CAREER: Graph-Based Security Analytics: New Algorithms, Robustness under Adversarial Settings, and Robustness Enhancements
CAREER: Graph-Based Security Analytics: New Algorithms, Robustness under Adversarial Settings, and Robustness Enhancements
批准号:
1750198
负责人:
Neil Gong
金额:
$42.91万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-03-15 至 2019-08-31
中文摘要
该项目的目标是使基于图形的安全分析变得实用和健壮。通用图算法和基于图的机器学习方法在应用于从检测计算机网络中的恶意网站和受攻击的设备到检测社交网络中的受攻击或不可信的帐户等一系列安全问题时取得了一定的成功。然而,由于现有的方法是针对一般上下文而不是针对特定的安全问题而设计的,因此它们在检测网络中的不良行为方面还有改进的空间。此外,在安全环境中,通常有一个坚定的对手试图逃避检测,而通用算法在设计上没有考虑到这一点,这使得它们容易受到攻击。该项目将开发考虑安全问题的独特特征的新型图推理算法,分析对此类算法的可能攻击的频谱,定义其对攻击的健壮性度量,并开发提高其健壮性的方法。该项目团队将创建和共享与基于图表的安全分析相关的数据集,以及实现其算法和稳健性测量的软件,以便与行业从业者和其他研究人员共享。他们还将指导本科生和研究生进行研究,使用问题和数据支持新的大学课程和面向K-12学生的科学、技术、工程和数学(STEM)推广活动。工作重点是同时将网络中的所有节点标记为恶意或良性的集体分类算法。第一个主要研究重点是提出分析技术,通过对给定节点及其邻居的恶意联合概率进行建模的局部规则,将随机游走和基于循环信任传播的算法相结合。为了做到这一点,该团队将开发算法的版本,放松相邻节点具有很强同源性的假设,开发相邻节点关系的特征,并创建利用这些特征的新的马尔可夫随机场公式。第二个研究重点将对集体分类算法的攻击面进行建模,描述攻击者的目标和能力、创建节点或边和生成网络活动等规避动作的成本,以及不同目标、能力和规避程度对算法性能的影响。第三个推动力将是通过开发抗攻击者的链接预测算法和相似性度量来开发识别此类规避的方法,然后通过开发基于本地规则的技术来减少规避努力,这些技术以混淆攻击的方式向图中添加噪声。该团队将对来自多个域的数据集的指标和算法进行评估,包括社交网络中的恶意用户、Web图中的恶意URL、域名服务重定向中嵌入的恶意域以及电子商务市场中的恶意订单。这些问题和相关的数据集将纳入现有的数据驱动安全课程和新的集体分类研究生研讨会课程。所有活动的结果将作为现有课程和新课程的案例和材料,以及围绕检测网络中的恶意行为而组织的K-12暑期计划和网络安全竞赛。该奖项反映了NSF的法定使命,并已通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The goal of this project is to make graph-based security analytics practical and robust. General-purpose graph algorithms and graph-based machine learning methods have had some success when applied to a number of security problems ranging from detecting malicious websites and compromised devices in computer networks to detecting compromised or inauthentic accounts in social networks. However, because the existing methods are designed for generic contexts rather than for specific security problems, there is room to improve their performance in detecting bad actors in networks. Further, in security contexts, there is often a determined adversary trying to evade detection that general-purpose algorithms are not designed to consider, which makes them vulnerable to attack. This project will develop novel graph inference algorithms that consider unique characteristics of security problems, analyze the spectrum of possible attacks on such algorithms, define measures of their robustness against attack, and develop methods to improve their robustness. The project team will create and share datasets related to graph-based security analytics along with software that implements their algorithms and robustness measures with both industrial practitioners and other researchers. They will also mentor undergraduate and graduate students in the research, using the problems and data to support new college courses and Science, Technology, Engineering, and Mathematics (STEM) outreach activities for K-12 students.The work focuses on collective classification algorithms that simultaneously label all nodes in a network as malicious or benign. The first main research thrust involves advancing analytic techniques that combine random walk and loopy belief propagation-based algorithms through local rules that model the joint probabilities of a given node and its neighbors being malicious. To do this, the team will develop versions of the algorithms that relax assumptions that neighboring nodes have strong homophily, developing characterizations of neighboring nodes' relationships and creating novel Markov Random Field formulations that leverage these characterizations. The second research thrust will model the attack surface of collective classification