NSF Convergence Accelerator Track - Track D - AI-Enabled, Privacy-Preserving Information Sharing for Securing Network Infrastructure
NSF Convergence Accelerator Track - Track D - AI-Enabled, Privacy-Preserving Information Sharing for Securing Network Infrastructure
批准号:
2040675
负责人:
Giulia Fanti
金额:
$96.8万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-09-15 至 2022-05-31
中文摘要
NSF融合加速器支持以使用为灵感、以团队为基础的多学科努力,以应对国家重要性的挑战,并将在不久的将来产生对社会有价值的成果。对企业网络的网络攻击对当今的企业运营构成了巨大的威胁。防御不断变化的威胁和正常用户流量既耗时又费力。为了应对这一挑战,许多部门正在努力采用人工智能和机器学习(AI/ML)模型来自动化安全事件检测和响应。然而,在实践中,支持AI/ML的工作流有两个障碍:(1)缺乏足够的数据来训练可靠的模型来检测新的攻击活动或模拟正常行为;(2)在短时间内对模型输出缺乏信心,导致在假阳性(即阻止合法用户)和假阴性(即错过攻击)之间进行不希望的权衡。理想情况下,共享数据将有助于解决这两个问题,然而,由于对消费者或企业隐私的担忧,这些信息很少被共享(如果有的话),而且在许多情况下共享的内容是匿名的,从而使数据失去价值。该项目将创建新的功能,用于共享有关安全事件的详细但保护隐私的信息,这些信息将极大地改变组织内部和组织之间的数据共享管道,并加速行业向人工智能驱动的安全工作流的过渡。拥有更好的人工智能驱动的网络安全工具,将在保护关键基础设施和所有行业的网络免受网络攻击方面产生巨大影响。该项目将采取跨学科的方法,涵盖AI/ML、安全、隐私、网络系统、法律和政策。它将解决隐私、效用和效率之间的基本权衡,主要有三个主要方面:(1)设计和实现新颖的生成性对抗网络(GAN),企业可以通过该网络对其网络数据进行建模,以便为其他企业的异常检测提供信息。这一重点将设计和实现新的GAN,并分析它们对隐私的影响以及其他人使用它们来检测恶意网络活动的效用。(2)设计和实施新的加密协议和系统工作流,高效地比较跨企业的假设(域名、IP子网、程序哈希等可疑标识),为策略部署提供信息。(3)对共享此类合成数据、ML模型和假设的影响进行新的法律和政策分析。通过解决这三个关键领域并吸引关键利益相关者参与,该项目开发的工具很有可能获得采用,并通过改善网络安全对国家具有巨大价值。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The NSF Convergence Accelerator supports use-inspired, team-based, multidisciplinary efforts that address challenges of national importance and will produce deliverables of value to society in the near future. Cyber attacks on enterprise networks pose a tremendous threat to business operations today. Defending against the ever-changing landscape of threats and normal user traffic is time-consuming and labor-intensive. To address this challenge, there is an ongoing effort across many sectors to adopt artificial intelligence and machine learning (AI/ML) models to automate security incident detection and response. In practice, however, there are two roadblocks to AI/ML-enabled workflows: (1) lack of sufficient data to train a reliable model to detect new attack campaigns or model normal behaviors; (2) lack of confidence in model outputs over a short timeframe, inducing undesirable tradeoffs between false positives (i.e., blocking legitimate users) and false negatives (i.e., missing attacks). Ideally, sharing data would help address both of these problems, however this information is rarely shared (if at all) due to concerns about consumer or business privacy, and what is shared in many cases is anonymized in such way that the data loses its value. This project will create new capabilities for sharing detailed yet privacy-preserving information about security incidents that will substantially alter the data-sharing pipeline, both within and across organizations and accelerate the industry transition to AI-driven security workflows. Having better AI-driven cybersecurity tools will have an enormous impact in protecting critical infrastructure and networks across all sectors from cybers attacks. This project will take an interdisciplinary approach spanning AI/ML, security, privacy, networked systems, law, and policy. It will tackle the fundamental tradeoffs among privacy, utility, and efficiency along three key thrusts: (1) design and implement novel generative adversarial networks (GANs) by which an enterprise can model its network data to inform anomaly detection by others. This thrust will design and implement novel GANs and analyze their privacy implications and their utility for use by others to detect malicious network activity. (2) Design and implement new cryptographic protocols and systems workflows for efficiently comparing hypotheses (suspicious identifiers, such as domain names, IP subnets, and program hashes) across enterprises to inform policy deployments. (3) Develop new legal and policy analyses on the implications of sharing such synthetic data, ML models, and hypotheses. By addressing these three critical areas and engaging key stakeholders, the tools developed by this project stand a high probably of gaining adoption and having tremendous value to the country by improving cybersecurity.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
--
发表时间:
2019-12
期刊:
ArXiv
影响因子:
--
作者:
[K. Wang;M. Reiter]
通讯作者:
K. Wang;M. Reiter
DOI:
--
发表时间:
2021-01
期刊:
影响因子:
--
作者:
[Todd P. Huster;Jeremy E. Cohen;Zinan Lin;Kevin S. Chan;Charles A. Kamhoua;Nandi O. Leslie;C. Chiang;Vyas Sekar]
通讯作者:
Todd P. Huster;Jeremy E. Cohen;Zinan Lin;Kevin S. Chan;Charles A. Kamhoua;Nandi O. Leslie;C. Chiang;Vyas Sekar
DOI:
10.48550/arxiv.2206.01349
发表时间:
2022-06
期刊:
影响因子:
--
作者:
[Zinan Lin;Vyas Sekar;G. Fanti]
通讯作者:
Zinan Lin;Vyas Sekar;G. Fanti
The Netivus Manifesto: making collaborative network management easier for the rest of us
Netivus 宣言:让我们其他人更轻松地进行协作网络管理
DOI:
--
发表时间:
2021
期刊:
ACM SIGCOMM Computer Communication Review
影响因子:
2.8
作者:
[Severini, Joseph, Mysore, Radhika Niranjan, Sekar, Vyas, Banerjee, Sujata, Reiter, Michael K.]
通讯作者:
Reiter, Michael K.
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
[K. Wang;M. Reiter]
通讯作者:
K. Wang;M. Reiter
共 6 条
CAREER: Theory and Practice of Privacy-Utility Tradeoffs in Enterprise Data Sharing
-
批准号:2338772
-
项目类别:Continuing Grant
-
资助金额:$59.73万
-
财政年份:2024
-
负责人:Giulia Fanti
-
依托单位:
Travel: Student Travel Grant for the 2023 ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems
-
批准号:2308412
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2023
-
负责人:Giulia Fanti
-
依托单位:
Collaborative Research: SaTC: CORE: Small: Accountability for Central Bank Digital Currency
-
批准号:2325477
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2023
-
负责人:Giulia Fanti
-
依托单位:
RINGS: Enabling Data-Driven Innovation for Next-Generation Networks Via Synthetic Data
-
批准号:2148359
-
项目类别:Continuing Grant
-
资助金额:$100.0万
-
财政年份:2022
-
负责人:Giulia Fanti
-
依托单位:
海外基金