CAREER: An Artificial Intelligence (AI)-enabled Analytics Perspective for Developing Proactive Cyber Threat Intelligence
CAREER: An Artificial Intelligence (AI)-enabled Analytics Perspective for Developing Proactive Cyber Threat Intelligence
批准号:
2338479
负责人:
Sagar Samtani
金额:
$60.46万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-07-01 至 2029-06-30
中文摘要
网络攻击继续给现代社会带来可怕的损失。越来越多的公司寻求整合有关新出现的威胁及其与其资产中漏洞的相关性的网络威胁情报(CTI)。然而,目前CTI分析师的大部分做法是被动的,即分析在攻击后手动检查利用(绕过漏洞并允许攻击者操纵网络资产的软件)。使用CTI的更积极主动的方法可能会防止许多网络攻击;特别是,诸如Dark Web黑客论坛之类的来源通常包括关于可能出现的利用趋势和攻击媒介的信号。然而,这些大型、国际化且不断发展的平台通常包含数百万篇帖子,这一规模使得传统的CTI分析变得令人望而却步、有限、容易出错和耗时。因此,该项目寻求开发基于文本分析和网络科学的人工智能(AI)分析技术,以识别新出现的趋势并将利用漏洞与漏洞联系起来。这项研究产生的模型和结果将被整合到网络安全专业学生和数据科学家的课程中,以帮助迅速培养一支训练有素的主动式人工智能CTI分析队伍。这个职业项目寻求发展两个主动型CTI研究。首先是一种新的历时图形转换器(DGT),通过改进平衡单词嵌入稳定性和捕获它们随时间变化的方法来检测和预测新出现的利用术语、语义和趋势。第二种是一种自我监督的神经信息检索方法,名为利用漏洞自我监督链接器,它以与CTI分析师的程序一致的方式将黑客利用与漏洞联系起来,并考虑到技术的配置、依赖和其他特征。这项研究的数据和方法将被整合到三个方面,以改善网络人工智能教育:(1)印第安纳大学网络安全人工智能课程的新课程,(2)资源,以增强NSF CyberCorps奖学金服务机构的网络安全课程,以及(3)由世界上最大的数据科学社区之一的开放数据科学会议为AI平台提供的主动CTI学习模块。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Cyber-attacks continue to exact a terrible toll on modern society. Increasingly, many firms seek to integrate cyber threat intelligence (CTI) about emerging threats and their relevance to vulnerabilities within their assets. However, much of the current CTI analyst practice is reactive, in which analysis manually examines exploits (software that circumvents vulnerabilities and allows an attacker to manipulate cyber-assets) after an attack. More proactive approaches to using CTI might prevent many cyber-attacks; in particular, sources such as Dark Web hacker forums often include signals about possible emerging exploit trends and attack vectors. However, these large, international, and ever-evolving platforms often contain millions of posts, a scale that makes conventional CTI analysis prohibitive, limited, error-prone, and time-consuming. Therefore, this project seeks to develop Artificial Intelligence (AI)-enabled analytics techniques based on text analysis and network science to identify emerging trends and to link exploits to vulnerabilities. The models and results produced from this research will be integrated into curricula for cybersecurity students and data scientists to help rapidly grow a well-trained workforce in proactive AI-enabled CTI analytics. This CAREER project seeks to develop two thrusts of proactive CTI research. The first is a novel Diachronic Graph Transformer (DGT) to detect and predict emerging exploit terms, semantics, and trends through advancing methods for balancing word embedding stability and capturing their shifts over time. The second is a self-supervised neural information retrieval method, entitled the Exploit-Vulnerability Self-Supervised Linker, that links hacker exploits to vulnerabilities in a manner consistent with CTI analysts' procedures and that accounts for a technology's configurations, dependencies, and other characteristics. The data and methods from this research will be integrated into three thrusts to improve cyber-AI education: (1) new lessons for an AI for Cybersecurity course at Indiana University, (2) resources to enhance the cybersecurity curricula of NSF CyberCorps Scholarship-for-Service institutions, and (3) proactive CTI learning modules for the AI+ platform offered by the Open Data Science Conference, one of the world's largest data science communities.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CRII: SaTC: Identifying Emerging Threats in the Online Hacker Community for Proactive Cyber Threat Intelligence: A Diachronic Graph Convolutional Autoencoder Framework
-
批准号:2041770
-
项目类别:Standard Grant
-
资助金额:$16.0万
-
财政年份:2020
-
负责人:Sagar Samtani
-
依托单位:
CRII: SaTC: Identifying Emerging Threats in the Online Hacker Community for Proactive Cyber Threat Intelligence: A Diachronic Graph Convolutional Autoencoder Framework
-
批准号:1850362
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2019
-
负责人:Sagar Samtani
-
依托单位:
海外基金