课题基金 / 基金详情

CAREER: Towards Automated Security Vulnerability and Patch Management for Power Grid Operations

CAREER: Towards Automated Security Vulnerability and Patch Management for Power Grid Operations
职业:实现电网运营的自动化安全漏洞和补丁管理
批准号:
1751255
负责人:
Qinghua Li
金额:
$42.76万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2018
资助国家:
美国
项目状态:
未结题
起止时间:
2018-05-01 至 2025-04-30

项目摘要

项目成果

Qinghua Li的其他基金

相似基金

相关文献

中文摘要
翻译
电网是国家安全、经济和日常生活的重要基础设施,面临诸多网络安全威胁。2015年,一场概念验证攻击袭击了乌克兰,导致数十万人的电力供应中断了几个小时。到目前为止,在许多成功的网络攻击中,软件中的安全漏洞发挥了重要作用,将系统暴露给旨在破坏并控制系统的攻击者。漏洞可能存在于控制器、仪表、断路器和控制计算机中,因此,电力公司通常使用漏洞和补丁管理来监控资产的安全漏洞,分析每个漏洞的补救和缓解措施(例如,应用补丁),并在攻击者利用漏洞之前部署该措施以保护漏洞。在能源行业,这仍然是一个高度手动的过程,电力公司花费大量时间对大量漏洞进行分析,增加了漏洞已知但无法缓解的时间窗口,使系统面临被攻击的高风险。这个问题没有得到足够的重视,也没有商业解决办法。这个项目将通过自动化分析过程来解决这个问题。如果成功,它将大大减少电力公司在漏洞和补丁管理上花费的人力资源和时间,并通过更快地减轻漏洞来提高国家能源基础设施的安全性。该项目还将为电力公司的安全操作员开设培训课程,并开设关于漏洞和补丁管理的研究生课程。将举办有关安全会议的工业讲习班和教程,以传播研究发现。本科生和代表性不足的学生将参与研究。该项目旨在开发电力公用事业中自动化漏洞和补丁管理的方法,可以加快如何补救和减轻安全漏洞的决策制定。它有几个研究任务。(i)开发一个自动化的解决方案,可以预测是否应该立即修补漏洞或以其他方式减轻漏洞。将使用机器学习方法建立预测模型,以预测人类操作员对漏洞的补救措施,并提供易于验证的基本原理,以便安全操作员可以在需要时验证预测。㈡设计一种定量方法,使缓解行动分析自动化。本任务将设计一个数据流模型,以捕获缓解行动与系统组件之间的相互作用以及系统组件之间的相互作用,并将缓解行动选择制定为优化问题,其目标是最大限度地减少所选缓解行动对给定一组电网漏洞的负面影响。㈢研制拟议工具的原型,并在电力公用事业合作伙伴中进行实地测试。(iv)为漏洞和补丁管理生态系统制定建议,包括供应商、第三方服务、监管机构和标准化组织。该项目对整个生态系统提出的建议旨在采用系统的、多方的方法来减轻漏洞,提供将能源部门的漏洞和补丁管理实践从手动转变为自动化操作的潜力。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The power grid is a critical infrastructure for national security, the economy, and daily life, and faces many cybersecurity threats. A proof-of-concept attack hit the Ukraine in 2015, and cut off the power supply to hundreds of thousands of people for several hours. In many successful cyber attacks so far, security vulnerabilities in software have played an important role, exposing systems to attackers who aim to compromise and hence control the system. Vulnerabilities may exist in controllers, meters, circuit breakers, and control computers, and as such, electric utilities usually use vulnerability and patch management to monitor the security vulnerabilities of assets, analyze the remediation and mitigation action for each vulnerability (e.g., applying a patch), and deploy the action to secure the vulnerabilities before attackers exploit them. This remains a heavily manual process in the energy sector, where electric utilities spend a tremendous amount of time on such analyses over a large number of vulnerabilities, and increases the time window in which vulnerabilities are known but not mitigated, putting the system into a high risk of being attacked. This problem has received insufficient attention and has defied commercial solutions. This project will address this problem through automating this analysis process. If successful, it will drastically reduce the human resources and time spent by electric utilities on vulnerability and patch management, and increase the security of the nation's energy infrastructure through mitigating vulnerabilities much more quickly. This project will also develop a training course for security operators in electric utilities and a graduate-level course on vulnerability and patch management. Industry workshops and tutorials on security conferences will be developed to disseminate research discoveries. Undergraduate students and underrepresented students will be involved in the research. This project aims to develop methodologies for automated vulnerability and patch management in electric utilities that can expedite decision making of how to remedy and mitigate security vulnerabilities. It has several research tasks. (i) Develop an automated solution that can predict whether a vulnerability should be patched immediately or mitigated in other ways. A prediction model will be built using machine learning methods to predict human operators' remediation actions for vulnerabilities, and easy-to-verify rationale will be provided so that security operators can validate the predictions if needed. (ii) Design a quantitative approach for automating mitigation action analysis. This task will devise a data flow model to capture the interactions between mitigation actions and system components and the interactions among system components, and formulate mitigation action selection as an optimization problem, where the goal is to minimize the negative impact of the selected mitigation actions for a given set of vulnerabilities to the power grid. (iii) Develop a prototype of the proposed tools and conduct field tests in electric utility partners. (iv) Develop recommendations for the vulnerability and patch management ecosystem, including vendors, third-party services, regulation authorities, and standardization organizations. The recommendations to the whole ecosystem developed in this project aims for a systematic, multi-party approach for mitigating vulnerabilities, offering the potential to transform vulnerability and patch management practices in the energy sector from manual to automated operations.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(5)
专著(0)
科研奖励(0)
会议论文
AI-based Cyber Event OSINT via Twitter Data
通过 Twitter 数据进行基于人工智能的网络事件 OSINT
DOI: 10.1109/icnc57223.2023.10074187
发表时间: 2023
期刊: Networking and Communications (ICNC
影响因子: --
作者: [Dale, Dakota, McClanahan, Kylie, Li, Qinghua]
通讯作者: Li, Qinghua
DOI: 10.1145/3465481.3470039
发表时间: 2021-08
期刊: Proceedings of the 16th International Conference on Availability, Reliability and Security
影响因子: --
作者: [P. Huff;Kylie McClanahan;Thao Le;Qinghua Li]
通讯作者: P. Huff;Kylie McClanahan;Thao Le;Qinghua Li
DOI: 10.1109/cns48642.2020.9162309
发表时间: 2020
期刊: IEEE Conference on Communications and Network Security (CNS
影响因子: --
作者: [Zhang, Fengli, Huff, Philip, McClanahan, Kylie, Li, Qinghua]
通讯作者: Li, Qinghua
A Distributed Ledger for Non-Attributable Cyber Threat Intelligence Exchange
用于无归属网络威胁情报交换的分布式账本
DOI: 10.1007/978-3-030-90019-9_9
发表时间: 2021
期刊: International Conference on Security and Privacy in Communication Systems (SecureComm
影响因子: --
作者: [Huff, Philip, Li, Qinghua]
通讯作者: Li, Qinghua
IUCRC Phase I: The University of Arkansas: Center for Infrastructure Trustworthiness in Energy Systems (CITES)
  • 批准号:
    2113903
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $52.5万
  • 财政年份:
    2021
  • 负责人:
    Qinghua Li
  • 依托单位:
I-Corps: Automated Software Security Vulnerability and Patch Management
  • 批准号:
    2139458
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2021
  • 负责人:
    Qinghua Li
  • 依托单位:
Planning IUCRC at The University of Arkansas: Center for Infrastructure Trustworthiness in Energy Systems (CITES)
  • 批准号:
    1822152
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2018
  • 负责人:
    Qinghua Li
  • 依托单位:
海外基金