CICI: UCSS: Enhancing the Usability of Vulnerability Assessment Results for Open-Source Software Technologies in Scientific Cyberinfrastructure: A Deep Learning Perspective
CICI: UCSS: Enhancing the Usability of Vulnerability Assessment Results for Open-Source Software Technologies in Scientific Cyberinfrastructure: A Deep Learning Perspective
批准号:
2319325
负责人:
Hsinchun Chen
金额:
$60.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-08-01 至 2026-07-31
中文摘要
联邦政府资助的科学网络基础设施(CI)加速了突破性的科学发现,包括黑洞成像、基因组测序、疫苗发现等。然而,有助于促进这些发现的开源软件(OSS)技术通常包含数千个漏洞,如果加以利用,可能会威胁到不可替代的科学分析。由于科学ci通常缺乏管理这些漏洞的人员,他们越来越多地将漏洞管理任务外包给第三方研究和教育安全提供商,如OmniSOC。然而,这些提供商的安全分析师经常面临着管理ci的OSS资产中存在的成千上万个漏洞的挑战。该项目扫描数千个科学CI OSS资产的漏洞,并采用新颖的人工智能分析来(1)管理科学CI中的OSS资产漏洞,(2)将它们与修复策略联系起来。漏洞扫描和分析结果集成到一个新颖的漏洞管理系统中,该系统允许安全分析师在科学ci中搜索、排序、浏览和协作漏洞数据和补救策略。该项目设计了一种新颖的人工智能支持的AZSecure可用和协作安全科学框架,该框架扫描四个主要类别的开源软件(OSS)资产(虚拟机,容器,基础设施即代码和GitHub)中的漏洞,跨越两个主要的NSF资助的科学网络基础设施(ci):(1) CyVerse用于生命科学和(2)Jetstream, NSF的第一个科学和工程云NSF和NIH。漏洞扫描支持三套启用人工智能的分析研究重点,以增强OmniSOC安全分析师的漏洞扫描结果的可用性。第一,通过多视图学习,结合漏洞严重性加权方案和新的组合关注机制,将OSS资产和漏洞数据聚合到漏洞管理任务的嵌入中。第二种方法使用自监督学习和转换,通过叠加多个词嵌入,并将漏洞严重程度评分与一种新的对比损失函数对齐,将漏洞扫描与补救策略联系起来。最后的重点是开发一个漏洞管理系统,该系统集成了扫描结果并使分析人员能够操作这些方法。项目执行包括为来自亚利桑那大学(NSA/DHS CD-, R-和共同指定)和IU (NSA/DHS CD-和R-指定)的NSF网络军团奖学金服务研究生提供角色。研究结果通过学术和行业出版物传播,并整合到亚利桑那大学和印第安纳大学排名第一的网络安全硕士项目中。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Federally funded scientific cyberinfrastructure (CI) has accelerated ground-breaking scientific discoveries, including black hole imaging, genome sequencing, vaccine discovery, and more. However, the open-source software (OSS) technologies that help facilitate these discoveries often contain thousands of vulnerabilities that, if exploited, could threaten irreplaceable scientific analysis. Since scientific CIs often lack the personnel to manage these vulnerabilities, they increasingly outsource their vulnerability management tasks to third-party Research & Education security providers such as OmniSOC. However, security analysts at these providers often face challenges managing the tens of thousands of vulnerabilities present in OSS assets at CIs. This project scans thousands of scientific CI OSS assets for vulnerabilities and employs novel Artificial Intelligence-enabled analytics to (1) manage OSS asset vulnerabilities in scientific CI and (2) link them to their remediation strategies. Vulnerability scan and analytics results are integrated into a novel Vulnerability Management System that allows security analysts search, sort, browse, and collaborate on vulnerability data and remediation strategies across scientific CIs.This project designs a novel Artificial Intelligence-enabled AZSecure Usable and Collaborative Security for Science Framework that scans for vulnerabilities in four major categories of open-source software (OSS) assets (virtual machines, containers, infrastructure-as-code, and GitHub) across two major NSF-funded scientific cyberinfrastructures (CIs): (1) CyVerse for life sciences and (2) Jetstream, NSF’s first Science and Engineering Cloud for NSF and NIH. The vulnerability scans support three sets of AI-enabled analytics research thrusts to enhance the usability of vulnerability scan results for OmniSOC’s security analysts. The first thrust aggregates OSS asset and vulnerability data into an embedding for vulnerability management tasks through multi-view learning incorporating a vulnerability severity weighting scheme and a novel combinatorial attention mechanism. The second thrust uses self-supervised learning and transformers to link vulnerability scans with remediation strategies by stacking multiple word embeddings and aligning vulnerability severity scores with a novel contrastive loss function. The final thrust develops a Vulnerability Management System that integrates scan results and enables analysts to operate the methods. Project execution includes roles for NSF CyberCorps Scholarship-for-Service graduate students from UArizona (NSA/DHS CD-, R, and CO-designated) and IU (NSA/DHS CD- and- R-designated). Findings are disseminated through academic and industry publications and integrated into the top-ranked MS in Cybersecurity programs at UArizona and IU.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
