Threat Inferencing for Autonomic Security Management of IoT Systems
Threat Inferencing for Autonomic Security Management of IoT Systems
批准号:
531268-2018
负责人:
Khazaei, Hamzeh
金额:
$1.82万
依托单位:
依托单位国家:
加拿大
项目类别:
Engage Grants Program
财政年份:
2018
资助国家:
加拿大
项目状态:
已结题
起止时间:
2018-01-01 至 2019-12-31
中文摘要
BlackBerry提供企业移动的系统管理(EMM)软件,称为统一端点管理器(UEM),该软件提供固定和移动的计算系统(包括具有物联网设备的计算系统)的设计、开发、部署和管理功能。 BlackBerry希望通过为安全策略提供新的管理自动化来帮助驯服现代企业系统策略管理的复杂性。 随着物联网和移动的混合部署越来越复杂,指定有效的上下文敏感安全策略来缓解潜在威胁是令人生畏的,而且也很难验证和调试它们。当物联网平台提供的策略规范语言表达能力不足时,这些问题尤其令人烦恼。新的自动安全策略管理技术将使黑莓能够提供对客户更具吸引力的解决方案,因为它们减少了常见的重大痛点,同时还可能提高安全性。为了为这些问题的有用子集开发自动化,我们将利用并采用IBM引入的自主计算范式,来设计和实现一个搜索-分析-计划-执行循环加上知识库(即,MAPE-k系统)来基于更抽象的安全策略自动管理具体的安全策略。 这种方法的基本价值是利用MAPE-k方法的能力,在发生更改时对安全策略操作进行推理。 要做到这一点,我们将向系统灌输推理威胁和响应所需的知识和逻辑,其中响应包括安装监视器和实施策略控制。 随着能力和操作环境的变化,系统可以自动适应。 我们将使用代表当前BlackBerry客户问题的原型系统探索解决方案空间。*
英文摘要
BlackBerry supplies enterprise mobile systems management (EMM) software called Unified Endpoint Manager (UEM), which offers functionality for the design, development, deployment, and management of fixed and mobile computing systems, including those with IoT devices. BlackBerry wishes to help tame the complexity of policy administration for modern enterprise system by offering new management automation for security policies. With increasingly complex mixed IoT and mobile deployments, it is daunting to specify effective context-sensitive security policies to mitigate against potential threats, and it is also difficult to validate and debug them. The problems are particularly vexatious when the policy specification languages offered by the IoT platforms are insufficiently expressive. New automatic security policy management techniques would allow BlackBerry to offer solutions more attractive to customers because they reduce common significant pain points, while also offering potentially improved security.****To develop automations for a useful subset of those problems we will leverage and adopt the autonomic computing paradigm, introduced by IBM, to design and implement a Monitor-Analyze-Plan-Execute loop plus knowledge base (i.e., MAPE-k system) to automatically manage concrete security policies based on a more abstract security policy. The essential value of this approach is leveraging the ability of the MAPE-k methods to reason about security policy actions in the presence of change. To do this, we will imbue the system with the knowledge and logic required to reason about threats and responses to them, where responses include installation of monitors and implementation of policy controls. As capabilities and operating environments change, the system can autonomically adapt in response. We will explore the solution space using a prototype system representing a current BlackBerry customer problem.********
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Smart Distributed Software and Systems
-
批准号:RGPIN-2018-05126
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2022
-
负责人:Khazaei, Hamzeh
-
依托单位:
Smart Distributed Software and Systems
-
批准号:RGPIN-2018-05126
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2021
-
负责人:Khazaei, Hamzeh
-
依托单位:
Smart Distributed Software and Systems
-
批准号:RGPIN-2018-05126
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2020
-
负责人:Khazaei, Hamzeh
-
依托单位:
Smart Distributed Software and Systems
-
批准号:RGPIN-2018-05126
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2019
-
负责人:Khazaei, Hamzeh
-
依托单位:
Smart Distributed Software and Systems
-
批准号:RGPIN-2018-05126
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2018
-
负责人:Khazaei, Hamzeh
-
依托单位:
Smart Distributed Software and Systems
-
批准号:DGECR-2018-00222
-
项目类别:Discovery Launch Supplement
-
资助金额:$0.91万
-
财政年份:2018
-
负责人:Khazaei, Hamzeh
-
依托单位:
海外基金