CAREER: Interpretable Provenance Analysis for Heterogeneous Systems at Scale
CAREER: Interpretable Provenance Analysis for Heterogeneous Systems at Scale
批准号:
2342250
负责人:
Shiqing Ma
金额:
$53.07万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-07-01 至 2028-06-30
中文摘要
网络犯罪事件的数量和现代攻击的复杂性正在增加,这使得取证分析更具挑战性。来源分析是取证分析任务的一种常见做法,这些任务记录历史系统执行事件,并根据事件之间的依赖关系将其转换为因果关系图。调查人员可以从这些图表中识别攻击根本原因和导致的损害,并利用所学知识进行攻击检测或安全执行。该项目的新颖性是一个可扩展和可解释的来源收集软件,用于由尖端人工智能组件组成的不同系统。该项目更广泛的意义和重要性是为论证现代复杂系统的不透明性奠定基础,并培训学生和安全专业人员的研究和安全分析技能。由于来源收集软件的实用性,所开发的技术提高了现代计算系统对网络攻击的韧性。该项目生成的攻击痕迹,包括标记和清理后的攻击痕迹,将为网络安全和大数据分析等多个领域的进一步研究提供支持。具体地说,该项目通过设计一个新的系统架构来协调各个内核组件,开发了一个可扩展的来源收集系统。它通过引入一种新的无损压缩方案来优化起源存储系统。在这些框架的基础上,该项目通过启用程序分析的语义标签和基于人工智能的行为分析,构建了可解释的来源分析和即时攻击检测方法。培训方法提供了学习高度偏见和未加标签的审计数据的新能力,这些数据的规模超过了大多数现有的数据驱动应用程序。该项目团队还为新兴异质系统中的深层神经网络模块设计了新的因果分析机制。这项技术提高了模型在攻击存在时的可解释性,特别是对于自动驾驶、身份识别和私人财产监视等关键任务中使用的模型。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The number of cybercrime incidents and the complexity of modern attacks are increasing, making forensics analysis more challenging. Provenance analysis is a common practice for forensics analysis tasks that record historical system execution events and convert them into causal graphs following the dependencies among events. Investigators can identify attack root causes and induced damages from such graphs and leverage learned knowledge for attack detection or security enforcement. The project’s novelties are a scalable and interpretable provenance collection software for heterogeneous systems consisting of cutting-edge artificial intelligence components. The project's broader significance and importance are building the foundation for reasoning about the opaqueness of modern complex systems and training research and security analysis skills of students and security professionals. Due to the provenance collection software practicality, the developed techniques improve modern computing systems’ resilience to cyber-attacks. The attack traces generated by this project, including the labeled and cleansed ones, will support further research in multiple areas, such as cyber security and big-data analysis.Specifically, the project develops a scalable provenance collection system by designing a new system architecture that coordinates individual kernel components. It optimizes the provenance storage system by introducing a novel lossless compression schema. On top of these frameworks, the project builds interpretable provenance analysis and on-the-fly attack detection methods through program analysis-enabled semantic labeling and artificial intelligence-based behavior analysis. The training methods provide new capabilities in learning from the highly biased and unlabeled audit data that are at a scale exceeding most existing data-driven applications. The project team also devises novel causality analysis mechanisms for deep neural network modules in emerging heterogeneous systems. This technique improves model interpretability in the presence of an attack, especially for models used in critical missions such as auto-driving, identity recognition, and private property surveillance.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Interpretable Provenance Analysis for Heterogeneous Systems at Scale
-
批准号:2238847
-
项目类别:Continuing Grant
-
资助金额:$53.07万
-
财政年份:2023
-
负责人:Shiqing Ma
-
依托单位:
海外基金