SaTC: CORE: Small: An Attribute-based Insider Threat Mitigation Framework
SaTC: CORE: Small: An Attribute-based Insider Threat Mitigation Framework
批准号:
2406038
负责人:
Daniel Takabi
金额:
$44.2万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
已结题
起止时间:
2023-10-01 至 2024-08-31
中文摘要
防御试图滥用计算机特权的恶意内部人员是信息安全部门面临的最关键问题之一。这是因为造成的损害可能是灾难性的。尽管内部威胁越来越受到研究界的关注,但在解决信息基础设施保护的特定方面仍然存在重大挑战。该项目旨在开发一种创新的、可演示的方法,以减轻组织面临的内部威胁。该项目开发的新机制将大大提高保护包括私营和公共部门在内的企业的最新水平。它将提高一个组织抵御这些重要威胁的准备,并将减少组织受到这些威胁的负面影响并承受潜在的负面经济和社会影响的风险。该项目将涉及研究生和本科生,有助于加强教育和研究之间的关系。通过参与该项目的不同方面,学生将接受国家安全关键领域的培训,从而促进他们的职业生涯,并为他们的职业成长做出贡献。该项目开发了新的分析、设计技术和工具包,以更好地保护组织的关键资产免受内部威胁和未经授权的访问。访问控制系统是缓解内部威胁的基础,基于属性的访问控制(ABAC)是近年来出现的一种很有前途的模型。该项目开发了一个基于ABAC的综合框架,利用移动目标防御(MTD)和欺骗技术的组合来应对内部威胁挑战。这是通过系统地开发几个组件来实现的。首先是防御性欺骗的科学基础,包括欺骗建模和规划,以及为内部威胁预防生成一致和负担得起的欺骗计划的方法。第二种是利用移动目标防御技术,增加内部人员的成本和时间负担,通过主动改变ABAC系统配置来实现未经授权的访问。第三种是在ABAC中引入蜂蜜元素的概念,并将其与主动欺骗和动目标防御技术相结合。该框架将显著提高大型企业的安全性,以便在考虑系统安全需求和对策有效性的情况下,部署主动应对内部威胁的对策。概念验证原型将展示监控内部访问并执行相应授权政策以缓解内部威胁的能力。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Defending against a malicious insider who attempts to abuse his computer privileges is one of the most critical problems facing the information security segment. This is because the damage inflicted is potentially catastrophic. While the insider threat is of increasing interest in the research community, major challenges remain in addressing aspects specific to information infrastructure protection. This project aims to develop an innovative, demonstrable approach to mitigate insider threats to an organization. The new mechanisms developed in this project will substantially enhance the state-of-the-art in securing enterprises including private and public sectors. It will improve an organization's preparedness to thwart these important threats, and will reduce the risk for the organizations to be negatively influenced by these threats and endure potentially negative economic and societal impacts. The project will involve both graduate and undergraduate students, contributing to a strengthened relationship between education and research. By getting involved in different aspects of the project, students will be trained in a critical area of national security, thereby enhancing their careers and contributing to their professional growth. The project develops novel analysis, design techniques, and toolkits to better protect an organization's critical assets from insider threat and unauthorized access. Access control systems are fundamental to mitigating insider threats and attribute-based access control (ABAC) has emerged as a promising model in recent years. This project develops a comprehensive framework based on ABAC that utilizes a combination of moving target defense (MTD) and deception techniques to address insider threat challenges. This is achieved through the development of several components in a systematic way. The first is a scientific foundation for defensive deception that includes deception modeling and planning, and an approach to generate consistent and affordable deception plans for insider threat prevention. The second utilizes moving target defense techniques to increase the cost and time burden on the insider to achieve an unauthorized access by proactively changing ABAC system configurations. The third one introduces the notion of honey elements in ABAC, and integrates them with active deception and moving target defense techniques. The framework will result in a significant improvement in the security of the large-scale enterprises so that proactive countermeasures for insider threats could be deployed with consideration of the system security requirements, and effectiveness of countermeasures. The proof-of-concept prototype will demonstrate the ability to monitor insider access and enforce corresponding authorization policies to mitigate insider threats.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: EDU: Secure and Private Artificial Intelligence
-
批准号:2413856
-
项目类别:Continuing Grant
-
资助金额:$39.97万
-
财政年份:2023
-
负责人:Daniel Takabi
-
依托单位:
Building Cybersecurity Analytics Capacity in Big Data Era: Developing Hands-on Labs for Integrating Data Science into Cybersecurity Curriculum
-
批准号:2415022
-
项目类别:Standard Grant
-
资助金额:$38.34万
-
财政年份:2023
-
负责人:Daniel Takabi
-
依托单位:
CyberTraining: Implementation: Small: Building Future Research Workforce in Trustworthy Artificial Intelligence (AI)
-
批准号:2413654
-
项目类别:Standard Grant
-
资助金额:$49.92万
-
财政年份:2023
-
负责人:Daniel Takabi
-
依托单位:
SaTC: EDU: Secure and Private Artificial Intelligence
-
批准号:2054968
-
项目类别:Continuing Grant
-
资助金额:$39.97万
-
财政年份:2021
-
负责人:Daniel Takabi
-
依托单位:
CyberTraining: Implementation: Small: Building Future Research Workforce in Trustworthy Artificial Intelligence (AI)
-
批准号:2118083
-
项目类别:Standard Grant
-
资助金额:$49.92万
-
财政年份:2021
-
负责人:Daniel Takabi
-
依托单位:
Building Cybersecurity Analytics Capacity in Big Data Era: Developing Hands-on Labs for Integrating Data Science into Cybersecurity Curriculum
-
批准号:2020636
-
项目类别:Standard Grant
-
资助金额:$38.34万
-
财政年份:2020
-
负责人:Daniel Takabi
-
依托单位:
NSF Student Travel Grant for 2019 ACM Conference on Computer and Communications Security (ACM CCS)
-
批准号:1932911
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2019
-
负责人:Daniel Takabi
-
依托单位:
NSF Student Travel Grant for 2019 ACM Conference on Computer and Communications Security (ACM CCS)
-
批准号:2001093
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2019
-
负责人:Daniel Takabi
-
依托单位:
SaTC: CORE: Small: An Attribute-based Insider Threat Mitigation Framework
-
批准号:2006329
-
项目类别:Standard Grant
-
资助金额:$44.2万
-
财政年份:2019
-
负责人:Daniel Takabi
-
依托单位:
NSF Student Travel Grant for 2018 ACM Conference on Computer and Communications Security (ACM CCS)
-
批准号:1837755
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2018
-
负责人:Daniel Takabi
-
依托单位:
SaTC: CORE: Small: An Attribute-based Insider Threat Mitigation Framework
-
批准号:1816853
-
项目类别:Standard Grant
-
资助金额:$51.6万
-
财政年份:2018
-
负责人:Daniel Takabi
-
依托单位:
Building Cybersecurity Analytics Capacity in Big Data Era: Developing Hands-on Labs for Integrating Data Science into Cybersecurity Curriculum
-
批准号:1820666
-
项目类别:Standard Grant
-
资助金额:$49.96万
-
财政年份:2018
-
负责人:Daniel Takabi
-
依托单位:
NSF Student Travel Grant for 2017 ACM Conference on Computer and Communications Security (ACM CCS)
-
批准号:1744868
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2017
-
负责人:Daniel Takabi
-
依托单位:
Student Travel Grant for ACM Conference on Computer and Communications Security (CCS) 2016
-
批准号:1607692
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2016
-
负责人:Daniel Takabi
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: