课题基金 / 基金详情

CAREER: Towards Automated Security Vulnerability and Patch Management for Power Grid Operations

CAREER: Towards Automated Security Vulnerability and Patch Management for Power Grid Operations
职业:实现电网运营的自动化安全漏洞和补丁管理
批准号:
1751255
负责人:
Qinghua Li
金额:
$42.76万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2018
资助国家:
美国
项目状态:
未结题
起止时间:
2018-05-01 至 2025-04-30

项目摘要

项目成果

Qinghua Li的其他基金

相似基金

相关文献

中文摘要
翻译
电网是关系国家安全、经济和日常生活的重要基础设施,面临着诸多网络安全威胁。2015年,乌克兰发生了一起概念验证袭击,数十万人的电力供应中断了几个小时。到目前为止,在许多成功的网络攻击中,软件中的安全漏洞发挥了重要作用,使系统暴露在旨在危害并控制系统的攻击者面前。控制器、仪表、断路器和控制计算机中可能存在漏洞,因此,电力公司通常使用漏洞和补丁管理来监控资产的安全漏洞,分析针对每个漏洞的补救和缓解操作(例如,应用补丁),并在攻击者利用漏洞之前部署该操作来保护漏洞。在能源领域,这仍然是一个高度手动的过程,电力公用事业公司在对大量漏洞进行此类分析上花费了大量时间,并增加了已知漏洞但未得到缓解的时间窗口,使系统面临很高的攻击风险。这个问题没有得到足够的重视,也没有得到商业解决方案。该项目将通过自动化这一分析过程来解决这一问题。如果成功,它将极大地减少电力公用事业公司在漏洞和补丁管理方面花费的人力资源和时间,并通过更快地缓解漏洞来提高国家能源基础设施的安全性。该项目还将为电力公司的安全操作员开发一个培训课程,以及一个关于脆弱性和补丁管理的研究生课程。将举办关于安全会议的行业讲习班和教程,以传播研究发现。本科生和代表性不足的学生将参与这项研究。该项目旨在开发电力设施中自动化漏洞和补丁管理的方法,以加快如何补救和减轻安全漏洞的决策。它有几项研究任务。(I)开发一种自动化解决方案,该解决方案可以预测是否应立即修补漏洞或以其他方式缓解漏洞。将使用机器学习方法建立预测模型,以预测人类操作员对漏洞的补救行动,并将提供易于验证的理论基础,以便安全操作员可以在需要时验证预测。(2)设计一种自动进行缓解行动分析的量化方法。这项任务将设计一个数据流模型来捕获缓解行动与系统组件之间的相互作用以及系统组件之间的相互作用,并将缓解行动选择作为一个优化问题,目标是将所选缓解行动对电网的一组给定脆弱性的负面影响降至最低。(3)开发拟议工具的原型,并在电力公司合作伙伴中进行实地测试。(Iv)为漏洞和补丁管理生态系统制定建议,包括供应商、第三方服务、监管当局和标准化组织。在该项目中提出的针对整个生态系统的建议旨在采用系统的、多方的方法来缓解漏洞,有可能将能源部门的漏洞和补丁管理实践从手动操作转变为自动化操作。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The power grid is a critical infrastructure for national security, the economy, and daily life, and faces many cybersecurity threats. A proof-of-concept attack hit the Ukraine in 2015, and cut off the power supply to hundreds of thousands of people for several hours. In many successful cyber attacks so far, security vulnerabilities in software have played an important role, exposing systems to attackers who aim to compromise and hence control the system. Vulnerabilities may exist in controllers, meters, circuit breakers, and control computers, and as such, electric utilities usually use vulnerability and patch management to monitor the security vulnerabilities of assets, analyze the remediation and mitigation action for each vulnerability (e.g., applying a patch), and deploy the action to secure the vulnerabilities before attackers exploit them. This remains a heavily manual process in the energy sector, where electric utilities spend a tremendous amount of time on such analyses over a large number of vulnerabilities, and increases the time window in which vulnerabilities are known but not mitigated, putting the system into a high risk of being attacked. This problem has received insufficient attention and has defied commercial solutions. This project will address this problem through automating this analysis process. If successful, it will drastically reduce the human resources and time spent by electric utilities on vulnerability and patch management, and increase the security of the nation's energy infrastructure through mitigating vulnerabilities much more quickly. This project will also develop a training course for security operators in electric utilities and a graduate-level course on vulnerability and patch management. Industry workshops and tutorials on security conferences will be developed to disseminate research discoveries. Undergraduate students and underrepresented students will be involved in