The Institute for Information Infrastructure Protection (I3P) is a
consortium of national cyber security institutions, including academic research centers,
U.S. federal government
The federal government of the United States (U.S. federal government or U.S. government) is the national government of the United States, a federal republic located primarily in North America, composed of 50 states, a city within a feder ...
laboratories, and
nonprofit organizations
A nonprofit organization (NPO) or non-profit organisation, also known as a non-business entity, not-for-profit organization, or nonprofit institution, is a legal entity organized and operated for a collective, public or social benefit, in co ...
, all of which have long-standing, widely recognized expertise in cyber security
research and development
Research and development (R&D or R+D), known in Europe as research and technological development (RTD), is the set of innovative activities undertaken by corporations or governments in developing new services or products, and improving existi ...
(R&D). The I3P is managed by
The George Washington University
, mottoeng = "God is Our Trust"
, established =
, type = Private federally chartered research university
, academic_affiliations =
, endowment = $2.8 billion (2022)
, presi ...
, which is home to a small administrative staff that oversees and helps direct consortium activities.
The I3P coordinates and funds cyber security research related to critical infrastructure protection and hosts high impact workshops that bring together leaders from both the public and private sectors.
The I3P brings a multi-disciplinary and multi-institutional perspective to complex and difficult problems, and works collaboratively with stakeholders in seeking solutions. Since its founding in 2002,
more than 100 researchers from a wide variety of disciplines and backgrounds have worked together to understand better and mitigate critical risks in the field of cyber security.
History
The I3P came into existence following several government assessments of the U.S.
information infrastructure’s susceptibility to catastrophic failure. The first study, published in 1998 by the
(PCAST), recommended that a nongovernmental organization be formed to address national cyber security issues. Subsequent studies–by the Institute for Defense Analyses, as well as a white paper jointly produced by the National Security Council and the Office of Science and Technology Policy, agreed with the PCAST assessment, affirming the need for an organization dedicated to protecting the nation’s critical infrastructures.
In 2002, the I3P was founded at
Dartmouth College
Dartmouth College (; ) is a private research university in Hanover, New Hampshire. Established in 1769 by Eleazar Wheelock, it is one of the nine colonial colleges chartered before the American Revolution. Although founded to educate Native ...
through a grant from the federal government.
Martin Wybourne chaired the I3P from 2003 to 2015. Since its inception, the I3P has:
* coordinated a national cyber security research and development program
* built informational and research bridges among academic, industrial, and government stakeholders
* developed and delivered technologies to address an array of vulnerabilities
Funding for the I3P has come from various sources, including the
Department of Homeland Security
The United States Department of Homeland Security (DHS) is the U.S. federal executive department responsible for public security, roughly comparable to the interior or home ministries of other countries. Its stated missions involve anti-te ...
(DHS), the
National Institute of Standards and Technology
The National Institute of Standards and Technology (NIST) is an agency of the United States Department of Commerce whose mission is to promote American innovation and industrial competitiveness. NIST's activities are organized into Outline of p ...
(NIST) and the
National Science Foundation
The National Science Foundation (NSF) is an independent agency of the United States government that supports fundamental research and education in all the non-medical fields of science and engineering. Its medical counterpart is the National ...
(NSF).
Member Institutions
The I3P consortium consists of 18 academic research centers, 5 national laboratories, and 3 nonprofit research organizations.
*
Binghamton University
The State University of New York at Binghamton (Binghamton University or SUNY Binghamton) is a public research university with campuses in Binghamton, Vestal, and Johnson City, New York. It is one of the four university centers in the State ...
*
Carnegie Mellon University, H. John Heinz III College of Public Policy and Management
*
Carnegie Mellon University, Software Engineering Institute
*
Dartmouth College
Dartmouth College (; ) is a private research university in Hanover, New Hampshire. Established in 1769 by Eleazar Wheelock, it is one of the nine colonial colleges chartered before the American Revolution. Although founded to educate Native ...
*
George Mason University
George Mason University (George Mason, Mason, or GMU) is a public research university in Fairfax County, Virginia with an independent City of Fairfax, Virginia postal address in the Washington, D.C. Metropolitan Area. The university was orig ...
*
George Washington University
, mottoeng = "God is Our Trust"
, established =
, type = Private federally chartered research university
, academic_affiliations =
, endowment = $2.8 billion (2022)
, presi ...
*
Georgia Institute of Technology
The Georgia Institute of Technology, commonly referred to as Georgia Tech or, in the state of Georgia, as Tech or The Institute, is a public research university and institute of technology in Atlanta, Georgia. Established in 1885, it is part of ...
*
Idaho National Laboratory
Idaho National Laboratory (INL) is one of the national laboratories of the United States Department of Energy and is managed by the Battelle Energy Alliance. While the laboratory does other research, historically it has been involved with nu ...
*
Indiana University
Indiana University (IU) is a system of public universities in the U.S. state of Indiana.
Campuses
Indiana University has two core campuses, five regional campuses, and two regional centers under the administration of IUPUI.
* Indiana Univers ...
*
Johns Hopkins University
Johns Hopkins University (Johns Hopkins, Hopkins, or JHU) is a private research university in Baltimore, Maryland. Founded in 1876, Johns Hopkins is the oldest research university in the United States and in the western hemisphere. It consiste ...
*
Lawrence Berkeley National Laboratory
Lawrence Berkeley National Laboratory (LBNL), commonly referred to as the Berkeley Lab, is a United States national laboratory that is owned by, and conducts scientific research on behalf of, the United States Department of Energy. Located in ...
*
MITRE Corporation
*
New York University
New York University (NYU) is a private research university in New York City. Chartered in 1831 by the New York State Legislature, NYU was founded by a group of New Yorkers led by then- Secretary of the Treasury Albert Gallatin.
In 1832, ...
*
Oak Ridge National Laboratory
Oak Ridge National Laboratory (ORNL) is a U.S. multiprogram science and technology national laboratory sponsored by the U.S. Department of Energy (DOE) and administered, managed, and operated by UT–Battelle as a federally funded research an ...
*
Pacific Northwest National Laboratory
Pacific Northwest National Laboratory (PNNL) is one of the United States Department of Energy national laboratories, managed by the Department of Energy's (DOE) Office of Science. The main campus of the laboratory is in Richland, Washington.
...
*
Purdue University
Purdue University is a public land-grant research university in West Lafayette, Indiana, and the flagship campus of the Purdue University system. The university was founded in 1869 after Lafayette businessman John Purdue donated land and ...
*
RAND Corporation
The RAND Corporation (from the phrase "research and development") is an American nonprofit global policy think tank created in 1948 by Douglas Aircraft Company to offer research and analysis to the United States Armed Forces. It is financ ...
*
Sandia National Laboratories
Sandia National Laboratories (SNL), also known as Sandia, is one of three research and development laboratories of the United States Department of Energy's National Nuclear Security Administration (NNSA). Headquartered in Kirtland Air Force Bas ...
*
SRI International
SRI International (SRI) is an American nonprofit organization, nonprofit scientific research, scientific research institute and organization headquartered in Menlo Park, California. The trustees of Stanford University established SRI in 1946 as ...
*
University of California, Berkeley
The University of California, Berkeley (UC Berkeley, Berkeley, Cal, or California) is a public land-grant research university in Berkeley, California. Established in 1868 as the University of California, it is the state's first land-grant u ...
*
University of California, Davis
The University of California, Davis (UC Davis, UCD, or Davis) is a public land-grant research university near Davis, California. Named a Public Ivy, it is the northernmost of the ten campuses of the University of California system. The inst ...
*
University of Idaho
The University of Idaho (U of I, or UIdaho) is a public land-grant research university in Moscow, Idaho. It is the state's land-grant and primary research university,, and the lead university in the Idaho Space Grant Consortium. The University ...
