Autonomous security for complex systems
复杂系统的自主安全
基本信息
- 批准号:RGPIN-2021-03278
- 负责人:
- 金额:$ 2.11万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Discovery Grants Program - Individual
- 财政年份:2021
- 资助国家:加拿大
- 起止时间:2021-01-01 至 2022-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Information technology-based systems are facing increasingly complex cyber-attacks. To deal with these cyber-attacks, large enterprises are deploying monitoring infrastructures based on Security Operations Centers (SOCs). SOCs integrate various security functions such as intrusion detection systems, firewalls and supervision systems. They are based on a complex organizational structure, generally at three levels, with a first level dedicated to the task of analyzing low-level alerts, the second level in charge of managing incidents and activating countermeasures, and the last level responsible for forensic analysis, monitoring and anticipation. At the first level, analysts manage alerts by applying checklists and best practice rules. Apart from these reflex reaction tasks, other tasks are generally performed manually and rely on human expertise. The consequence of this complex structure is that the deployment of a SOC is expensive in terms of purchase, operation and maintenance. SOCs are therefore security solutions that are difficult for SMEs (Small and Medium-sized Enterprises) to access. In the absence of adapted solutions, SMEs are increasingly vulnerable to cyber-attacks. To address this problem, we propose to develop the concept of Autonomous Cybersecurity Systems (ACS). The aim is to design concrete solutions to further automate security functions, particularly those that are currently performed manually in SOCs. The concept of ACS will improve the global security of companies and especially SMEs by addressing the following points: (1) Reducing the risk of human error by further automating the decision-making process, (2) Ensuring better management of cyber-attacks by reducing response time, (3) Making security solutions more accessible to businesses, particularly SMEs, by reducing operation and maintenance costs. The following topics will be studied in the research program : T1: Automatic generation of attack graphs. This topic aims to define an Artificial Intelligence-based solution that takes as input the textual descriptions of vulnerabilities and generates an ontological description of the graphs of attacks instantiated on the system considered. T2: Classification of attacker profiles and attack attribution. The objectives will be first to construct a classification of attacker profiles and then analyze the attacker typologies and go further into the so-called attribution problem which aims to trace the source of the attack. T3. Security posture evaluation and impact measurement. The suggested approach is based on the definition of metrics and the identification of dependencies between business services, the objective being to develop an expert system to assist the decision making process in the choice of response to cyber-attacks. By developing solutions to deal with cyber attacks and attackers, this program will enhance trust in digital systems and will have transformative impacts for the Canadian society and economy.
基于信息技术的系统正面临日益复杂的网络攻击。为了应对这些网络攻击,大型企业正在部署基于安全运营中心(SOC)的监控基础设施。SOC集成了各种安全功能,如入侵检测系统,防火墙和监控系统。它们基于复杂的组织结构,通常分为三级,第一级专门负责分析低级别警报,第二级负责管理事件和启动对策,最后一级负责法医分析,监测和预测。在第一级,分析师通过应用检查表和最佳实践规则来管理警报。除了这些反射反应任务之外,其他任务通常手动执行并依赖于人类专业知识。这种复杂结构的结果是,SOC的部署在购买、操作和维护方面是昂贵的。因此,SOC是中小型企业难以访问的安全解决方案。在缺乏适应性解决方案的情况下,中小企业越来越容易受到网络攻击。为了解决这个问题,我们提出了自主网络安全系统(ACS)的概念。其目的是设计具体的解决方案,以进一步自动化安全功能,特别是那些目前在SOC中手动执行的功能。ACS的概念将通过解决以下几点来改善公司,特别是中小企业的全球安全:(1)通过进一步自动化决策过程来降低人为错误的风险,(2)通过减少响应时间来确保更好地管理网络攻击,(3)通过降低运营和维护成本,使安全解决方案更容易为企业,特别是中小企业所用。研究计划将研究以下主题:T1:攻击图的自动生成。本主题旨在定义一种基于人工智能的解决方案,该解决方案将漏洞的文本描述作为输入,并生成所考虑系统上实例化的攻击图的本体描述。 T2:攻击者配置文件和攻击归因的分类。我们的目标是首先构建一个攻击者配置文件的分类,然后分析攻击者的类型学,并进一步进入所谓的归属问题,其目的是跟踪攻击的来源。T3安全态势评估和影响衡量。建议的方法是基于定义的指标和识别业务服务之间的依赖关系,其目标是开发一个专家系统,以协助决策过程中的选择,以应对网络攻击。通过开发应对网络攻击和攻击者的解决方案,该计划将增强对数字系统的信任,并将对加拿大社会和经济产生变革性影响。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Cuppens, Frederic其他文献
Physical resilience to insider attacks in IoT networks: Independent cryptographically secure sequences for DSSS anti-jamming
- DOI:
10.1016/j.comnet.2020.107751 - 发表时间:
2021-01-07 - 期刊:
- 影响因子:5.6
- 作者:
Navas, Renzo E.;Cuppens, Frederic;Papadopoulos, Georgios Z. - 通讯作者:
Papadopoulos, Georgios Z.
