SI2-SSE: AttackTagger: Early Threat Detection for Scientific Cyberinfrastructure
SI2-SSE: AttackTagger: Early Threat Detection for Scientific Cyberinfrastructure
批准号:
1535070
负责人:
Alexander Withers
金额:
$49.91万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2020-08-31
中文摘要
支持科学研究的网络基础设施(例如,提供对独特科学仪器的访问的网络基础设施,如望远镜,或放置在现场的高度分布的传感器阵列,或计算超级计算中心)面临着防御网络攻击的艰巨挑战。中等规模的研究项目团队几乎没有网络安全专业知识来防御日益多样化、高级和不断演变的攻击。即使是拥有安全专业知识的较大设施,也经常被大量的安全日志数据淹没,它们需要分析才能识别攻击者和攻击,这是防御他们的第一步。由于缺乏工具和时间来巧妙地检测隐藏在持续网络流量噪声中的攻击,传统识别攻击者的方法面临的挑战被放大。挑战不一定是部署额外的监控,而是通过利用在大量已经被主动收集的安全、网络和系统日志中找到的所有可用信息来识别这种恶意流量。该项目建议构建和部署研究环境中需要的高级日志分析工具,名为AttackTagger,该工具可以进行扩展,以能够应对安全日志数据的急剧增长,并在当今不断发展的安全格局中检测新出现的威胁模式。AttackTagger将使支持国家优先事项的科学研究更加安全。AttackTagger将是一个复杂的日志分析工具,旨在通过为高级模式匹配构建因子图模型来发现潜在的恶意活动,如凭证盗窃。AttackTagger将与现有的安全软件集成,以便在现有的安全生态系统中轻松部署,并将处理和计算工作卸载到更适合的组件。它可以使用各种系统和网络安全日志。AttackTagger利用因子图模型实现高级模式匹配,因子图模型是一种概率图形模型,可以使用无向图表示,特别是二部图来描述随机变量之间的复杂依赖关系。二分图表示法由表示随机变量的变量节点、表示局部函数(或因子函数)的因子节点以及连接这两类节点的边组成。因子图中的变量依赖关系使用全局函数来表示,该全局函数被分解为局部函数的乘积。在安全领域的实践中,与贝叶斯网络和马尔可夫随机场方法相比,使用因子图来定义事件和用户状态之间的关系更加灵活。具体地说,使用因子图允许捕获事件之间的顺序关系,并且使得能够集成外部知识,例如专家知识或用户简档。
英文摘要
The cyber infrastructure that supports science research (such as the cyberinfrastructure that provides access to unique scientific instrumentation such as a telescope, or an array of highly distributed sensors placed in the field, or a computational supercomputing center) faces the daunting challenge of defending against cyber attacks. Modest to medium research project teams have little cyber security expertise to defend against the increasingly diverse, advanced and constantly evolving attacks. Even larger facilities that have with security expertise are often overwhelmed with the amount of security log data they need to analyze in order to identify attackers and attacks, which is the first step to defending against them. The challenges of the traditional approach of identifying an attacker are amplified by the lack of tools and time to detect attacks skillfully hidden in the noise of ongoing network traffic. The challenge is not necessarily in deploying additional monitoring but to identify this malicious traffic by utilizing all available information found in the plethora of security, network, and system logs that are already being actively collected. This project proposes to build and deploy, is needed in research environments, an advanced log analysis tool, named AttackTagger, that can scale to be able to address the dramatic increase in security log data, and detect emerging threat patterns in today's constantly evolving security landscape. AttackTagger will make science research in support of national priorities more secure.AttackTagger will be a sophisticated log analysis tool designed to find potentially malicious activity, such as credential theft, by building factor graph models for advanced pattern matching. AttackTagger will integrate with existing security software so as to be easily deployable within existing security ecosystems and to offload processing and computational work onto better suited components. It can consume a wide variety of system and network security logs. AttackTagger accomplishes advanced pattern matching by utilizing a Factor Graph model, which is a type of probabilistic graphical model that can describe complex dependencies among random variables using an undirected graph representation, specifically a bipartite graph. The bipartite graph representation consists of variable nodes representing random variables, factor nodes representing local functions (or factor functions , and edges connecting the two types of nodes. Variable dependencies in a factor graph are expressed using a global function, which is factored into a product of local functions. In the practice of the security domain, using factor graphs is more flexible to define relations among the events and the user state compared to Bayesian Network and Markov Random Field approaches. Specifically, using factor graphs allows capturing sequential relation among events and enables integration of the external knowledge, e.g., expert knowledge or a user profile.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CICI: Secure Data Architecture: Shared Intelligence Platform for Protecting our National Cyberinfrastructure
-
批准号:1547249
-
项目类别:Standard Grant
-
资助金额:$49.92万
-
财政年份:2015
-
负责人:Alexander Withers
-
依托单位:
国内基金
海外基金
登录
查看更多内容
化脓性链球菌分泌性酯酶Sse抑制LC3相关吞噬促其侵袭的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:张晓兰
-
依托单位:
太阳能电池Cu2ZnSn(SSe)4/CdS界面过渡层结构模拟及缺陷态消除研究
-
批准号:--
-
项目类别:面上项目
-
资助金额:55万元
-
批准年份:2022
-
负责人:刘成延
-
依托单位:
掺杂实现Cu2ZnSn(SSe)4吸收层表层稳定弱n型特性的第一性原理研究
-
批准号:12004100
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:刘成延
-
依托单位:
基于SSE的航空信息系统信息安全保障评价指标体系的研究
-
批准号:60776808
-
项目类别:联合基金项目
-
资助金额:19.0万元
-
批准年份:2007
-
负责人:吴志军
-
依托单位: