SaTC: EDU: A Formal Approach to Digital Forensics and Incident Response Investigations

Information

  • NSF Award
  • 1821829
Owner
  • Award Id
    1821829
  • Award Effective Date
    9/1/2018 - 6 years ago
  • Award Expiration Date
    8/31/2020 - 4 years ago
  • Award Amount
    $ 299,998.00
  • Award Instrument
    Standard Grant

SaTC: EDU: A Formal Approach to Digital Forensics and Incident Response Investigations

The goal of this project is to develop a platform for digital forensics and incident response (DFIR) education. The platform will be built based on an existing proof-of-concept prototype called Nugget. The resulting platform will be tool-agnostic and will support different pedagogical approaches. The platform will provide the ability to formulate and apply forensic queries over different, and potentially large, data sources in an easy to understand manner. The project will make it possible for domain experts, such as cybersecurity and law enforcement analysts, to learn and perform forensic investigations. A set of hands-on materials, that utilize the platform, will be developed to support a two-course sequence in digital forensics and incident response. <br/><br/>The platform will provide a formal and unifying conceptual framework for all DFIR analytical techniques, and will enable different approaches to DFIR education. This will allow courses from introductory to research-centric graduate courses, to use the same conceptual framework, and will enable instructors to focus more clearly on concepts rather than specific tools. The associated runtime environment will allow the separation of the specification of a query from its implementation. This project will result in a tool that provides the means to incrementally integrate advanced forensic capabilities, such as SaaS forensics, data analytics, and eventually deeper AI techniques into cybersecurity curricula. The platform will provide the means to acquire and analyze data from popular cloud services, such as cloud drives and online collaboration, and will also integrate with security monitoring/incident response systems.<br/><br/>This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.

  • Program Officer
    Victor P. Piotrowski
  • Min Amd Letter Date
    8/17/2018 - 6 years ago
  • Max Amd Letter Date
    8/17/2018 - 6 years ago
  • ARRA Amount

Institutions

  • Name
    University of New Orleans
  • City
    New Orleans
  • State
    LA
  • Country
    United States
  • Address
    2000 Lakeshore Drive
  • Postal Code
    701480001
  • Phone Number
    5042806836

Investigators

  • First Name
    Vassil
  • Last Name
    Roussev
  • Email Address
    vassil@cs.uno.edu
  • Start Date
    8/17/2018 12:00:00 AM

Program Element

  • Text
    Secure &Trustworthy Cyberspace
  • Code
    8060

Program Reference

  • Text
    SaTC: Secure and Trustworthy Cyberspace
  • Text
    CYBER SECURITY ACT PROPOSALS
  • Code
    7254
  • Text
    CNCI
  • Code
    7434
  • Text
    EXP PROG TO STIM COMP RES
  • Code
    9150
  • Text
    UNDERGRADUATE EDUCATION
  • Code
    9178
  • Text
    GRADUATE INVOLVEMENT
  • Code
    9179
  • Text
    SCIENCE, MATH, ENG & TECH EDUCATION