the research. This project aims to develop methodologies for automated vulnerability and patch management in electric utilities that can expedite decision making of how to remedy and mitigate security vulnerabilities. It has several research tasks. (i) Develop an automated solution that can predict whether a vulnerability should be patched immediately or mitigated in other ways. A prediction model will be built using machine learning methods to predict human operators' remediation actions for vulnerabilities, and easy-to-verify rationale will be provided so that security operators can validate the predictions if needed. (ii) Design a quantitative approach for automating mitigation action analysis. This task will devise a data flow model to capture the interactions between mitigation actions and system components and the interactions among system components, and formulate mitigation action selection as an optimization problem, where the goal is to minimize the negative impact of the selected mitigation actions for a given set of vulnerabilities to the power grid. (iii) Develop a prototype of the proposed tools and conduct field tests in electric utility partners. (iv) Develop recommendations for the vulnerability and patch management ecosystem, including vendors, third-party services, regulation authorities, and standardization organizations. The recommendations to the whole ecosystem developed in this project aims for a systematic, multi-party approach for mitigating vulnerabilities, offering the potential to transform vulnerability and patch management practices in the energy sector from manual to automated operations.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(5)
专著(0)
科研奖励(0)
会议论文
AI-based Cyber Event OSINT via Twitter Data
通过 Twitter 数据进行基于人工智能的网络事件 OSINT
DOI: 10.1109/icnc57223.2023.10074187
发表时间: 2023
期刊: Networking and Communications (ICNC
影响因子: --
作者: [Dale, Dakota, McClanahan, Kylie, Li, Qinghua]
通讯作者: Li, Qinghua
DOI: 10.1145/3465481.3470039
发表时间: 2021-08
期刊: Proceedings of the 16th International Conference on Availability, Reliability and Security
影响因子: --
作者: [P. Huff;Kylie McClanahan;Thao Le;Qinghua Li]
通讯作者: P. Huff;Kylie McClanahan;Thao Le;Qinghua Li
DOI: 10.1109/cns48642.2020.9162309
发表时间: 2020
期刊: IEEE Conference on Communications and Network Security (CNS
影响因子: --
作者: [Zhang, Fengli, Huff, Philip, McClanahan, Kylie, Li, Qinghua]
通讯作者: Li, Qinghua
A Distributed Ledger for Non-Attributable Cyber Threat Intelligence Exchange
用于无归属网络威胁情报交换的分布式账本
DOI: 10.1007/978-3-030-90019-9_9
发表时间: 2021
期刊: International Conference on Security and Privacy in Communication Systems (SecureComm
影响因子: --
作者: [Huff, Philip, Li, Qinghua]
通讯作者: Li, Qinghua
IUCRC Phase I: The University of Arkansas: Center for Infrastructure Trustworthiness in Energy Systems (CITES)
  • 批准号:
    2113903
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $52.5万
  • 财政年份:
    2021
  • 负责人:
    Qinghua Li
  • 依托单位:
I-Corps: Automated Software Security Vulnerability and Patch Management
  • 批准号:
    2139458
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2021
  • 负责人:
    Qinghua Li
  • 依托单位:
Planning IUCRC at The University of Arkansas: Center for Infrastructure Trustworthiness in Energy Systems (CITES)
  • 批准号:
    1822152
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2018
  • 负责人:
    Qinghua Li
  • 依托单位:
海外基金