CAREER: Reasoning under Uncertainty in Cybersecurity
CAREER: Reasoning under Uncertainty in Cybersecurity
批准号:
1622402
负责人:
Xinming Ou
金额:
$2.32万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-08-07 至 2017-02-28
中文摘要
网络安全,就像现实世界的安全一样,依赖于调查方法,将分散在多个地方的证据拼凑起来,得出安全漏洞发生了什么以及它们是如何发生的结论。虽然执法机构在现实世界中使用基于人工分析的有效证据推理,但在网络世界中,我们需要自动推理方法来处理每天针对我们国家信息基础设施的自动网络攻击。本研究旨在发现和发展这种自动推理方法。由于这种推理的不确定性,再加上网络攻击的特点,这个问题很难解决。网络安全的不确定性来自两个方面。首先是不知道攻击者的行为和选择所带来的不确定性。由于黑客在网络世界中基本上是隐形的,我们必须依靠各种类型的传感器来报告潜在攻击的症状。不确定性的第二个来源来自这些传感器。由于在大多数情况下,网络攻击的症状与良性网络活动的症状明显重叠,因此不可能依靠单一的传感器对攻击是否发生和成功做出绝对正确的判断。一个关键问题是如何使用这些不完美的传感器进行推理,以便人们可以得出关于系统安全状态的几乎确定的结论。这种在不确定性下进行推理的挑战并不新鲜。在过去的四十年里,计算机科学研究人员已经开发了一系列的不确定性推理模型和方法,特别是在人工智能领域。然而,网络威胁的出现对这一问题提出了新的挑战。现有的方法通常需要一个知识工程过程来为问题域构建知识模型。这种方法在诸如疾病诊断等较为静态和行为良好的问题领域中工作得相当好。这些问题领域与网络安全之间的一个关键区别是,后者必须处理活跃的恶意攻击者,这些攻击者将试图打破推理模型中所做的任何假设。因此,网络安全的知识模型不能是静态的,否则很容易被规避。如何采取有效实用的知识工程方法来应对网络安全中的不确定性,是亟待解决的最大开放性问题。本研究采用实证、自下而上的方法来解决上述挑战。PI将从人类安全分析师如何对网络事件进行推理的实证研究开始,而不是从现有的理论开始,并试图在此过程中捕捉推理的本质。然后,PI将通过在生产网络上运行入侵检测传感器并与系统管理员合作来理解和推理警报来执行此实证研究。下一步是开发一个模拟人类推理过程的推理模型,并将自动推理引擎应用于新的数据上,看看它的表现如何。在这个螺旋式的理论发展过程中,PI总是可以确保方法适用于实际的网络安全分析,并不断发现模型中的漏洞,从而揭示什么是最合适的理论以及如何将它们应用于这个问题。最终目标是为网络安全不确定性下的推理找到正确的理论框架,并通过对生产系统数据的可重复实验来验证这些理论。这项研究与PI紧密结合。美国的教育努力既针对学生,也针对整个社会。该研究的实证性质为安全从业人员和研究人员之间的对话提供了一个宝贵的场所,这将导致双向教育过程:从事该项目的学生可以获得将先进知识应用于实际问题的基本技能;像系统管理员这样的安全从业者可以通过与研究团队的合作学习最新的网络安全技术。本研究所开展的实证研究将为学院网络安全课程的教材更新提供源源不断的数据和实例。将开设新的课程,重点关注网络安全防御的不确定性。将有许多本科生参与研究工作,这将为他们提供独特的教育体验。此外,在堪萨斯州立大学已经建立的外展项目的帮助下,研究产生的试验台基础设施也将被用作公众关于网络安全问题的教育平台。
英文摘要
Cyber security, like security in the physical world, relies upon investigation methodologies that piece together dispersed evidence spread across multiple places, and come to a conclusion on what security breaches have happened and how they happened. While effective evidential reasoning based on manual analysis are used in the physical world by law-enforcement agencies, in the cyber world we need automated reasoning methodologies to handle the automated cyber attacks against our nation's information infrastructures every day. This research aims at discovering and developing such automated reasoning methodologies. The problem is difficult due to the uncertain nature of such reasoning, which is compounded by the characteristics of cyber attacks.The uncertainty in cyber security comes from two sources. The first is the uncertainty from not knowing the attacker's actions and choices. Since hackers are essentially invisible in the cyberworld, we have to rely upon various types of sensors that report symptoms of potential attacks. The second source of uncertainty comes from these sensors. Since in most cases the symptoms of cyberattacks significantly overlap with symptoms from benign network activities, it is not possible to rely on a single sensor to give an absolutely correct judgment on whether an attack has happened and succeeded. A key question is how to use these imperfect sensors to conduct reasoning so that one can come up with almost certain conclusions regarding a system's security status. This challenge of reasoning under uncertainty is not new. In the past four decades computer science researchers have developed an array of reasoning models and methods for uncertainty, especially in the area of artificial intelligence. However, the emergence of cyber threats poses a newchallenge to this problem. The existing methodologies typically require a knowledge-engineering process to build a knowledge model for the problem domain. This has worked reasonably well with the more static and well-behaved problem domains such as disease diagnosis. A key difference between these problem domains and cyber security is that the latter has to deal with an activemalicious attacker who will try to break whatever assumptions made in the reasoning model. For this reason, the knowledge model for cyber security cannot be static because then they can be easily evaded. What will be an effective and practical knowledge engineering approach to handle the uncertainty in cyber security