课题基金 / 基金详情

CRII: SaTC: RUI: An Intelligent Data-Driven Framework to Achieve Proactive Cybersecurity

CRII: SaTC: RUI: An Intelligent Data-Driven Framework to Achieve Proactive Cybersecurity
CRII:SaTC:RUI:实现主动网络安全的智能数据驱动框架
批准号:
2246220
负责人:
Ericsson Santana Marin
金额:
$17.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-04-15 至 2025-03-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
黑客越来越多地在黑暗网络的地下世界分享网络攻击部署的信息。在这些隐藏和匿名的环境中,网络犯罪分子讨论如何1)识别软件漏洞,2)创建或购买利用漏洞,3)选择目标并招募合作者,4)访问所需的基础设施,以及5)计划和执行攻击。尽管这种行为帮助黑客制造了大量恶意软件,但它也为防御者提供了宝贵的情报,因为在线共享的信息可以被用作各种类型网络威胁的前兆。该项目依赖于主动的网络威胁情报分析,解决了以下关键研究问题:能否准确地预测上述正在出现的网络威胁?随着对黑客通信的不断检索和分析,这项研究将揭示可用于建立网络威胁预测的恶意黑客的资产、能力、行为和兴趣。为此,正在调查两个更细粒度的问题。这些调查构成了该项目的新颖性,也是设计更好的网络防御系统的关键因素。首先,软件漏洞利用的预测是通过分类技术进行的,该技术将黑客在黑客论坛和市场上的数字痕迹以及安全建议与现实世界的黑客企图相关联。然后,对积极的预测(即,它将被利用)进行排序,以确定补丁的优先级,从而克服了该领域的机器学习工作没有解决的两个当前缺陷:1)预测的利用缺乏区分,2)缺乏预测的时间间隔。其次,还执行了对恶意信息级联的预期,这些恶意信息可能会以病毒的比例传播。这里,利用社交网络分析的分类技术被用来提取黑客拓扑信息并估计社会影响力,预测黑客论坛中包含的哪些技术、策略或利用在不久的将来可能被广泛采用。这两个项目的努力都将导致预测具有时间敏感性的网络威胁的新技术,使防御者在对抗攻击者方面有更好的机会。项目交付成果、数据和模型将通过安全社区传播。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Information for cyber-attack deployment has been increasingly shared by hackers on the underground world of the darkweb. In those hidden and anonymous environments, cyber criminals discuss how to 1) identify software vulnerabilities, 2) create or purchase exploits, 3) choose a target and recruit collaborators, 4) obtain access to the infrastructure needed, and 5) plan and execute the attack. Although this behavior helps hackers to produce a huge amount of malware, it also provides valuable intelligence for defenders, as the information shared online can be leveraged as precursors to various types of cyber threats. By relying on proactive cyber-threat intelligence analysis, this project addresses the following key research question: can emerging cyber-threats be accurately and aforesaid predicted? With continuous retrieval and analysis of hacker communication, this research will shed light on the assets, capabilities, behaviors, and interests of malicious hackers that can be leveraged for establishing cyber threat prediction.To accomplish that, two finer-grained problems are being investigated. These investigations constitute the project’s novelties and are key factors for the design of better cyber-defense systems. First, the prediction of software vulnerability exploitation is conducted through classification techniques that correlate hackers' digital traces on hacker forums and marketplaces, and security advisories with real- world hacking attempts. The positive predictions (i.e., it will be exploited) are then ranked for patch prioritization, overcoming two current shortcomings not addressed by machine learning work in this domain: 1) the lack of differentiation of the predicted exploitation and 2) the lack of time interval for predictions. Second, the anticipation of malicious information cascades that might propagate to viral proportions is also performed. Here, classification techniques leveraging social network analysis are used to extract hacker topological information and to estimate social influence, predicting which techniques, strategies, or exploits included in hacking forums might be widely adopted in the near future. Both project efforts will lead to new techniques to predict cyber threats that are time sensitive, giving defenders a better chance in the fight against attackers. The project deliverables, data and models, will be disseminated through the security community.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3639362
发表时间: 2024-01
期刊: ACM Computing Surveys
影响因子: 16.6
作者: [Jack Hughes;Sergio Pastrana;Alice Hutchings;Sadia Afroz;Sagar Samtani;Weifeng Li;Ericsson Santana Marin]
通讯作者: Jack Hughes;Sergio Pastrana;Alice Hutchings;Sadia Afroz;Sagar Samtani;Weifeng Li;Ericsson Santana Marin
海外基金