课题基金 / 基金详情

A Holistic Framework for Emerging Long-term Attacks Detection and Response Using Diverse Heterogeneous Data Sources

A Holistic Framework for Emerging Long-term Attacks Detection and Response Using Diverse Heterogeneous Data Sources
使用不同异构数据源检测和响应新兴长期攻击的整体框架
批准号:
RGPIN-2020-05321
负责人:
Traore, Issa
金额:
$2.55万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31

项目摘要

项目成果

Traore, Issa的其他基金

相似基金

相关文献

中文摘要
翻译
最近,人们发现一个国家支持的黑客组织多年来一直在渗透欧盟(EU)的外交通信网络,下载了数千份敏感电报。这次攻击持续了三年而未被发现,目标是100多个组织和机构,如联合国、外交部和财政部。这种攻击是一种新兴的威胁,由有针对性的和长期的攻击活动组成,这些攻击活动是由有明确目标的熟练黑客发起的,他们为实现目标而不懈地努力。由于黑客适应和逃避防御方法的能力,这些漏洞可以在很长一段时间内不被发现。值得注意的是,基于数量的攻击已经演变为类似于“低而慢”的隐形攻击。虽然容量攻击通常发生在设定的时间框架内,低和慢攻击依赖于持续的恶意请求流,没有明显的开始或结束;这使得当前的入侵检测系统(IDS)以及安全信息和事件管理(SIEM)工具对它们的检测具有挑战性。该研究计划的长期目标是通过使用更多样化的数据源,引领新一代安全数据分析技术的发展,这些数据源可以获得更好的威胁环境态势感知,并为网络事件归因和弹性部署可靠的解决方案。该研究计划的短期目标是开发一个新的框架,用于使用来自传统安全生态系统和组织外部的数据来检测、响应和调查长期攻击。该研究将利用大动态不确定多图理论连贯地表达和分析各种异构数据源的安全数据,并有意地将看似无害和不相关的事件联系起来,以暴露隐藏的和长期的攻击模式。实际上,现有的攻击图受到可伸缩性挑战的影响:它们的范围有限,针对特定类型的威胁,依赖于有限的数据源集。该研究将通过开发新技术来观察和处理更大规模的恶意模式和活动,包括可能跨越整个数据中心的长期活动,从而加强现有的网络防御。通过加强对数字资产和关键基础设施的保护,以及提高加拿大网络安全行业的竞争力,这将使加拿大受益。11名高素质人才(HQPs),包括4名博士生、3名硕士生和4名本科生,将直接在该项目中接受安全威胁评估和缓解方面的培训。该项目将由伊萨·特拉奥雷(Issa Traore)博士领导,他是几篇有影响力的网络安全论文的合著者,也是《IEEE信息安全和取证交易》(IEEE Transactions on Information Security and Forensics)的现任编辑委员会成员。
英文摘要
Recently, it was discovered that a state-sponsored hacker group has been infiltrating the European Union's (EU) diplomatic communications network for years, downloading thousands of sensitive cables. The attack ran undetected for a three-year period and targeted more than 100 organisations and institutions, such as the United Nations and ministries of foreign affairs and finance. The attack is a type of emerging threat consisting of targeted and long-term campaigns delivered by skilled hackers who have clearly defined objectives and relentlessly work towards achieving their aims. These breaches can go undetected for a long period of time because of the hackers' ability to adapt to and escape defensive methods. Noticeably, there has been an evolution from volume-based attacks towards stealth-like `low and slow' style attacks. Although volumetric attacks often occur within a set time frame, low and slow attacks rely on an ongoing stream of malicious requests and have no distinct beginning or end; this makes their detection by current intrusion detection systems (IDS) and security information and event management (SIEM) tools challenging. The long-term objective of the research program is to spearhead the development of a new generation of security data analytics techniques by using more diverse data sources that can gain better situational awareness of the threat environment and deploy sound solutions for cyber incident attribution and resiliency. The short-term objective of the research program is to develop a new framework for detecting, responding and investigating long-term attacks using data from both the traditional security ecosystem and beyond the organisation perimeter. The research will leverage the large dynamic uncertain multigraph theory to coherently express and analyse security data across various heterogeneous data sources and meaningfully link seemingly innocuous and unrelated events to expose hidden and long-term attack patterns. Indeed, existing attack graphs are crippled by scalability challenges: they are limited in scope, target particular types of threats and rely on a limited set of data sources. The research will strengthen existing cyber defenses by developing novel techniques to observe and process malicious patterns and activities at a larger scale, including the long-term activities that may span beyond an entire data center. This will benefit Canada by strengthening the protection of digital assets and critical infrastructure and by increasing the competitiveness of the Canadian cybersecurity industry. 11 Highly Qualified Personnel (HQPs), four PhD students, three master's students and four undergraduate students, will be trained in security threat assessment and mitigation directly in the program. The program will be led by Dr. Issa Traore, who is the coauthor of several influential cybersecurity papers and a current member of the editorial board of the IEEE Transactions on Information Security and Forensics.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
A Holistic Framework for Emerging Long-term Attacks Detection and Response Using Diverse Heterogeneous Data Sources
  • 批准号:
    RGPIN-2020-05321
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.55万
  • 财政年份:
    2021
  • 负责人:
    Traore, Issa
  • 依托单位:
A Holistic Framework for Emerging Long-term Attacks Detection and Response Using Diverse Heterogeneous Data Sources
  • 批准号:
    RGPIN-2020-05321
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.55万
  • 财政年份:
    2020
  • 负责人:
    Traore, Issa
  • 依托单位:
Novel Software-based Biometrics for Security of Mobile Devices
  • 批准号:
    RGPIN-2015-04837
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.75万
  • 财政年份:
    2019
  • 负责人:
    Traore, Issa
  • 依托单位:
Identity and behavior-based secure personalized message classification system
  • 批准号:
    531909-2018
  • 项目类别:
    Idea to Innovation
  • 资助金额:
    $9.08万
  • 财政年份:
    2018
  • 负责人:
    Traore, Issa
  • 依托单位:
海外基金