课题基金 / 基金详情

Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening

Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
通过定量威胁建模和网络强化提高计算基础设施抵御零日攻击的弹性
批准号:
RGPIN-2017-06686
负责人:
Wang, Lingyu
金额:
$1.89万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2019
资助国家:
加拿大
项目状态:
已结题
起止时间:
2019-01-01 至 2020-12-31

项目摘要

项目成果

Wang, Lingyu的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Today's computing infrastructures are playing the role of nerve systems in enterprises, governmental or military organizations, and critical infrastructures, such as power grids. However, the scale and severity of security breaches in computing infrastructures have continued to grow at an ever-increasing pace, which is evidenced by many high profile security incidents, such as the recent large scale DDoS attacks caused by the Mirai Botnet and the cyber-physical attack on Ukraine power grid in 2015 which left more than 230,000 residents in the dark. The so-called zero day attacks, which exploit previously unknown or unpatched vulnerabilities, are usually behind such security incidents (e.g., Stuxnet employs four different zero day vulnerabilities to target an industrial control system). Therefore, going beyond traditional defense approaches to evaluate and improve the resilience of computing infrastructures against potential zero day attacks is important. Most existing solutions for threat modeling, security metrics, and network hardening are based on known facts about existing vulnerabilities and are not applicable to zero day attacks. In such a context, the proposed research program aims to develop a series of novel techniques for modeling, measuring, and mitigating zero day attacks, and to apply such techniques to mission critical computing infrastructures, such as data centers, enterprise networks, and critical infrastructures, in order to improve their resilience against zero day attacks. ******Specifically, the long term objective of our research program is to develop a series of techniques for understanding (threat modeling), measuring (security metrics), and mitigating (network hardening) the risk of zero day attacks, and to apply such techniques to specific computing infrastructures. Our initial efforts will be focused on developing two specific security metrics and network hardening methods, and then apply those to two specific computing infrastructures, i.e., cloud and SCADA systems. Specifically, the short-term objectives are as follows. Design a new security metric by lifting the attack surface concept from software level to network level, and validate the metric through its correlation with known vulnerabilities. Integrate vulnerability discovery models with the k-zero day safety metric to develop a predictive model for estimating the future risk of zero day attacks based on historical data. Develop network hardening solutions based on those security metrics, realistic cost models, and optimization techniques to determine the optimal solutions under given cost constraints. Apply the metrics and hardening solutions to cloud data centers and SCADA systems by considering the unique characteristics of such infrastructures (e.g., the co-existence of physical and virtual components in cloud and the timelineness measured in milliseconds for SCADA).
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2022
  • 负责人:
    Wang, Lingyu
  • 依托单位:
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2020
  • 负责人:
    Wang, Lingyu
  • 依托单位:
海外基金