课题基金 / 基金详情

CAREER: Critical Infrastructure Resiliency through Robust Provenance and Information Sharing

CAREER: Critical Infrastructure Resiliency through Robust Provenance and Information Sharing
职业:通过可靠的来源和信息共享实现关键基础设施的弹性
批准号:
2239609
负责人:
Deepak Tosh
金额:
$49.21万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-06-01 至 2028-05-31

项目摘要

项目成果

Deepak Tosh的其他基金

相似基金

相关文献

中文摘要
翻译
关键的国家基础设施包括各种网络物理组件,用于监视和控制对人类生活和社会有直接影响的复杂操作。在使关键的国家基础设施现代化的努力中,先进的传感器和通信技术在提高其运作效率和提供对人类无法接近的物理过程的更详细的了解方面发挥着重要作用。然而,这有可能危及操作技术的安全性,并扩大网络威胁范围,从而为底层数据、设备和物理过程提供了网络利用的机会。该项目研究如何设计一个开销感知的来源框架,在关键基础设施中整合隐式本地弹性,以确保数据和操作的可信度,同时通过持续的轻量级身份验证阻止恶意设备。为了进一步提高整个关键基础设施部门的网络弹性,本项目还探讨了设计分布式信息共享模型,以促进互惠并降低网络利用风险。除了研究贡献外,该项目还有一个紧密整合的教育计划,包括在下一代工程师中开发关键基础设施安全技能,为初中和高中教师提供暑期培训,以在课堂上引起网络安全兴趣,并向地区和国家利益相关者传播新的关键基础设施安全知识。该项目的成果对关键基础设施部门的运营商具有重要价值,有助于他们更好地了解和及时合作解决潜在的网络挑战。随着越来越多的具有网络能力的操作技术组件被部署,使操作环境变得复杂、相互依赖和高度异构,在关键的国家基础设施中实现抵御新兴网络威胁的弹性提出了重大挑战。该项目特别侧重于通过两个主要目标来增强操作技术的网络弹性:首先,设计开销感知溯源机制,关键基础设施实体可以在本地采用该机制,以具有针对各种网络攻击的隐式弹性。来源方案确保在操作技术环境中由各种物理过程产生的数据的可信度,同时准确识别相关设备并确保物理过程所造成的状态变化的完整性。其次,通过设计分布式网络信息共享机制,发展整个社区的网络弹性,使不同的利益相关者能够协作并有效地交流其网络知识,以主动防御国家网络基础设施。通过计算机科学、网络安全、工业和系统工程、嵌入式系统、经济学和博弈论的跨学科研究组成部分,该项目有助于理解数据和过程来源对网络弹性的有效性、设备可信度持续轻量级认证的集成挑战、网络信息共享对运营技术整体风险态势的影响。信息共享中诱导互惠的因素。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Critical national infrastructures encompass a variety of cyber physical components to monitor and control complex operations that has direct impact to human lives and our society. In the efforts of modernizing the critical national infrastructures, advanced sensor and communication technologies are playing an important role in enhancing their operational efficiency and offering finer view on the human inaccessible physical processes. However, this has potential to jeopardize the security of the operational technology and expand the cyber threat landscape, which opens opportunities of cyber exploitation to the underlying data, devices, and the physical processes. This project investigates how to devise an overhead aware provenance framework to incorporate implicit local resiliency in the critical infrastructure that assures data and operational trustworthiness while thwarting rogue devices through continuous lightweight authentications. To further enhance the cyber resiliency of the critical infrastructure sector as a whole, this project also explores on designing distributed information sharing models that promotes reciprocity and reduces the risks of cyber exploitation. In addition to the research contributions, this project has a tightly integrated education plan which involves developing critical infrastructure security skill sets among next generation engineers, summer training for the middle and high school teachers to induce cybersecurity interests in their classrooms and disseminating new critical infrastructure security knowledge to regional and national stakeholders. The outcomes of the project have significant value to the operators of the critical infrastructure sector to better understand and address the underlying cyber challenges in a timely and collaborative manner.Achieving resilience in critical national infrastructures against emerging cyber threats poses a significant challenge as more and more network capable operational technology components are being deployed, making the operational environment complex, interdependent, and highly heterogeneous. This project particularly focuses on enhancing cyber resiliency of the operational technology through two major objectives: First, devise overhead aware provenance mechanisms that the critical infrastructure entities can adopt locally to have an implicit resiliency against diverse cyber attacks. The provenance schemes ensure trustworthiness of the data generated from various physical processes in the operational technology environment, while accurately identifying the associated devices and assuring the integrity of state changes made by the physical processes. Second, develop community wide cyber resilience by designing distributed cyber information sharing mechanisms that allows disparate stakeholders to collaborate and effectively communicate their cyber knowledge for proactively defending the national cyber infrastructure. With the interdisciplinary research components from computer science, cybersecurity, industrial and systems engineering, embedded systems, economics, and game theory, this project contributes to the understanding of the effectiveness of data and process provenance for cyber resiliency, the integration challenges of continuous lightweight authentication for device trustworthiness, the impact of cyber information sharing on overall risk posture of operational technology, and the factors contributing to induce reciprocity in information sharing.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
RET Site: Cybersecurity Research Experience for Educators through Data Science (CREEDS)
  • 批准号:
    2206982
  • 项目类别:
    Standard Grant
  • 资助金额:
    $60.0万
  • 财政年份:
    2022
  • 负责人:
    Deepak Tosh
  • 依托单位:
海外基金