Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
批准号:
RGPIN-2021-04106
负责人:
Majumdar, Suryadipta
金额:
$2.11万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Artificial intelligence (AI) has ushered in many revolutionary changes in our lives, especially through its direct impacts on emerging technologies, such as cloud computing and Internet of Things (IoT). This digital transformation has also been rapidly changing the cybersecurity landscape. For instance, today's complex cloud and IoT systems reportedly suffer from various implementation flaws and misconfigurations, and adversaries frequently exploit those vulnerabilities to craft sophisticated and powerful cyberattacks by weaponizing the power of AI. As a result, the transparency and accountability of those systems often become questionable. To that end, security auditing (which verifies the security of a system), might be a promising solution, as it has been a popular choice in the industry for years. However, the traditional retroactive approach to security auditing has become insufficient against AI-enhanced cyberthreats to emerging technologies mainly due to: the lack of readily available security rules or models for auditing, need for a continuous security guarantee for the dynamic nature of those technologies, privacy concerns associated with data sharing, and resource constraints for conducting auditing in several technologies (e.g., IoT). The proposed research program seeks to defend against this new paradigm of AI-enhanced cyberthreats and build proactive security auditing solutions that can be applied to cloud and IoT systems. Our short-term objectives are to build techniques to: (i) derive actionable security rules and models for auditing by understanding AI-enhanced threats, (ii) proactively prepare for potential security breaches so that our auditing solution can prevent a breach at runtime, and (iii) overcome resource constraint and privacy concerns by distributing the auditing workload. In pursuit of these objectives, the proposed research will first build an automated technique to learn security rules from both high-level security standards and AI-enhanced cyberthreats. Second, it will develop a proactive approach that conducts auditing on predicted future changes as well as derived capabilities (i.e., what actions a component can perform) of each component in a system. Finally, it will devise a distributed and lightweight auditing technique that clusters similar components and then locally conducts auditing on each cluster. In summary, the proposed research will help advance the field of cybersecurity for cloud and IoT systems, especially against newer and stronger adversaries with AI capabilities, and provide the Canadian industry with implementable solutions in the near future with the ultimate aim of ensuring proactive security for emerging technologies.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
-
批准号:DGDND-2021-04106
-
项目类别:DND/NSERC Discovery Grant Supplement
-
资助金额:$2.91万
-
财政年份:2022
-
负责人:Majumdar, Suryadipta
-
依托单位:
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
-
批准号:RGPIN-2021-04106
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2021
-
负责人:Majumdar, Suryadipta
-
依托单位:
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
-
批准号:DGDND-2021-04106
-
项目类别:DND/NSERC Discovery Grant Supplement
-
资助金额:$2.91万
-
财政年份:2021
-
负责人:Majumdar, Suryadipta
-
依托单位:
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
-
批准号:DGECR-2021-00381
-
项目类别:Discovery Launch Supplement
-
资助金额:$0.91万
-
财政年份:2021
-
负责人:Majumdar, Suryadipta
-
依托单位:
Safeguarding Cloud-based Information Systems through Security Compliance Verification
-
批准号:504979-2017
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Doctoral
-
资助金额:$2.55万
-
财政年份:2018
-
负责人:Majumdar, Suryadipta
-
依托单位:
Safeguarding Cloud-based Information Systems through Security Compliance Verification
-
批准号:504979-2017
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Doctoral
-
资助金额:$2.55万
-
财政年份:2017
-
负责人:Majumdar, Suryadipta
-
依托单位:
Towards Strengthening Security Guarantee in Cloud
-
批准号:516536-2017
-
项目类别:Canadian Graduate Scholarships Foreign Study Supplements
-
资助金额:$0.44万
-
财政年份:2017
-
负责人:Majumdar, Suryadipta
-
依托单位:
海外基金