课题基金 / 基金详情

SaTC: CORE: Small: Scalable and Meaningful Threat Intelligence Generation

SaTC: CORE: Small: Scalable and Meaningful Threat Intelligence Generation
SaTC:核心:小型:可扩展且有意义的威胁情报生成
批准号:
1717062
负责人:
Damon McCoy
金额:
$49.21万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-15 至 2021-07-31

项目摘要

项目成果

Damon McCoy的其他基金

相似基金

相关文献

中文摘要
翻译
威胁情报被组织用来通过检测和阻止与已知攻击者系统的通信来保护系统和最终用户。高质量的威胁情报还可以提供检测攻击者工具的方法,这些工具通常不像他们的攻击基础设施那么短暂。不幸的是,产生高质量的威胁情报往往是一个高度手动和低效的过程。这导致有用的威胁情报数量有限,只能提供给那些负担得起的公司。这项研究开发了新的数据分析方法来识别攻击者的基础设施和攻击工具。我们的方法利用高效收集大量原始攻击者数据的能力,对其进行处理,并构建人工智能技术来发现攻击模式。该项目提高了生成高质量威胁情报数据的效率,并使更多公司能够负担得起。要实现这一提高生成有用威胁情报效率的目标,需要在几个关键挑战上取得进展。该项目(I)研究基于监督机器学习的方法,高效地从攻击者那里收集大规模数据,(Ii)改进存储这些数据和其他免费可用的原始威胁情报数据的方法,以便可以轻松地连接这些数据,(Iii)识别可以从这些原始数据中提取的健壮特征,这些特征可以用于培训监督机器学习检测技术,以及(Iv)能够高性能和高效地生成大规模有用的威胁情报数据。因此,本研究具有改变威胁情报数据生成方式的潜力,并通过使威胁情报更容易访问来提高组织的安全性。这项工作还为本科生和研究生创造了许多教育机会,让他们利用数据分析技术获得经验,有效地检测新出现的威胁并提高组织的安全性。
英文摘要
Threat intelligence is used by organizations to protect systems and end-users by detecting and blocking communications with known attackers' systems. Quality threat intelligence can also provide methods of detecting attackers' tools, which are often less ephemeral than their attack infrastructure. Unfortunately, producing quality threat intelligence is often a highly manual and inefficient process. This has resulted in limited amounts of useful threat intelligence which is available only to those companies that can afford it. This research develops new data-analytics methods to identify an attacker's infrastructure and attack tools. Our methods leverage the ability to efficiently collect large amounts of raw attacker data, process it, and build artificial intelligence techniques to discover attack patterns. This project improves the efficiency of generating high quality threat intelligence data, and makes it more affordable to a large range of companies. Achieving this goal of improving the efficiency of generating useful threat intelligence requires progress on several key challenges. The project (i) investigates supervised machine learning based methods for efficiently collected large-scale amounts of data from attackers, (ii) improves methods for storing this data and other freely available raw threat intelligence data such that it can be easily joined, (iii) identifies robust features that can be extracted from this raw data which can be used for training supervised machine learning detection techniques, and (iv) enables high performance and efficient generation of large-scale useful threat intelligence data. Consequently, this research has the potential to transform the way in which threat intelligence data is produced and improve the security of organizations by making threat intelligence more accessible. This work also creates many educational opportunities for undergraduate and graduate students to gain experience using data-analytics techniques to efficiently detect emerging threats and improve the security of organizations.
期刊论文(11)
专著(0)
科研奖励(0)
会议论文
Clinical Computer Security for Victims of Intimate Partner Violence
亲密伴侣暴力受害者的临床计算机安全
DOI: --
发表时间: 2019
期刊: 28th USENIX Security Symposium
影响因子: --
作者: [Havron, Sam, Freed, Diana, Chatterjee, Rahul, McCoy, Damon, Dell, Nicola, Ristenpart, Thomas]
通讯作者: Ristenpart, Thomas
A Security Analysis of the Facebook Ad Library
Facebook 广告库的安全分析
DOI: 10.1109/sp40000.2020.00084
发表时间: 2020
期刊: 2020 IEEE Symposium on Security and Privacy (SP
影响因子: --
作者: [Edelson, Laura, Lauinger, Tobias, McCoy, Damon]
通讯作者: McCoy, Damon
DOI: --
发表时间: 2019
期刊:
影响因子: --
作者: [Arman Noroozian;J. Koenders;Eelco van Veldhuizen;C. Gañán;Sumayah A. Alrwais;Damon McCoy;M. V. Eeten]
通讯作者: Arman Noroozian;J. Koenders;Eelco van Veldhuizen;C. Gañán;Sumayah A. Alrwais;Damon McCoy;M. V. Eeten
DOI: --
发表时间: 2018
期刊:
影响因子: --
作者: [Mohammad Rezaeirad;Brown Farinholt;Hitesh Dharmdasani;P. Pearce;Kirill Levchenko;Damon McCoy]
通讯作者: Mohammad Rezaeirad;Brown Farinholt;Hitesh Dharmdasani;P. Pearce;Kirill Levchenko;Damon McCoy
共 8 条
    Collaborative Research: SaTC: CORE: Medium: Understanding and Combatting Impersonation Attacks and Data Leakage in Online Advertising
    • 批准号:
      2247516
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $40.0万
    • 财政年份:
      2023
    • 负责人:
      Damon McCoy
    • 依托单位:
    Collaborative Research: SaTC: CORE: Medium: Methods and Tools for Effective, Auditable, and Interpretable Online Ad Transparency
    • 批准号:
      2151837
    • 项目类别:
      Standard Grant
    • 资助金额:
      $38.37万
    • 财政年份:
      2022
    • 负责人:
      Damon McCoy
    • 依托单位:
    D-ISN: TRACK 1: Collaborative Research: An Interdisciplinary Approach to Understanding, Modeling, and Disrupting Drug and Counterfeit Illicit Supply Chains
    • 批准号:
      2039693
    • 项目类别:
      Standard Grant
    • 资助金额:
      $35.0万
    • 财政年份:
      2020
    • 负责人:
      Damon McCoy
    • 依托单位:
    NSF Student Travel Grant for 2020 Privacy Enhancing Technologies Symposium (PETS)
    • 批准号:
      2022209
    • 项目类别:
      Standard Grant
    • 资助金额:
      $1.8万
    • 财政年份:
      2020
    • 负责人:
      Damon McCoy
    • 依托单位:
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: