SaTC: CORE: Medium: After the Breach: Detecting Lateral Movement, Reconnaissance, and Exfiltration in Enterprise Networks
SaTC: CORE: Medium: After the Breach: Detecting Lateral Movement, Reconnaissance, and Exfiltration in Enterprise Networks
批准号:
2152644
负责人:
Stefan Savage
金额:
$120.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-06-01 至 2025-05-31
中文摘要
大规模数据泄露和勒索软件攻击已成为政府机构和企业面临的紧迫威胁。然而,区分这些事件的因素很少是最初获得未经授权访问的技术机制,而是获得这种访问后采取的有条理的行动。因此,虽然防止初始入侵的努力仍然很重要,但开发合理的方法来检测和阻止已经在组织内部运行的攻击者的行为显然同样重要。 该项目正是解决了这个问题:如何通过组织内部的操作来检测,识别和修复恶意行为者。为了实现这一目标,该项目的新奇之处在于开发了一个网络分析系统,以模拟计算机和网络事件的因果关系-在这种方式中,一台机器上发生的动作可以解释为攻击者从另一台机器转向,以追求组织中的更多访问。该项目更广泛的意义和重要性在于为评估检测和减轻企业规模数据泄露的最佳做法提供了一个有充分依据的严格基础。调查人员使用此类活动的推断因果图,开发和评估检测器,以获得内部侦察,横向移动和外部通信的证据。使用经验数据源和模拟器来测试一系列企业网络模型,研究人员探索了这种因果框架可以在多大程度上区分已知的攻击和发生的广泛的良性活动。 最后,该项目还评估了此类框架在分类和事故后响应方面的价值,消除了识别哪些机器和帐户可能受到损害的人工工作。该奖项反映了NSF的法定使命,并被认为值得通过使用基金会的知识价值和更广泛的影响审查标准进行评估来支持。
英文摘要
Large-scale data breaches and ransomware attacks have become a pressing threat for government agencies and corporations alike. However, what distinguishes these events is rarely the technical mechanisms by which unauthorized access was first obtained, but rather the methodical actions taken after gaining such access. Thus, while efforts to protect against initial intrusions remain important, it is clearly every bit as important to develop sound approaches for detecting and subduing the actions of attackers already operating inside an organization. This project tackles precisely this problem: how to detect, identify and remediate malicious actors via their operational actions inside an organization. To address this goal, the project’s novelty is in developing a network analysis system to model the causality of computer and network events – ways in which an action that occurred on one machine can be explained as an attacker pivoting from another machine in pursuit of increased access in an organization. The project’s broader significance and importance are in providing a well-founded rigorous basis for evaluating best practices for detecting and mitigating enterprise-scale data breaches.Using an inferred causal graph of such activities, the investigators develop and evaluate detectors for evidence of internal reconnaissance, lateral movement and external communication. Using both empirical data sources and a simulator for testing a range of enterprise network models, the investigators explore the extent to which this causal framework can distinguish known attacks from the broad range of benign activities that take place. Finally, the project also evaluates the value of such frameworks for both triage and post-incident response, removing the manual work involved in identifying which machines and accounts may have been compromised.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
The Challenges of Blockchain-based Naming Systems for Malware Defenders
基于区块链的命名系统对恶意软件防御者的挑战
DOI:
--
发表时间:
2022
期刊:
APWG Symposium on Electronic Crime Research (eCrime
影响因子:
--
作者:
[Randall, Audrey, Hardaker, Wes, Schulman, Aaron, Savage, Stefan, Voelker, Geoffrey M.]
通讯作者:
Voelker, Geoffrey M.
Retroactive Identification of Targeted DNS Infrastructure Hijacking
目标 DNS 基础设施劫持的追溯识别
DOI:
10.1145/3517745.3561425
发表时间:
2022
期刊:
Proceedings of the 22nd ACM Internet Measurement Conference
影响因子:
--
作者:
[Akiwate, Gautam, Sommese, Raffaele, Jonker, Mattijs, Durumeric, Zakir, Claffy, KC, Voelker, Geoffrey M., Savage, Stefan]
通讯作者:
Savage, Stefan
SaTC: CORE: Medium: Large-Scale Characterization of DNS Abuse
-
批准号:1705050
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2017
-
负责人:Stefan Savage
-
依托单位:
TWC: Frontier: Collaborative: Beyond Technical Security: Developing an Empirical Basis for Socio-Economic Perspectives
-
批准号:1237264
-
项目类别:Continuing Grant
-
资助金额:$466.6万
-
财政年份:2012
-
负责人:Stefan Savage
-
依托单位:
TC: Medium: Collaborative Research:Foundations, Architectures, and Methodologies for Secure and Private Cyber-physical Vehicles
-
批准号:0963702
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2010
-
负责人:Stefan Savage
-
依托单位:
Collaborative Research: CT-M: Understanding and Exploiting Economic Incentives in Internet-based Scams
-
批准号:0831138
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2008
-
负责人:Stefan Savage
-
依托单位:
Collaborative Research: Cybertrust Center for Internet Epidemiology and Defenses
-
批准号:0433668
-
项目类别:Continuing Grant
-
资助金额:$310.0万
-
财政年份:2004
-
负责人:Stefan Savage
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: