University of Arizona researchers are developing a form of cybersecurity inspired by human biological systems that detect and address threats in their earliest stages. The team will also offer training and research opportunities to students from underrepresented backgrounds.
The Partnership for Proactive Cybersecurity Training project is funded by a three-year, $3 million grant from the National Nuclear Security Administration's Minority Serving Institution Partnership Program. The UA, which was designated as a Hispanic-Serving Institution in 2018, is collaborating with Howard University, Navajo Technical University and Argonne National Laboratory.
"I felt we could learn about how the body protects us by reacting to threats and maybe apply it to cyber by building a 'cyber immune system,'" said Salim Hariri, UA electrical and computer engineering professor and the project's principal investigator. "We're trying to build these abilities where, when somebody attacks your computer, these measures can detect the attack and act on it before you're even aware something is compromised."
The team hopes to create a scientific approach that catalogs exactly which strategies attackers have at their disposal, almost like a playbook in football. Then, researchers can develop their own playbook of defense methods, carefully monitor the "vitals" of the cybersystem, and be ready to respond at the first sign of an attack.
"The moment we see abnormal behavior, we want to be able to say, 'Oh, that's play No. 5 and I already have a way to respond to it, and I can act on it quickly,'" Hariri said. "An attacker can reach hundreds of thousands of devices in a fraction of a second, so we need our ability to detect threats and protect a system to work just as quickly."
The team is using machine learning methods. In this type of artificial intelligence, machines teach themselves how to recognize patterns and learn new tasks, meaning humans don't have to step in and program the machines every time they want them to do something new.
To teach a machine to recognize a cactus, for example, a researcher would show the machine thousands of photos of cactuses until the machine learned to recognize the color, spines and size that make a cactus a cactus. Likewise, a machine exposed to thousands of examples of cybersecurity threats through machine learning techniques would come to recognize such threats on its own.
Machine learning is especially useful in a cybersecurity context because attackers, with a whole playbook of tactics at their disposal, often evolve their methods. How they attack a computer today might be different from the way they do it tomorrow, so the cybersecurity system must be able to learn as it goes along, detect changes in the environment and even anticipate changes before they occur.
Training Opportunities for Underrepresented Groups
The grant takes a two-pronged approach to improving the science of cybersecurity. While researchers develop these new techniques, they'll also be training students from the UA, Howard University and Navajo Technical University – especially underrepresented minority groups and women – to become highly skilled members of the cybersecurity workforce.
The initiative will include an eight-week summer education program on the UA campus, set to begin in 2020, and a cybersecurity class that takes place in a virtual lab, which can be accessed from anywhere with internet connectivity. It will also provide students opportunities to do internships with the Department of Energy and in other government labs, where they will conduct research and learn about emerging technologies, preparing them to go on to jobs in the cybersecurity field. In addition, the team will integrate cybersecurity modules into existing UA courses.
"We hear a lot of stories about advances in computing or physical technology being used to improve human health," said UA President Robert C. Robbins. "But what makes the Fourth Industrial Revolution unique is the physical, biological and data sciences converging in unexpected ways. Researchers learning from human biological systems to inspire a new tool that improves cybersecurity is the kind of innovative thinking we need, and is characteristic of the UA's problem-solving culture. Involving underrepresented students makes this effort an even more powerful example of UA expertise creating real-world impact at the intersection of research and the student experience. We are building a highly skilled workforce that will continue tackling grand challenges well into the future."