CAREER: SaTC: Bridging the Gap Between Research and Practice: Automation and Metrics in Security Operation Centers
CAREER: SaTC: Bridging the Gap Between Research and Practice: Automation and Metrics in Security Operation Centers
批准号:
2143393
负责人:
Alexandru Bardas
金额:
$52.43万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-06-01 至 2027-05-31
中文摘要
安全运营中心(SOC)是工业、学术界和政府部门现代企业网络的核心实体。组织通常部署SOC来管理其网络运营、防御网络空间中的威胁并维护法规遵从性。自动化和指标在SOC环境的有效性中起着关键作用。不幸的是,SOC中的安全驱动的自动化通常是以特别的方式实现的,并没有准确地反映在指标中。尽管SOC环境正在应对不断变化的威胁,但其企业网络上的IT系统和SOC程序是相当静态的。当前的SOC指标倾向于关注直接的量化测量(例如,关闭票据的数量),而没有准确地评估人工分析师在自动化过程中的作用。该项目的创新之处包括创建了一个SOC框架,该框架支持针对操作环境进行量身定制的以安全为重点的自动化,评估人类在此过程中的角色,并在指标中反映结果。该项目更广泛的意义和重要性集中在触发当前攻击者操作模式的重大变化上,并将SOC的格局从所有防御需要成功,转变为所有攻击需要成功才能保持持久访问--将局面扭转到对手身上。此外,该项目通过将研究成果整合到网络安全课程中来提供课程增强的机会,为学生提供参与安全操作研究的机会,从而支持网络安全研究或专业人员的职业生涯。在技术方面,该项目探索了功能丰富的DevOps/DevSecOps方法在动态操作环境中的集成,以建立安全基线。在这种情况下,DevOps和DevSecOps是在与网络安全相关的设置中结合软件开发和IT运营的实践集。在人力资本方面,研究团队采用社会技术方法来研究组织环境,通过分析人和技术人工制品作为交互组件来研究组织环境。该项目取代了部分的、社会的或技术的方法,将研究和教育成果整合在一起,使它们相互补充。该项目包括一个人种学的SOC实地工作部分、为实现安全基线而设计的多段抽象、从SOC分析员到基础设施程序员过渡的分析部分,以及跨不同环境的SOC框架部分的评价工作。结果通过出版物、演示文稿/教程和在线资源广泛传播。总体而言,该项目的结果将发展SOC可用的手段,显著增加攻击者的负担,降低他们危害企业网络的能力。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Security Operation Centers (SOCs) are pivotal entities of modern enterprise networks in industry, academia, and the government sector. Organizations usually deploy SOCs to manage their network operations, defend against threats in the cyber space, and maintain regulatory compliance. Automation and metrics play key roles in the effectiveness of SOC environments. Unfortunately, security-driven automation in SOCs is often implemented in ad-hoc ways and is not accurately reflected in the metrics. Even though SOC environments are dealing with constantly changing threats, IT systems on their enterprise networks and SOC procedures are fairly static. Current SOC metrics tend to focus on straight-forward quantitative measurements (e.g., number of closed tickets) while the role of human analysts in the automation process is not accurately assessed. This project's novelties include the creation of a SOC framework that enables tailored security-focused automation for operational environments, assesses the role of humans in this process, and reflects the outcomes in the metrics. The project's broader significance and importance are focused on triggering a major change in the current attacker mode of operation and shift the SOC landscape from all defenses need to be successful, to all attacks need to be successful to maintain persistent access -- "turning the tables" on adversaries. Moreover, this project provides opportunities for curriculum enhancements via integrating research results in cybersecurity courses, affords an opportunity for students to participate in research on security operations, and thereby supports careers in cybersecurity research or professions.On the technical side, this project explores the integration of the feature-rich DevOps/DevSecOps approaches in dynamic operational environments to establish security baselines. In this context DevOps and DevSecOps are sets of practices that combine software development and IT operations in cybersecurity-related setups. On the human capital side, the research team adopts a sociotechnical approach to study organizational environments by analyzing people and technological artifacts as interacting components. In place of partial, social or technical approaches, the project integrates research and education outcomes so they feed into each other. The project includes an ethnographic SOC fieldwork component, designing multi-segment abstractions for enabling security baselines, an analysis component of the SOC analyst to infrastructure programmer transition, and an evaluation effort of the SOC framework components across different environments. Results are broadly disseminated via publications, presentations/tutorials, and online resources. Overall, the outcomes of this project will evolve the means available to SOCs to significantly increase the burden on attackers and lower their capabilities to compromise enterprise networks.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CRII: SaTC: Creating and Managing Structurally-Morphing IT Systems - Moving Targets
-
批准号:1850406
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2019
-
负责人:Alexandru Bardas
-
依托单位:
EAGER: SaTC: Early-Stage Interdisciplinary Collaboration: Collaborative: A Sociotechnical Metrics Framework for Network and Security Operations Centers
-
批准号:1915824
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2019
-
负责人:Alexandru Bardas
-
依托单位:
海外基金