Your browser doesn't support javascript. This means that the content or functionality of our website will be limited or unavailable. If you need more information about Vinnova, please contact us.

Panoptes - data models for managed security services

Reference number
Coordinator RISE Research Institutes of Sweden AB - RISE SICS, Kista
Funding from Vinnova SEK 468 000
Project duration January 2020 - October 2020
Status Completed
Venture Collaboration projects in cybersecurity and digital infrastructure

Purpose and goal

The PANOPTES pre-study has identified a set of open research challenges and initial solutions for managed security services. The project produced investigated reduced data collection with an improved selection of data features and machine learning model architectures, along with approaches to protecting the data models in confidential computing enclaves. Other project results include successful consortium building activities that have resulted in four project applications.

Expected results and effects

The project defined a core challenge of developing adaptive machine learning (ML) methods for detecting slowly evolving attacks. This topic is particularly important since many targeted attacks belong to this class. Adaptive ML-based methods will be implemented by tracking the behaviour of suspicious processes over time and multiple operating system sessions, including state transition models. Addressing this challenge will improve detection of targeted attacks, increase the effectiveness of security analysts and improve the overall cybersecurity stance of organisations.

Planned approach and implementation

The project was conducted using a combination of (a) literature reviews, (b) industry consultation and (c) consortium building activities. The literature review was conducted in the first part of the project to identify the state of the art and approaches for managed security services. Industry consultation included discussions with diverse industry contacts and discussions with leading cybersecurity providers at the CyberTech conference in TelAviv in February 2020. Consortium building conducted throughout the project resulted in 3 successful project applications.

The project description has been provided by the project members themselves and the text has not been looked at by our editors.

Last updated 23 December 2020

Reference number 2019-05017

Page statistics