*
University of Illinois
The University of Illinois Urbana-Champaign (U of I, Illinois, University of Illinois, or UIUC) is a public land-grant research university in Illinois in the twin cities of Champaign and Urbana. It is the flagship institution of the Unive ...
*
University of Massachusetts, Amherst
The University of Massachusetts Amherst (UMass Amherst, UMass) is a public research university in Amherst, Massachusetts and the sole public land-grant university in Commonwealth of Massachusetts. Founded in 1863 as an agricultural college, it ...
*
University of Tulsa
The University of Tulsa (TU) is a private research university in Tulsa, Oklahoma. It has a historic affiliation with the Presbyterian Church and the campus architectural style is predominantly Collegiate Gothic. The school traces its origin ...
*
University of Virginia
The University of Virginia (UVA) is a public research university in Charlottesville, Virginia. Founded in 1819 by Thomas Jefferson, the university is ranked among the top academic institutions in the United States, with College admission ...
Each member institution appoints a primary and secondary representative to attend regular consortium meetings.
Research areas
2011-2014 Research Projects
Advanced Technological Education
The I3P has partnered with the
Community College System of New Hampshire
The Community College System of New Hampshire (previously New Hampshire Community Technical Colleges (NHCTC) and prior to that New Hampshire Vocational Technical Colleges (NHVTC)) is an organization of seven public community colleges located thro ...
(CCSNH) on an educational project, “Cybersecurity in Healthcare Industry: Curriculum Adaptation and Implementation.” Funded by the
National Science Foundation
The National Science Foundation (NSF) is an independent agency of the United States government that supports fundamental research and education in all the non-medical fields of science and engineering. Its medical counterpart is the National ...
’s (NSF) Advanced Technological Education (ATE) program, the goal of the project is to produce well-qualified technicians to serve the healthcare information technology needs of rural northern New England.
Improving CSIRTs
The I3P launched a project called "Improving CSIRT Skills, Dynamics, and Effectiveness." This effort, funded by the
United States Department of Homeland Security
The United States Department of Homeland Security (DHS) is the Federal government of the United States, U.S. United States federal executive departments, federal executive department responsible for public security, roughly comparable to the I ...
's Science and Technology Directorate, aims to explore what makes and sustains a good CSIRT. The results should help organizations ensure that their CSIRTs fulfill their maximum potential and become invaluable tools in securing cyber infrastructure. The interdisciplinary team working on the new project will include cyber security and business researchers from Dartmouth College, organizational psychologists from George Mason University, and researchers and practitioners from Hewlett-Packard.
Usable Security
In April 2011, I3P convened a NIST-sponsored workshop examining the challenge of integrating security and usability into the design and development of software. One of the several workshop recommendations was the development of case studies to show software developers how usable security has been integrated into an organization's software development process. Consequently, the I3P has begun a Usable Security Project. Using a uniform study methodology, the project will document usable security in three different organizations. The results will be used to understand how key usable security problems were addressed, to teach developers about solutions, and to enable other researchers to perform comparative studies.
Information Sharing
The nation's Critical Infrastructure is under threat of cyber attack today as never before. The main response to the cyber threat facing the country is increased information sharing. Traditionally, agencies store data in databases, and the information is not readily available to others who might benefit from it. The Obama administration made it clear that this strategy will not work – data must be readily available for sharing. The preferred way to do this would be using a cloud, where numerous government agencies would all store information, and the information would be available to all who have the appropriate credentials. This model has tremendous added benefits – but what are the associated risks? Researchers from RAND and The University of Virginia took on the challenge of answering that question in our Information Sharing Project.
2010-2011 Research Projects
Privacy in the Digital Era
Researchers from five I3P academic institutions are engaged in a sweeping effort to understand privacy in the digital era. Over the course of 18 months, this research project will take a multidisciplinary look at privacy, examining the roles of human behavior, data exposure, and policy expression on the way people understand and protect their privacy.
