课题基金 / 基金详情

I-Corps: Translation potential of using provenance-based threat detection for improving cybersecurity

I-Corps: Translation potential of using provenance-based threat detection for improving cybersecurity
I-Corps:使用基于来源的威胁检测来提高网络安全的转化潜力
批准号:
2424261
负责人:
Adam Bates
金额:
$5.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-04-15 至 2025-03-31

项目摘要

项目成果

Adam Bates的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The broader impact of this I-Corps project is the development of technology for securing computer workstations and servers from attack. The approach based on the historical record that traces data from its original source to its current location (called data provenance analysis). Securing endpoint computers is a vital component of enterprise security. Current solutions adopt a strategy for detecting attacks by comparing endpoint activity to a set of detection rules that describe common attack behaviors. However, this is an error prone practice, leading to large volumes of false alerts while failing to detect sophisticated attacks. In addition, the maintenance requirements of investigating these false alerts pose a formidable challenge within smaller to medium-sized businesses (SMBs), which lack the necessary security resources and personnel. This impediment is even more visible within SMBs housing sensitive user data, where a security breach can have profound and enduring financial and societal consequences. This technology may be used to establish data provenance analysis as a more precise and practical means of detecting attacks on endpoints. In addition, this solution may save U.S. companies millions of dollars by thwarting attacks that could have otherwise resulted in the compromise of customer data.This I-Corps project utilizes experiential learning coupled with a first-hand investigation of the industry ecosystem to assess the translation potential of the technology. The solution is based on the development of analysis of data provenance to ensure cyber security. Data provenance techniques incrementally parse individual endpoint events (e.g., process executions and file accesses) into a causal dependency graph that describes the history of system execution. The graphical representation of endpoint activity highlights the relationships between objects, making it easier to identify suspicious activities. A key finding of this research is a method of overcoming the inherent architectural limitations in the machine learning models used to analyze data provenance graphs. Leveraging this method, a model was trained that comprehensively captures the typical behavior of programs by associating them with their full historical context. Attacks are detected by comparing suspicious programs to the models’ expectations of each program’s behavior, which is informed by the programs’ provenance. This approach significantly reduces the occurrence of false alerts when compared to current endpoint security solutions, while also eliminating the need for frequent system tuning such as the adding and removing of detection rules.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: Principled Foundations for the Design and Evaluation of Graph-Based Host Intrusion Detection Systems
CAREER: Scalable Information Flow Monitoring and Enforcement through Data Provenance Unification
CRII: SaTC: Transparent Capture and Aggregation of Secure Data Provenance for Smart Devices
海外基金