课题基金 / 基金详情

EAGER: Improving Incentives and Awareness, to Increase the Security Posture of Critical Infrastructures

EAGER: Improving Incentives and Awareness, to Increase the Security Posture of Critical Infrastructures
EAGER:提高激励和意识,增强关键基础设施的安全态势
批准号:
1547502
负责人:
Alvaro Cardenas
金额:
$16.4万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2018-08-31

项目摘要

项目成果

Alvaro Cardenas的其他基金

相似基金

相关文献

中文摘要
翻译
保护电网、供水网络和交通网络等网络物理关键基础设施免受计算机攻击事关国家安全、公共安全和经济稳定;然而,这些关键资产大多由私人公司拥有和运营,这些公司的运营要求紧迫,安全预算紧张,而且不愿接受监管。因此,尚不清楚仅靠市场激励就能创造足够的动力来改善这些系统的安全态势。本项目研究如何激励CPS安全的投资和风险管理。第二个相关问题是,虽然当前的网络物理基础设施由运营中心监控,但该系统目前不能帮助操作员识别问题、警报或故障是否是物理事故的结果,或者是否有任何迹象表明是网络攻击导致了问题。第二个研究重点旨在通过建立一个工业安全运营中心的基础来改进对这些系统安全状态的评估,以帮助运营商识别警报的根本原因(事故或网络攻击)。有大量工作专注于相互依赖的安全以及参与保护和保险市场的公司模型。大多数安全模型和经济相互依存的投资公式只关注信息技术基础设施,旨在模拟网络犯罪活动,在网络犯罪活动中,攻击者是理性的利润驱动的代理人,而防御者不断经历安全漏洞,使他们能够基于数据生成风险模型。相比之下,对关键基础设施系统的计算机攻击代表了一组完全不同的恶意代理。这些代理人可能不受利润驱动,只会零星地发起攻击。此外,相互依赖的物理基础设施由联邦代理管理,网络攻击将产生物理后果,扩大受攻击公司的范围。该项目利用并扩展了大规模关键基础设施的可靠性投资文献,以及保险、资产相互依赖的公司之间的合同和极端风险。第二个研究重点利用CPS行业对分析传感器网络收集的数据的兴趣。安全信息和事件管理器(SIEM)解决方案专为企业IT设计,不包括、聚合和关联来自物理世界的传感器数据。为了缩小这一差距,本提案调查了如何为新系统聚合信息,该系统整合了来自控制中心和安全运营中心的数据,从而为创建工业安全运营中心(ISOC)奠定了基础。
英文摘要
The protection of cyber-physical critical infrastructures such as the power grid, water distribution networks, and transportation networks against computer attacks is a matter of national security, public safety, and economic stability; however, most of these critical assets are owned and operated by private companies with pressing operational requirements, tight security budgets, and aversion to regulatory oversight. As a result it is not clear that market incentives alone will create enough momentum to improve the security posture of these systems. This project studies how to incentivize investments and risk management for CPS security. A second related problem is that while current cyber-physical infrastructures are monitored by an operations center, this system does not currently help operators identify if a problem, alarm, or fault was the result of a physical accident or if there is any indication that a cyber-attack caused the problem. This second research focus aims to improve the assessment of the security states of these systems by developing the foundations towards an industrial security operations center to help operators identify the root cause (accident or cyber-attack) of alerts.There is a large body of work focusing on interdependent security with models of firms participating in protection and insurance markets. Most of the security models and economic interdependent investment formulations focus solely on information technology infrastructures, and are meant to model cybercriminal activities, where attackers are rational profit-driven agents and defenders experience constant security breaches allowing them to generate risk models based on data. In contrast, computer attacks to critical infrastructure systems represent a completely different set of malicious agents. These agents may not be profit-driven and will attack only sporadically. In addition, interdependent physical infrastructures are managed by federated agents, and cyber-attacks will have physical consequences extending the domain of the single firm attacked. This project leverages and extends the literature of investment in reliability for large-scale critical infrastructures as well as insurance, contracts between firms with interdependent assets, and extreme risk. The second research focus leverages the interest of the CPS industry in analyzing the data collected by sensor networks. Security Information and Event Managers (SIEM) solutions were designed for enterprise IT, and do not include, aggregate, and correlate the sensor data from the physical world. To mitigate this gap this proposal investigates how to aggregate information for a new system incorporating the data from control centers and those from security operations centers, laying thus the foundation to create an Industrial Security Operations Center (ISOC).
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Conference: Post-Alert: Data Attribution and Attack-Response
  • 批准号:
    2321134
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2023
  • 负责人:
    Alvaro Cardenas
  • 依托单位:
NSF Student Travel Grant for 2020 IEEE Symposium and Workshops on Security and Privacy
  • 批准号:
    2000427
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.5万
  • 财政年份:
    2020
  • 负责人:
    Alvaro Cardenas
  • 依托单位:
CPS: Medium: Collaborative Research: Security vs. Privacy in Cyber-Physical Systems
  • 批准号:
    1929410
  • 项目类别:
    Standard Grant
  • 资助金额:
    $63.48万
  • 财政年份:
    2019
  • 负责人:
    Alvaro Cardenas
  • 依托单位:
CAREER: Practical Control Engineering Principles to Improve the Security and Privacy of Cyber-Physical Systems
  • 批准号:
    1931573
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $45.33万
  • 财政年份:
    2019
  • 负责人:
    Alvaro Cardenas
  • 依托单位:
国内基金
海外基金
Improving modelling of compact binary evolution.
  • 批准号:
    10903001
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2009
  • 负责人:
    史蒂芬
  • 依托单位: