CRII

group_project

Visible to the public CRII: SaTC: Exploring the Real World Applicability of Denial of Service Mitigation via Routing

Distributed Denial of Service (DDoS) attacks disrupt the ability of computers to communicate over the Internet by flooding victims with large volumes of unwanted network traffic. Due to their high economic impact and low technical complexity, such attacks remain one of the most problematic and common attacks experienced by companies, organizations, and high-profile individuals.

group_project

Visible to the public CRII: SaTC: Preempting Physical Damage from Control-related Attacks on Smart Grids' Cyber-Physical Infrastructure

Control-related attacks are a severe threat to cyber-physical systems (CPSs) such as smart grids, because they can introduce catastrophic physical damage by using malicious control commands crafted in a legitimate format. While current research efforts have focused on detecting malicious commands that lead to physical damage, the investigator proposes to preemptively prevent the damage by disrupting and misleading adversaries' preparation before they issue the malicious commands.

group_project

Visible to the public CRII: SaTC: Secure Instruction Set Extensions for Lattice-Based Post-Quantum Cryptosystems

The emergence of quantum computers poses a serious threat for existing security standards, which motivates post-quantum cryptography (PQC) research. Various PQC schemes have been proposed for standardization, whose mathematical soundness are under investigation. Unfortunately, even a mathematically sound cryptography scheme may be attacked at the implementation level. The primary research goal of this project is to develop secure implementations for lattice-based cryptosystems, a major class of PQC encryption proposals.

group_project

Visible to the public CRII: SaTC: Secure Branch Predictors for High Performance Processors

Branch predictor (BP) is one of the key performance improvement mechanisms in today's processors. Recent studies demonstrate that it can be used to initiate powerful attacks such as side-channel and speculative execution-based attacks. These attacks allow adversaries to steal sensitive data and compromise computer systems. This project investigates security threats introduced by existing BP designs and develops new safe designs to stop BP-related attacks without significantly degrading the performance.

group_project

Visible to the public CRII: SaTC: Identifying Emerging Threats in the Online Hacker Community for Proactive Cyber Threat Intelligence: A Diachronic Graph Convolutional Autoencoder Framework

Hackers often target the information systems that underlie critical systems in domains ranging from finance to healthcare. The estimated cost of defending against and responding to hacking incidents currently runs at hundreds of billions of dollars annually. To reduce these costs, many organizations have aimed to develop timely, relevant, actionable, and shareable Cyber Threat Intelligence (CTI) about security and privacy threats to support cybersecurity decision-making. However, existing methods tend to react to known threats rather than proactively detecting emerging ones.

group_project

Visible to the public CRII: SaTC: Towards Secure Wide-area Localization

Modern localization systems such as the Global Positioning System have widely demonstrated vulnerabilities to signal-spoofing and jamming attacks. With the advent of autonomous cyber-physical systems such as self-driving cars and unmanned aerial vehicles, the ability to securely estimate, track and verify one's location is increasingly critical, indicative of a strong need to realize localization systems that are resilient to modern day cyber-physical attacks.

group_project

Visible to the public CRII: SaTC: Rowhammer Attack on Fresh and Recycled Memory Chips: Security Risks and Defenses

Rowhammer is a software-assisted cyber attack that causes malicious changes to the target memory cells of dynamic random-access memory (DRAM) due to charge leakage, by crafting memory access patterns which rapidly access the same row multiple times. This research focuses on proper hardware characterization towards a Rowhammer-resistant memory system. This characterization will also inform whether Rowhammer susceptibility increases with aging, and if so, will enable a method for detecting recycled chips.

group_project

Visible to the public CRII: SaTC: Data Privacy for Strategic Agents

This project lays the groundwork for understanding how existing tools for privacy-preserving data analysis interact with strategic and human aspects of practical privacy guarantees. When strategic individuals have privacy concerns about the use of their data, they may modify their behavior to ensure less, or perhaps more favorable, information is revealed. The project's novelties are an interdisciplinary approach, which combines tools from algorithm design, machine learning, and economics.

group_project

Visible to the public CRII: SaTC: PrivateNet - Preserving Differential Privacy in Deep Learning under Model Attacks

The rapid development of machine learning in the domain of healthcare presents clear privacy issues, when deep neural networks and other models are built based on patients' personal and highly sensitive data such as clinical records or tracked health data. Further, these models can be vulnerable to attackers trying to infer the sensitive data that was used to build the model.

group_project

Visible to the public CRII: SaTC: Moderating Effects of Automation on Information Transmission in Social Forums

This project aims to develop and deploy an information veracity evaluation system to support online discourse moderation and human comprehension of online information. Understanding information's nature can help users to identify essential products and services, and even potentially help to inform democratic participation.