CAREER: Interpretable Provenance Analysis for Heterogeneous Systems at Scale
CAREER: Interpretable Provenance Analysis for Heterogeneous Systems at Scale
批准号:
2342250
负责人:
Shiqing Ma
金额:
$53.07万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-07-01 至 2028-06-30
中文摘要
网络犯罪事件的数量和现代攻击的复杂性正在增加,使取证分析更具挑战性。起源分析是取证分析任务的常见实践,记录历史系统执行事件并将其转换为事件之间依赖关系的因果图。调查人员可以从这些图表中识别攻击的根本原因和诱发的损害,并利用学到的知识进行攻击检测或安全执行。该项目的新颖之处是一个可扩展和可解释的出处收集软件,用于由尖端人工智能组件组成的异构系统。该项目的更广泛的意义和重要性是为推理现代复杂系统的不透明性奠定基础,并培养学生和安全专业人员的研究和安全分析技能。由于出处收集软件的实用性,所开发的技术提高了现代计算系统对网络攻击的弹性。该项目生成的攻击痕迹,包括标记和清理的痕迹,将支持网络安全和大数据分析等多个领域的进一步研究。具体来说,该项目通过设计一种新的系统架构来协调各个内核组件,从而开发一个可扩展的来源收集系统。它通过引入一种新的无损压缩方案来优化出处存储系统。在这些框架之上,该项目通过支持程序分析的语义标记和基于人工智能的行为分析,构建了可解释的起源分析和动态攻击检测方法。训练方法提供了从高度偏见和未标记的审计数据中学习的新能力,这些数据的规模超过了大多数现有的数据驱动应用程序。该项目团队还为新兴异构系统中的深度神经网络模块设计了新颖的因果关系分析机制。该技术提高了模型在攻击情况下的可解释性,特别是用于自动驾驶、身份识别和私人财产监视等关键任务的模型。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The number of cybercrime incidents and the complexity of modern attacks are increasing, making forensics analysis more challenging. Provenance analysis is a common practice for forensics analysis tasks that record historical system execution events and convert them into causal graphs following the dependencies among events. Investigators can identify attack root causes and induced damages from such graphs and leverage learned knowledge for attack detection or security enforcement. The project’s novelties are a scalable and interpretable provenance collection software for heterogeneous systems consisting of cutting-edge artificial intelligence components. The project's broader significance and importance are building the foundation for reasoning about the opaqueness of modern complex systems and training research and security analysis skills of students and security professionals. Due to the provenance collection software practicality, the developed techniques improve modern computing systems’ resilience to cyber-attacks. The attack traces generated by this project, including the labeled and cleansed ones, will support further research in multiple areas, such as cyber security and big-data analysis.Specifically, the project develops a scalable provenance collection system by designing a new system architecture that coordinates individual kernel components. It optimizes the provenance storage system by introducing a novel lossless compression schema. On top of these frameworks, the project builds interpretable provenance analysis and on-the-fly attack detection methods through program analysis-enabled semantic labeling and artificial intelligence-based behavior analysis. The training methods provide new capabilities in learning from the highly biased and unlabeled audit data that are at a scale exceeding most existing data-driven applications. The project team also devises novel causality analysis mechanisms for deep neural network modules in emerging heterogeneous systems. This technique improves model interpretability in the presence of an attack, especially for models used in critical missions such as auto-driving, identity recognition, and private property surveillance.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Interpretable Provenance Analysis for Heterogeneous Systems at Scale
-
批准号:2238847
-
项目类别:Continuing Grant
-
资助金额:$53.07万
-
财政年份:2023
-
负责人:Shiqing Ma
-
依托单位:
海外基金