I-Corps: Trustworthy Cyberspace Through Data-Security as a Service.
I-Corps: Trustworthy Cyberspace Through Data-Security as a Service.
批准号:
1558967
负责人:
Mohit Tiwari
金额:
$5.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2016-02-29
中文摘要
数据泄露是社会进步的主要威胁。在金融、医疗保健和任何企业中使用计算机都需要保护敏感数据,使其不受未经授权的访问。然而,像摩根大通这样的银行,像国歌这样的医疗保险公司,以及塔吉特和家得宝这样的企业,一直是大规模数据泄露的目标,这些数据泄露造成了数百万美元的损失,侵蚀了用户的信任和声誉,在某些情况下,甚至让首席执行官丢掉了工作。随着我们将家庭、办公室和车辆连接到计算机,我们必须奠定保护敏感数据的安全基础。发生漏洞是因为数据在被应用程序使用时很容易受到攻击。一旦应用程序被利用,它就会被用来将敏感数据记录泄露给未经授权的用户。无论是通过HIPAA等法规来监管政策和流程,还是对静态和传输中的数据进行加密,都无法完全解决因应用程序受损而导致的此类漏洞。取而代之的是,引入了数据安全即服务。该团队的关键见解是,虽然现有的安全机制保护应用程序,但拟议的平台采取用户的访问控制策略,自动将它们转换为不受信任的应用程序上的信息流控制策略,并确保即使应用程序是恶意或受攻击的,它也不会将数据泄露给未经授权的用户或远程服务器。除了保护数据外,拟议的平台还让企业不必审查他们信任的每个敏感数据应用程序-这可能会为今天无法访问敏感数据的用户和企业释放许多创造性的应用程序。这个i-Corps团队已经联系了几个外部资源,这些资源将帮助团队实现所需的i-Corps目标和发现客户。这包括来自医院、平台提供商和医疗应用程序开发商的高层管理人员。
英文摘要
Data breaches are a major threat to societal progress. The use of computers in financial, healthcare, and in any business enterprise requires that sensitive data be protected from unauthorized access. However, banks like JP Morgan Chase, medical insurance companies like Anthem, and enterprises like Target and Home Depot have been the target of massive data breaches that have cost millions of dollars, eroded trust and reputation among users, and in some cases, even cost the chief executives their jobs. As we move towards wiring up homes, offices, and vehicles to computers, it is imperative that we lay a secure foundation that protects sensitive data.Breaches occur because data is vulnerable when in use by applications. Once an application is exploited, it is used to leak sensitive data records to an unauthorized user. Neither regulating policies and processes through regulations like HIPAA nor encrypting data at rest and in transit can fully address such breaches that stem from compromised apps. Instead, data-security as a service is introduced. The team's key insight is that while existing security mechanisms protect applications, the proposed platform takes users' access control policies, translates them into information flow control policies on untrusted apps automatically, and ensures that even if an app is malicious or compromised it cannot leak data to an unauthorized user or remote server. In addition to protecting data, the proposed platform frees enterprises from vetting each application they trust sensitive data to - this could unleash many creative apps for users and enterprises that today do not have access to sensitive data. This I-Corps team has been in touch with several external resources that will assist the team in accomplishing the required I-Corps objectives and customer discovery. This includes high-level executives from hospitals, platform providers, and medical application developers.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Collaborative: Oblivious ISAs for Secure and Efficient Enclave Programming
-
批准号:1817020
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2018
-
负责人:Mohit Tiwari
-
依托单位:
SaTC: CORE: Medium: Guarding Noisy Neighborhoods with Weak Detectors
-
批准号:1704778
-
项目类别:Standard Grant
-
资助金额:$119.39万
-
财政年份:2017
-
负责人:Mohit Tiwari
-
依托单位:
STTR Phase I: Building a Trustworthy Cyberspace through Data Security as a Service
-
批准号:1549833
-
项目类别:Standard Grant
-
资助金额:$22.5万
-
财政年份:2016
-
负责人:Mohit Tiwari
-
依托单位:
CAREER: Exo-Core: An Architecture to Detect Malware as Computational Anomalies
-
批准号:1453806
-
项目类别:Continuing Grant
-
资助金额:$52.27万
-
财政年份:2015
-
负责人:Mohit Tiwari
-
依托单位:
TWC: Medium: Collaborative: DIORE: Digital Insertion and Observation Resistant Execution
-
批准号:1314709
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2013
-
负责人:Mohit Tiwari
-
依托单位:
海外基金