Resilience Estimation of Cyber-Physical Systems via Quantitative Metrics
- DOI:
10.1109/access.2021.3066108 - 发表时间:
2021-01-01 - 期刊:
- 影响因子:3.9
- 作者:
Barbeau, Michel;Cuppens, Frederic;Garcia-Alfaro, Joaquin - 通讯作者:
Garcia-Alfaro, Joaquin
Cuppens, Frederic的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Cuppens, Frederic', 18)}}的其他基金
Autonomous security for complex systems
复杂系统的自主安全
- 批准号:
RGPIN-2021-03278 - 财政年份:2022
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Evaluation de la posture de sécurité dans le Cloud
云安全态势评估
- 批准号:
560415-2020 - 财政年份:2021
- 资助金额:
$ 2.11万 - 项目类别:
Alliance Grants
相似国自然基金
黄淮海平原典型区域土壤盐渍化演变机制与发生风险防控对策研究
- 批准号:41171178
- 批准年份:2011
- 资助金额:65.0 万元
- 项目类别:面上项目
存储安全中介系统理论、仿真和实现技术研究
- 批准号:61070154
- 批准年份:2010
- 资助金额:30.0 万元
- 项目类别:面上项目
最优证券设计及完善中国资本市场的路径选择
- 批准号:70873012
- 批准年份:2008
- 资助金额:27.0 万元
- 项目类别:面上项目
相似海外基金
Climate Change Effects on Pregnancy via a Traditional Food
气候变化通过传统食物对怀孕的影响
- 批准号:
10822202 - 财政年份:2024
- 资助金额:
$ 2.11万 - 项目类别:
Housing policy, neighborhood context, and pathways to midlife mortality in a social experiment
社会实验中的住房政策、社区环境和中年死亡率的途径
- 批准号:
10868129 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Implementation of an impact assessment tool to optimize responsible stewardship of genomic data in the cloud
实施影响评估工具以优化云中基因组数据的负责任管理
- 批准号:
10721762 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Maximizing the Scalability of the Chronic Disease Self-Management Program (CDSMP) Among Older Adults in State Correctional Settings
最大限度地提高州惩教机构中老年人慢性病自我管理计划 (CDSMP) 的可扩展性
- 批准号:
10654994 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
ASHA 2: An Ethnographic Study Embedded in a Depression Treatment Trial
ASHA 2:抑郁症治疗试验中的人种学研究
- 批准号:
10746492 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
A Next Generation Data Infrastructure to Understand Disparities across the Life Course
下一代数据基础设施可了解整个生命周期的差异
- 批准号:
10588092 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
A Vitamin K analog countermeasure for organophosphate poisoning
维生素 K 类似物治疗有机磷中毒的对策
- 批准号:
10602913 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Building Social and Structural Connections for the Prevention of OUD among Youth Experiencing Homelessness: An RCT Examining Biopsychosocial Mechanisms
建立社会和结构联系以预防无家可归青年中的 OUD:一项检验生物心理社会机制的随机对照试验
- 批准号:
10775030 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
AnVIL Clinical Environment for Innovation and Translation (ACE-IT)
AnVIL 创新与转化临床环境 (ACE-IT)
- 批准号:
10747551 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别: