SaTC: CORE: Medium: Collaborative: RADAR: Real-time Advanced Detection and Attack Reconstruction
SaTC:核心:中等:协作:雷达:实时高级检测和攻击重建
基本信息
- 批准号:1918542
- 负责人:
- 金额:$ 61.2万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2019
- 资助国家:美国
- 起止时间:2019-10-01 至 2024-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
There has been a rapid escalation of targeted cyber-attacks, called Advanced Persistent Threats (APTs), on high-profile enterprises. These skilled attacks routinely bypass widely deployed protection mechanisms. Existing second-line cyber defenses (e.g., intrusion detection systems) are helpful, but they often generate a flood of information that overwhelms cyber analysts. Moreover, analysts lack the tools to piece together attack fragments spanning multiple applications and/or hosts. This project will hence focus on developing the principles, techniques, and tools for accurate attack detection and real-time reconstruction of attacker activities across large enterprises.Many intellectual challenges arise in APT campaign reconstruction, including: (a) developing a wide range of policy-based, anomaly-based and signature-based attack detectors, (b) connecting the dots in the presence of unreliable detectors, (c) scaling to large enterprise networks, and (d) resisting adversarial manipulation. To overcome these challenges, this project will explore several novel directions, including (i) domain-specific languages for cyber attack detection and forensics, (ii) novel detection techniques that leverage natural language descriptions of recent attacks, (iii) alternative dependence propagation semantics that mitigate dependence explosion, and (iv) mapping attack steps to the high-level objectives ("kill-chain") of APT actors.Cyber technologies are inextricably woven into the fabric of today's society. Repeated cyber attacks undermine the society's trust in this fabric. Even in purely economic terms, worldwide cybercrime led to $600 billion in losses in 2017 (Source: McAfee). This project will help arrest these downward trends. It will also educate graduate, undergraduate and K-12 students through cybersecurity coursework, research, and outreach activities. Enhanced participation of women and minorities will be targeted through alliances with partners, including the National Center for Women & Information Technology, Governor's State University, and Chicago Public Schools. Project-related data, results, publications and tools will be made available through the web sites of the research laboratories collaborating on this project: http://seclab.cs.stonybrook.edu/ and http://sisl.lab.uic.edu/.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
针对知名企业的有针对性的网络攻击迅速升级,称为高级持续威胁(APT)。这些熟练的攻击通常会绕过广泛部署的保护机制。现有的二线网络防御系统(如入侵检测系统)是有帮助的,但它们通常会产生大量信息,使网络分析师不堪重负。此外,分析人员缺乏工具来拼凑跨越多个应用程序和/或主机的攻击片段。因此,该项目将专注于开发准确的攻击检测和实时重建大型企业中的攻击者活动的原则、技术和工具。APT战役重建中出现了许多智力挑战,包括:(A)开发广泛的基于策略、基于异常和基于签名的攻击检测器,(B)在存在不可靠检测器的情况下将点连接起来,(C)扩展到大型企业网络,以及(D)抵抗对手操纵。为了克服这些挑战,这个项目将探索几个新的方向,包括(I)用于网络攻击检测和取证的特定领域的语言,(Ii)利用最近攻击的自然语言描述的新检测技术,(Iii)缓解依赖爆炸的替代依赖传播语义,以及(Iv)将攻击步骤映射到APT参与者的高级目标(“杀伤链”)。反复的网络攻击破坏了社会对这种结构的信任。即使从纯粹的经济角度来看,2017年全球范围内的网络犯罪也导致了6000亿美元的损失(来源:McAfee)。这一项目将有助于遏制这些下降趋势。它还将通过网络安全课程、研究和推广活动来教育研究生、本科生和K-12学生。将通过与国家妇女和信息技术中心、州长州立大学和芝加哥公立学校等伙伴结盟,加强妇女和少数群体的参与。与项目相关的数据、结果、出版物和工具将通过与该项目合作的研究实验室的网站提供:http://seclab.cs.stonybrook.edu/和http://sisl.lab.uic.edu/.This奖反映了美国国家科学基金会的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(3)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Extractor: Extracting Attack Behavior from Threat Reports
- DOI:10.1109/eurosp51992.2021.00046
- 发表时间:2021-04
- 期刊:
- 影响因子:0
- 作者:Kiavash Satvat;Rigel Gjomemo;V. Venkatakrishnan
- 通讯作者:Kiavash Satvat;Rigel Gjomemo;V. Venkatakrishnan
POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting
- DOI:10.1145/3319535.3363217
- 发表时间:2019-09
- 期刊:
- 影响因子:0
- 作者:Sadegh M. Milajerdi;Birhanu Eshete;Rigel Gjomemo;V. Venkatakrishnan
- 通讯作者:Sadegh M. Milajerdi;Birhanu Eshete;Rigel Gjomemo;V. Venkatakrishnan
OSTINATO: Cross-host Attack Correlation Through Attack Activity Similarity Detection
