课题基金 / 基金详情

Collaborative Research: SaTC: CORE: Small: Flanker: Automatically Detecting Lateral Movement in Organizations Using Heterogeneous Data and Graph Representation Learning

Collaborative Research: SaTC: CORE: Small: Flanker: Automatically Detecting Lateral Movement in Organizations Using Heterogeneous Data and Graph Representation Learning
协作研究:SaTC:核心:小型:侧翼:使用异构数据和图表示学习自动检测组织中的横向运动
批准号:
2127232
负责人:
Gianluca Stringhini
金额:
$25.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-10-01 至 2024-09-30

项目摘要

项目成果

Gianluca Stringhini的其他基金

相似基金

相关文献

中文摘要
翻译
在现代网络攻击中,攻击者不会针对单个计算机系统。 相反,他们首先在公司的网络中建立一个初步的立足点,然后通过损害其他资产来扩大他们的漏洞,直到他们到达组织内部的最终目标。这种推进计算机漏洞的过程被称为横向移动。检测横向移动具有挑战性,因为攻击者可以使用多个载体进行感染(例如,网络钓鱼电子邮件)和网络中的计算机系统呈现很大程度的多样性(例如,工作站、网络设备)。由于这个原因,目前没有有效检测横向移动的综合系统。然而,尽快发现和阻止计算机漏洞对于确保美国公司和公民的安全和繁荣至关重要。该项目的目的是通过开发Flanker来填补这一空白,Flanker是一种能够自动检测组织网络中横向移动的系统。与现有方法不同,Flanker的目标是在各种数据源上操作(例如,来自网络和应用程序的数据),以便能够检测跨组织内不同在线服务和计算机的网络攻击。该项目包括四个阶段。在第一阶段,研究人员从各种来源收集异构数据集,并开发技术来清除噪音,并将其匿名化以保护用户的身份。在第二阶段,这些数据被用来构建一个表示网络活动的图,图表示学习方法被用来为这个网络活动构建一个模型。在第三阶段,该模型用于通过应用异常检测或监督学习技术来自动检测横向移动攻击。最后,研究人员开发可视化技术,使安全分析人员能够正确理解检测结果,并采取适当的对策来应对攻击。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
In modern cyberattacks, adversaries do not target single computer systems. Instead, they first set an initial foothold into a company's network and later amplify their breach by compromising additional assets, until they reach their final target inside an organization. This process of advancing computer breaches is known as lateral movement. Detecting lateral movement is challenging, because attackers can use multiple vectors for infection (e.g., phishing emails) and computer systems in a network present a large degree of diversity (e.g., workstations, network equipment). For this reason, no comprehensive system to effectively detect lateral movement is currently available. Yet, detecting and stopping computer breaches as soon as possible is critical to ensure the safety and the prosperity of U.S. corporations and citizens. The aim of this project is to fill this gap by developing Flanker, a system able to automatically detect lateral movement in the network of an organization. Unlike existing approaches, the goal of Flanker is to operate on a variety of data sources (e.g., data coming from network and applications) to be able to detect cyberattacks as they span different online services and computers across the organization.This project consists of four phases. In the first phase the investigators collect heterogeneous datasets from a variety of sources and develop techniques to clean them from noise and anonymize them to protect the identity of users. In the second phase this data is used to build a graph that represents network activity, and graph representation learning approaches are used to build a model for this network activity. In the third phase this model is used to automatically detect lateral movement attacks, by either applying anomaly detection or supervised learning techniques. Finally, the investigators develop visualization techniques to enable a security analyst to properly understand the detection results and adopt appropriate countermeasures against the attack.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2023
期刊:
影响因子: --
作者: [Ioannis Angelakopoulos;G. Stringhini;Manuel Egele]
通讯作者: Ioannis Angelakopoulos;G. Stringhini;Manuel Egele
DOI: 10.1145/3538969.3544435
发表时间: 2022-08
期刊: Proceedings of the 17th International Conference on Availability, Reliability and Security
影响因子: --
作者: [François Labrèche;Enrico Mariconti;G. Stringhini]
通讯作者: François Labrèche;Enrico Mariconti;G. Stringhini
DOI: 10.1145/3548606.3560580
发表时间: 2022-09
期刊: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Mohammad Naseri;Yufei Han;Enrico Mariconti;Yun Shen;G. Stringhini;Emiliano De Cristofaro]
通讯作者: Mohammad Naseri;Yufei Han;Enrico Mariconti;Yun Shen;G. Stringhini;Emiliano De Cristofaro
DOI: 10.1145/3548606.3559358
发表时间: 2022-04
期刊: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Yun Shen;Yufei Han;Zhikun Zhang;Min Chen;Tingyue Yu;Michael Backes;Yang Zhang;G. Stringhini]
通讯作者: Yun Shen;Yufei Han;Zhikun Zhang;Min Chen;Tingyue Yu;Michael Backes;Yang Zhang;G. Stringhini
Collaborative Research: SaTC: TTP: Medium: iDRAMA.cloud: A Platform for Measuring and Understanding Information Manipulation
  • 批准号:
    2247868
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $49.43万
  • 财政年份:
    2023
  • 负责人:
    Gianluca Stringhini
  • 依托单位:
Collaborative Research: SaTC: CORE: Small: Detecting Accounts Involved in Influence Campaigns on Social Media
  • 批准号:
    2114407
  • 项目类别:
    Standard Grant
  • 资助金额:
    $28.0万
  • 财政年份:
    2021
  • 负责人:
    Gianluca Stringhini
  • 依托单位:
CAREER: Towards Data-Driven Methods to Counter Online Aggression
  • 批准号:
    1942610
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $54.93万
  • 财政年份:
    2020
  • 负责人:
    Gianluca Stringhini
  • 依托单位:
Inferring the Purpose of Network Activities
  • 批准号:
    EP/N008448/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $12.52万
  • 财政年份:
    2015
  • 负责人:
    Gianluca Stringhini
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)