Where Cybersecurity Research Could Make the Biggest Difference
CMU鈥檚 Software Engineering Institute identifies the most impactful opportunities across national security missions and systems
Media Inquiries
Cyber threats are evolving and expanding as increasingly complex systems and artificial intelligence create new security challenges. For cybersecurity researchers, that raises a fundamental question: Which problems are most important to solve?聽
Researchers at 糖心Vlog视频鈥檚 Software Engineering Institute have developed a framework to help answer that question. 鈥�鈥� identifies seven enduring areas of cybersecurity research and 37 specific research opportunities with the potential to improve cyber operations and strengthen national security.聽
Within the complex, rapidly changing landscape of cybersecurity, the researchers argue, there are enduring subjects where research and development can drive significant operational improvements even as particular technologies, systems and threats continue to change.聽
鈥淭here is greater urgency than ever before to take considered action to improve the nation鈥檚 cybersecurity posture 鈥� and in a way that accelerates the delivery of capability to the mission,鈥� said聽, the framework鈥檚 editor and a special adviser to the director of the SEI.
More than 25 SEI technical experts, led by Scherlis and聽, director of the SEI鈥檚聽, selected seven topic areas based on their potential impact on cyber operations and envisioned capabilities across national security missions.聽
Seven enduring cybersecurity challenges
The framework identifies seven areas where research and development has the greatest potential to improve cyber operations and capabilities across national security missions:
- Analytic and Operational Tradecraft for Cybersecurity
- Securing AI-Based Systems and Workflows
- Cyber-Physical System Security
- Cybersecurity for Complex Integrated Systems
- Insider Threat and Human鈥揝ystems Interaction
- Secure Engineering and Mission Confidence for Critical Software-Reliant Systems
- Modeling and Simulation in Support of Security
Within those areas, the framework identifies high-priority research opportunities and recommends both near- and long-term actions.聽
For example, AI systems present a particular cybersecurity challenge. An AI model may offer capabilities that are useful for a mission while still containing weaknesses that cannot easily be eliminated. The framework identifies research into ways to design larger systems that can safely incorporate vulnerable AI models, as well as better methods for testing AI systems, identifying weaknesses and determining if safeguards actually work.聽
The framework also recommends that organizations structure their cybersecurity research around three elements of cyber risk: the characteristics of potential threats, the consequences a cyber event could have for a mission and the vulnerabilities in the systems involved.聽
Research focused on mission
Broader cybersecurity research, including聽 by the聽, informed the framework, which focuses specifically on the needs of national security operations.聽
The SEI brings leading-edge research in all seven topic areas to bear on the most pressing mission problems.聽
鈥淲e benefit from an extraordinary range and depth of expertise and experience in our core areas of cybersecurity, software and AI,鈥� said Scherlis.
The researchers hope the framework can help research organizations, government agencies and technology developers make decisions not only about today鈥檚 cybersecurity needs, but about the capabilities they will need in the future.聽
鈥淥ur collective security depends on our ability to out-innovate and act with greater velocity and precision than those who seek to exploit our vulnerabilities,鈥� said Touhill. 鈥淲e call on leaders in the research, operations and product development communities to use this framework to set vision-driven cyber research agendas. In today鈥檚 rapidly evolving digital environment, we must work together to engineer the future of national security in the digital age.鈥