课题基金 / 基金详情

Defending Against Multi-Step Network Intrusions in large-scale computer networks

Defending Against Multi-Step Network Intrusions in large-scale computer networks
防御大规模计算机网络中的多步网络入侵
批准号:
341840-2007
负责人:
Wang, Lingyu
金额:
$1.57万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2009
资助国家:
加拿大
项目状态:
已结题
起止时间:
2009-01-01 至 2010-12-31

项目摘要

项目成果

Wang, Lingyu的其他基金

相似基金

相关文献

中文摘要
翻译
从长远来看,拟议的研究计划旨在开发自动解释和预测攻击者在保护计算机网络免受入侵方面的进度、策略和意图的技术。在短期内,研究将集中在可扩展和高效的知识表示和算法,以及用于防御大规模、分布式计算机系统中的多步骤入侵的实用系统的设计、实现和评估。更具体地说,拟议的研究计划将确定当前知识表示可扩展性差的根本原因,并通过提出表示有关漏洞和网络连接的知识的新方法来消除这一限制。这项研究将设计启发式算法来寻找加固网络的最小成本解决方案,并通过广泛的实验对设计的算法进行评估。它还将在一个集成框架中提出用于衡量风险、成本和抗攻击能力的安全指标,并根据建议的指标设计高效的算法来优化网络配置。最后,它将研究攻击图的分布式计算和分析,同时考虑可能禁止向其他方泄露漏洞信息的潜在本地安全策略。
英文摘要
In the long term, the proposed research program aims to develop techniques for automatically interpreting and predicting attackers' progress, strategies, and intentions in defending computer networks against intrusions. In the short term, the research will be focused on scalable and efficient knowledge representations and algorithms, and on the design, implementation, and evaluation of practical systems for defending against multi-step intrusions in large-scale, distributed computer systems. More specifically, the proposed research program will identify root causes to the poor scalability of current knowledge representation and remove the limitation by proposing novel ways of representing knowledge about vulnerabilities and network connectivity. The research will devise heuristic algorithms for finding minimum-cost solutions to harden a network and evaluate the devised algorithms through extensive experiments. It will also propose security metrics for measuring risks, costs, resistance to attacks in an integrated framework and design efficient algorithms for optimizing network configurations based on the proposed metrics. Finally, it will study the distributed computation and analysis of attack graphs while taking into consideration potential local security policies that may prohibit the disclosure of vulnerability information to other parties.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2022
  • 负责人:
    Wang, Lingyu
  • 依托单位:
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2020
  • 负责人:
    Wang, Lingyu
  • 依托单位:
海外基金