EAGER: A Framework For Economical Cyber Security Inspection and Assurance
EAGER: A Framework For Economical Cyber Security Inspection and Assurance
批准号:
1912166
负责人:
Theodore Allen
金额:
$30.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-03-15 至 2022-02-28
中文摘要
该项目旨在开发和应用智能检测方法,以保持网络安全的低成本,同时确保科学成果的安全性。许多其他行业使用统计抽样和序贯检验方法来保证质量。然而,目前许多网络安全依赖于对给定类型的项目的100%(例如最高优先级域名服务器日志)或0%(例如许多类型的可能的硬件检查)的尝试检查。该项目与俄亥俄州立大学和威斯康星大学这两所主要大学合作,开发了根据网络安全目标量身定做的新检查方法。具体目标涉及硬件、网络软件漏洞、日志检查以及应急管理和相关科学研究。该项目探讨了这些新方法对高级质量专业人员的有用性,以支持广泛采用。通过更聪明而不是更努力地工作,使用这种方法的科学家可以更有信心地认为他们的结果是可信的,同时,成本曲线可以弯曲,以便研究可以保持成本竞争力。具体地说,该项目以概率方式对安全指标进行建模,并开发测试模式来估计这些指标。这项研究解决了各种领域和网络安全挑战:(1)超级计算日志和硬件检查;(2)普通部门漏洞采样和评估以及改进的日志和采样(侧重于科学基础设施);(3)资源丰富的部门分层采样硬件、改进的漏洞决策和战略日志生成和采样;以及(4)UW应急管理系统中心。将探索攻击防御和标准质量保证的指标,并将其作为技术的验证输出。该项目力求通过制定一个保证框架,使现有的质量控制和保证方法适应和推广到数字领域,从而满足重要的安全需要。保证框架提供了许多优势:它可以处理顺序决策,它可以寻求对不确定数据具有健壮性的解决方案,并且它平衡了成本和威胁减少。拟研究的检验方法包括多重完全检验和检验员检验、尝试100%检验和最优补充、分层抽样、序贯抽样和最优多保真检验。在每种情况下,都将开发和应用运行特性曲线和系统完整性的其他估计。拟议方法的一个关键和独特的元素是多种检查方法的组合,包括新方法,以提供一个全面的框架,以经济高效地增强完整性。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project seeks to develop and apply smart inspection methods to keep the costs of cyber security low, while ensuring the security of scientific results. Many other industries use statistical sampling and sequential inspection methods for quality assurance. Yet, at present much of cyber security relies on attempted inspection of either 100% of items of a given type (such as top priority domain name server logs) or 0% (such as many types of possible hardware inspections). Working across two major universities, Ohio State University and the University of Wisconsin, the project develops new inspection methods, tailored to cyber security objectives. Specific objectives relate to hardware, cyber software vulnerabilities, log inspection, and emergency management and related scientific research. The project explores the usefulness of these new methods to senior quality professionals to support widespread adoption. By working smarter and not harder, scientists using this approach can feel more confident that their results are trustworthy, and, at the same time, the cost curve can be bent so that research can remain cost-competitive.Specifically, the project models security metrics probabilistically and develops patterns of testing to estimate these metrics. The research addresses a variety of domains and cyber security challenges: (1) supercomputing log and hardware inspections, (2) ordinary department vulnerability sampling and estimation and improved logging and sampling (focusing on scientific infrastructure), (3) highly resourced department stratified sampling hardware, improved vulnerability decision-making, and strategic log generation and sampling, and (4) the UW Emergency Management system center. Metrics from attack-defend and standard quality assurance will be explored and serve as validation outputs for the techniques. This project seeks to meet the vital security needs by formulating an assurance framework that adapts and extends existing methods in quality control and assurance to the cyber domain. The assurance framework offers many advantages: it can address sequential decision-making, it can seek solutions that are robust to uncertain data, and it balances cost with threat reduction. The inspection methods to be studied include Multiple Complete Inspection & Inspector Inspection, Attempted 100% Inspection with Optimal Supplementation, Stratified Sampling, Sequential Sampling, and Optimal Multi-Fidelity Inspection. In each case, operating characteristic curves and other estimates of system integrity will be developed and applied. A key and unique element of the proposed approach is the combination of multiple inspection methods, including new methods, to provide a comprehensive framework for cost-effectively enhancing integrity.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1002/asmb.2487
发表时间:
2019-10
期刊:
Applied Stochastic Models in Business and Industry
影响因子:
1.4
作者:
[Enhao Liu;T. Allen;Sayak Roychowdhury]
通讯作者:
Enhao Liu;T. Allen;Sayak Roychowdhury
DOI:
10.1016/j.cie.2019.106243
发表时间:
2020-02
期刊:
Comput. Ind. Eng.
影响因子:
--
作者:
[T. Allen;Muer Yang;Shijie Huang;Olivia K. Hernandez]
通讯作者:
T. Allen;Muer Yang;Shijie Huang;Olivia K. Hernandez
DOI:
10.1287/deca.2020.0412
发表时间:
2020-05
期刊:
Decis. Anal.
影响因子:
--
作者:
[T. Allen;Olivia K. Hernandez;A. Alomair]
通讯作者:
T. Allen;Olivia K. Hernandez;A. Alomair
DOI:
10.1080/24725854.2020.1781306
发表时间:
2020-07
期刊:
IISE Transactions
影响因子:
2.6
作者:
[Forough Enayaty-Ahangar;Laura A. Albert;E. Dubois]
通讯作者:
Forough Enayaty-Ahangar;Laura A. Albert;E. Dubois
The Ohio State Model For ICS Cybersecurity
俄亥俄州 ICS 网络安全模型
DOI:
10.1109/icmiam54662.2021.9715206
发表时间:
2021
期刊:
2021 International Conference on Maintenance and Intelligent Asset Management (ICMIAM
影响因子:
--
作者:
[Allen, Theodore T., McCarty, John, Feng, Tu, Tseng, Shih-Hsien, Buck, Vimal, Pardee, Robert]
通讯作者:
Pardee, Robert
共 7 条
SBE: TTP Option: Medium: Data-Driven Cyber Vulnerability Maintenance
-
批准号:1409214
-
项目类别:Standard Grant
-
资助金额:$59.45万
-
财政年份:2014
-
负责人:Theodore Allen
-
依托单位:
海外基金