课题基金 / 基金详情

Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening

Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
通过定量威胁建模和网络强化提高计算基础设施抵御零日攻击的弹性
批准号:
RGPIN-2017-06686
负责人:
Wang, Lingyu
金额:
$1.89万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2019
资助国家:
加拿大
项目状态:
已结题
起止时间:
2019-01-01 至 2020-12-31

项目摘要

项目成果

Wang, Lingyu的其他基金

相似基金

相关文献

中文摘要
翻译
今天的计算基础设施在企业、政府或军事组织以及关键基础设施(如电网)中扮演着神经系统的角色。然而,计算基础设施安全漏洞的规模和严重程度持续以越来越快的速度增长,许多引人注目的安全事件证明了这一点,例如最近由Mirai僵尸网络引起的大规模DDoS攻击,以及2015年对乌克兰电网的网络物理攻击,使超过23万居民陷入黑暗。所谓的零日攻击,利用以前未知或未修补的漏洞,通常是这些安全事件的背后(例如,震网利用四个不同的零日漏洞来攻击工业控制系统)。因此,超越传统的防御方法来评估和提高计算基础设施抵御潜在零日攻击的弹性是很重要的。大多数现有的威胁建模、安全度量和网络加固解决方案都是基于已知的现有漏洞,不适用于零日攻击。在这样的背景下,拟议的研究计划旨在开发一系列用于建模、测量和减轻零日攻击的新技术,并将这些技术应用于关键任务计算基础设施,如数据中心、企业网络和关键基础设施,以提高它们对零日攻击的弹性。******具体来说,我们研究计划的长期目标是开发一系列技术来理解(威胁建模)、测量(安全度量)和减轻(网络加固)零日攻击的风险,并将这些技术应用于特定的计算基础设施。我们最初的努力将集中于开发两种特定的安全指标和网络加固方法,然后将它们应用于两种特定的计算基础设施,即云和SCADA系统。具体而言,短期目标如下:将攻击面概念从软件层面提升到网络层面,设计了新的安全度量,并通过与已知漏洞的相关性对度量进行验证。将漏洞发现模型与k-零日安全度量标准集成,开发基于历史数据的预测模型,用于估计未来零日攻击的风险。根据这些安全指标、实际成本模型和优化技术开发网络强化解决方案,以确定给定成本约束下的最佳解决方案。通过考虑云数据中心和SCADA系统的独特特征(例如,云中物理和虚拟组件的共存以及SCADA以毫秒为单位测量的时间),将度量和强化解决方案应用于云数据中心和SCADA系统。
英文摘要
Today's computing infrastructures are playing the role of nerve systems in enterprises, governmental or military organizations, and critical infrastructures, such as power grids. However, the scale and severity of security breaches in computing infrastructures have continued to grow at an ever-increasing pace, which is evidenced by many high profile security incidents, such as the recent large scale DDoS attacks caused by the Mirai Botnet and the cyber-physical attack on Ukraine power grid in 2015 which left more than 230,000 residents in the dark. The so-called zero day attacks, which exploit previously unknown or unpatched vulnerabilities, are usually behind such security incidents (e.g., Stuxnet employs four different zero day vulnerabilities to target an industrial control system). Therefore, going beyond traditional defense approaches to evaluate and improve the resilience of computing infrastructures against potential zero day attacks is important. Most existing solutions for threat modeling, security metrics, and network hardening are based on known facts about existing vulnerabilities and are not applicable to zero day attacks. In such a context, the proposed research program aims to develop a series of novel techniques for modeling, measuring, and mitigating zero day attacks, and to apply such techniques to mission critical computing infrastructures, such as data centers, enterprise networks, and critical infrastructures, in order to improve their resilience against zero day attacks. ******Specifically, the long term objective of our research program is to develop a series of techniques for understanding (threat modeling), measuring (security metrics), and mitigating (network hardening) the risk of zero day attacks, and to apply such techniques to specific computing infrastructures. Our initial efforts will be focused on developing two specific security metrics and network hardening methods, and then apply those to two specific computing infrastructures, i.e., cloud and SCADA systems. Specifically, the short-term objectives are as follows. Design a new security metric by lifting the attack surface concept from software level to network level, and validate the metric through its correlation with known vulnerabilities. Integrate vulnerability discovery models with the k-zero day safety metric to develop a predictive model for estimating the future risk of zero day attacks based on historical data. Develop network hardening solutions based on those security metrics, realistic cost models, and optimization techniques to determine the optimal solutions under given cost constraints. Apply the metrics and hardening solutions to cloud data centers and SCADA systems by considering the unique characteristics of such infrastructures (e.g., the co-existence of physical and virtual components in cloud and the timelineness measured in milliseconds for SCADA).
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2022
  • 负责人:
    Wang, Lingyu
  • 依托单位:
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2020
  • 负责人:
    Wang, Lingyu
  • 依托单位:
海外基金