algorithms, characterizing the goals and capabilities of attackers, the cost of evasive moves such as creating nodes or edges and generating network activity, and the effect of different goals, capabilities, and levels of evasion on the algorithms' performance. The third thrust will be to develop methods to identify such evasion by developing attacker-resistant link prediction algorithms and similarity metrics, then mitigate evasion efforts through developing local rule-based techniques that add noise to graphs in ways that confound attacks. The team will evaluate the metrics and algorithms on datasets from a number of domains, including malicious users in social networks, malicious URLs in the web graph, malicious domains embedded in domain name service redirects, and malicious orders in an e-commerce marketplace. These problems, and the associated datasets, will be integrated into an existing course on data-driven security and a new graduate seminar course on collective classification. Results from all activities will be used as cases and materials in both existing and new courses, as well as a K-12 summer program and cybersecurity competition organized around detecting malicious actors in networks.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3274694.3274706
发表时间:
2018-09
期刊:
Proceedings of the 34th Annual Computer Security Applications Conference
影响因子:
--
作者:
[Minghong Fang;Guolei Yang;N. Gong;Jia Liu]
通讯作者:
Minghong Fang;Guolei Yang;N. Gong;Jia Liu
DOI:
10.14722/ndss.2019.23226
发表时间:
2018-12
期刊:
ArXiv
影响因子:
--
作者:
[Binghui Wang;Jinyuan Jia;N. Gong]
通讯作者:
Binghui Wang;Jinyuan Jia;N. Gong
SybilBlind: Detecting Fake Users in Online Social Networks without Manual Labels
SybilBlind:在没有手动标签的情况下检测在线社交网络中的虚假用户
DOI:
--
发表时间:
2018
期刊:
Intrusions and Defenses
影响因子:
--
作者:
[Wang, Binghui, Zhang, Le, Gong, Neil Zhenqiang]
通讯作者:
Gong, Neil Zhenqiang
DOI:
10.1109/cns.2018.8433147
发表时间:
2018-03
期刊:
ArXiv
影响因子:
--
作者:
[Peng Gao;Binghui Wang;N. Gong;Sanjeev R. Kulkarni;Kurt Thomas;Prateek Mittal]
通讯作者:
Peng Gao;Binghui Wang;N. Gong;Sanjeev R. Kulkarni;Kurt Thomas;Prateek Mittal
Collaborative Research: SaTC: CORE: Medium: Towards Secure Federated Learning
-
批准号:2131859
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2022
-
负责人:Neil Gong
-
依托单位:
Collaborative Research: SaTC: CORE: Small: Securing Recommender Systems against Data Poisoning Attacks
-
批准号:2125977
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2022
-
负责人:Neil Gong
-
依托单位:
SaTC: CORE: Medium: Collaborative: Towards Robust Machine Learning Systems
-
批准号:1937786
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2019
-
负责人:Neil Gong
-
依托单位:
CAREER: Graph-Based Security Analytics: New Algorithms, Robustness under Adversarial Settings, and Robustness Enhancements
-
批准号:1937787
-
项目类别:Continuing Grant
-
资助金额:$37.11万
-
财政年份:2019
-
负责人:Neil Gong
-
依托单位:
SaTC: CORE: Medium: Collaborative: Towards Robust Machine Learning Systems
-
批准号:1801584
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2018
-
负责人:Neil Gong
-
依托单位:
国内基金
海外基金
登录
查看更多内容
基于Graph-PINN的层结稳定度参数化建模与沙尘跨介质耦合传输模拟研
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:梅奥
-
依托单位:
平面三角剖分flip graph的强凸性研究
-
批准号:12301432
-
项目类别:青年科学基金项目
-
资助金额:30.00万元
-
批准年份:2023
-
负责人:王子丽
-
依托单位:
基于graph的多对比度磁共振图像重建方法
-
批准号:61901188
-
项目类别:青年科学基金项目
-
资助金额:24.5万元
-
批准年份:2019
-
负责人:赖宗英
-
依托单位:
基于de bruijn graph梳理的宏基因组拼接算法开发
-
批准号:61771009
-
项目类别:面上项目
-
资助金额:50.0万元
-
批准年份:2017
-
负责人:李国君
-
依托单位:
基于Graph和ISA的红外目标分割与识别方法研究
-
批准号:61101246
-
项目类别:青年科学基金项目
-
资助金额:22.0万元
-
批准年份:2011
-
负责人:刘靳
-
依托单位:
中国Web Graph的挖掘与应用研究
-
批准号:60473122
-
项目类别:面上项目
-
资助金额:23.0万元
-
批准年份:2004
-
负责人:俞勇
-
依托单位: