Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Wednesday, September 26, 2012

NSF Invests $50 Million in Research to Secure Our Nation's Cyberspace



Multiple awards include two large "Frontier" collaborative projects totaling $15 million

The National Science Foundation (NSF) today awarded $50 million for research projects to build a cybersecure society and protect the United States' vast information infrastructure.

The investments were made through the NSF's Secure and Trustworthy Cyberspace (SaTC) program, which builds on the agency's long-term support for a wide range of cutting edge interdisciplinary research and education activities to secure critical infrastructure that is vulnerable to a wide range of threats that challenge its security.

"Securing cyberspace is key to America's global economic competitiveness and prosperity," said NSF Director Subra Suresh. "NSF's investment in the fundamental research of cybersecurity is core to national security and economic vitality that embraces efficiency while also maintaining privacy."

In response to the SaTC call for proposals, more than 70 new research projects were funded, with award amounts ranging from about $100,000 to $10 million. This SaTC funding portfolio invests in state-of-the-art research in incentives that reduce the likelihood of cyber attacks and mitigate the negative effects arising from them. Together, these SaTC awards aim to improve the resilience of operating systems, software, hardware and critical infrastructure while preserving privacy, promoting usability and ensuring trustworthiness through foundational research and prototype deployments.

Two of the SaTC funded projects are Frontier awards, which are large, multi-institution projects that aim to provide high-level visibility to grand challenge research areas.

The SaTC program supports research from a number of disciplinary perspectives with investments from NSF's Directorates for Computer and Information Science and Engineering (CISE); Mathematical and Physical Sciences; and Social, Behavioral and Economic Sciences, as well as the Office of Cyberinfrastructure.

"We are excited that the SaTC award portfolio contains many interdisciplinary projects, including these two Frontier projects at the scale and complexity of research centers," said Farnam Jahanian, assistant director of NSF's CISE directorate. "The challenges they address--the technical and economic elements of Internet security and the issues associated with sharing of data in cyberspace while protecting individual privacy--are fundamental; addressing them will help establish a scientific basis for developing and operating computing and communications infrastructure that can resist attacks and be tailored to meet a wide range of technical and policy requirements."

What follows are descriptions of the two Frontier awards.

Beyond Technical Security: Developing an Empirical Basis for Socio-Economic Perspectives

University of California-San Diego - Stefan Savage
International Computer Science Institute - Vern Paxson
George Mason University - Damon McCoy

This project will receive a five-year grant totaling $10 million to tackle the technical and economic elements of Internet security: how the motivations and interactions of attackers, defenders and users shape the threats we face, how they evolve over time and how they can best be addressed.

While security is mediated by the technical workings of computers and networks, a commensurate level of scrutiny is driven by conflict between economic and social issues. Today's online attackers are commonly profit-seeking, and the implicit social networks that link them together play a critical role in fostering underlying cybercrime markets. By using a socio-economic lens, this project seeks to gain insights for understanding attackers, as well as victims, in order to help consumers, corporations and governments make large investments in security technology with greater understanding of their ultimate return-on-investment.

Security research has tended to focus only on the technologies that enable and defend against attacks. This project also emphasizes the economic incentives that motivate the majority of Internet attacks, the elaborate marketplaces that support them, and the relationships among cyber criminals who rely upon each other for services and expertise.

Grappling with both the economic and technical dimensions of cybersecurity is of fundamental importance for achieving a secure future information infrastructure, and developing a sound understanding requires research grounded in observation and experiment. Accordingly, the research will focus on four key components to:
1.Pursue in-depth empirical analyses of a range of online criminal activities.
2.Map out the evolving attacker ecosystem that preys on online social networks, and the extent to which unsafe online behavior is itself adopted and transmitted.
3.Study how relationships among these criminals are established, maintained and evolve over time.
4.Measure the efficacy of today's security interventions, both at large and at the level of individual users.

Consequently, this research has the potential to dramatically benefit society by undermining entire cybercrime ecosystems by, for example, disrupting underground activities, infrastructure and social networks.

Privacy Tools for Sharing Research Data

Harvard University - Salil Vadhan

A multi-disciplinary team of researchers at Harvard University will receive a four-year grant totaling nearly $5 million to develop tools and policies to aid the collection, analysis and sharing of data in cyberspace, while protecting individual privacy.

Today, information technology, advances in statistical computing and the deluge of data available through the Internet are transforming all areas of science and engineering. However, maintaining the privacy of human subjects is a major challenge. Given the complexities involved in ensuring privacy for shared research data, Vadhan will be joined by a team of professors with expertise in areas such as mathematics and statistics, government, technology and law. Together they will engage in a multi-disciplinary approach to refine and develop definitions and measures for privacy and data utility. They will also design an array of technological, legal and policy tools that can be used when dealing with sensitive data.

These tools will be tested and deployed at the Harvard Institute for Quantitative Social Science's Dataverse Network, an open-source digital repository that offers the largest catalogue of science datasets in the world. The ideas and tools developed in this project will have a significant broad impact on society since the issues addressed in the work arise in many other important domains, including public health and electronic commerce.

 -NSF-

Monday, July 16, 2012

Deception and Cybersecurity


WATCH Series

July 19, 2012 12:00 PM  to
July 19, 2012 1:00 PM
NSF, Room 110

Abstract
Deception is one of the most significant and pervasive social phenomena of our age, but the psychology of deception is poorly understood in the context of cybersecurity. We know little about important questions, including:  How does communication technology change the ways and reasons we deceive others? Can people detect if they are being lied to in online contexts any better (or worse) than offline? And can computer programs identify patterns on the Internet that reveal whether someone is lying or not that can exceed human-detection? In this talk we will examine these questions and recent research that may shed some light on the answers, focusing on the motivations for deception, a review of the state-of-the-art in deception detection research, and a sense of what the future holds for the way we lie.  

Speaker
Jeff Hancock is an Associate Professor in the Departments of Communication and Information Science. He is currently the Chair of the Information Science Department and the co-Director of Cognitive Science at Cornell University.  He is also Associate Editor of Discourse Processes. His work is concerned with how social media affect psychological and interpersonal processes, with a particular emphasis on understanding how language can reveal psychological and social dynamics, such as deception and credibility, emotional contagion, intimacy and relationships, and social support. Funding from the National Science Foundation and the Department of Defense supports his research, which has been frequently featured in the popular media, including the New York Times, CNN, NPR, and the BBC. Dr. Hancock earned his PhD in psychology at Dalhousie University, Canada, and joined Cornell in 2002.

Meeting Type
Lecture

Contacts
 Keith Marzullo, (703) 292-8950 kmarzull@nsf.gov

NSF Related Organizations
 Directorate for Computer & Information Science & Engineering

Tuesday, June 19, 2012

Beyond Passwords Or: How I Learned To Stop Hating And Worked Without Forced Authentication


“Everyone knows there is a problem with passwords.  What I would like to do is I’d like to move us to a world where you sit down at a console, identify yourself, and you just start working.  The authentication happens in the background – invisible to you – while you continue doing your work without interruptions.”  - Mr. Richard Guidorizzi, DARPA Program Manager, Beyond Passwords

The current standard method for validating a user’s identity for authentication on an information system requires humans to do something that is inherently unnatural: create, remember, and manage long, complex passwords.

Moreover, as long as the session remains active, typical systems incorporate no mechanisms to verify that the user originally authenticated is the user still in control of the keyboard.

Thus unauthorized individuals may improperly obtain extended access to information system resources if a password is compromised or if a user does not exercise adequate vigilance after initially authenticating at the console.

The Active Authentication program seeks to address this problem by developing novel ways of validating the identity of the person at the console that focus on the unique aspects of the individual through the use of software based biometrics.  Biometrics are defined as the characteristics used to uniquely recognize humans based on one or more intrinsic physical or behavioral traits.

This program focuses on the behavioral traits that can be observed through how we interact with the world.  Just as when you touch something your finger you leave behind a fingerprint, when you interact with technology you do so in a pattern based on how your mind processes information, leaving behind a “cognitive fingerprint.”


The first phase of the program will focus on researching biometrics that do not require the installation of additional hardware sensors, rather the program will look for research on biometrics that can be captured through the technology we already use looking for aspects of this “cognitive fingerprint.”

These could include, for example, how the user handles the mouse and how the user crafts written language in an e-mail or document.  A heavy emphasis will be placed on validating any potential new biometrics with empirical tests to ensure they would be effective in large scale deployments.

The later phases of the program will focus on developing a solution that integrates any available biometrics using a new authentication platform suitable for deployment on a standard a Department of Defense desktop or laptop.

The combinatorial approach of using multiple modalities for continuous user identification and authentication is expected to deliver a system that is accurate, robust, and transparent to the user’s normal computing experience.  The authentication platform will be developed with open Application Programming Interfaces (APIs) to allow the integration of other software or hardware biometrics available in the future from other sources.

Information for this article and video provided by DARPA

Wednesday, June 13, 2012

National Initiative for Cybersecurity Education (NICE) Overview


WATCH Series
June 21, 2012 12:00 PM  to
June 21, 2012 1:00 PM
Room 110, NSF

Abstract
A brief history, along with present and future plans for this national initiative will be covered, followed by a Q&A period.

Speaker
In early 2010 the National Institute of Standards and Technology (NIST) was selected as the lead agency for the National Initiative for Cybersecurity Education (NICE) and they identified Dr. McDuffie to be the Lead for this effort and has now completed his transition to this new position. In his previous position he had been appointed the Associate Director of the National Coordination Office (NCO) for Networking and Information Technology Research and Development (NITRD) in February 2008. From early September 2009 until early November 2009 he served as Acting Director of the NCO. His appointment as the Associate Director of the NCO comes after joining the NIST as a Computer Scientist in their Information Technology Laboratory, Office of Federal and Industrial Relations. In August 2006, Dr. McDuffie joined the NCO where he served as the Technical Coordinator for the Cyber Security and Information Assurance (CSIA) Interagency Working Group (IWG), Federal Agency Administration of Science and Technology Education and Research (FASTER) Committee of Practice (CoP), and the Software Design and Productivity (SDP) Coordination Group (CG).

Prior to joining the NCO, Dr. McDuffie served as the Deputy Director of the Office of Naval Research (ONR) - Science and Technology for America's Readiness (N-STAR) Initiative. He served as the Lead Program Director for the Federal Cyber Service: Scholarship for Service (SFS) Program at the National Science Foundation (NSF).

He served as an Assistant Professor at Florida State University in the Department of Computer Science where he taught both graduate and undergraduate courses in CS for seven years. Dr. McDuffie has participated in software engineering projects for the U.S. Air Force, the National Center for Atmospheric Research, the Federal Aviation Administration, Lockheed Missiles and Space Company, Los Alamos National Laboratory, and the National Security Agency.

Dr. McDuffie received his Ph.D. and M.S. degrees in Computer Science from the Florida Institute of Technology in Melbourne, Florida.

Meeting Type
Lecture

Contacts
 Keith Marzullo, (703) 292-8950 kmarzull@nsf.gov

NSF Related Organizations
 Directorate for Computer & Information Science & Engineering