Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)

针对人工智能增强型网络威胁的主动安全审核:从云到物联网 (IoT)

基本信息

  • 批准号:
    RGPIN-2021-04106
  • 负责人:
  • 金额:
    $ 2.11万
  • 依托单位:
  • 依托单位国家:
    加拿大
  • 项目类别:
    Discovery Grants Program - Individual
  • 财政年份:
    2022
  • 资助国家:
    加拿大
  • 起止时间:
    2022-01-01 至 2023-12-31
  • 项目状态:
    已结题

项目摘要

Artificial intelligence (AI) has ushered in many revolutionary changes in our lives, especially through its direct impacts on emerging technologies, such as cloud computing and Internet of Things (IoT). This digital transformation has also been rapidly changing the cybersecurity landscape. For instance, today's complex cloud and IoT systems reportedly suffer from various implementation flaws and misconfigurations, and adversaries frequently exploit those vulnerabilities to craft sophisticated and powerful cyberattacks by weaponizing the power of AI. As a result, the transparency and accountability of those systems often become questionable. To that end, security auditing (which verifies the security of a system), might be a promising solution, as it has been a popular choice in the industry for years. However, the traditional retroactive approach to security auditing has become insufficient against AI-enhanced cyberthreats to emerging technologies mainly due to: the lack of readily available security rules or models for auditing, need for a continuous security guarantee for the dynamic nature of those technologies, privacy concerns associated with data sharing, and resource constraints for conducting auditing in several technologies (e.g., IoT). The proposed research program seeks to defend against this new paradigm of AI-enhanced cyberthreats and build proactive security auditing solutions that can be applied to cloud and IoT systems. Our short-term objectives are to build techniques to: (i) derive actionable security rules and models for auditing by understanding AI-enhanced threats, (ii) proactively prepare for potential security breaches so that our auditing solution can prevent a breach at runtime, and (iii) overcome resource constraint and privacy concerns by distributing the auditing workload. In pursuit of these objectives, the proposed research will first build an automated technique to learn security rules from both high-level security standards and AI-enhanced cyberthreats. Second, it will develop a proactive approach that conducts auditing on predicted future changes as well as derived capabilities (i.e., what actions a component can perform) of each component in a system. Finally, it will devise a distributed and lightweight auditing technique that clusters similar components and then locally conducts auditing on each cluster. In summary, the proposed research will help advance the field of cybersecurity for cloud and IoT systems, especially against newer and stronger adversaries with AI capabilities, and provide the Canadian industry with implementable solutions in the near future with the ultimate aim of ensuring proactive security for emerging technologies.
人工智能(AI)为我们的生活带来了许多革命性的变化,特别是通过其对云计算和物联网(IoT)等新兴技术的直接影响。这种数字化转型也正在迅速改变网络安全格局。例如,据报道,当今复杂的云计算和物联网系统存在各种实施缺陷和错误配置,对手经常利用这些漏洞通过将人工智能的力量武器化来制造复杂而强大的网络攻击。因此,这些制度的透明度和问责制往往令人怀疑。为此,安全审计(验证系统的安全性)可能是一个很有前途的解决方案,因为它多年来一直是业界的热门选择。然而,传统的追溯性安全审计方法已经不足以应对新兴技术的人工智能增强的网络威胁,主要原因是:缺乏现成的安全规则或审计模型,需要为这些技术的动态性质提供持续的安全保证,与数据共享相关的隐私问题,以及在几种技术中进行审计的资源限制(例如,物联网)。拟议的研究计划旨在防御这种新的AI增强型网络威胁模式,并构建可应用于云和物联网系统的主动安全审计解决方案。我们的短期目标是建立技术:(i)通过理解AI增强的威胁来获得可操作的安全规则和审计模型,(ii)主动为潜在的安全漏洞做好准备,以便我们的审计解决方案可以在运行时防止漏洞,以及(iii)通过分配审计工作量来克服资源限制和隐私问题。为了实现这些目标,拟议的研究将首先建立一种自动化技术,从高级安全标准和人工智能增强的网络威胁中学习安全规则。其次,它将制定一种积极主动的方法,对预测的未来变化以及衍生能力(即,组件可以执行什么动作)。最后,设计了一种分布式的轻量级审计技术,将相似的组件聚集在一起,然后在每个集群上进行本地审计。总之,拟议的研究将有助于推进云和物联网系统的网络安全领域,特别是针对具有人工智能能力的更新和更强大的对手,并在不久的将来为加拿大行业提供可实施的解决方案,最终目标是确保新兴技术的主动安全。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Majumdar, Suryadipta其他文献

Majumdar, Suryadipta的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Majumdar, Suryadipta', 18)}}的其他基金

Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
针对人工智能增强型网络威胁的主动安全审核:从云到物联网 (IoT)
  • 批准号:
    DGDND-2021-04106
  • 财政年份:
    2022
  • 资助金额:
    $ 2.11万
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
针对人工智能增强型网络威胁的主动安全审核:从云到物联网 (IoT)
  • 批准号:
    RGPIN-2021-04106
  • 财政年份:
    2021
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Discovery Grants Program - Individual
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
针对人工智能增强型网络威胁的主动安全审核:从云到物联网 (IoT)
  • 批准号:
    DGDND-2021-04106
  • 财政年份:
    2021
  • 资助金额:
    $ 2.11万
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
针对人工智能增强型网络威胁的主动安全审核:从云到物联网 (IoT)
  • 批准号:
    DGECR-2021-00381
  • 财政年份:
    2021
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Discovery Launch Supplement
Safeguarding Cloud-based Information Systems through Security Compliance Verification
通过安全合规性验证保护基于云的信息系统
  • 批准号:
    504979-2017
  • 财政年份:
    2018
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Alexander Graham Bell Canada Graduate Scholarships - Doctoral
Safeguarding Cloud-based Information Systems through Security Compliance Verification
通过安全合规性验证保护基于云的信息系统
  • 批准号:
    504979-2017
  • 财政年份:
    2017
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Alexander Graham Bell Canada Graduate Scholarships - Doctoral
Towards Strengthening Security Guarantee in Cloud
强化云安全保障
  • 批准号:
    516536-2017
  • 财政年份:
    2017
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Canadian Graduate Scholarships Foreign Study Supplements

相似海外基金

Towards Actionable Security Guidelines for IoT Compliance Auditing and Integration with Trustworthiness
制定物联网合规性审计和可信度集成的可行安全指南
  • 批准号:
    577183-2022
  • 财政年份:
    2022
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Alliance Grants
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
针对人工智能增强型网络威胁的主动安全审核:从云到物联网 (IoT)
  • 批准号:
    DGDND-2021-04106
  • 财政年份:
    2022
  • 资助金额:
    $ 2.11万
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
针对人工智能增强型网络威胁的主动安全审核:从云到物联网 (IoT)
  • 批准号:
    RGPIN-2021-04106
  • 财政年份:
    2021
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Discovery Grants Program - Individual
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
针对人工智能增强型网络威胁的主动安全审核:从云到物联网 (IoT)
  • 批准号:
    DGDND-2021-04106
  • 财政年份:
    2021
  • 资助金额:
    $ 2.11万
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
Proactive Security Auditing against AI-enhanced Cyberthreats: from Clouds to Internet of Things (IoT)
针对人工智能增强型网络威胁的主动安全审核:从云到物联网 (IoT)
  • 批准号:
    DGECR-2021-00381
  • 财政年份:
    2021
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Discovery Launch Supplement
Auditing and monitoring the security of NFV and SDN-based cloud environments
审计和监控基于 NFV 和 SDN 的云环境的安全性
  • 批准号:
    517415-2017
  • 财政年份:
    2018
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Collaborative Research and Development Grants
Auditing and monitoring the security of NFV and SDN-based cloud environments
审计和监控基于 NFV 和 SDN 的云环境的安全性
  • 批准号:
    517415-2017
  • 财政年份:
    2017
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Collaborative Research and Development Grants
I-Corps: Explanation-Based Auditing: Improving the Security of Electronic Medical Records
I-Corps:基于解释的审计:提高电子病历的安全性
  • 批准号:
    1340372
  • 财政年份:
    2013
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Standard Grant
Analyyzing and Improving the Behaviour of Information Security Auditing Mechaanisms specifically for Web Services
分析和改进专门针对Web服务的信息安全审计机制的行为
  • 批准号:
    360827-2009
  • 财政年份:
    2009
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Postgraduate Scholarships - Master's
Analyyzing and Improving the Behaviour of Information Security Auditing Mechaanisms specifically for Web Services
分析和改进专门针对Web服务的信息安全审计机制的行为
  • 批准号:
    360827-2008
  • 财政年份:
    2008
  • 资助金额:
    $ 2.11万
  • 项目类别:
    Alexander Graham Bell Canada Graduate Scholarships - Master's
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了