally to a way to model user activities by labeled hypergraph distributions and by a Markov network whose factors represent the data relationships. The key tradeoff being studied theoretically is between the expressivity and the complexity of the provenance model. The research results are validated and evaluated by intimately collaborating with a large financial institution to build a prototype insider threat detection engine operating on its existing operational RDBMS. In particular, with the help of the security team from the financial institution, the research team addresses database performance, learning scalability, and software tool development issues arising during the evaluation and deployment of the system. Research results are reported via technical papers and disseminated through conferences and journals, through a new research webpage at the UB's NSA- and DHS-certified center of excellence (CAE) in Information Assurance, and at the center's future workshops.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Parameter Estimation Theory and Algorithms under Latent Variable Models and Model Misspecification
-
批准号:2015361
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2020
-
负责人:Xuanlong Nguyen
-
依托单位:
CAREER: Geometric approaches to hierarchical and nonparametric model-based inference
-
批准号:1351362
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2014
-
负责人:Xuanlong Nguyen
-
依托单位:
CIF: Collaborative Research:Small: Distributed Detection Algorithms and Stochastic Modeling for Large Monitoring Sensor Networks
-
批准号:1115769
-
项目类别:Standard Grant
-
资助金额:$26.35万
-
财政年份:2011
-
负责人:Xuanlong Nguyen
-
依托单位:
海外基金