课题基金 / 基金详情

A Holistic Framework for Emerging Long-term Attacks Detection and Response Using Diverse Heterogeneous Data Sources

A Holistic Framework for Emerging Long-term Attacks Detection and Response Using Diverse Heterogeneous Data Sources
使用不同异构数据源检测和响应新兴长期攻击的整体框架
批准号:
RGPIN-2020-05321
负责人:
Traore, Issa
金额:
$2.55万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2021
资助国家:
加拿大
项目状态:
已结题
起止时间:
2021-01-01 至 2022-12-31

项目摘要

项目成果

Traore, Issa的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Recently, it was discovered that a state-sponsored hacker group has been infiltrating the European Union's (EU) diplomatic communications network for years, downloading thousands of sensitive cables. The attack ran undetected for a three-year period and targeted more than 100 organisations and institutions, such as the United Nations and ministries of foreign affairs and finance. The attack is a type of emerging threat consisting of targeted and long-term campaigns delivered by skilled hackers who have clearly defined objectives and relentlessly work towards achieving their aims. These breaches can go undetected for a long period of time because of the hackers' ability to adapt to and escape defensive methods. Noticeably, there has been an evolution from volume-based attacks towards stealth-like `low and slow' style attacks. Although volumetric attacks often occur within a set time frame, low and slow attacks rely on an ongoing stream of malicious requests and have no distinct beginning or end; this makes their detection by current intrusion detection systems (IDS) and security information and event management (SIEM) tools challenging. The long-term objective of the research program is to spearhead the development of a new generation of security data analytics techniques by using more diverse data sources that can gain better situational awareness of the threat environment and deploy sound solutions for cyber incident attribution and resiliency. The short-term objective of the research program is to develop a new framework for detecting, responding and investigating long-term attacks using data from both the traditional security ecosystem and beyond the organisation perimeter. The research will leverage the large dynamic uncertain multigraph theory to coherently express and analyse security data across various heterogeneous data sources and meaningfully link seemingly innocuous and unrelated events to expose hidden and long-term attack patterns. Indeed, existing attack graphs are crippled by scalability challenges: they are limited in scope, target particular types of threats and rely on a limited set of data sources. The research will strengthen existing cyber defenses by developing novel techniques to observe and process malicious patterns and activities at a larger scale, including the long-term activities that may span beyond an entire data center. This will benefit Canada by strengthening the protection of digital assets and critical infrastructure and by increasing the competitiveness of the Canadian cybersecurity industry. 11 Highly Qualified Personnel (HQPs), four PhD students, three master's students and four undergraduate students, will be trained in security threat assessment and mitigation directly in the program. The program will be led by Dr. Issa Traore, who is the coauthor of several influential cybersecurity papers and a current member of the editorial board of the IEEE Transactions on Information Security and Forensics.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
A Holistic Framework for Emerging Long-term Attacks Detection and Response Using Diverse Heterogeneous Data Sources
  • 批准号:
    RGPIN-2020-05321
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.55万
  • 财政年份:
    2022
  • 负责人:
    Traore, Issa
  • 依托单位:
A Holistic Framework for Emerging Long-term Attacks Detection and Response Using Diverse Heterogeneous Data Sources
  • 批准号:
    RGPIN-2020-05321
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.55万
  • 财政年份:
    2020
  • 负责人:
    Traore, Issa
  • 依托单位:
Novel Software-based Biometrics for Security of Mobile Devices
  • 批准号:
    RGPIN-2015-04837
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.75万
  • 财政年份:
    2019
  • 负责人:
    Traore, Issa
  • 依托单位:
Identity and behavior-based secure personalized message classification system
  • 批准号:
    531909-2018
  • 项目类别:
    Idea to Innovation
  • 资助金额:
    $9.08万
  • 财政年份:
    2018
  • 负责人:
    Traore, Issa
  • 依托单位:
海外基金