课题基金 / 基金详情

Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening

Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
通过定量威胁建模和网络强化提高计算基础设施抵御零日攻击的弹性
批准号:
RGPIN-2017-06686
负责人:
Wang, Lingyu
金额:
$1.89万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2017
资助国家:
加拿大
项目状态:
已结题
起止时间:
2017-01-01 至 2018-12-31

项目摘要

项目成果

Wang, Lingyu的其他基金

相似基金

相关文献

中文摘要
翻译
当今的计算基础设施在企业、政府或军事组织以及关键基础设施(如电网)中扮演着神经系统的角色。然而,计算基础设施中安全漏洞的规模和严重性继续以不断增长的速度增长,这可以从许多备受瞩目的安全事件中得到证明,例如最近由米拉伊僵尸网络引起的大规模DDoS攻击以及2015年对乌克兰电网的网络物理攻击,这使得超过23万居民处于黑暗之中。所谓的零日攻击,利用以前未知或未修补的漏洞,通常是这种安全事件的背后(例如,Stuxnet使用四种不同的零日漏洞来攻击工业控制系统)。因此,超越传统的防御方法来评估和提高计算基础设施对潜在零日攻击的弹性非常重要。大多数现有的威胁建模、安全指标和网络加固解决方案都是基于现有漏洞的已知事实,不适用于零日攻击。在这样的背景下,拟议的研究计划旨在开发一系列新的技术建模,测量和减轻零日攻击,并将这些技术应用于使命关键计算基础设施,如数据中心,企业网络和关键基础设施,以提高其对零日攻击的弹性。
英文摘要
Today's computing infrastructures are playing the role of nerve systems in enterprises, governmental or military organizations, and critical infrastructures, such as power grids. However, the scale and severity of security breaches in computing infrastructures have continued to grow at an ever-increasing pace, which is evidenced by many high profile security incidents, such as the recent large scale DDoS attacks caused by the Mirai Botnet and the cyber-physical attack on Ukraine power grid in 2015 which left more than 230,000 residents in the dark. The so-called zero day attacks, which exploit previously unknown or unpatched vulnerabilities, are usually behind such security incidents (e.g., Stuxnet employs four different zero day vulnerabilities to target an industrial control system). Therefore, going beyond traditional defense approaches to evaluate and improve the resilience of computing infrastructures against potential zero day attacks is important. Most existing solutions for threat modeling, security metrics, and network hardening are based on known facts about existing vulnerabilities and are not applicable to zero day attacks. In such a context, the proposed research program aims to develop a series of novel techniques for modeling, measuring, and mitigating zero day attacks, and to apply such techniques to mission critical computing infrastructures, such as data centers, enterprise networks, and critical infrastructures, in order to improve their resilience against zero day attacks.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2022
  • 负责人:
    Wang, Lingyu
  • 依托单位:
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2020
  • 负责人:
    Wang, Lingyu
  • 依托单位:
海外基金