课题基金 / 基金详情

CISE-MSI: DP: SaTC: MSI Research Capacity Building for Artificial Intelligence (AI)-enabled Vulnerability Assessment and Remediation in Cyberinfrastructure

CISE-MSI: DP: SaTC: MSI Research Capacity Building for Artificial Intelligence (AI)-enabled Vulnerability Assessment and Remediation in Cyberinfrastructure
CISE-MSI:DP:SaTC:MSI 针对网络基础设施中人工智能 (AI) 启用的漏洞评估和修复的研究能力建设
批准号:
2219464
负责人:
Roberto Mejias
金额:
$60.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-08-01 至 2025-07-31
关键词:

项目摘要

项目成果

Roberto Mejias的其他基金

相似基金

相关文献

中文摘要
翻译
该奖项的全部或部分资金来自《2021年美国救援计划法案》(公共法律117-2)。联邦机构和亚马逊网络服务等公共云提供商已投资数百万美元开发高性能计算资源,以支持高影响的计算工作流。用户通过带有开源软件的虚拟机(VM)和应用程序容器(例如Docker)等技术访问这些高级资源,这些开源软件往往包含多个不同严重程度的漏洞。尽管漏洞扫描程序可以帮助发现这些威胁,但安全从业者很难有效地评估、排定优先级并进行补救,因为扫描程序通常会在多个虚拟环境中返回数十万个结果。该项目将创建一个新的启用人工智能(AI)的框架,以(1)检测漏洞并自动跨多个维度的漏洞数据对易受攻击的VM进行优先排序,以及(2)将从扫描仪发现的漏洞与已披露的漏洞联系起来,以确定合适的补救策略。这两个项目的推进将实现云基础设施的自动化漏洞评估分析。项目成果将通过在学术和行业出版场所传播知识以及纳入网络安全和数据分析课程,促进网络安全、深度学习和文本分析方面的发展。此外,这项工作将实现网络安全与人工智能分析教育和研究经验的独特结合,为两个西班牙裔服务机构中代表性不足的人口提供教育和研究经验,从而促进下一代网络安全专业人员的发展。这项研究利用从团队的NSF资助的合作伙伴组织收集的全面开源软件和漏洞数据集,促进设计一个由两个新颖且相互关联的研究推动力组成的新型人工智能启用的漏洞评估和补救(AI-VAR)框架。第一个重点结合并扩展了网络科学、多视图表示学习、自动编码器和注意力机制的原则,以在云基础设施中创建易受攻击的VM组以确定优先顺序,而第二个重点利用自我监督的对比表示学习和转换器中的最新方法,从漏洞扫描描述中捕获文本特征,并将发现的漏洞与包含补救策略的已披露漏洞联系起来。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This award is funded in whole or in part under the American Rescue Plan Act of 2021 (Public Law 117-2).Federal agencies and public cloud providers such as Amazon Web Services have invested millions of dollars developing high-performance computing resources to support high-impact computational workflows. Users access these advanced resources through technologies such as virtual machines (VMs) and application containers (e.g., Docker) with open-source software that often contains multiple vulnerabilities at different severity levels. Although vulnerability scanners can help aid in the discovery of these threats, security practitioners struggle to effectively assess, prioritize, and remediate them since scanners often return hundreds of thousands of results across multiple virtual environments. This project will create a novel artificial intelligence (AI) enabled framework to (1) detect vulnerabilities and automatically prioritize vulnerable VMs across multiple dimensions of vulnerability data, and (2) link the discovered vulnerabilities from scanners with disclosed vulnerabilities to identify suitable remediation strategies. The two project thrusts will enable automated vulnerability assessment analytics for cloud infrastructures. Project outcomes will contribute to developments in cybersecurity, deep learning, and text analytics through the dissemination of knowledge at academic and industry publication venues as well as integration into cybersecurity and data analytics curricula. Moreover, this work will enable a unique combination of cybersecurity and AI analytics education and research experience for underrepresented demographics across two Hispanic Serving Institutions, and thereby foster the development of the next generation of cybersecurity professionals.This research leverages comprehensive open-source software and vulnerability datasets collected from the team’s NSF-funded partner organizations to facilitate the design of a novel AI-enabled Vulnerability Assessment and Remediation (AI-VAR) framework that consists of two novel and interconnected research thrusts. The first thrust combines and extends principles from network science, multi-view representation learning, autoencoders, and attention mechanisms to create groups of vulnerable VMs in cloud infrastructures for prioritization, while the second thrust draws upon state-of-the-art methods in self-supervised contrastive representation learning and transformers to capture textual features from vulnerability scan descriptions and link discovered vulnerabilities with disclosed vulnerabilities that contain remediation strategies.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Developing a Technology, Cyber Security, and Culturally Inclusive Pathway to Increase Student Participation and Persistence in STEM
  • 批准号:
    1953699
  • 项目类别:
    Standard Grant
  • 资助金额:
    $181.15万
  • 财政年份:
    2020
  • 负责人:
    Roberto Mejias
  • 依托单位:
国内基金
海外基金
MSI2 通过 YTHDF2 介导的m6A 修饰调控CD48/CD244 信号通路促进急性髓系白血病免疫逃逸的机制研究
  • 批准号:
    ZCLQN26H0801
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
    李帆帆
  • 依托单位:
RhoBTB2-Cul3-RBX1介导MSI2泛素化导致儿童神经发育障碍的机制研究
  • 批准号:
    2025JJ60695
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    陈施梦
  • 依托单位:
从GPR81/HIF-1 α驱动的MDSC代谢重塑联 合DESI-MSI/AFM策略探讨紫草多糖抑制 CRC进程的药效物质结构和作用机制
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2025
  • 负责人:
    邵萌
  • 依托单位:
微卫星不稳定性(MSI)检测试剂盒(基于8个MSI位点、荧光PCR-毛细管电泳法)在结直肠癌真实世界中的应用评价
  • 批准号:
    25SF1906300
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    周晓燕
  • 依托单位: