NSA Funds 'Lablets' for Security Research

The National Security Agency (NSA) is funding the creation of four small laboratories on just as many campuses as part of a new initiative to support the development of programs for security research. Recently, the NSA invited nearly 300 institutions to go after funding to develop "lablets," little labs with the express purpose of conducting basic research, building a community and talking up the need for a "science for security" (SoS). Four universities — Carnegie Mellon, North Carolina State, U Illinois at Urbana-Champaign and U Maryland — jumped at the opportunity. Each of the first three schools will receive $2.5 million; U Maryland will receive $4.5 million over three years.

A major goal of the initiative is to create a unified body of knowledge and analytics methods and tools that can serve as the basis of an engineering discipline, curriculum and rigorous design methodologies. The results that come out of the lablets will be documented and distributed via a wiki.

The research to be performed at the lablets will be directed in five areas:

  • Scalability and composability;
  • Policy-governed secure collaboration;
  • Security metrics;
  • Resilient architectures; and
  • Understanding and accounting for human behavior

Carnegie Mellon's lablet will be directed by William Scherlis, professor and director of the Institute for Software Research. "The point of all this is to build a network of SoS thinking," he said. His group, consisting of 15 faculty members and about 20 post-doctoral researchers, technical staff members and graduate students, will focus on two of the study areas: scalability and composability, and human behavior and usability.

The former will examine large, complex software systems made possible by assembling many separate components. He explained that the "challenge" is to "develop methods to enable the construction of secure systems with known security properties by assembling components, each of which has known quality and security properties," but without having to reanalyze the security properties for the entire system once it's composed.

In the area of human behavior and usability, the researchers will work to develop models of human behavior that enable the design, modeling and analysis of systems with specified security properties to address potential insider threats. Another interest here is to improve support for the people who develop systems and evaluate their security.

North Carolina State will explore analytics with a drilldown into data encryption. That work will be housed at the school's Institute for Next Generation IT Systems.

U Illinois researchers will delve into resiliency, and specifically a system's "demonstrable ability to maintain security properties even during ongoing cyber attacks."

U Maryland will bring together five departments on campus — computer science, electrical and computer engineering, information studies, criminology and mechanical engineering — to study the verification and composition of security properties; conduct experiments on vulnerability exploits; and, like Carnegie Mellon, dive into the topic of human behavior and its impact on security.

"The university's designation as a science of security lablet is a testament to the breadth of our expertise in cybersecurity," said Patrick O'Shea, vice president and chief research officer at U Maryland. "It also speaks to our broader mission of addressing grand scientific and societal challenges by forming innovative transdisciplinary partnerships across multiple departments on campus."

The lablets are expected to draw research help from other institutions and will involve research work already being undertaken by the universities that were awarded contracts.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • academic building surrounded by clouds and glowing lightbulbs

    University of Pittsburgh Partners with AWS on Cloud Innovation Center

    The University of Pittsburgh is teaming up with Amazon Web Services to establish a new Cloud Innovation Center focused on health sciences and sports analytics.

  • glowing digital brain made of blue circuitry hovers above multiple stylized clouds of interconnected network nodes against a dark, futuristic background

    Report: 85% of Organizations Are Using Some Form of AI

    Eighty-five percent of organizations today are leveraging some form of AI, according to the latest State of AI in the Cloud 2025 report from Wiz. While AI's role in innovation and disruption continues to expand, security vulnerabilities and governance challenges remain pressing concerns.

  • illustration of a football stadium with helmet on the left and laptop with ed tech icons on the right

    The 2025 NFL Draft and Ed Tech Selection: A Strategic Parallel

    In the fast-evolving landscape of collegiate football, the NFL, and higher education, one might not immediately draw connections between the 2025 NFL Draft and the selection of proper educational technology for a college campus. However, upon closer examination, both processes share striking similarities: a rigorous assessment of needs, long-term strategic impact, talent or tool evaluation, financial considerations, and adaptability to a dynamic future.

  • Three cubes of noticeably increasing sizes are arranged in a straight row on a subtle abstract background

    A Sense of Scale

    Gardner Campbell explores the notion of scale in education and shares some of his own experience "playing with scale" — scaling up and/or scaling down — in an English course at VCU.