NSA Funds 'Lablets' for Security Research

The National Security Agency (NSA) is funding the creation of four small laboratories on just as many campuses as part of a new initiative to support the development of programs for security research. Recently, the NSA invited nearly 300 institutions to go after funding to develop "lablets," little labs with the express purpose of conducting basic research, building a community and talking up the need for a "science for security" (SoS). Four universities — Carnegie Mellon, North Carolina State, U Illinois at Urbana-Champaign and U Maryland — jumped at the opportunity. Each of the first three schools will receive $2.5 million; U Maryland will receive $4.5 million over three years.

A major goal of the initiative is to create a unified body of knowledge and analytics methods and tools that can serve as the basis of an engineering discipline, curriculum and rigorous design methodologies. The results that come out of the lablets will be documented and distributed via a wiki.

The research to be performed at the lablets will be directed in five areas:

  • Scalability and composability;
  • Policy-governed secure collaboration;
  • Security metrics;
  • Resilient architectures; and
  • Understanding and accounting for human behavior

Carnegie Mellon's lablet will be directed by William Scherlis, professor and director of the Institute for Software Research. "The point of all this is to build a network of SoS thinking," he said. His group, consisting of 15 faculty members and about 20 post-doctoral researchers, technical staff members and graduate students, will focus on two of the study areas: scalability and composability, and human behavior and usability.

The former will examine large, complex software systems made possible by assembling many separate components. He explained that the "challenge" is to "develop methods to enable the construction of secure systems with known security properties by assembling components, each of which has known quality and security properties," but without having to reanalyze the security properties for the entire system once it's composed.

In the area of human behavior and usability, the researchers will work to develop models of human behavior that enable the design, modeling and analysis of systems with specified security properties to address potential insider threats. Another interest here is to improve support for the people who develop systems and evaluate their security.

North Carolina State will explore analytics with a drilldown into data encryption. That work will be housed at the school's Institute for Next Generation IT Systems.

U Illinois researchers will delve into resiliency, and specifically a system's "demonstrable ability to maintain security properties even during ongoing cyber attacks."

U Maryland will bring together five departments on campus — computer science, electrical and computer engineering, information studies, criminology and mechanical engineering — to study the verification and composition of security properties; conduct experiments on vulnerability exploits; and, like Carnegie Mellon, dive into the topic of human behavior and its impact on security.

"The university's designation as a science of security lablet is a testament to the breadth of our expertise in cybersecurity," said Patrick O'Shea, vice president and chief research officer at U Maryland. "It also speaks to our broader mission of addressing grand scientific and societal challenges by forming innovative transdisciplinary partnerships across multiple departments on campus."

The lablets are expected to draw research help from other institutions and will involve research work already being undertaken by the universities that were awarded contracts.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • The AI Show

    Register for Free to Attend the World's Greatest Show for All Things AI in EDU

    The AI Show @ ASU+GSV, held April 5–7, 2025, at the San Diego Convention Center, is a free event designed to help educators, students, and parents navigate AI's role in education. Featuring hands-on workshops, AI-powered networking, live demos from 125+ EdTech exhibitors, and keynote speakers like Colin Kaepernick and Stevie Van Zandt, the event offers practical insights into AI-driven teaching, learning, and career opportunities. Attendees will gain actionable strategies to integrate AI into classrooms while exploring innovations that promote equity, accessibility, and student success.

  • cloud, database stack, computer screen, binary code, and flowcharts interconnected by lines and arrows

    Salesforce to Acquire Data Management Firm Informatica

    Salesforce has announced plans to acquire data management company Informatica for $8 billion. The deal is aimed at strengthening Salesforce's AI foundation and expanding its enterprise data capabilities.

  • stylized AI code and a neural network symbol, paired with glitching code and a red warning triangle

    New Anthropic AI Models Demonstrate Coding Prowess, Behavior Risks

    Anthropic has released Claude Opus 4 and Claude Sonnet 4, its most advanced artificial intelligence models to date, boasting a significant leap in autonomous coding capabilities while simultaneously revealing troubling tendencies toward self-preservation that include attempted blackmail.

  • NVIDIA DGX line

    NVIDIA Intros Personal AI Supercomputers

    NVIDIA has introduced a new lineup of AI-powered computing solutions designed to accelerate enterprise workloads.