I-Corps: Automated Software Security Vulnerability and Patch Management
I-Corps:自动化软件安全漏洞和补丁管理
基本信息
- 批准号:2139458
- 负责人:
- 金额:$ 5万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-07-15 至 2023-06-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The broader impact/commercial potential of this I-Corps project is to decrease the vulnerability and improve the patch management practices in the electric power sector as well as many other critical infrastructure sectors such as oil and natural gas, healthcare, and manufacturing. The project may bring automation and optimization to cybersecurity operations that now often rely heavily on manual processes. The project will enhance the cybersecurity of the nation's critical infrastructures by performing more timely and more effective risk assessment and vulnerability mitigation. Through automated analysis and decision-making, the technology also seeks to reduce the cost associated with cybersecurity operations, addressing a pain point faced by many organizations in critical infrastructure sectors. The technology is particularly beneficial to small- and medium-sized organizations that often have limited cybersecurity personnel and resources to keep pace with the large number of potential cybersecurity vulnerabilities.This I-Corps project will explore the feasibility of commercializing an automated vulnerability and patch management technology that leverages recent advances in artificial intelligence to automate and optimize vulnerability analysis and decision-making. This technology's novelty includes: 1) a method for identifying the vulnerabilities applicable to given assets in an organization; 2) methods for assessing the risk of vulnerabilities; 3) a method to predict and recommend risk-aware remediation actions for vulnerabilities; 4) a method to identify potential strategies for mitigating vulnerabilities when patching is unavailable; and 5) a method for optimal scheduling of vulnerability mitigation actions to minimize security risks. The research addresses several key limitations of current solutions and practice, such as the high cost, long delay, and high risk rooted in manual operations. The project also addresses coarse granularity of risk assessment and the largely unguided or poorly guided mitigation action scheduling. Preliminary research results show that the technology may reduce the remediation decision-making time of the current practice from weeks or months to seconds.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
这个I-Corps项目的更广泛的影响/商业潜力是减少脆弱性,改善电力部门以及许多其他关键基础设施部门(如石油和天然气,医疗保健和制造业)的补丁管理实践。 该项目可能会为网络安全操作带来自动化和优化,这些操作现在通常严重依赖手动流程。 该项目将通过进行更及时和更有效的风险评估和脆弱性缓解,加强国家重要基础设施的网络安全。通过自动化分析和决策,该技术还寻求降低与网络安全运营相关的成本,解决关键基础设施领域许多组织面临的痛点。该技术特别有利于中小型组织,这些组织通常只有有限的网络安全人员和资源来应对大量潜在的网络安全漏洞。I-Corps项目将探索将自动漏洞和补丁管理技术商业化的可行性,该技术利用人工智能的最新进展来自动化和优化漏洞分析和决策。该技术的新奇包括:1)用于识别适用于组织中给定资产的漏洞的方法; 2)用于评估漏洞风险的方法; 3)用于预测和推荐针对漏洞的风险感知补救措施的方法; 4)用于识别在修补不可用时用于减轻漏洞的潜在策略的方法;以及5)用于最优调度脆弱性缓解动作以最小化安全风险的方法。该研究解决了当前解决方案和实践的几个关键限制,例如高成本,长延迟和高风险,根源于手动操作。 该项目还解决了风险评估的粗粒度问题,以及在很大程度上没有指导或指导不力的减缓行动时间安排问题。初步研究结果表明,该技术可以将当前实践的补救决策时间从数周或数月缩短到数秒。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Qinghua Li其他文献
Production of the antifungal biopesticide physcion through the combination of microbial fermentation and chemical post-treatment
微生物发酵与化学后处理相结合生产抗真菌生物农药大黄素甲醚
- DOI:
10.1186/s40643-023-00625-8 - 发表时间:
2023 - 期刊:
- 影响因子:4.6
- 作者:
Z. Zhuang;Xueqing Zhong;Qinghua Li;Tian Liu;Q. Yang;Guo;Qing;Qunfei Zhao;Wen Liu - 通讯作者:
Wen Liu
Small bandgap naphthalene diimide copolymers for efficient inorganic–organic hybrid solar cells
用于高效无机-有机混合太阳能电池的小带隙萘二酰亚胺共聚物
- DOI:
10.1039/c4ra12188k - 发表时间:
2015 - 期刊:
- 影响因子:3.9
- 作者:
Yuancheng Qin;Xing Li;Weifu Sun;Xubiao Luo;Mingjun Li;Xinghua Tang;Xiao Jin;Yu Xie;Xinhua Ouyang;Qinghua Li - 通讯作者:
Qinghua Li
Reduced energy offset via substitutional doping for efficient organic/inorganic hybrid solar cells
通过高效有机/无机混合太阳能电池的替代掺杂减少能量抵消
- DOI:
10.1364/oe.23.00a444 - 发表时间:
2015 - 期刊:
- 影响因子:3.8
- 作者:
Xiao Jin;Weifu Sun;Qin Zhang;Kelian Ruan;Yuanyuan Cheng;Haijiao Xu;Zhongyuan Xu;Qinghua Li - 通讯作者:
Qinghua Li
Full-ionic liquid gel electrolytes: Enhanced photovoltaic performances in dye-sensitized solar cells
全离子液体凝胶电解质:增强染料敏化太阳能电池的光伏性能
- DOI:
10.1016/j.jpowsour.2014.04.095 - 发表时间:
2014-10 - 期刊:
- 影响因子:9.2
- 作者:
Qinghua Li;Qunwei Tang;Benlin He;Peizhi Yang - 通讯作者:
Peizhi Yang
Modeling heat transfer during friction stir welding using a meshless particle method
使用无网格粒子方法模拟搅拌摩擦焊过程中的传热
- DOI:
10.1016/j.ijheatmasstransfer.2016.08.047 - 发表时间:
2017 - 期刊:
- 影响因子:5.2
- 作者:
Yihua Xiao;Haifei Zhan;Yuantong Gu;Qinghua Li - 通讯作者:
Qinghua Li
Qinghua Li的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Qinghua Li', 18)}}的其他基金
IUCRC Phase I: The University of Arkansas: Center for Infrastructure Trustworthiness in Energy Systems (CITES)
IUCRC 第一阶段:阿肯色大学:能源系统基础设施可信度中心 (CITES)
- 批准号:
2113903 - 财政年份:2021
- 资助金额:
$ 5万 - 项目类别:
Continuing Grant
Planning IUCRC at The University of Arkansas: Center for Infrastructure Trustworthiness in Energy Systems (CITES)
阿肯色大学规划 IUCCRC:能源系统基础设施可信度中心 (CITES)
- 批准号:
1822152 - 财政年份:2018
- 资助金额:
$ 5万 - 项目类别:
Standard Grant
CAREER: Towards Automated Security Vulnerability and Patch Management for Power Grid Operations
职业:实现电网运营的自动化安全漏洞和补丁管理
- 批准号:
1751255 - 财政年份:2018
- 资助金额:
$ 5万 - 项目类别:
Continuing Grant
相似海外基金
TELEMETRY - Trustworthy mEthodologies, open knowLedgE & autoMated tools for sEcurity Testing of IoT software, haRdware & ecosYstems
遥测 - 值得信赖的方法,开放的知识
- 批准号:
10087006 - 财政年份:2023
- 资助金额:
$ 5万 - 项目类别:
EU-Funded
Round 6 Cont. Development and Application of Certification Metrology for Automated Software-based Spatial Target Characterisation
第 6 轮(续)
- 批准号:
10061924 - 财政年份:2023
- 资助金额:
$ 5万 - 项目类别:
Collaborative R&D
23-016713 NHLBI, ITAC REQUIRES RENEWAL OF ITS INFRASTRUCTURE AS CODE (IAC) SOFTWARE SOLUTION, CHEF, IN ORDER TO SUPPORT NHLBI'S MISSION NEEDS FOR THE AUTOMATED CONFIGURATION AND MANAGEMENT OF NHLBI S
23-016713 NHLBI、ITAC 要求更新其基础设施作为代码 (IAC) 软件解决方案、CHEF,以支持 NHLBI 对 NHLBI S 的自动化配置和管理的任务需求
- 批准号:
10974181 - 财政年份:2023
- 资助金额:
$ 5万 - 项目类别:
Automated Testing of Software Systems
软件系统的自动化测试
- 批准号:
CRC-2018-00051 - 财政年份:2022
- 资助金额:
$ 5万 - 项目类别:
Canada Research Chairs
Systematic and Automated Software Migration via Model-Driven Engineering
通过模型驱动工程实现系统化、自动化的软件迁移
- 批准号:
RGPIN-2020-05713 - 财政年份:2022
- 资助金额:
$ 5万 - 项目类别:
Discovery Grants Program - Individual
Fully Automated Software Logging
全自动软件记录
- 批准号:
RGPIN-2018-04932 - 财政年份:2022
- 资助金额:
$ 5万 - 项目类别:
Discovery Grants Program - Individual
Enhancing Automated Software Evolution via Building and Utilizing Large-Scale Software Evolution Corpora
通过构建和利用大规模软件演进语料库增强自动化软件演进
- 批准号:
22H03567 - 财政年份:2022
- 资助金额:
$ 5万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
SHF: Medium: Automated Software Engineering Techniques for Improving the Accessibility of Software
SHF:中:用于提高软件可访问性的自动化软件工程技术
- 批准号:
2211790 - 财政年份:2022
- 资助金额:
$ 5万 - 项目类别:
Continuing Grant
Software for automated diagnosis of upper gastro-intestinal examination with contrast media
使用造影剂进行上消化道检查自动诊断的软件
- 批准号:
22K07728 - 财政年份:2022
- 资助金额:
$ 5万 - 项目类别:
Grant-in-Aid for Scientific Research (C)