TWC: Medium: Collaborative: Data is Social: Exploiting Data Relationships to Detect Insider Attacks
TWC:媒介:协作:数据是社交的:利用数据关系检测内部攻击
基本信息
- 批准号:1409303
- 负责人:
- 金额:$ 24万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2014
- 资助国家:美国
- 起止时间:2014-10-01 至 2018-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Insider attacks present an extremely serious, pervasive and costly security problem under critical domains such as national defense and financial and banking sector. Accurate insider threat detection has proved to be a very challenging problem. This project explores detecting insider threats in a banking environment by analyzing database searches. This research addresses the challenge by formulating and devising machine learning-based solutions to the insider attack problem on relational database management systems (RDBMS), which are ubiquitous and are highly susceptible to insider attacks. In particular, the research uses a new general model for database provenance, which captures both the data values accessed or modified by a user's activity and summarizes the computational path and the underlying relationship between those data values. The provenance model leads naturally to a way to model user activities by labeled hypergraph distributions and by a Markov network whose factors represent the data relationships. The key tradeoff being studied theoretically is between the expressivity and the complexity of the provenance model. The research results are validated and evaluated by intimately collaborating with a large financial institution to build a prototype insider threat detection engine operating on its existing operational RDBMS. In particular, with the help of the security team from the financial institution, the research team addresses database performance, learning scalability, and software tool development issues arising during the evaluation and deployment of the system. Research results are reported via technical papers and disseminated through conferences and journals, through a new research webpage at the UB's NSA- and DHS-certified center of excellence (CAE) in Information Assurance, and at the center's future workshops.
内部攻击在国防、金融和银行等关键领域是一个极其严重、普遍和代价高昂的安全问题。准确的内部威胁检测已被证明是一个非常具有挑战性的问题。 该项目探讨通过分析数据库搜索来检测银行环境中的内部威胁。 本研究通过制定和设计基于机器学习的解决方案来解决关系数据库管理系统(RDBMS)的内部攻击问题,这是无处不在的,非常容易受到内部攻击。特别是,该研究使用了一个新的通用模型的数据库出处,它捕获的数据值访问或修改用户的活动,并总结了计算路径和这些数据值之间的潜在关系。起源模型自然地导致一种方式来建模用户活动的标记超图分布和马尔可夫网络的因素表示的数据关系。理论上研究的关键权衡是来源模型的表达性和复杂性之间的权衡。 通过与一家大型金融机构密切合作,在其现有的可操作RDBMS上构建一个原型内部威胁检测引擎,对研究结果进行了验证和评估。 特别是,在金融机构安全团队的帮助下,研究团队解决了系统评估和部署过程中出现的数据库性能、学习可扩展性和软件工具开发问题。研究结果通过技术论文报告,并通过会议和期刊传播,通过UB的NSA和DHS认证的信息保证卓越中心(CAE)的新研究网页,以及该中心未来的研讨会。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Xuanlong Nguyen其他文献
Xuanlong Nguyen的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Xuanlong Nguyen', 18)}}的其他基金
Parameter Estimation Theory and Algorithms under Latent Variable Models and Model Misspecification
潜变量模型和模型错误指定下的参数估计理论和算法
- 批准号:
2015361 - 财政年份:2020
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
CAREER: Geometric approaches to hierarchical and nonparametric model-based inference
职业:基于分层和非参数模型的推理的几何方法
- 批准号:
1351362 - 财政年份:2014
- 资助金额:
$ 24万 - 项目类别:
Continuing Grant
CIF: Collaborative Research:Small: Distributed Detection Algorithms and Stochastic Modeling for Large Monitoring Sensor Networks
CIF:协作研究:小型:大型监控传感器网络的分布式检测算法和随机建模
- 批准号:
1115769 - 财政年份:2011
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
相似海外基金
TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
- 批准号:
1840790 - 财政年份:2018
- 资助金额:
$ 24万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC:媒介:协作:大规模密码熵的黑盒评估
- 批准号:
1937622 - 财政年份:2018
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Building a Privacy-Preserving Social Networking Platform from a Technological and Sociological Perspective
TWC SBE:媒介:协作:从技术和社会学角度构建保护隐私的社交网络平台
- 批准号:
1855391 - 财政年份:2018
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1834213 - 财政年份:2018
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC:媒介:协作:通过机器取消学习有效修复学习系统
- 批准号:
1854000 - 财政年份:2018
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Seal: Secure Engine for AnaLytics - From Secure Similarity Search to Secure Data Analytics
TWC:媒介:协作:Seal:AnaLytics 的安全引擎 - 从安全相似性搜索到安全数据分析
- 批准号:
1929901 - 财政年份:2018
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1748127 - 财政年份:2017
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Dollars for Hertz: Making Trustworthy Spectrum Sharing Technically and Economically Viable
TWC SBE:媒介:协作:赫兹美元:使值得信赖的频谱共享在技术上和经济上可行
- 批准号:
1801986 - 财政年份:2017
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: New Protocols and Systems for RAM-Based Secure Computation
TWC:媒介:协作:基于 RAM 的安全计算的新协议和系统
- 批准号:
1562888 - 财政年份:2016
- 资助金额:
$ 24万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1563848 - 财政年份:2016
- 资助金额:
$ 24万 - 项目类别:
Standard Grant