SaTC: EDU: A Formal Approach to Digital Forensics and Incident Response Investigations
SaTC:EDU:数字取证和事件响应调查的正式方法
基本信息
- 批准号:1821829
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-09-01 至 2020-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The goal of this project is to develop a platform for digital forensics and incident response (DFIR) education. The platform will be built based on an existing proof-of-concept prototype called Nugget. The resulting platform will be tool-agnostic and will support different pedagogical approaches. The platform will provide the ability to formulate and apply forensic queries over different, and potentially large, data sources in an easy to understand manner. The project will make it possible for domain experts, such as cybersecurity and law enforcement analysts, to learn and perform forensic investigations. A set of hands-on materials, that utilize the platform, will be developed to support a two-course sequence in digital forensics and incident response. The platform will provide a formal and unifying conceptual framework for all DFIR analytical techniques, and will enable different approaches to DFIR education. This will allow courses from introductory to research-centric graduate courses, to use the same conceptual framework, and will enable instructors to focus more clearly on concepts rather than specific tools. The associated runtime environment will allow the separation of the specification of a query from its implementation. This project will result in a tool that provides the means to incrementally integrate advanced forensic capabilities, such as SaaS forensics, data analytics, and eventually deeper AI techniques into cybersecurity curricula. The platform will provide the means to acquire and analyze data from popular cloud services, such as cloud drives and online collaboration, and will also integrate with security monitoring/incident response systems.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该项目的目标是为数字取证和事件响应(DFIR)教育开发一个平台。该平台将基于现有的概念验证原型“Nugget”构建。最终的平台将是工具不可知的,并将支持不同的教学方法。该平台将提供以易于理解的方式对不同的、可能很大的数据源制定和应用取证查询的能力。该项目将使领域专家,如网络安全和执法分析师,学习和执行法医调查成为可能。将开发一套利用该平台的动手材料,以支持数字取证和事件响应的两门课程。该平台将为所有DFIR分析技术提供正式和统一的概念框架,并将使DFIR教育的不同方法成为可能。这将允许从入门课程到以研究为中心的研究生课程使用相同的概念框架,并使教师能够更清楚地关注概念,而不是特定的工具。关联的运行时环境将允许将查询的规范与其实现分离。该项目将提供一种工具,提供增量集成高级取证功能的手段,如SaaS取证、数据分析,最终将更深入的人工智能技术整合到网络安全课程中。该平台将提供从流行的云服务(如云驱动器和在线协作)获取和分析数据的方法,并将与安全监控/事件响应系统集成。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Nugget: A digital forensics language
- DOI:10.1016/j.diin.2018.01.006
- 发表时间:2018-03
- 期刊:
- 影响因子:0
- 作者:Christopher Stelly;Vassil Roussev
- 通讯作者:Christopher Stelly;Vassil Roussev
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Vassil Roussev其他文献
File fragment encoding classification - An empirical approach
文件片段编码分类 - 一种经验方法
- DOI:
10.1016/j.diin.2013.06.008 - 发表时间:
2013 - 期刊:
- 影响因子:0
- 作者:
Vassil Roussev;Candice Quates - 通讯作者:
Candice Quates
Forensic analysis of cloud-native artifacts
云原生工件的取证分析
- DOI:
10.1016/j.diin.2016.01.013 - 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Vassil Roussev;S. McCulley - 通讯作者:
S. McCulley
Content-Based Image Retrieval for Digital Forensics
用于数字取证的基于内容的图像检索
- DOI:
10.1007/0-387-31163-7_22 - 发表时间:
2005 - 期刊:
- 影响因子:0
- 作者:
Yixin Chen;Vassil Roussev;G. Richard;Yun Gao - 通讯作者:
Yun Gao
Forensics Knowledge Area Issue 1 . 0
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Vassil Roussev - 通讯作者:
Vassil Roussev
Vassil Roussev的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Vassil Roussev', 18)}}的其他基金
CC* Network Design: ARCHES (Advanced Research Computing in the Humanities Engineering and Sciences) Network at the University of New Orleans
CC* 网络设计:新奥尔良大学 ARCHES(人文工程和科学高级研究计算)网络
- 批准号:
1660241 - 财政年份:2017
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
EDU: Automated Platform for Cyber Security Learning and Experimentation (AutoCUE)
EDU:网络安全学习和实验自动化平台 (AutoCUE)
- 批准号:
1623253 - 财政年份:2016
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
EDU: Lightweight Environment for Network Security Education
EDU:网络安全教育的轻量级环境
- 批准号:
1419358 - 财政年份:2014
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
相似国自然基金
EDU增强冬小麦O3抗性的生理生态学机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: New to IUSE: EDU DCL:Diversifying Economics Education through Plug and Play Video Modules with Diverse Role Models, Relevant Research, and Active Learning
协作研究:IUSE 新增功能:EDU DCL:通过具有不同角色模型、相关研究和主动学习的即插即用视频模块实现经济学教育多元化
- 批准号:
2315700 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
越境する「日本型教育」の拡散・借用・再文脈化過程の動態的研究:EDU-Portを事例に
“日式教育”跨境扩散、借用与重构过程的动态研究——以EDU-Port为例
- 批准号:
24K05749 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
Collaborative Research: New to IUSE: EDU DCL:Diversifying Economics Education through Plug and Play Video Modules with Diverse Role Models, Relevant Research, and Active Learning
协作研究:IUSE 新增功能:EDU DCL:通过具有不同角色模型、相关研究和主动学习的即插即用视频模块实现经济学教育多元化
- 批准号:
2315699 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: New to IUSE: EDU DCL:Diversifying Economics Education through Plug and Play Video Modules with Diverse Role Models, Relevant Research, and Active Learning
协作研究:IUSE 新增功能:EDU DCL:通过具有不同角色模型、相关研究和主动学习的即插即用视频模块实现经济学教育多元化
- 批准号:
2315697 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: New to IUSE: EDU DCL:Diversifying Economics Education through Plug and Play Video Modules with Diverse Role Models, Relevant Research, and Active Learning
协作研究:IUSE 新增功能:EDU DCL:通过具有不同角色模型、相关研究和主动学习的即插即用视频模块实现经济学教育多元化
- 批准号:
2315696 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: New to IUSE: EDU DCL:Diversifying Economics Education through Plug and Play Video Modules with Diverse Role Models, Relevant Research, and Active Learning
协作研究:IUSE 新增功能:EDU DCL:通过具有不同角色模型、相关研究和主动学习的即插即用视频模块实现经济学教育多元化
- 批准号:
2315698 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: New to IUSE: EDU DCL:Diversifying Economics Education through Plug and Play Video Modules with Diverse Role Models, Relevant Research, and Active Learning
协作研究:IUSE 新增功能:EDU DCL:通过具有不同角色模型、相关研究和主动学习的即插即用视频模块实现经济学教育多元化
- 批准号:
2315701 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
SaTC: EDU: AI for Cybersecurity Education via an LLM-enabled Security Knowledge Graph
SaTC:EDU:通过支持 LLM 的安全知识图进行网络安全教育的人工智能
- 批准号:
2335666 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: Adversarial Malware Analysis - An Artificial Intelligence Driven Hands-On Curriculum for Next Generation Cyber Security Workforce
协作研究:SaTC:EDU:对抗性恶意软件分析 - 下一代网络安全劳动力的人工智能驱动实践课程
- 批准号:
2230609 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: RoCCeM: Bringing Robotics, Cybersecurity and Computer Science to the Middled School Classroom
合作研究:SaTC:EDU:RoCCeM:将机器人、网络安全和计算机科学带入中学课堂
- 批准号:
2312057 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant