CICI: RSSD: DISCERN: Datasets to Illuminate Suspicious Computations on Engineering Research Networks

Information

  • NSF Award
  • 2319864
Owner
  • Award Id
    2319864
  • Award Effective Date
    9/1/2023 - 8 months ago
  • Award Expiration Date
    8/31/2025 - a year from now
  • Award Amount
    $ 600,000.00
  • Award Instrument
    Standard Grant

CICI: RSSD: DISCERN: Datasets to Illuminate Suspicious Computations on Engineering Research Networks

Scientific cyberinfrastructures (CIs) contain rich and powerful resources to support a wide range of experiments across the science and engineering research communities. However, CI resources and the experimental data they generate are compelling attack targets for cyber threat actors, who may seek to abuse CIs through activities such as (1) exfiltration or encryption of valuable experiment data; (2) enlistment of compromised resources into botnets, for purposes such as denial of service attacks; or (3) illicit non-scientific activities such as cryptocurrency mining. The DISCERN project (Datasets Illuminating Suspicious Computations on Engineering Research Networks) seeks to improve the cybersecurity posture of CIs by producing datasets that capture both legitimate and illegitimate use of CI resources. DISCERN's primary goal is to produce rich and diverse datasets that capture many realistic legitimate and illegitimate usage scenarios, thereby enabling cybersecurity innovations in areas such as threat detection and workload classification, to better secure the national CI ecosystem.<br/><br/>DISCERN's methods and datasets are developed through DeterLab, a leading networking and cybersecurity testbed. DISCERN first instruments DeterLab to collect data about user activities at multiple levels of abstraction, including (1) interactions with user interfaces, (2) process, network, and file system events on platform operating systems and hypervisors, and (3) experimental node resource usage and internal and external traffic interacting with user experiments. All data is collected in a privacy-preserving and intellectual-property-preserving manner to protect users and their research. DISCERN also captures rich illegitimate use data through deployment of carefully designed ethical attacks that misuse DeterLab nodes in a variety of realistic misuse scenarios. All datasets and instrumentation tools developed by DISCERN are designed to be portable to other scientific CIs, and the DISCERN team engages in close collaboration with operators of those CIs to promote adoption of DISCERN tools and enable production of their own CI-usage datasets.<br/><br/>This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.

  • Program Officer
    Rob Beverlyrbeverly@nsf.gov7032927068
  • Min Amd Letter Date
    7/19/2023 - 10 months ago
  • Max Amd Letter Date
    7/19/2023 - 10 months ago
  • ARRA Amount

Institutions

  • Name
    University of Southern California
  • City
    LOS ANGELES
  • State
    CA
  • Country
    United States
  • Address
    3720 S FLOWER ST
  • Postal Code
    900894304
  • Phone Number
    2137407762

Investigators

  • First Name
    Jelena
  • Last Name
    Mirkovic
  • Email Address
    mirkovic@isi.edu
  • Start Date
    7/19/2023 12:00:00 AM
  • First Name
    Brian
  • Last Name
    Kocoloski
  • Email Address
    bkocolos@isi.edu
  • Start Date
    7/19/2023 12:00:00 AM

Program Element

  • Text
    Cybersecurity Innovation
  • Code
    8027

Program Reference

  • Text
    Cyber Secur - Cyberinfrastruc
  • Code
    8027