is the biggest open problem that needs to be answered from theresearch.This research adopts an empirical, bottom-up approach to tackle the above challenges. Instead of starting from the existing theories, the PI will start from empirical study on how a human security analysts would reason about cyber events and try to capture the essence of the reasoning in the process. Then, the PI will carry out this empirical study by running intrusion detection sensors on production networks and work with system administrators to understand and reason about the alerts. The next step is to develop a reasoning model that simulates the human reasoning process, and apply the automated reasoning engine on fresh new data to see how it fares. In this spiral theory development process the PI can always make sure that the methodologies are applicable to real cyber-security analysis and constantly find gaps in the model that reveal what will be the most appropriate theories and how to apply them in this problem. The eventual goal is to find the right theoretical framework for reasoning under uncertainty in cyber-security, and validate such theories through repeatable experiments on data from production systems.This research is tightly integrated into the PI?s education efforts both for students and targeted at the society at large. The empirical nature of the research provides a valuable venue for dialogue between security practitioners and researchers, which will result in a two-way education process: students working on the project can acquire the essential skills of applying advanced knowledge to a practical problem; and security practitioners like system administrators can learn the state-of-the art in cyber security technology through collaborative work with the research team. The empirical study carried out from the research will provide endless data and examples to refresh the materials of the cyber-security courses taught by the PI. New courses with a focus on uncertainty in cyber security defense will be developed. There will be a number of undergraduate students who take part in the research efforts, which will provide a unique education experience for them. Moreover, the test-bed infrastructure produced from the research will also be used as an education platform for the general public about cyber-security problems, with the help of the out-reach programs already established at Kansas State University.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3243734.3243835
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Fengguo Wei;Xingwei Lin;Xinming Ou;Ting Chen;Xiaosong Zhang]
通讯作者:
Fengguo Wei;Xingwei Lin;Xinming Ou;Ting Chen;Xiaosong Zhang
Experimental Study of Machine Learning based Malware Detection Systems’ Practical Utility
基于机器学习的恶意软件检测系统的实验研究——实用性
DOI:
--
发表时间:
2020
期刊:
HICSS SYMPOSIUM ON CYBERSECURITY BIG DATA ANALYTICS
影响因子:
--
作者:
[Li, Yuping, Caragea, Doina, Hall, Lawrence, Ou, Xinming]
通讯作者:
Ou, Xinming
SaTC: CORE: Medium: Collaborative: Understanding Security in the Software Development Lifecycle: A Holistic, Mixed-Methods Approach
-
批准号:1801633
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Xinming Ou
-
依托单位:
SaTC: CORE: Small: Collaborative: Data-driven Approaches for Large-scale Security Analysis of Mobile Applications
-
批准号:1717862
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2017
-
负责人:Xinming Ou
-
依托单位:
An Innovative Cybersecurity Curriculum for Civilian and Military Workforce
-
批准号:1129534
-
项目类别:Standard Grant
-
资助金额:$29.97万
-
财政年份:2011
-
负责人:Xinming Ou
-
依托单位:
TC:Small:Collaborative Research:Models and Techniques for Enterprise Network Security Metrics
-
批准号:1018703
-
项目类别:Standard Grant
-
资助金额:$39.67万
-
财政年份:2010
-
负责人:Xinming Ou
-
依托单位:
CAREER: Reasoning under Uncertainty in Cybersecurity
-
批准号:0954138
-
项目类别:Continuing Grant
-
资助金额:$42.97万
-
财政年份:2010
-
负责人:Xinming Ou
-
依托单位:
CT-ISG: Model-based, Automatic Network Security Management
-
批准号:0716665
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Xinming Ou
-
依托单位:
海外基金