Leveraging Human Behavior to Reduce Cyber Security Risk
This project brings a behavioral-sciences lens to security, examining the interface between human beings and computers through a set of rigorous empirical studies. The multi-disciplinary project draws together social scientists and information security professionals to illuminate the intricacies of human perceptions, cognitions, and biases, and how these impact computer security. The project’s goal is to leverage these new insights in a way that produces more secure systems and processes.
2008-2009 Research Projects
Better Security Through Risk Pricing
I3P researchers on this project have examined ways to quantify cyber risk by exploring the potential for a multi-factor scoring system, analogous to risk scoring in the insurance sector. Overall, the work takes into account the two key determinants of cyber risk: technologies that reduce the likelihood of attack and internal capabilities to respond to successful or potential attacks.
2007-2009 Research Projects
Survivability and Recovery of Process Control Systems Research
This project builds on an earlier I3P project in control-systems security to develop strategies for enhancing control-
system resilience
Robustness is the property of being strong and healthy in constitution. When it is transposed into a system, it refers to the ability of tolerating perturbations that might affect the system’s functional body. In the same line ''robustness'' ca ...
and allowing for rapid recovery in the event of a successful cyber attack.
Business Rationale for Cyber Security
This project, an offshoot of an earlier study on the economics of security, addresses the challenge of corporate decision-making when it comes to investing in cyber security. It attempted to answer questions such as, “How much is needed?” “How much is enough?” “And how does one measure the return on investment?” The study includes an investigation of investment strategies, including risks and vulnerabilities, supply-chain interdependencies, and technological fixes.
Safeguarding Digital Identity
Multidisciplinary in scope, this project addresses the security of digital identities, emphasizing the development of technical approaches for managing digital identities that also meet political, social, and legal needs. The work has focused primarily on the two sectors for which privacy and identity protection are paramount: financial services and healthcare.
Insider Threat
This project addresses the need to detect, monitor, and prevent insider attacks, which can inflict serious harm on an organization. The researchers have undertaken a systematic analysis of insider threat, one that addresses technical challenges but also takes into account ethical, legal, and economic dimensions.
U.S. Senate Cyber Security Report
The I3P delivered a report titled National Cyber Security Research and Development Challenges: An Industry, Academic and Government Perspective, to U.S. Senators
Joseph Lieberman
Joseph Isadore Lieberman (; born February 24, 1942) is an American politician, lobbyist, and attorney who served as a United States senator from Connecticut from 1989 to 2013. A former member of the Democratic Party, he was its nominee for Vi ...
and
Susan Collins
Susan Margaret Collins (born December 7, 1952) is an American politician serving as the senior United States senator from Maine. A member of the Republican Party, she has held her seat since 1997 and is Maine's longest-serving member of Con ...
on February 18, 2009. The report reflects the finding of three forums hosted by the I3P in 2008 that brought together high-level experts from industry, government and academia to identify R&D opportunities that would advance cyber security research in the next five to 10 years. The report contains specific recommendations for technology and policy research that reflect the input of the participants and also the concerns of both the public and private sectors.
Workshops
The I3P connects with and engages with stakeholders through workshops and other outreach activities that are often held in partnership with other organizations. The workshops encompass a range of topics, some directly related to I3P research projects; others that are intended to bring the right people together to probe a particularly difficult foundational challenge, such as security systems engineering or workforce development.
Postdoctoral Fellowship Program
The I3P sponsored a postdoctoral research fellowship program from 2004-2011 that provides funding for a year of research at an I3P member institution. These competitive awards were granted according to the merit of the proposed work, the extent to which the proposed work explored creative and original concepts, and the potential impact of the topic on the U.S. information infrastructure. Prospective applicants were expected to address a core area of cyber security research, including trustworthy computing, enterprise security management, secure systems engineering, network response, and recovery, identity management and forensics, wireless computing and metrics, as well as the legal, policy, and economic dimensions of security.
References
External links
Official website
{{DEFAULTSORT:Institute For Information Infrastructure Protection
Computer security organizations