OSTINATO:通过攻击活动相似性检测进行跨主机攻击关联
- DOI:
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Ghosh, Sutanu K.;Satvat, Kiavash;Gjomemo, Rigel;Venkatakrishnan, V. N.:
- 通讯作者:Venkatakrishnan, V. N.:
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Venkat Venkatakrishnan其他文献
Venkat Venkatakrishnan的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Venkat Venkatakrishnan', 18)}}的其他基金
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1514472 - 财政年份:2015
- 资助金额:
$ 61.2万 - 项目类别:
Standard Grant
I-Corps: Automated Web Application Analysis
I-Corps:自动化 Web 应用程序分析
- 批准号:
1248717 - 财政年份:2012
- 资助金额:
$ 61.2万 - 项目类别:
Standard Grant
SFS Scholarships in Cybersecurity and Information Assurance
SFS 网络安全和信息保障奖学金
- 批准号:
1241685 - 财政年份:2012
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
IGERT: Electronic Security and Privacy: Technological, Human, Enterprise and Legal Considerations
IGERT:电子安全和隐私:技术、人力、企业和法律考虑因素
- 批准号:
1069311 - 财政年份:2011
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
- 批准号:
1065537 - 财政年份:2011
- 资助金额:
$ 61.2万 - 项目类别:
Standard Grant
A Series of Workshops on Security in Emerging Areas
新兴地区安全系列研讨会
- 批准号:
1139947 - 财政年份:2011
- 资助金额:
$ 61.2万 - 项目类别:
Standard Grant
CAREER: A Framework for Preventing Web-based Attacks
职业:防止基于 Web 的攻击的框架
- 批准号:
0845894 - 财政年份:2009
- 资助金额:
$ 61.2万 - 项目类别:
Standard Grant
TC: A U.S.-France Collaborative Symposium of Young Engineering Scientists (YESS 2009)
TC:美国-法国青年工程科学家合作研讨会(YESS 2009)
- 批准号:
0946768 - 财政年份:2009
- 资助金额:
$ 61.2万 - 项目类别:
Standard Grant
TC: Small: Keeping Jack in the Box: Confining the Role of Untrusted Inputs in Web Scenarios
TC:小:将 Jack 留在盒子里:限制不可信输入在 Web 场景中的作用
- 批准号:
0917229 - 财政年份:2009
- 资助金额:
$ 61.2万 - 项目类别:
Standard Grant
CT-ER : Runtime Techniques for protecting confidential data in large scale software
CT-ER:保护大型软件中机密数据的运行时技术
- 批准号:
0716584 - 财政年份:2007
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
相似国自然基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
- 批准号:82371765
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
锕系元素5f-in-core的GTH赝势和基组的开发
- 批准号:22303037
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:52 万元
- 项目类别:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
- 批准号:
- 批准年份:2020
- 资助金额:55 万元
- 项目类别:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
- 批准号:92053110
- 批准年份:2020
- 资助金额:70.0 万元
- 项目类别:重大研究计划
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
- 批准号:81902805
- 批准年份:2019
- 资助金额:20.5 万元
- 项目类别:青年科学基金项目
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
- 批准号:41973063
- 批准年份:2019
- 资助金额:65.0 万元
- 项目类别:面上项目
CORDEX-CORE区域气候模拟与预估研讨会
- 批准号:41981240365
- 批准年份:2019
- 资助金额:1.5 万元
- 项目类别:国际(地区)合作与交流项目
RBM38通过协助Pol-ε结合、招募core调控HBV复制
- 批准号:31900138
- 批准年份:2019
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Testing the causal influence of social media on well-being and animosity
SaTC:核心:中:测试社交媒体对幸福感和敌意的因果影响
- 批准号:
2334148 - 财政年份:2024
- 资助金额:
$ 61.2万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330941 - 财政年份:2024
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Increasing user autonomy and advertiser and platform responsibility in online advertising
SaTC:核心:中:增加在线广告中的用户自主权以及广告商和平台责任
- 批准号:
2318290 - 财政年份:2024
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Collaborative: Hardening Off-the-Shelf Software Against Side Channel Attacks
SaTC:核心:媒介:协作:强化现成软件以抵御侧通道攻击
- 批准号:
2425665 - 财政年份:2024
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Understanding the Impact of Privacy Interventions on the Online Publishing Ecosystem
协作研究:SaTC:核心:媒介:了解隐私干预对在线出版生态系统的影响
- 批准号:
2237329 - 财政年份:2023
- 资助金额:
$ 61.2万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Securing Interactions between Driver and Vehicle Using Batteries
合作研究:SaTC:核心:中:使用电池确保驾驶员和车辆之间的交互安全
- 批准号:
2245224 - 财政年份:2023
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Understanding and Combatting Impersonation Attacks and Data Leakage in Online Advertising
协作研究:SaTC:核心:媒介:理解和打击在线广告中的冒充攻击和数据泄露
- 批准号:
2247516 - 财政年份:2023
- 资助金额:
$ 61.2万 - 项目类别:
Continuing Grant