SaTC: CORE: Small: Scalable Cyber Attack Investigation using Declarative Queriesand Interrogative Analysis
SaTC: CORE: Small: Scalable Cyber Attack Investigation using Declarative Queriesand Interrogative Analysis
批准号:
2028748
负责人:
Xusheng Xiao
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2024-09-30
中文摘要
最近利用多重漏洞的网络攻击甚至困扰着保护最严密的公司。这导致了这样的解决方案:无处不在地监视作为一系列系统事件的系统活动,并通过将事件及其对攻击的依赖关系重构为依赖关系图,应用因果关系分析来揭示攻击步骤。然而,现有的技术主要利用事件时间来识别依赖关系。这将包括许多不重要的依赖关系,这些依赖关系是由不相关的系统活动带来的。此外,由于有限的可扩展性,这些技术不能很容易地合并来自安全分析人员的专业知识,并且为安全分析人员积极探索依赖关系提供很少的支持。该项目预计将通过使用系统审计日志加强攻击调查,并提供上下文信息,帮助入侵检测系统更好地优先考虑警报,从而对系统安全产生重大的积极影响。该项目积极让少数民族和代表性不足群体的学生参与研究和培训经验。该建议的目标是开发一个通用的查询框架,通过从系统审计日志中构造攻击相关事件的小图来表达和提取上下文攻击信息。该项目主要集中在以下研究任务上:(1)建立一个通用的基础设施,根据系统事件的各种属性计算依赖关系的判别权重,以识别与攻击相关的事件和攻击的入口点;(2)开发一种声明性图查询语言,提供专门的语言结构来表达各种格式的因果关系分析;(3)设计一个可扩展的疑问分析框架,该框架可以通过跟踪验证和假设场景的表达性因果结构来自动澄清因果分析,并采用新的“为什么”和“如果”语义。该项目将推动从复杂系统中揭示攻击来源的最新技术,使安全分析人员参与到交互式和可解释的安全分析管道中,并更好地理解构建有效攻击调查系统的基本和实际挑战。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Recent cyber-attacks that exploit multiple vulnerabilities plague even the most protected companies. This has led to the solutions that ubiquitously monitor system activities as a series of system events, and apply causality analysis to reveal the attack steps through reconstructing the events and their dependencies on the attack as dependency graphs. Nevertheless, existing techniques mainly exploit event time to identify dependencies. This will include many less-important dependencies brought by irrelevant system activities. Moreover, these techniques cannot easily incorporate expert knowledge from security analysts due to limited extensibility, and provide little support to engage security analysts to actively explore the dependencies. The project is expected to make a major positive impact on system security by enhancing attack investigation using system audit logs, and provide contextual information to help intrusion detection systems better prioritize alerts. The project actively involves students from minority and underrepresented groups for research and training experiences. The goal of this proposal is to develop a general query framework to express and extract contextual attack information, by constructing small graphs of attack-relevant events from system audit logs. The project is focused on the following research tasks: (1) build a general infrastructure that computes discriminative weights for dependencies based on various properties of system events to identify attack-relevant events and entry points for attacks; (2) develop a declarative graph query language that provides specialized language constructs to express various formats of causality analysis; (3) devise a scalable interrogative analysis framework that can automatically clarify causality analysis by tracking expressive causal structures for both verified and hypothetical scenarios, enabled by new ``Why'' and ``What-if'' semantics. This project will advance the state of the art in revealing attack provenance from complex systems, on engaging security analysts to interactive and explainable security analytical pipelines, and to gain better understanding of the fundamental and practical challenges for building an effective attack investigation system.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1109/sp46214.2022.9833632
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Zhiqiang Xu;Pengcheng Fang;Changlin Liu;Xusheng Xiao;Yu Wen;Dan Meng]
通讯作者:
Zhiqiang Xu;Pengcheng Fang;Changlin Liu;Xusheng Xiao;Yu Wen;Dan Meng
Back-Propagating System Dependency Impact for Attack Investigation
攻击调查的反向传播系统依赖性影响
DOI:
--
发表时间:
2022
期刊:
USENIX Security Symposium
影响因子:
--
作者:
[Fang, Pengcheng, Gao, Peng, Liu, Changlin, Ayday, Erman, Jee, Kangkook, Wang, Ting, Ye, Yanfang, Liu, Zhuotao, Xiao, Xusheng]
通讯作者:
Xiao, Xusheng
CAREER: Enhancing Mobile Application Security through Contextual Integrity and User Awareness
-
批准号:2318483
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2023
-
负责人:Xusheng Xiao
-
依托单位:
Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis
-
批准号:2221842
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2022
-
负责人:Xusheng Xiao
-
依托单位:
Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis
-
批准号:2318486
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2022
-
负责人:Xusheng Xiao
-
依托单位:
CAREER: Enhancing Mobile Application Security through Contextual Integrity and User Awareness
-
批准号:2046953
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2021
-
负责人:Xusheng Xiao
-
依托单位:
CRII: SaTC: Enhancing Mobile App Security by Detecting Icon-Behavior Contradiction
-
批准号:1755772
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2018
-
负责人:Xusheng Xiao
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: