Leveraging the Multi-Stakeholder Nature of Cyber Security
利用网络安全的多利益相关者性质
基本信息
- 批准号:EP/P011918/1
- 负责人:
- 金额:$ 98.17万
- 依托单位:
- 依托单位国家:英国
- 项目类别:Research Grant
- 财政年份:2017
- 资助国家:英国
- 起止时间:2017 至 无数据
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Cyber Security (CyS) is a challenging, distributed, multi-stakeholder problem. It is distributed in the sense that the expertise to comprehensively assess the level of security of a given IT system is commonly not all available in one location; e.g. detail on the IT components within a company is available within that company, while detail on operating system software vulnerability may be available to the OS manufacturer and further expert insight may be available to public security agencies, such as CESG. It is a multi-stakeholder problem because a number of human stakeholders, from IT designers to users with varying levels of expertise, need to effectively communicate and work together in order to deliver systems with an appropriate level of CyS assurance.This interdisciplinary project brings together leading academic experts from the University of Nottingham, UK and Carnegie Mellon University, USA, with a strongly integrated project partner: CESG - the UK's National Technical Authority for Information Assurance. The project is designed to leverage the distributed, multiple human stakeholder nature of CyS by developing a novel framework with the necessary scientific underpinning to improve user access to user-tailored CyS information, operationalised as a cutting-edge, data-driven Online CYber Security decision support System (OCYSS). This approach id designed to directly address an acute shortage of availability and access to highly qualified CyS experts by both small-to-large scale users from government to industry. The role of OCYSS is to effectively and efficiently integrate expert and user inputs, capturing commonly uncertain vulnerability levels of individual components as well as vulnerabilities arising from the interaction/combination of these components, to efficiently deliver appropriate, balanced, informed and up-to-date threat analysis and CyS decision support to users. Importantly, the OCYSS framework:- Addresses the limited availability of CyS experts by comprehensively capturing and aggregating their insight and expertise to assess the vulnerability, including associated levels of uncertainty, of individual system components (e.g. intrusion detection, encryption) and their interactions (e.g. SSL 3.0 and weak password). This information is captured centrally by OCYSS and updated regularly. - Avoids delays in threat analysis and potential mitigation by providing a direct pathway for newly discovered component vulnerabilities & component interaction vulnerabilities (and associated uncertainty) to be rapidly put forward, incl. by manufacturers such as Oracle and third party organisations such as Symantec.- Is designed to deliver user-tailored, comprehensive and up-to-date threat analysis and decision support which is continuously updated as new information becomes available. OCYSS two-stage outputs capture uncertainty in A) the threat analysis inputs (e.g. uncertainty around a component vulnerability over time and by different experts) and B) in intuitive benefit-cost analysis on threat mitigation in response to asset ranking by users (e.g. a low value asset may not warrant a high investment to address a low threat).Going beyond the scope of a standard research project, this project is designed to not only deliver cutting-edge science, developing key advances in data science and HCI, but to also deliver a real-world, open source prototype of the OCYSS framework. This enables the project to conduct an exceptional level of evaluation and tailoring to real-world CyS challenges, including the deployment of OCYSS in real-world contexts such as government departments advised by CESG. Further, through this approach, the project is able to deliver both open source algorithms and a substantial open-source software platform prototype, facilitating the academic reproduction of results, as well as substantially boosting the potential of commercial up-take of the project outcomes.
网络安全(CyS)是一个具有挑战性的,分布式的,多利益相关者的问题。它是分布式的,因为全面评估给定IT系统安全级别的专业知识通常不是在一个位置都可用;例如,公司内IT组件的详细信息在该公司内可用,而操作系统软件漏洞的详细信息可能提供给操作系统制造商,进一步的专家见解可能提供给公共安全机构,如CESG。这是一个多利益相关者的问题,因为许多人类利益相关者,从IT设计人员到具有不同专业知识水平的用户,需要有效地沟通和合作,以提供具有适当水平CyS保证的系统。这个跨学科项目汇集了来自英国诺丁汉大学和美国卡内基梅隆大学的领先学术专家,以及一个强大的综合项目合作伙伴:CESG -英国国家信息保障技术管理局。该项目旨在通过开发一个具有必要科学基础的新型框架来利用CyS的分布式,多人利益相关者的性质,以改善用户对用户定制的CyS信息的访问,作为一个尖端的,数据驱动的在线网络安全决策支持系统(OCYSS)。这种方法旨在直接解决从政府到行业的小型到大型用户对高素质CyS专家的可用性和访问的严重短缺。OCYSS的作用是有效和高效地整合专家和用户的输入,捕获单个组件的通常不确定的漏洞级别以及这些组件的相互作用/组合产生的漏洞,以有效地向用户提供适当,平衡,知情和最新的威胁分析和CyS决策支持。重要的是,OCYSS框架:-通过全面捕获和聚合CyS专家的洞察力和专业知识来评估脆弱性,包括各个系统组件(例如入侵检测,加密)及其交互(例如SSL 3.0和弱密码)的相关不确定性水平,从而消除CyS专家的有限可用性。这些信息由OCYSS集中收集,并定期更新。- 通过为新发现的组件漏洞和组件交互漏洞(以及相关的不确定性)提供直接途径,避免威胁分析和潜在缓解的延迟。由Oracle等制造商和赛门铁克等第三方组织提供。旨在提供用户定制的、全面的、最新的威胁分析和决策支持,并随着新信息的出现而不断更新。OCYSS两阶段输出捕获A)威胁分析输入中的不确定性(例如,随着时间的推移和不同专家对组件漏洞的不确定性)和B)响应于用户的资产排名,对威胁缓解进行直观的收益-成本分析(例如,低价值资产可能不值得为解决低威胁而进行高投资)。超出标准研究项目的范围,该项目不仅旨在提供尖端科学,开发数据科学和HCI的关键进展,而且还提供OCYSS框架的真实世界,开源原型。这使该项目能够针对现实世界的CyS挑战进行卓越的评估和定制,包括在现实世界的环境中部署OCYSS,例如由CESG建议的政府部门。此外,通过这种方法,该项目能够提供开源算法和大量开源软件平台原型,促进学术成果的复制,并大大提高项目成果的商业吸收潜力。
项目成果
期刊论文数量(10)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Responsible research and innovation in practice: Driving both the 'How' and the 'What' to research
实践中负责任的研究和创新:推动研究“如何”和“什么”
- DOI:10.1016/j.jrt.2022.100042
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Chen J
- 通讯作者:Chen J
Do People Prefer to Give Interval-Valued or Point Estimates and Why?
人们更喜欢给出区间值估计还是点估计?为什么?
- DOI:10.1109/fuzz45933.2021.9494507
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Ellerby Z
- 通讯作者:Ellerby Z
Insights from interval-valued ratings of consumer products-a DECSYS appraisal
消费产品区间值评级的见解——DECSYS 评估
- DOI:10.1109/fuzz48607.2020.9177634
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Ellerby Z
- 通讯作者:Ellerby Z
Extension of Restricted Equivalence Functions and Similarity Measures for Type-2 Fuzzy Sets
- DOI:10.1109/tfuzz.2021.3136349
- 发表时间:2022-09
- 期刊:
- 影响因子:11.9
- 作者:Laura De Miguel;R. Santiago;Christian Wagner;J. Garibaldi;Z. Takác̆;A.F. Roldan Lopez de Hierro;H. Bustince
- 通讯作者:Laura De Miguel;R. Santiago;Christian Wagner;J. Garibaldi;Z. Takác̆;A.F. Roldan Lopez de Hierro;H. Bustince
DECSYS – Discrete and Ellipse-based response Capture SYStem
DECSYS – 离散和基于椭圆的响应捕获系统
- DOI:10.1109/fuzz-ieee.2019.8858996
- 发表时间:2019
- 期刊:
- 影响因子:0
- 作者:Zack Ellerby;Josie McCulloch;J. Young;Christian Wagner
- 通讯作者:Christian Wagner
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Christian Wagner其他文献
Towards data-driven environmental planning and policy design-leveraging fuzzy logic to operationalize a planning framework
迈向数据驱动的环境规划和政策设计——利用模糊逻辑来实施规划框架
- DOI:
10.1109/fuzz-ieee.2014.6891783 - 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Amir Pourabdollah;Christian Wagner;Simon Miller;Michael Smith;K. Wallace - 通讯作者:
K. Wallace
An approach for the generation and adaptation of zSlices based general type-2 fuzzy sets from interval type-2 fuzzy sets to model agreement with application to Intelligent Environments
一种基于 zSlices 的通用 2 类模糊集的生成和适应方法,从区间 2 类模糊集到智能环境应用的模型协议
- DOI:
- 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
Christian Wagner;H. Hagras - 通讯作者:
H. Hagras
The WHO-5 well-being questionnaire in type 1 diabetes: screening for depression in pediatric and young adult subjects
WHO-5 1 型糖尿病健康问卷:儿科和青年受试者抑郁症筛查
- DOI:
- 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
S. Tittel;B. Kulzer;P. Warschburger;Ulrich Merz;A. Galler;Christian Wagner;M. Plaumann;E. Siegel;R. Holl - 通讯作者:
R. Holl
The interplay of landscape composition and configuration: new pathways to manage 1 functional biodiversity and agro-ecosystem services across Europe
景观组成和配置的相互作用:管理欧洲功能性生物多样性和农业生态系统服务的新途径
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Emily A. Martin;M. Dainese;Y. Clough;A. Báldi;R. Bommarco;V. Gagic;M. Garratt;A. Holzschuh;D. Kleijn;;Hostyánszki;Lorenzo Marini;S. Potts;Henrik G. Smith;D. A. Hassan;Matthias;Albrecht;Georg K. S. Andersson;J. Asís;S. Aviron;M. Balzan;Laura Baños;I. Bartomeus;P. Batáry;F. Burel;;López;E. D. Concepción;Valérie Coudrain;Juliana Dänhardt;Mario Díaz;Diekötter;C. Dormann;R. Duflot;M. Entling;N. Farwig;Christina Fischer;Thomas Frank;L. Garibaldi;John Hermann;Felix Herzog;Diego J. Inclán;K. Jacot;F. Jauker;P. Jeanneret;Marina Kaiser;Jochen;Krauss;V. L. Féon;Jon Marshall;A. Moonen;Gerardo Moreno;Verena Riedinger;M. Rundlöf;A. Rusch;J. Scheper;Gudrun Schneider;Christof Schüepp;S. Stutz;L. Sutter;Giovanni Tamburini;Carsten Thies;José;Tormos;T. Tscharntke;Matthias Tschumi;D. Uzman;Christian Wagner;Muhammad Zubair;I. Steffan‐Dewenter - 通讯作者:
I. Steffan‐Dewenter
Expert systems and creativity
专家系统和创造力
- DOI:
10.1007/978-3-642-86679-1_10 - 发表时间:
1987 - 期刊:
- 影响因子:0
- 作者:
K. MacCrimmon;Christian Wagner - 通讯作者:
Christian Wagner
Christian Wagner的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Christian Wagner', 18)}}的其他基金
SBE-UKRI:A Novel Theory of Ordered Judgment Processes
SBE-UKRI:有序判断过程的新颖理论
- 批准号:
ES/Z000084/1 - 财政年份:2024
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Digital Catapult Fellowship Programme
数字弹射器奖学金计划
- 批准号:
EP/M029263/1 - 财政年份:2015
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Towards managing risk from climate change through comprehensive, inclusive and resilient UK infrastructure planning
通过全面、包容和有弹性的英国基础设施规划来管理气候变化风险
- 批准号:
NE/M008401/1 - 财政年份:2014
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Towards Data-Driven Environmental Policy Design
迈向数据驱动的环境政策设计
- 批准号:
EP/K012479/1 - 财政年份:2013
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
Automotive 2020 Scholarship Program
汽车2020年奖学金计划
- 批准号:
0220554 - 财政年份:2003
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
Improving Manufacturing with Artificial Intelligence Techniques
利用人工智能技术改进制造
- 批准号:
9251110 - 财政年份:1992
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
On the Development of Alternatives: A Human - Computer System
论替代方案的开发:人机系统
- 批准号:
9016305 - 财政年份:1991
- 资助金额:
$ 98.17万 - 项目类别:
Continuing Grant
相似国自然基金
基于Multi-Pass Cell的高功率皮秒激光脉冲非线性压缩关键技术研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
Multi-decadeurbansubsidencemonitoringwithmulti-temporaryPStechnique
- 批准号:
- 批准年份:2022
- 资助金额:80 万元
- 项目类别:
High-precision force-reflected bilateral teleoperation of multi-DOF hydraulic robotic manipulators
- 批准号:52111530069
- 批准年份:2021
- 资助金额:10 万元
- 项目类别:国际(地区)合作与交流项目
基于8色荧光标记的Multi-InDel复合检测体系在降解混合检材鉴定的应用研究
- 批准号:
- 批准年份:2021
- 资助金额:30 万元
- 项目类别:青年科学基金项目
大地电磁强噪音压制的Multi-RRMC技术及其在青藏高原东南缘-印支块体地壳流追踪中的应用
- 批准号:
- 批准年份:2021
- 资助金额:15 万元
- 项目类别:
大规模非确定图数据分析及其Multi-Accelerator并行系统架构研究
- 批准号:62002350
- 批准年份:2020
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
3D multi-parameters CEST联合DKI对椎间盘退变机制中微环境微结构改变的定量研究
- 批准号:82001782
- 批准年份:2020
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
高速Multi-bit/cycle SAR ADC性能优化理论研究
- 批准号:62004023
- 批准年份:2020
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
基于multi-SNP标记及不拆分策略的复杂混合样本身份溯源研究
- 批准号:
- 批准年份:2020
- 资助金额:56 万元
- 项目类别:面上项目
大地电磁强噪音压制的Multi-RRMC技术及其在青藏高原东南缘—印支块体地壳流追踪中的应用
- 批准号:
- 批准年份:2020
- 资助金额:万元
- 项目类别:国际(地区)合作与交流项目
相似海外基金
Multi-Stakeholder Determinants of Medicare Diabetes Prevention Program Implementation and Participation
医疗保险糖尿病预防计划实施和参与的多利益相关者决定因素
- 批准号:
10578862 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
A Value-Driven Multi-Sector Stakeholder Decision-Making Framework to Support Disaster Resilient Communities
支持抗灾社区的价值驱动的多部门利益相关者决策框架
- 批准号:
2325467 - 财政年份:2023
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
Quality Indicators for Transition from Paediatric to Adult Care for Youth with Chronic Physical, Developmental, and Mental Health Conditions: A National Consensus-Building Multi-stakeholder Initiative
患有慢性身体、发育和心理健康问题的青少年从儿科向成人护理过渡的质量指标:一项建立全国共识的多方利益相关者倡议
- 批准号:
460950 - 财政年份:2022
- 资助金额:
$ 98.17万 - 项目类别:
Operating Grants
'Building Back Better Together': A Multi-stakeholder Approach to Address the Healthcare Workforce Crisis and Promote Healthcare Transformation
“共同重建更好的家园”:解决医疗保健劳动力危机和促进医疗保健转型的多利益相关者方法
- 批准号:
475175 - 财政年份:2022
- 资助金额:
$ 98.17万 - 项目类别:
Operating Grants
Tackling health disparities through social innovation: a multi-stakeholder coalition for inclusive health in Brent, London
通过社会创新解决健康差距:伦敦布伦特的包容性健康多利益相关者联盟
- 批准号:
AH/X005984/1 - 财政年份:2022
- 资助金额:
$ 98.17万 - 项目类别:
Research Grant
GOALI: Coordination of Multi-Stakeholder Process Networks in a Highly Electrified Chemical Industry
目标:在高度电气化的化工行业中协调多利益相关者流程网络
- 批准号:
2215526 - 财政年份:2022
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
Collaborative Research: RI: III: SHF: Small: Multi-Stakeholder Decision Making: Qualitative Preference Languages, Interactive Reasoning, and Explanation
协作研究:RI:III:SHF:小型:多利益相关者决策:定性偏好语言、交互式推理和解释
- 批准号:
2225824 - 财政年份:2022
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
Collaborative Research: RI: III: SHF: Small: Multi-Stakeholder Decision Making: Qualitative Preference Languages, Interactive Reasoning, and Explanation
协作研究:RI:III:SHF:小型:多利益相关者决策:定性偏好语言、交互式推理和解释
- 批准号:
2225823 - 财政年份:2022
- 资助金额:
$ 98.17万 - 项目类别:
Standard Grant
Co-constructing and evaluating a precision health strategy to promote physical activity in primary care: a multi-stakeholder plan
共同构建和评估精准健康策略,以促进初级保健中的身体活动:多方利益相关者计划
- 批准号:
468220 - 财政年份:2022
- 资助金额:
$ 98.17万 - 项目类别:
Miscellaneous Programs
A multi-stakeholder workshop to co-develop future priorities for the Canadian MPS and PKU Registries
多方利益相关者研讨会共同制定加拿大公安部和北京大学登记处未来的优先事项
- 批准号:
468199 - 财政年份:2022
- 资助金额:
$ 98.17万 - 项目类别:
Miscellaneous Programs