SaTC: CORE: Small: Scalable Cyber Attack Investigation using Declarative Queriesand Interrogative Analysis
SaTC: CORE: Small: Scalable Cyber Attack Investigation using Declarative Queriesand Interrogative Analysis
批准号:
2028748
负责人:
Xusheng Xiao
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2024-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Recent cyber-attacks that exploit multiple vulnerabilities plague even the most protected companies. This has led to the solutions that ubiquitously monitor system activities as a series of system events, and apply causality analysis to reveal the attack steps through reconstructing the events and their dependencies on the attack as dependency graphs. Nevertheless, existing techniques mainly exploit event time to identify dependencies. This will include many less-important dependencies brought by irrelevant system activities. Moreover, these techniques cannot easily incorporate expert knowledge from security analysts due to limited extensibility, and provide little support to engage security analysts to actively explore the dependencies. The project is expected to make a major positive impact on system security by enhancing attack investigation using system audit logs, and provide contextual information to help intrusion detection systems better prioritize alerts. The project actively involves students from minority and underrepresented groups for research and training experiences. The goal of this proposal is to develop a general query framework to express and extract contextual attack information, by constructing small graphs of attack-relevant events from system audit logs. The project is focused on the following research tasks: (1) build a general infrastructure that computes discriminative weights for dependencies based on various properties of system events to identify attack-relevant events and entry points for attacks; (2) develop a declarative graph query language that provides specialized language constructs to express various formats of causality analysis; (3) devise a scalable interrogative analysis framework that can automatically clarify causality analysis by tracking expressive causal structures for both verified and hypothetical scenarios, enabled by new ``Why'' and ``What-if'' semantics. This project will advance the state of the art in revealing attack provenance from complex systems, on engaging security analysts to interactive and explainable security analytical pipelines, and to gain better understanding of the fundamental and practical challenges for building an effective attack investigation system.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1109/sp46214.2022.9833632
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Zhiqiang Xu;Pengcheng Fang;Changlin Liu;Xusheng Xiao;Yu Wen;Dan Meng]
通讯作者:
Zhiqiang Xu;Pengcheng Fang;Changlin Liu;Xusheng Xiao;Yu Wen;Dan Meng
Back-Propagating System Dependency Impact for Attack Investigation
攻击调查的反向传播系统依赖性影响
DOI:
--
发表时间:
2022
期刊:
USENIX Security Symposium
影响因子:
--
作者:
[Fang, Pengcheng, Gao, Peng, Liu, Changlin, Ayday, Erman, Jee, Kangkook, Wang, Ting, Ye, Yanfang, Liu, Zhuotao, Xiao, Xusheng]
通讯作者:
Xiao, Xusheng
CAREER: Enhancing Mobile Application Security through Contextual Integrity and User Awareness
-
批准号:2318483
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2023
-
负责人:Xusheng Xiao
-
依托单位:
Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis
-
批准号:2221842
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2022
-
负责人:Xusheng Xiao
-
依托单位:
Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis
-
批准号:2318486
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2022
-
负责人:Xusheng Xiao
-
依托单位:
CAREER: Enhancing Mobile Application Security through Contextual Integrity and User Awareness
-
批准号:2046953
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2021
-
负责人:Xusheng Xiao
-
依托单位:
CRII: SaTC: Enhancing Mobile App Security by Detecting Icon-Behavior Contradiction
-
批准号:1755772
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2018
-
负责人:Xusheng Xiao
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: