课题基金 / 基金详情

Next Generation Provenance-based Intrusion Detection System

Next Generation Provenance-based Intrusion Detection System
下一代基于来源的入侵检测系统
批准号:
RGPIN-2022-03639
负责人:
Pasquier, Thomas
金额:
$2.11万
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31

项目摘要

项目成果

Pasquier, Thomas的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Worldwide, attacks on computer systems are adversely affecting everyday life, from schools closing in Iowa, cancellation of hospital appointments in Ireland, supermarkets closure in Sweden, to fuel disruption in the US. Of particular concern is the increased number of Advanced Persistent Threat (APT) attacks. APTs are subtle targeted attacks designed by well-resourced and skilled attackers. The attackers extend their control of a system over a period of months or years before finally launching a potentially devastating attack that can, in certain cases, affect critical infrastructures. APTs remain undetected for years due to the opacity and complexity of modern computer systems. Over the last few years, provenance-based intrusion detection has been heralded as a potential solution in the academic security community. Provenance is the representation of system execution as a directed acyclic graph that captures the causal relationship between events greatly increasing system observability. Intrusion detection techniques applied to this graph data can detect attacks and investigate suspicious behaviors. However, such systems have not been widely deployed for a few fundamental reasons. First, current academic prototypes and experimental setups are not adapted to current industry standards and practices. Second, there is a global shortage of security talent making attack investigation an expensive endeavor. Provenance-based systems are unfamiliar and require complex investigation strategies, leading to a high adoption cost. Finally, academic evaluation standards have been relatively poor when compared with more conventional intrusion detection techniques casting doubt upon their real effectiveness. In the proposed research program, I will design a practical end-to-end provenance-based intrusion detection solution that meets current industry standards and practices. A core objective of this research is to design a solution that can be readily deployed in modern cloud-based platforms that are today's prevalent deployment choice. Further, the solution we develop will focus on reducing expert time dedicated to low-value tasks (e.g., triaging false positives or parsing through gigabytes of log records). Finally, I will design a strong evaluation strategy to demonstrate the validity of provenance-based approaches. This research is at the intersection of systems and applied machine learning. I envision my group contributing to systems observability research by developing trustworthy tools providing visibility into systems behavior and to machine learning applied to security by developing explainable graph-based intrusion detection solutions. As part of this research, my team will also work to integrate this new knowledge into robust open-source tools. These tools can then be used by industry practitioners to develop trustworthy security solutions.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Next Generation Provenance-based Intrusion Detection System
  • 批准号:
    DGECR-2022-00372
  • 项目类别:
    Discovery Launch Supplement
  • 资助金额:
    $0.91万
  • 财政年份:
    2022
  • 负责人:
    Pasquier, Thomas
  • 依托单位:
国内基金
海外基金
Next Generation Majorana Nanowire Hybrids