$1,199,998 Cybersecurity Innovation

Universities lack the hands to defend their research infrastructure — building AI that reconstructs the campaign rather than trimming alerts

Arizona State University Arizona Started Aug 2026

The National Science Foundation awarded roughly $1.2 million to Arizona State University to build a system that reduces the triage burden from advanced attacks on scientific cyberinfrastructure while reconstructing complete attack campaigns from heterogeneous system traces.

Grant overview (primary data)

  • Award amount$1,199,998
  • RecipientArizona State University (Arizona)
  • ProgramCybersecurity Innovation
  • Period2026-08-01 〜 2029-07-31
  • FunderU.S. National Science Foundation (NSF) / NSF

Key points

  • A system that reduces triage burden from advanced attacks on scientific cyberinfrastructure while reconstructing complete attack campaigns ($1,199,998).
  • It identifies existing solutions as either generating excessive false positives from isolated events or detecting only known attacks through predefined patterns.
  • Three lines of work: adaptive provenance collection, contextual knowledge extraction, and a collaborative AI framework that correlates and reconstructs.
  • Investigation results are required to be explainable, because with few hands conclusions are not enough without their grounds.
  • The 120 NSF awards this site holds as of 2026-09-02 come from 93 institutions; Arizona accounts for 4 by state.

1Where the defending side is short of resources

Discussion of cyber defense tends to assume large firms or government agencies. What this award targets is the cyberinfrastructure of scientific institutions such as universities. Computing resources built for research are valuable and so become targets, while dedicated staff and budget stay limited.

The description states that collaborations with university cyberinfrastructure facilitators confirmed this asymmetry as an operational difficulty.

2Two shapes of existing solution

Analyzing isolated eventsRelying on predefined patterns
Looks at individual system events on their ownMatches against known attack shapes
Generates excessive false positivesDetects only a limited range of known attacks
Triage workload growsNew techniques slip through

Neither holds up where staffing is the binding constraint. Too many false positives and people are needed for triage; only known patterns and there is little point in looking. The project proposes a third path: integrating system audit data, application-specific semantics and threat intelligence, with collective AI agents correlating across them.

3Three lines of work

First, an adaptive provenance collection framework combining lightweight anomaly detection with selective memory monitoring to efficiently capture evidence of stealthy attacks. Second, contextual knowledge extraction deriving application semantics from system logs and structured knowledge from threat intelligence reports.

Third, a collaborative AI framework integrating audit data, application context and threat intelligence to correlate alerts, reconstruct attack campaigns, retrieve evidence and generate explainable investigation results. That explainable is set as a condition follows from limited staffing: with few hands, conclusions are not enough without the grounds for them.

4Program and the spread of institutions

The program is Cybersecurity Innovation, and the award belongs to the CICI framework. The 120 NSF awards this site holds as of 2026-09-02 come from 93 institutions, with few repeating. By state, Arizona accounts for 4. Protecting research infrastructure itself is investment in the foundation that makes research possible rather than in a research result — a form of infrastructure funding. Amounts are the obligated amount as of the check date and may change.

Why it matters

Where the defending side is short of resources, effectiveness turns on how much investigative work can be removed rather than on detection accuracy alone. Setting explainability as a requirement states the condition for using AI in a thinly staffed operation.

FAQ

Why are universities targeted?
Computing resources built for research are valuable, while dedicated staff and budget are often limited. The project starts from that asymmetry.
What does reconstructing a campaign mean?
Rather than reading each alert on its own, matching heterogeneous system traces to rebuild how a sequence of attack steps unfolded.

Sources (primary)

Source: NSF Award Search (U.S. National Science Foundation, public domain). Amounts are the obligated amount. For privacy, we do not handle principal investigator names.

#NSF awards#Cybersecurity#Research infrastructure#AI agents#Universities
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.