课题基金 / 基金详情

CICI: UCSS: Enhancing the Usability of Vulnerability Assessment Results for Open-Source Software Technologies in Scientific Cyberinfrastructure: A Deep Learning Perspective

CICI: UCSS: Enhancing the Usability of Vulnerability Assessment Results for Open-Source Software Technologies in Scientific Cyberinfrastructure: A Deep Learning Perspective
CICI:UCSS:增强科学网络基础设施中开源软件技术漏洞评估结果的可用性:深度学习视角
批准号:
2319325
负责人:
Hsinchun Chen
金额:
$60.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-08-01 至 2026-07-31

项目摘要

项目成果

Hsinchun Chen的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Federally funded scientific cyberinfrastructure (CI) has accelerated ground-breaking scientific discoveries, including black hole imaging, genome sequencing, vaccine discovery, and more. However, the open-source software (OSS) technologies that help facilitate these discoveries often contain thousands of vulnerabilities that, if exploited, could threaten irreplaceable scientific analysis. Since scientific CIs often lack the personnel to manage these vulnerabilities, they increasingly outsource their vulnerability management tasks to third-party Research & Education security providers such as OmniSOC. However, security analysts at these providers often face challenges managing the tens of thousands of vulnerabilities present in OSS assets at CIs. This project scans thousands of scientific CI OSS assets for vulnerabilities and employs novel Artificial Intelligence-enabled analytics to (1) manage OSS asset vulnerabilities in scientific CI and (2) link them to their remediation strategies. Vulnerability scan and analytics results are integrated into a novel Vulnerability Management System that allows security analysts search, sort, browse, and collaborate on vulnerability data and remediation strategies across scientific CIs.This project designs a novel Artificial Intelligence-enabled AZSecure Usable and Collaborative Security for Science Framework that scans for vulnerabilities in four major categories of open-source software (OSS) assets (virtual machines, containers, infrastructure-as-code, and GitHub) across two major NSF-funded scientific cyberinfrastructures (CIs): (1) CyVerse for life sciences and (2) Jetstream, NSF’s first Science and Engineering Cloud for NSF and NIH. The vulnerability scans support three sets of AI-enabled analytics research thrusts to enhance the usability of vulnerability scan results for OmniSOC’s security analysts. The first thrust aggregates OSS asset and vulnerability data into an embedding for vulnerability management tasks through multi-view learning incorporating a vulnerability severity weighting scheme and a novel combinatorial attention mechanism. The second thrust uses self-supervised learning and transformers to link vulnerability scans with remediation strategies by stacking multiple word embeddings and aligning vulnerability severity scores with a novel contrastive loss function. The final thrust develops a Vulnerability Management System that integrates scan results and enables analysts to operate the methods. Project execution includes roles for NSF CyberCorps Scholarship-for-Service graduate students from UArizona (NSA/DHS CD-, R, and CO-designated) and IU (NSA/DHS CD- and- R-designated). Findings are disseminated through academic and industry publications and integrated into the top-ranked MS in Cybersecurity programs at UArizona and IU.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
EAGER: SaTC-EDU: Artificial Intelligence and Cybersecurity Research and Education at Scale
  • 批准号:
    2038483
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.77万
  • 财政年份:
    2020
  • 负责人:
    Hsinchun Chen
  • 依托单位:
SaTC: CORE: Small: Cybersecurity Big Data Research for Hacker Communities: A Topic and Language Modeling Approach
  • 批准号:
    1936370
  • 项目类别:
    Standard Grant
  • 资助金额:
    $51.06万
  • 财政年份:
    2019
  • 负责人:
    Hsinchun Chen
  • 依托单位:
CICI: SSC: Proactive Cyber Threat Intelligence and Comprehensive Network Monitoring for Scientific Cyberinfrastructure: The AZSecure Framework
  • 批准号:
    1917117
  • 项目类别:
    Standard Grant
  • 资助金额:
    $99.8万
  • 财政年份:
    2019
  • 负责人:
    Hsinchun Chen
  • 依托单位:
Cybersecurity Scholarship-for-Service Renewal at The University of Arizona:The AZSecure SFS Program
  • 批准号:
    1921485
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $358.55万
  • 财政年份:
    2019
  • 负责人:
    Hsinchun Chen
  • 依托单位:
海外基金