EAGER: SaTC-EDU: Artificial Intelligence and Cybersecurity Research and Education at Scale
-
批准号:2038483
-
项目类别:Standard Grant
-
资助金额:$29.77万
-
财政年份:2020
-
负责人:Hsinchun Chen
-
依托单位:
SaTC: CORE: Small: Cybersecurity Big Data Research for Hacker Communities: A Topic and Language Modeling Approach
-
批准号:1936370
-
项目类别:Standard Grant
-
资助金额:$51.06万
-
财政年份:2019
-
负责人:Hsinchun Chen
-
依托单位:
CICI: SSC: Proactive Cyber Threat Intelligence and Comprehensive Network Monitoring for Scientific Cyberinfrastructure: The AZSecure Framework
-
批准号:1917117
-
项目类别:Standard Grant
-
资助金额:$99.8万
-
财政年份:2019
-
负责人:Hsinchun Chen
-
依托单位:
Cybersecurity Scholarship-for-Service Renewal at The University of Arizona:The AZSecure SFS Program
-
批准号:1921485
-
项目类别:Continuing Grant
-
资助金额:$358.55万
-
财政年份:2019
-
负责人:Hsinchun Chen
-
依托单位:
EAGER: A Longitudinal Study of Knowledge Diffusion and Societal Impact of Nanomanufacturing Research & Development: Harnessing Data for Science and Engineering
-
批准号:1832926
-
项目类别:Continuing Grant
-
资助金额:$15.84万
-
财政年份:2018
-
负责人:Hsinchun Chen
-
依托单位:
Cybersecurity Big Data and Analytics Sharing Platform
-
批准号:1719477
-
项目类别:Standard Grant
-
资助金额:$18.0万
-
财政年份:2017
-
负责人:Hsinchun Chen
-
依托单位:
EAGER: A Systems Approach for Identification and Evaluation of Nanoscience and Nanomanufacturing Opportunities and Risks
-
批准号:1442116
-
项目类别:Standard Grant
-
资助金额:$24.79万
-
财政年份:2014
-
负责人:Hsinchun Chen
-
依托单位:
CIF21 DIBBs: DIBBs for Intelligence and Security Informatics Research Community
-
批准号:1443019
-
项目类别:Standard Grant
-
资助金额:$149.95万
-
财政年份:2014
-
负责人:Hsinchun Chen
-
依托单位:
SBE TTP: Medium: Securing Cyber Space: Understanding the Cyber Attackers and Attacks via Social Media Analytics
-
批准号:1314631
-
项目类别:Standard Grant
-
资助金额:$119.07万
-
财政年份:2013
-
负责人:Hsinchun Chen
-
依托单位:
Cybersecurity Scholarship-for-Service at The Unive
-
批准号:1303362
-
项目类别:Continuing Grant
-
资助金额:$422.73万
-
财政年份:2013
-
负责人:Hsinchun Chen
-
依托单位:
EAGER: Two Decades of Nanotechnology Development: Global Competitive Landscape and Knowledge Diffusion via ERGM and SIR Analysis
-
批准号:1249210
-
项目类别:Standard Grant
-
资助金额:$29.84万
-
财政年份:2012
-
负责人:Hsinchun Chen
-
依托单位:
EAGER: Long-term View on Nanotechnology R&D as Reflected in Scientific Papers, Patents, and NSF Awards
-
批准号:1057624
-
项目类别:Standard Grant
-
资助金额:$27.95万
-
财政年份:2010
-
负责人:Hsinchun Chen
-
依托单位:
EAGER:Unveiling Trends in Global Nanotechnology Research and Development
-
批准号:0926270
-
项目类别:Standard Grant
-
资助金额:$25.03万
-
财政年份:2009
-
负责人:Hsinchun Chen
-
依托单位:
SGER: Inter-Repository Patent Analysis to Understand Worldwide Nanotechnology Research and Development
-
批准号:0738803
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Hsinchun Chen
-
依托单位:
EXP-LA: Explosives and IEDs in the Dark Web: Discovery, Categorization, and Analysis
-
批准号:0730908
-
项目类别:Standard Grant
-
资助金额:$79.74万
-
财政年份:2007
-
负责人:Hsinchun Chen
-
依托单位:
CRI: CRD - Developing a Dark Web Collection and Infrastructure for Computational and Social Sciences
-
批准号:0709338
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2007
-
负责人:Hsinchun Chen
-
依托单位:
International Conference on Intelligence and Security Informatics (ISI 2006)
-
批准号:0636210
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:Hsinchun Chen
-
依托单位:
Arizona Biosurveillance Workshops
-
批准号:0636637
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:Hsinchun Chen
-
依托单位:
SGER: Multilingual Online Stylometric Authorship Identification: An Exploratory Study
-
批准号:0646942
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:Hsinchun Chen
-
依托单位:
SGER: Worldwide Nanotechnology Development: A Comparative Study of Global Patents
-
批准号:0654232
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:Hsinchun Chen
-
依托单位:
海外基金