Oxford University Centre for Doctoral Training in Cyber Security
Oxford University Centre for Doctoral Training in Cyber Security
批准号:
EP/K035606/1
负责人:
金额:
$468.34万
依托单位:
依托单位国家:
英国
项目类别:
Training Grant
财政年份:
2013
资助国家:
英国
项目状态:
已结题
起止时间:
2013 至 --
中文摘要
CDT的绝大多数研究将符合以下列出的四个主题,无论是专注于应用领域还是基础研究挑战。这些代表着显著的应用领域和新兴的网络安全目标,综合起来涵盖了当今社会面临的一些最紧迫的网络安全挑战1。大数据的安全性涵盖了在各种环境中获取、管理和利用数据的过程。安全和隐私问题经常出现在这里--而且可能相互冲突--以及公共政策和经济问题。不仅必须装点新出现的安全挑战,还必须考虑到重大的技术和设计挑战,预见因数据的数量和形式而产生的新的潜在攻击媒介,如去匿名化风险的增加。这项研究的一个主要应用领域是医学研究,因为以前预期的公共数据、研究和临床背景之间的界限正在瓦解:在基因组数据的处理、自主数据收集和个人健康数据的共同管理方面。网络物理安全考虑数字和物理环境的集成和交互,以及它们的新兴安全属性;特别是与传感器、移动设备、物联网和智能电网相关的安全属性。通过这种方式,我们使用位置和时间等物理信息来增强传统的安全性,从而实现了新的安全模型。应用领域包括关键基础设施监测、交通运输和辅助生活。有效的系统验证和保证。这个主题的核心是利用牛津在用于硬件和软件验证、安全性证明和协议验证的形式化建模和抽象方法方面的长期优势。它还必须解决采购和供应链管理中的问题,以及犯罪学和恶意软件分析、高保证系统和系统架构。实时安全出现在面向用户的工具和面向网络的工具中。基于用户行为的持续身份验证与常见的一次性身份验证方法相比,侵入性更小,效率更高。不断发展的访问控制允许根据过去的行为而不是静态的策略做出决定。有效地使用视觉分析和机器学习可以增强这些方法,并应用于网络安全管理、异常检测和动态重新配置。这些文章以不同的方式归功于一个综合的态势感知目标。这些主题与大学许多现有的研究优势相联系,并将它们的视野扩展到技术迅速崛起并引发紧迫的网络安全问题的领域。该提案得到了广泛相关行业的大力支持,惠普实验室、Sophos、诺基亚、巴克莱、Citrix、英特尔、IBM、微软英国、洛克希德·马丁、泰利斯和马尔文中小企业网络安全集群所附的支持信就是明证。
英文摘要
The great majority of the CDT's research will fit into the four themes listed below, whether focussed upon application domains or on underpinning research challenges. These represent both notable application areas and emerging cyber security goals, and taken together cover some of the most pressing cyber security challenges our society faces today.1. Security of 'Big Data' covers the acquisition, management, and exploitation of data in a wide variety of contexts. Security and privacy concerns often arise here - and may conflict with each other - together with issues for public policy and economic concerns. Not only must emerging security challenges be ad-dressed, new potential attack vectors arising from the volume and form of the data, such as enhanced risks of de-anonymisation, must be anticipated - having regard to major technical and design challenges. A major application area for this research is in medical re-search, as the formerly expected boundaries between public data, research, and clinical contexts crumble: in the handling of genomic data, autonomous data collection, and the co-management of personal health data.2. Cyber-Physical Security considers the integration and interaction of digital and physical environments, and their emergent security properties; particularly relating to sensors, mobile devices, the internet of things, and smart power grids. In this way, we augment conventional security with physical information such as location and time, enabling novel security models. Applications arise in critical infrastructure monitoring, transportation, and assisted living.3. Effective Systems Verification and Assurance. At its heart, this theme draws on Oxford's longstanding strength in formal methods for modelling and abstraction applied to hardware and software verification, proof of security, and protocol verification. It must al-so address issues in procurement and supply chain management, as well as criminology and malware analysis, high-assurance systems, and systems architectures.4. Real-Time Security arises in both user-facing and network-facing tools. Continuous authentication, based on user behaviour, can be less intrusive and more effective than commonplace one-time authentication methods. Evolving access control allows decisions to be made based on past behaviour instead of a static policy. Effective use of visual analytics and machine learning can enhance these approaches, and apply to network security management, anomaly detection, and dynamic reconfiguration. These pieces con-tribute in various ways to an integrated goal of situational awareness.These themes link to many existing research strengths of the University, and extend their horizon into areas where technology is rapidly emerging and raising pressing cyber security concerns. The proposal has strong support from a broad sweep of relevant industry sectors, evidenced by letters of support attached from HP Labs, Sophos, Nokia, Barclays, Citrix, Intel, IBM, Microsoft UK, Lockheed Martin, Thales, and the Malvern Cyber Security Cluster of SMEs.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金