课题基金 / 基金详情

SBE: TTP Option: Medium: Data-Driven Cyber Vulnerability Maintenance

SBE: TTP Option: Medium: Data-Driven Cyber Vulnerability Maintenance
SBE:TTP 选项:中:数据驱动的网络漏洞维护
批准号:
1409214
负责人:
Theodore Allen
金额:
$59.45万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-08-01 至 2018-07-31
关键词:

项目摘要

项目成果

Theodore Allen的其他基金

相似基金

相关文献

中文摘要
翻译
研究人员发现,超过90%的成功网络攻击利用了可用补丁修复的漏洞。漏洞可能是个人计算机、移动的设备或打印机上的弱密码或存在漏洞的软件。然而,关于手动应用补丁的决策是困难的。首先,每个月都有相当一部分漏洞通过自动修补得到修复。其次,应用补丁可能会产生副作用,使软件无法使用。第三,组织估计应用补丁的利润的能力有限。此研究生成优化策略,指定应将哪些修补程序应用于哪些主机。它通过创建基于数据的相关成本模型来做到这一点。这些方法包括一种新型的误差估计程序,它解决了数据有限的事实,特别是在很少应用的行动成本方面。相关的数学扩展了称为马尔可夫决策过程的一般决策工具,以解决有限数据的不确定性。这种扩展是通过解决开放的基本数学问题来实现的。在向实践的过渡中,计划了多个真实的应用程序。主要合作伙伴是俄亥俄州州立大学,该大学同意与PI共享数万台计算机和团队的月度数据,以改进政策。除了调整与主机安全性相关的策略外,PI还处理密码更新和网络漏洞策略。
英文摘要
Researchers have found that over 90% of successful cyber attacks exploit vulnerabilities that could have been fixed with available patches. Vulnerabilities can be weak passwords or software with bugs on personal computers, mobile devices, or printers. Yet, decision-making about manually applying patches is difficult. First, a substantial fraction of vulnerabilities are fixed each month by automatic patching. Second, applying patches can have side-effects, making software unusable. Third, organizations have limited abilities to estimate the profit from applying patches. This research generates optimized policies that specify which patches should be applied to which hosts. It does this by creating models of related costs that are based on data. The methods include a novel type of error estimation procedure which addresses the fact that data is limited, particularly in relation to the costs of actions that have rarely been applied. The associated mathematics extends a general decision tool called Markov decision processes to address uncertainty from limited data. This extension is achieved by solving open, fundamental mathematical problems. There are multiple real world applications planned in the transition to practice. The major partner is The Ohio State University which agrees to share monthly data on tens of thousands of computers and teams with the PIs for policy improvement. In addition to tuning individual host vulnerability-related policies, the PIs address password updating and network vulnerability policies.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1287/deca.2017.0360
发表时间: 2017-11
期刊: Decis. Anal.
影响因子: --
作者: [Theodore T. Allen;Zhenhuan Sui;Nathan L. Parker]
通讯作者: Theodore T. Allen;Zhenhuan Sui;Nathan L. Parker
Control charting methods for autocorrelated cyber vulnerability data
自相关网络漏洞数据的控制图方法
DOI: 10.1080/08982112.2015.1125926
发表时间: 2016
期刊: Quality engineering
影响因子: 2
作者: [Afful-Dadzie, A, Allen, T. T.]
通讯作者: Allen, T. T.
EAGER: A Framework For Economical Cyber Security Inspection and Assurance
  • 批准号:
    1912166
  • 项目类别:
    Standard Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2019
  • 负责人:
    Theodore Allen
  • 依托单位:
国内基金
海外基金
RNA结合蛋白TTP在阿尔茨海默病中的作用机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2023
  • 负责人:
  • 依托单位:
TTP和XPO4蛋白介导lncRNA转运在子宫颈鳞状细胞癌中功能及机制的研究
  • 批准号:
    --
  • 项目类别:
    面上项目
  • 资助金额:
    54万元
  • 批准年份:
    2022
  • 负责人:
    陈亮
  • 依托单位:
平滑肌中TTP在血压调控中的作用及机制研究
  • 批准号:
    --
  • 项目类别:
    面上项目
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    张文程
  • 依托单位:
TTP-KDM3A/CYP19A1调控滋养层细胞分化和侵袭的机制研究
  • 批准号:
    82171669
  • 项目类别:
    面上项目
  • 资助金额:
    54万元
  • 批准年份:
    2021
  • 负责人:
    林羿
  • 依托单位: