课题基金 / 基金详情

Intelligence-driven Cyber Security Defense Tools

Intelligence-driven Cyber Security Defense Tools
情报驱动的网络安全防御工具
批准号:
RGPIN-2014-05208
负责人:
Ghorbani, Aliakbar
金额:
$1.89万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2017
资助国家:
加拿大
项目状态:
已结题
起止时间:
2017-01-01 至 2018-12-31

项目摘要

项目成果

Ghorbani, Aliakbar的其他基金

相似基金

相关文献

中文摘要
翻译
调查显示,由于基础设施系统各个层面的安全违规行为,估计每年的负担在130亿至1.6万亿美元之间。随着这一问题的严重性,与安全相关的问题被推到了企业和政府关注的前沿,迫使专家们寻找全面而智能的系统安全解决方案。目前,缺乏可靠和全面的实用安全评估和管理工具,使人们能够了解紧急威胁对系统的影响,并制定全面和积极主动的解决方案来保护基础设施。这方面的另一个重大挑战是,成熟和已经广泛使用的分析办法和方法处理与系统安全状况有关的大量数据的能力,以及它们提取有助于立即预防和缓解事故的情报和相关信息的能力。未来五年,我们将重点推进智能驱动的网络安全防御研究,识别和开发一批模型、方法、技术和工具库,以了解突发威胁对系统的影响(S),并开发全面和主动的解决方案来保护基础设施。拟议研究的目标是通过对威胁采取更全面的方法,建立更有见地的观点,减少发生灾难性事件的可能性。我们认为,只有在收集、组织、分析、关联和利用企业内与安全相关的所有信息时,才能生成有效和可操作的情报。我们将专注于开发:1.恶意软件分析:网络空间中的恶意软件数量和僵尸网络活动每年都以前所未有的速度增长,再加上快速变化的威胁格局(即移动计算、社交网络的发展),揭示了主要基于对有据可查的威胁(签名)的识别的传统方法的严重不足。由于网络空间的有效防御需要对恶意软件威胁进行准确的评估和识别,因此我的研究活动将集中在以下几个方面:威胁分析、威胁归属和威胁检测。这方面的主要兴趣之一将是移动恶意软件和僵尸网络威胁。大数据安全分析:在安全领域,事件日志提供了丰富的信息来源,可用于分析攻击和系统故障的剖析,通常会准确指出薄弱环节和潜在的解决方案。在这一领域,我的研究目标是:1)大规模系统中安全数据的动态识别/构建和预测分析,主要目标是提高不断出现新的特别格式的领域专家的工作效率;以及2)大规模安全数据的预测分析,目的是开发预测分析方法,通过模拟攻击的影响和管理员引入的潜在网络变化/缓解策略来实现网络安全的全面分析。3.安全可视化:安全可视化应该具有优雅和视觉吸引力的设计,同时具有信息性、互动性和探索性功能。这方面的一个根本挑战是在大数据现象存在的情况下传统可视化技术的可扩展性。我们在这方面的研究重点在于解决这一挑战,即设计和开发一个可扩展的可视化系统,该系统能够应对不断增长的数据量,同时为用户提供交互体验。
英文摘要
Surveys suggest an estimated annual burden of between $13 billion and $1.6 trillion as a result of security violations in various dimensions of infrastructure systems. With the magnitude of this problem, security related issues were brought to the forefront of enterprise and government concerns and forced experts to search for comprehensive and intelligent solutions for systems’ security. Currently, there is a lack of sound and comprehensive tools for practical security assessment and management that allow the understanding of an impact of emergent threats on a system and the development of comprehensive and proactive solutions to safeguard an infrastructure. Another major challenge in this respect is the capability of well-established and already widely-used analytical approaches and methodologies to cope with the wealth of data pertinent to a system’s security status and their ability to extract intelligent and relevant information useful for an immediate incident prevention and mitigation. Over the next five years we will focus on advancing research in intelligent-driven cyber security defense by identifying and developing a bank of models, methodologies, techniques, and tools for understanding the impact(s) of emergent threats on a system and developing a comprehensive and proactive solutions to safeguard an infrastructure. The goal of the proposed research is to reduce the likelihood of catastrophic incidents by taking a holistic approach in creating a more informed view of threats. We believe that effective and actionable intelligence can be generated only when all information within an enterprise with security relevance gets collected, organized, analyzed, correlated, and leveraged. We will focus on developing:1. Malware Analysis: Unprecedented growth in malware numbers and botnet activity in cyberspace each year, coupled with a rapidly changing threat landscape (i.e., evolution of mobile computing, social networks) revealed an acute inadequacy of traditional approaches predominantly based on recognition of well-documented threats (signatures). Since an effective defense in cyber space requires accurate assessment and recognition of malware threats, my research activities will focus on several areas: threats analysis, threat attribution and threat detection. One of the main interests in this context will be mobile malware and botnet threats.2. Big Data Security Analytics: In security domain event logs provide a rich source of information that allows to analyze the anatomy of attacks and system failures often pinpointing weak spots and potential solutions. In this area my research objectives are: 1) dynamic recognition/structuring and predictive analytics for security data in large-scale systems, with the primary goal of improving the productivity of domain experts that are challenged with constantly appearing of new ad hoc formats; and, 2) Predictive analytics for large-scale security data, with the aim of developing predictive analytic methods to allow a comprehensive analysis of network security through modeling impacts of attacks and potential network changes/mitigation strategies introduced by an administrator. 3. Security Visualization: Security visualizations should have an elegant and visually appealing design, while being informative, interactive, and providing exploratory capabilities. One of the fundamental challenges in this respect is scalability of conventional visualization techniques in the presence of Big Data phenomenon. Our research focus in this direction lies in addressing this challenge, i.e., to design and develop a scalable visualization system able to cope with ever-increasing amounts of data while providing an interactive experience to a user.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Human-Centric Cybersecurity
  • 批准号:
    RGPIN-2020-04121
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.99万
  • 财政年份:
    2022
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
Cybersecurity
  • 批准号:
    CRC-2015-00106
  • 项目类别:
    Canada Research Chairs
  • 资助金额:
    $14.57万
  • 财政年份:
    2022
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
Human-Centric Cybersecurity
  • 批准号:
    DGDND-2020-04121
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
  • 资助金额:
    $2.91万
  • 财政年份:
    2022
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
Human-Centric Cybersecurity
  • 批准号:
    RGPIN-2020-04121
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.99万
  • 财政年份:
    2021
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
国内基金
海外基金
Data-driven Recommendation System Construction of an Online Medical Platform Based on the Fusion of Information
基于Cache的远程计时攻击研究