TTP: Small: Network-Level Security Posture Assessment and Predictive Analytics: From Theory to Practice
TTP:小:网络级安全态势评估和预测分析:从理论到实践
基本信息
- 批准号:1616575
- 负责人:
- 金额:$ 50万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2016
- 资助国家:美国
- 起止时间:2016-08-15 至 2021-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This project addresses the following two key questions in cyber security: (1) how is the security condition of a network assessed, and (2) to what extent can we predict data breaches or other cyber security incidents for an organization. The ability to answer both questions has far-reaching social and economic impact. Recent data breaches such as those at Target, JP Morgan, Home Depot, Office of Personnel Management (OPM), and Anthem Healthcare, to name just a few, highlight the increasing social and economic impact of such cyber security incidents. Often, by the time a breach is detected, it is too late and damage has already occurred. Consequently, being able to predict such incidents accurately can greatly enhance an organization's ability to put preventative and proactive measures in place. The answers to these questions also have implications on public policy design - not only for the security policies themselves, but also for related incentive mechanisms. Such mechanisms might be aimed at encouraging adoption of better security policies and cybersecurity frameworks, including cyber insurance, liability limitation, and rate recovery among others. Presidential Policy Directive (PPD) 21, on Critical Infrastructure Security and Resilience, encourages efforts to strengthen and maintain secure, functioning, and resilient critical infrastructure. Understanding the potential attack vector presented by an enterprise or organization is a crucial part of achieving this goal.This project follows a comprehensive agenda aimed at transitioning to practice technologies developed by the research team in the domain of quantitative assessment of the security posture at both a network and an organizational level. The use of such assessments enables more accurate forecasting of cyber security incidents. The technological innovation is a sound quantitative framework that combines a large collection of cybersecurity data, novel data processing methods, advanced machine learning techniques, and extensive cybersecurity domain expertise. The resulting framework produces accurate predictions of security incidents for a given organization, thereby providing tangible information and crucial input for decision makers such as an insurance underwriter, or an enterprise customer seeking to validate vendor specifications.
该项目解决了网络安全中的以下两个关键问题:(1)如何评估网络的安全状况,以及(2)我们可以在多大程度上预测组织的数据泄露或其他网络安全事件。回答这两个问题的能力具有深远的社会和经济影响。最近的数据泄露事件,如塔吉特(Target)、摩根大通(JP Morgan)、家得宝(Home Depot)、人事管理办公室(OPM)和国歌医疗(Anhim Healthcare)等,突显出此类网络安全事件的社会和经济影响越来越大。通常,当检测到漏洞时,为时已晚,损害已经发生。因此,能够准确地预测此类事件可以极大地提高组织实施预防性和前瞻性措施的能力。这些问题的答案也对公共政策设计有影响--不仅对安全政策本身,而且对相关的激励机制。这种机制可能旨在鼓励采用更好的安全政策和网络安全框架,包括网络保险、责任限制和费率追回等。关于关键基础设施安全和复原力的总统政策指令(PPD)21鼓励努力加强和维护安全、运行和有弹性的关键基础设施。了解企业或组织提供的潜在攻击媒介是实现这一目标的关键部分。该项目遵循一个全面的议程,旨在将研究团队在网络和组织级别的安全态势定量评估领域开发的技术过渡到实践。使用这种评估可以更准确地预测网络安全事件。技术创新是一个完善的量化框架,结合了大量的网络安全数据、新颖的数据处理方法、先进的机器学习技术和广泛的网络安全领域专业知识。由此产生的框架可为给定组织生成准确的安全事件预测,从而为决策者(如保险承保人或寻求验证供应商规格的企业客户)提供切实的信息和重要的输入。
项目成果
期刊论文数量(5)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Will Catastrophic Cyber-Risk Aggregation Thrive in the IoT Age? A Cautionary Economics Tale for (Re-)Insurers and Likes
灾难性网络风险聚合会在物联网时代蓬勃发展吗?
- DOI:10.1145/3446635
- 发表时间:2021
- 期刊:
- 影响因子:2.5
- 作者:Pal, Ranjan;Huang, Ziyuan;Lototsky, Sergey;Yin, Xinlong;Liu, Mingyan;Crowcroft, Jon;Sastry, Nishanth;De, Swades;Nag, Bodhibrata
- 通讯作者:Nag, Bodhibrata
Preference-Based Privacy Markets
基于偏好的隐私市场
- DOI:10.1109/access.2020.3014882
- 发表时间:2020
- 期刊:
- 影响因子:3.9
- 作者:Pal, Ranjan;Crowcroft, Jon;Wang, Yixuan;Li, Yong;De, Swades;Tarkoma, Sasu;Liu, Mingyan;Nag, Bodhibrata;Kumar, Abhishek;Hui, Pan
- 通讯作者:Hui, Pan
Aggregate Cyber-Risk Management in the IoT Age: Cautionary Statistics for (Re)Insurers and Likes
物联网时代的总体网络风险管理:(再)保险公司和类似机构的警示统计数据
- DOI:10.1109/jiot.2020.3039254
- 发表时间:2021
- 期刊:
- 影响因子:10.6
- 作者:Pal, Ranjan;Huang, Ziyuan;Yin, Xinlong;Lototsky, Sergey;De, Swades;Tarkoma, Sasu;Liu, Mingyan;Crowcroft, Jon;Sastry, Nishanth
- 通讯作者:Sastry, Nishanth
Designing Cyber Insurance Policies: The Role of Pre-Screening and Security Interdependence
- DOI:10.1109/tifs.2018.2812205
- 发表时间:2018-03
- 期刊:
- 影响因子:6.8
- 作者:Mohammad Mahdi Khalili;Parinaz Naghizadeh;M. Liu
- 通讯作者:Mohammad Mahdi Khalili;Parinaz Naghizadeh;M. Liu
Incentivizing effort in interdependent security games using resource pooling
使用资源池激励相互依赖的安全游戏的努力
- DOI:10.1145/3338506.3340272
- 发表时间:2019
- 期刊:
- 影响因子:0
- 作者:Khalili, Mohammad Mahdi;Zhang, Xueru;Liu, Mingyan
- 通讯作者:Liu, Mingyan
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Mingyan Liu其他文献
A theoretical model to predict the rising trajectory of single bubble with zigzagging path in still water
预测静水中锯齿形单个气泡上升轨迹的理论模型
- DOI:
- 发表时间:
2024 - 期刊:
- 影响因子:3.8
- 作者:
Lubin Zhang;Yongli Ma;Mingyan Liu - 通讯作者:
Mingyan Liu
Potentially commercialisable alga, emCoelastrella/em sp. SDEC-28, for stable growth and multiple product applications in pilot-scale seawater-wastewater cultivation
潜在可商业化的藻类,小球藻(Coelastrella)sp. SDEC - 28,用于在中试规模的海水 - 废水养殖中稳定生长以及多种产品应用
- DOI:
10.1016/j.algal.2025.104057 - 发表时间:
2025-07-01 - 期刊:
- 影响因子:4.500
- 作者:
Zhen Xie;Huiying Chen;Meng Ma;Mingyan Liu;Haiyan Pei - 通讯作者:
Haiyan Pei
Gas-liquid mass transfer and reaction characteristics of gas–liquid-solid circulating micro-fluidized bed
- DOI:
10.1016/j.cej.2024.158249 - 发表时间:
2025-01-01 - 期刊:
- 影响因子:
- 作者:
Hao Guo;Yongli Ma;Yan Sun;Mingyan Liu - 通讯作者:
Mingyan Liu
Experimental investigation of collision behavior of fluidized solid particles on the tube wall of a graphite evaporator by vibration signal analysis
- DOI:
10.1016/j.powtec.2016.12.067 - 发表时间:
2017-07-01 - 期刊:
- 影响因子:
- 作者:
Yue Ma;Mingyan Liu;Min An;Xiaoping Xu - 通讯作者:
Xiaoping Xu
Enantiomerization of helicenes on graphene-like surface: a DFT study
- DOI:
10.1007/s00214-025-03184-7 - 发表时间:
2025-04-10 - 期刊:
- 影响因子:1.500
- 作者:
Xunshan Liu;Huimin Duan;Yi Guo;Na Yang;Yongmiao Shen;Mingyan Liu;Chengshuo Shen - 通讯作者:
Chengshuo Shen
Mingyan Liu的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Mingyan Liu', 18)}}的其他基金
EAGER: Theory and Practice of Risk-Informed Cyber Insurance Policies: Risk Dependency, Risk Aggregation, and Active Threat Landscape
EAGER:风险知情网络保险政策的理论与实践:风险依赖性、风险聚合和主动威胁格局
- 批准号:
1939006 - 财政年份:2019
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CPS:Small:Collaborative Research: Incentivizing Desirable User Behavior in a Class of CPS
CPS:Small:协作研究:在一类 CPS 中激励期望的用户行为
- 批准号:
1739517 - 财政年份:2017
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CI-NEW: Collaborative Research: COVE-Computer Vision Exchange for Data, Annotations and Tools
CI-NEW:协作研究:COVE-数据、注释和工具的计算机视觉交换
- 批准号:
1628987 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TWC: Small: Understanding Network Level Malicious Activities: Classification, Community Detection and Inference of Security Interdependence
TWC:小:了解网络级恶意活动:分类、社区检测和安全依赖性推断
- 批准号:
1422211 - 财政年份:2014
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
NeTS: Small: Collaborative Research: Playing the Devil's Advocate: The Profit Perspective in Secondary Spectrum Markets
NetS:小型:协作研究:扮演魔鬼代言人:二级频谱市场的利润视角
- 批准号:
1217689 - 财政年份:2012
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CAREER: Capacity-Driven Design of Large-Scale Wireless Sensor Networks
职业:大规模无线传感器网络的容量驱动设计
- 批准号:
0238035 - 财政年份:2003
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
相似国自然基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
- 批准号:
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
- 批准号:n/a
- 批准年份:2022
- 资助金额:10.0 万元
- 项目类别:省市级项目
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
- 批准号:32000033
- 批准年份:2020
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
- 批准号:31972324
- 批准年份:2019
- 资助金额:58.0 万元
- 项目类别:面上项目
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
- 批准号:81900988
- 批准年份:2019
- 资助金额:21.0 万元
- 项目类别:青年科学基金项目
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
- 批准号:31802058
- 批准年份:2018
- 资助金额:26.0 万元
- 项目类别:青年科学基金项目
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
- 批准号:31870821
- 批准年份:2018
- 资助金额:56.0 万元
- 项目类别:面上项目
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
- 批准号:31772128
- 批准年份:2017
- 资助金额:60.0 万元
- 项目类别:面上项目
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
- 批准号:81704176
- 批准年份:2017
- 资助金额:20.0 万元
- 项目类别:青年科学基金项目
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
- 批准号:91640114
- 批准年份:2016
- 资助金额:85.0 万元
- 项目类别:重大研究计划
相似海外基金
Collaborative Research: SHF: Small: Efficient and Scalable Privacy-Preserving Neural Network Inference based on Ciphertext-Ciphertext Fully Homomorphic Encryption
合作研究:SHF:小型:基于密文-密文全同态加密的高效、可扩展的隐私保护神经网络推理
- 批准号:
2412357 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
DESIGN: Creating cultural change in small to medium-sized professional societies: a training network approach
设计:在中小型专业团体中创造文化变革:培训网络方法
- 批准号:
2334964 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CC* Integration-Small: Network-Aware Edge Computing for Real-time Wildfire Detection
CC* Integration-Small:用于实时野火检测的网络感知边缘计算
- 批准号:
2346755 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
NeTS: Small: Revisiting Network Algorithmics using the CRAM Model
NeTS:小型:使用 CRAM 模型重新审视网络算法
- 批准号:
2333587 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SaTC: CORE: Small: NSF-DST: Understanding Network Structure and Communication for Supporting Information Authenticity
SaTC:核心:小型:NSF-DST:了解支持信息真实性的网络结构和通信
- 批准号:
2343387 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CC* Integration-Small: M2- NET: An Integrated Access and Backhaul Millimeter-wave Wireless Network for Campus Connectivity and Research
CC* Integration-Small:M2-NET:用于校园连接和研究的集成接入和回程毫米波无线网络
- 批准号:
2346621 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CNS Core: Small: Network Wide Sensing by Leveraging Cellular Communication Networks
CNS 核心:小型:利用蜂窝通信网络进行全网络传感
- 批准号:
2343469 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CSR: Small: Processing-in-Memory enabled Manycore Systems to Accelerate Graph Neural Network-based Data Analytics
CSR:小型:启用内存处理的众核系统可加速基于图神经网络的数据分析
- 批准号:
2308530 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Collaborative Research: NeTS: Small: Digital Network Twins: Mapping Next Generation Wireless into Digital Reality
合作研究:NeTS:小型:数字网络双胞胎:将下一代无线映射到数字现实
- 批准号:
2312138 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Collaborative Research: NeTS: Small: Digital Network Twins: Mapping Next Generation Wireless into Digital Reality
合作研究:NeTS:小型:数字网络双胞胎:将下一代无线映射到数字现实
- 批准号:
2312139 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant