课题基金 / 基金详情

Intelligence-driven Cyber Security Defense Tools

Intelligence-driven Cyber Security Defense Tools
情报驱动的网络安全防御工具
批准号:
RGPIN-2014-05208
负责人:
Ghorbani, Aliakbar
金额:
$1.89万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2017
资助国家:
加拿大
项目状态:
已结题
起止时间:
2017-01-01 至 2018-12-31

项目摘要

项目成果

Ghorbani, Aliakbar的其他基金

相似基金

相关文献

中文摘要
翻译
调查显示,由于基础设施系统各个方面的安全违规,估计每年的负担在130亿至1.6万亿美元之间。随着这个问题的严重性,与安全相关的问题被带到企业和政府关注的最前沿,并迫使专家为系统安全寻找全面和智能的解决方案。目前,缺乏用于实际安全评估和管理的健全和全面的工具,使人们能够了解紧急威胁对系统的影响,并制定全面和主动的解决方案来保护基础设施。在这方面的另一个主要挑战是,是否有能力采用行之有效且已被广泛使用的分析方法和方法来处理与系统安全状况有关的大量数据,以及是否有能力提取对立即预防和减轻事故有用的智能和相关信息。在接下来的五年里,我们将通过识别和开发一系列模型、方法、技术和工具,专注于推进智能驱动的网络安全防御研究,以理解紧急威胁对系统的影响,并开发全面、主动的解决方案来保护基础设施。拟议研究的目标是通过采取全面的方法,建立一个更明智的威胁观,来减少灾难性事件发生的可能性。我们相信,只有当企业中与安全相关的所有信息都被收集、组织、分析、关联和利用时,才能生成有效和可操作的情报。重点发展:1。恶意软件分析:每年网络空间中恶意软件数量和僵尸网络活动的空前增长,加上快速变化的威胁环境(即移动计算,社交网络的发展),表明传统方法主要基于识别充分记录的威胁(签名)的严重不足。由于网络空间的有效防御需要准确的评估和识别恶意软件威胁,我的研究活动将集中在几个领域:威胁分析,威胁归因和威胁检测。在这种情况下,一个主要的兴趣将是移动恶意软件和僵尸网络威胁。大数据安全分析:在安全领域,事件日志提供了丰富的信息源,可以分析攻击和系统故障,通常可以精确定位弱点和潜在的解决方案。在这一领域,我的研究目标是:1)大规模系统中安全数据的动态识别/结构化和预测分析,主要目标是提高领域专家的生产力,这些专家面临着不断出现的新临时格式的挑战;2)大规模安全数据的预测分析,目的是开发预测分析方法,通过建模攻击的影响和管理员引入的潜在网络变化/缓解策略,对网络安全进行全面分析。3. 安全性可视化:安全性可视化应该具有优雅且视觉上吸引人的设计,同时提供信息、交互并提供探索功能。这方面的一个基本挑战是传统可视化技术在大数据现象下的可扩展性。我们在这个方向上的研究重点在于解决这个挑战,即设计和开发一个可扩展的可视化系统,能够处理不断增加的数据量,同时为用户提供交互式体验。
英文摘要
Surveys suggest an estimated annual burden of between $13 billion and $1.6 trillion as a result of security violations in various dimensions of infrastructure systems. With the magnitude of this problem, security related issues were brought to the forefront of enterprise and government concerns and forced experts to search for comprehensive and intelligent solutions for systems’ security. Currently, there is a lack of sound and comprehensive tools for practical security assessment and management that allow the understanding of an impact of emergent threats on a system and the development of comprehensive and proactive solutions to safeguard an infrastructure. Another major challenge in this respect is the capability of well-established and already widely-used analytical approaches and methodologies to cope with the wealth of data pertinent to a system’s security status and their ability to extract intelligent and relevant information useful for an immediate incident prevention and mitigation. Over the next five years we will focus on advancing research in intelligent-driven cyber security defense by identifying and developing a bank of models, methodologies, techniques, and tools for understanding the impact(s) of emergent threats on a system and developing a comprehensive and proactive solutions to safeguard an infrastructure. The goal of the proposed research is to reduce the likelihood of catastrophic incidents by taking a holistic approach in creating a more informed view of threats. We believe that effective and actionable intelligence can be generated only when all information within an enterprise with security relevance gets collected, organized, analyzed, correlated, and leveraged. We will focus on developing:1. Malware Analysis: Unprecedented growth in malware numbers and botnet activity in cyberspace each year, coupled with a rapidly changing threat landscape (i.e., evolution of mobile computing, social networks) revealed an acute inadequacy of traditional approaches predominantly based on recognition of well-documented threats (signatures). Since an effective defense in cyber space requires accurate assessment and recognition of malware threats, my research activities will focus on several areas: threats analysis, threat attribution and threat detection. One of the main interests in this context will be mobile malware and botnet threats.2. Big Data Security Analytics: In security domain event logs provide a rich source of information that allows to analyze the anatomy of attacks and system failures often pinpointing weak spots and potential solutions. In this area my research objectives are: 1) dynamic recognition/structuring and predictive analytics for security data in large-scale systems, with the primary goal of improving the productivity of domain experts that are challenged with constantly appearing of new ad hoc formats; and, 2) Predictive analytics for large-scale security data, with the aim of developing predictive analytic methods to allow a comprehensive analysis of network security through modeling impacts of attacks and potential network changes/mitigation strategies introduced by an administrator. 3. Security Visualization: Security visualizations should have an elegant and visually appealing design, while being informative, interactive, and providing exploratory capabilities. One of the fundamental challenges in this respect is scalability of conventional visualization techniques in the presence of Big Data phenomenon. Our research focus in this direction lies in addressing this challenge, i.e., to design and develop a scalable visualization system able to cope with ever-increasing amounts of data while providing an interactive experience to a user.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Human-Centric Cybersecurity
  • 批准号:
    RGPIN-2020-04121
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.99万
  • 财政年份:
    2022
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
Cybersecurity
  • 批准号:
    CRC-2015-00106
  • 项目类别:
    Canada Research Chairs
  • 资助金额:
    $14.57万
  • 财政年份:
    2022
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
Human-Centric Cybersecurity
  • 批准号:
    DGDND-2020-04121
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
  • 资助金额:
    $2.91万
  • 财政年份:
    2022
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
Human-Centric Cybersecurity
  • 批准号:
    RGPIN-2020-04121
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.99万
  • 财政年份:
    2021
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
国内基金
海外基金
Data-driven Recommendation System Construction of an Online Medical Platform Based on the Fusion of Information
基于Cache的远程计时攻击研究