课题基金 / 基金详情

Intelligence-driven Cyber Security Defense Tools

Intelligence-driven Cyber Security Defense Tools
情报驱动的网络安全防御工具
批准号:
RGPIN-2014-05208
负责人:
Ghorbani, Aliakbar
金额:
$1.89万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2018
资助国家:
加拿大
项目状态:
已结题
起止时间:
2018-01-01 至 2019-12-31

项目摘要

项目成果

Ghorbani, Aliakbar的其他基金

相似基金

相关文献

中文摘要
翻译
调查显示,由于基础设施系统各个方面的安全违规行为,估计每年的负担在130亿美元至1.6万亿美元之间。随着这一问题的严重性,与安全相关的问题被带到了企业和政府关注的最前沿,迫使专家们为系统安全寻找全面和智能的解决方案。目前,缺乏用于实际安全评估和管理的可靠和全面的工具,这些工具可以了解紧急威胁对系统的影响,并开发全面和主动的解决方案来保护基础设施。这方面的另一个主要挑战是,是否有能力利用行之有效和已经广泛使用的分析办法和方法来处理与系统安全状况有关的大量数据,以及是否有能力提取有助于立即预防和缓解事故的智能和相关信息。在接下来的五年里,我们将专注于推进智能驱动的网络安全防御研究,确定和开发一系列模型、方法、技术和工具,以了解紧急威胁对系统的影响,并开发全面、主动的解决方案来保护基础设施。拟议研究的目标是通过采取全面的方法来减少灾难性事件的可能性,以创建一个更明智的威胁视图。我们相信,只有当企业内与安全相关的所有信息都得到收集、组织、分析、关联和利用时,才能生成有效和可操作的情报。* * 我们将重点发展:** 1。恶意软件分析:每年网络空间中恶意软件数量和僵尸网络活动的空前增长,加上快速变化的威胁环境(即,移动的计算、社交网络)的发展揭示了主要基于识别有充分证据的威胁(签名)的传统方法的严重不足。由于网络空间的有效防御需要准确评估和识别恶意软件威胁,我的研究活动将集中在几个领域:威胁分析,威胁归因和威胁检测。在这种情况下,主要关注点之一是移动的恶意软件和僵尸网络威胁。** 2.大数据安全分析:在安全领域,事件日志提供了丰富的信息来源,可以分析攻击和系统故障的解剖结构,通常可以精确定位弱点和潜在的解决方案。在这个领域,我的研究目标是:1)大规模系统中安全数据的动态识别/结构化和预测分析,主要目标是提高领域专家的生产力,不断出现新的特设格式;以及,2)大规模安全数据的预测分析,其目的是开发预测分析方法,以允许通过对攻击的影响和管理员引入的潜在网络改变/缓解策略进行建模来全面分析网络安全。* * 三.安全可视化:安全可视化应该有一个优雅的和视觉上吸引人的设计,同时是信息,交互式的,并提供探索性的功能。在这方面的基本挑战之一是传统的可视化技术在大数据现象的存在下的可扩展性。我们在这一方向的研究重点在于应对这一挑战,即,设计和开发一种可扩展的可视化系统,该系统能够处理不断增加的数据量,同时向用户提供交互式体验。
英文摘要
Surveys suggest an estimated annual burden of between $13 billion and $1.6 trillion as a result of security violations in various dimensions of infrastructure systems. With the magnitude of this problem, security related issues were brought to the forefront of enterprise and government concerns and forced experts to search for comprehensive and intelligent solutions for systems' security. Currently, there is a lack of sound and comprehensive tools for practical security assessment and management that allow the understanding of an impact of emergent threats on a system and the development of comprehensive and proactive solutions to safeguard an infrastructure. Another major challenge in this respect is the capability of well-established and already widely-used analytical approaches and methodologies to cope with the wealth of data pertinent to a system's security status and their ability to extract intelligent and relevant information useful for an immediate incident prevention and mitigation. Over the next five years we will focus on advancing research in intelligent-driven cyber security defense by identifying and developing a bank of models, methodologies, techniques, and tools for understanding the impact(s) of emergent threats on a system and developing a comprehensive and proactive solutions to safeguard an infrastructure. The goal of the proposed research is to reduce the likelihood of catastrophic incidents by taking a holistic approach in creating a more informed view of threats. We believe that effective and actionable intelligence can be generated only when all information within an enterprise with security relevance gets collected, organized, analyzed, correlated, and leveraged. **We will focus on developing:**1. Malware Analysis: Unprecedented growth in malware numbers and botnet activity in cyberspace each year, coupled with a rapidly changing threat landscape (i.e., evolution of mobile computing, social networks) revealed an acute inadequacy of traditional approaches predominantly based on recognition of well-documented threats (signatures). Since an effective defense in cyber space requires accurate assessment and recognition of malware threats, my research activities will focus on several areas: threats analysis, threat attribution and threat detection. One of the main interests in this context will be mobile malware and botnet threats.**2. Big Data Security Analytics: In security domain event logs provide a rich source of information that allows to analyze the anatomy of attacks and system failures often pinpointing weak spots and potential solutions. In this area my research objectives are: 1) dynamic recognition/structuring and predictive analytics for security data in large-scale systems, with the primary goal of improving the productivity of domain experts that are challenged with constantly appearing of new ad hoc formats; and, 2) Predictive analytics for large-scale security data, with the aim of developing predictive analytic methods to allow a comprehensive analysis of network security through modeling impacts of attacks and potential network changes/mitigation strategies introduced by an administrator. **3. Security Visualization: Security visualizations should have an elegant and visually appealing design, while being informative, interactive, and providing exploratory capabilities. One of the fundamental challenges in this respect is scalability of conventional visualization techniques in the presence of Big Data phenomenon. Our research focus in this direction lies in addressing this challenge, i.e., to design and develop a scalable visualization system able to cope with ever-increasing amounts of data while providing an interactive experience to a user.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Human-Centric Cybersecurity
  • 批准号:
    RGPIN-2020-04121
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.99万
  • 财政年份:
    2022
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
Human-Centric Cybersecurity
  • 批准号:
    DGDND-2020-04121
  • 项目类别:
    DND/NSERC Discovery Grant Supplement
  • 资助金额:
    $2.91万
  • 财政年份:
    2022
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
Cybersecurity
  • 批准号:
    CRC-2015-00106
  • 项目类别:
    Canada Research Chairs
  • 资助金额:
    $14.57万
  • 财政年份:
    2022
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
Human-Centric Cybersecurity
  • 批准号:
    RGPIN-2020-04121
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.99万
  • 财政年份:
    2021
  • 负责人:
    Ghorbani, Aliakbar
  • 依托单位:
国内基金
海外基金
Data-driven Recommendation System Construction of an Online Medical Platform Based on the Fusion of Information
基于Cache的远程计时攻击研究