CRII: SaTC: Secure and Comprehensive Forensic Audit Infrastructure for Transparent Heterogeneous Computing
CRII: SaTC: Secure and Comprehensive Forensic Audit Infrastructure for Transparent Heterogeneous Computing
批准号:
1850392
负责人:
Yonghwi Kwon
金额:
$17.44万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-03-01 至 2022-02-28
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Cyber attackers are increasingly targeting emerging smart devices (e.g., Internet of Things devices) causing devastating damages to various enterprises and government agencies. To combat these attacks, rapid and effective investigation is critical to understand attack paths and measure the damages. Unfortunately, forensic logging infrastructures are not efficient and effective enough. Many devices completely lack forensic logging systems and others rely on ineffective logging schemes, delaying or often completely preventing forensic investigation. This research aims to combat advanced cyber-attacks such as Advanced Persistent Threats (APTs) that actively leverage emerging devices. It would design and develop fundamental security primitives that improve state-of-the-art forensic logging in terms of accuracy, efficiency, effectiveness, reliability, and applicability. This research directly contributes to national security by advancing research in and developing techniques for the forensic investigation of advanced cyber-attacks exploiting emerging devices which have recently become a new major attack vector. The investigator is committed to the open and timely dissemination of the outcomes of the proposed research in order to encourage future research in this area. Also, the research will be integrated into new curriculum materials that the investigator will develop, including dedicated lab sessions on Internet of Things forensic analysis and associated APT investigation.This research aims to design and develop fundamental security primitives for forensic logging: (1) Improving the current ineffective forensic logging systems that generate confusing forensic logs which hinder the forensic investigation significantly. (2) Reducing the space overhead of forensic logging systems to increase its applicability. (3) Enabling forensic analysis on unmodifiable devices (e.g., proprietary devices) that cannot be modified and instrumented via a novel forensic causality inference technique. This research provides the following unique set of capabilities that were not previously possible. First is the design and implementation of a novel event-execution path encoding scheme that can precisely capture event execution context information. This will allow forensic analysts to disambiguate confusing event logs. Second is a technique for instrumentation-free forensic analysis via causality inference. Devices that do not allow any modification and instrumentation will be traced and analyzed via other devices that are connected to them leveraging a novel causality inference technique.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(13)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware Analysis
MalMax:自动动态 Web 服务器恶意软件分析的多方面执行
DOI:
10.1145/3319535.3363199
发表时间:
2019
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Naderi-Afooshteh, Abbas, Kwon, Yonghwi, Nguyen-Tuong, Anh, Razmjoo-Qalaei, Ali, Zamiri-Gourabi, Mohammad-Reza, Davidson, Jack W.]
通讯作者:
Davidson, Jack W.
Security Analysis on Practices of Certificate Authorities in the HTTPS Phishing Ecosystem
HTTPS钓鱼生态系统中证书颁发机构的做法安全分析
DOI:
10.1145/3433210.3453100
发表时间:
2021
期刊:
The 2021 ACM Asia Conference on Computer and Communications Security (ASIA CCS'21
影响因子:
--
作者:
[Kim, Doowon, Cho, Haehyun, Kwon, Yonghwi, Doupé, Adam, Son, Sooel, Ahn, Gail-Joon, Dumitras, Tudor]
通讯作者:
Dumitras, Tudor
DOI:
10.1109/icse.2019.00121
发表时间:
2019-05
期刊:
2019 IEEE/ACM 41st International Conference on Software Engineering (ICSE)
影响因子:
--
作者:
[Kenneth A. Miller;Yonghwi Kwon;Yi Sun;Zhuo Zhang;X. Zhang;Zhiqiang Lin]
通讯作者:
Kenneth A. Miller;Yonghwi Kwon;Yi Sun;Zhuo Zhang;X. Zhang;Zhiqiang Lin
DOI:
10.1109/sp46214.2022.9833685
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Chi-Gon Jung;A. Ahad;Yuseok Jeon;Yonghwi Kwon]
通讯作者:
Chi-Gon Jung;A. Ahad;Yuseok Jeon;Yonghwi Kwon
DOI:
10.1109/sp40000.2020.00035
发表时间:
2020-05
期刊:
2020 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Wei You;Zhuo Zhang;Yonghwi Kwon;Yousra Aafer;Fei Peng;Yu Shi;C. Harmon;X. Zhang]
通讯作者:
Wei You;Zhuo Zhang;Yonghwi Kwon;Yousra Aafer;Fei Peng;Yu Shi;C. Harmon;X. Zhang
共 11 条
SaTC: CORE: Medium: Collaborative: Doctor WHO: Investigation and Prevention of Online Content Management System Abuse
-
批准号:2426653
-
项目类别:Standard Grant
-
资助金额:$38.77万
-
财政年份:2023
-
负责人:Yonghwi Kwon
-
依托单位:
CAREER: Automated Forensic-in-the-Loop Cyber Defense Infrastructure
-
批准号:2145616
-
项目类别:Continuing Grant
-
资助金额:$54.76万
-
财政年份:2022
-
负责人:Yonghwi Kwon
-
依托单位:
OAC Core: Small: Collaborative Research: Data Provenance Infrastructure towards Robust andReliable Data Sharing and Analytics
-
批准号:1908021
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2019
-
负责人:Yonghwi Kwon
-
依托单位:
SaTC: CORE: Medium: Collaborative: Doctor WHO: Investigation and Prevention of Online Content Management System Abuse
-
批准号:1916499
-
项目类别:Standard Grant
-
资助金额:$38.77万
-
财政年份:2019
-
负责人:Yonghwi Kwon
-
依托单位:
海外基金