Institute for Information Infrastructure Protection
Encyclopedia
The Institute for Information Infrastructure Protection (I3P) is a consortium
of national cyber security institutions, including academic research centers, government laboratories and non-profit organizations, all of which have long-standing, widely recognized expertise in cyber security research and development (R&D). The I3P is managed by Dartmouth College
, which is home to a small administrative staff that oversees and helps direct consortium activities.
The I3P coordinates and funds cyber security research in several areas related to critical infrastructure protection and hosts high-impact workshops that bring together thought leaders from both the public and private sectors. The I3P brings a multi-disciplinary and multi-institutional perspective to complex and difficult problems, and works collaboratively with stakeholders in seeking solutions. Since its founding, in 2002, more than 100 researchers from a wide variety of disciplines and backgrounds have worked together to better understand and mitigate critical risks in the field of cyber security.
The I3P came into existence following several government assessments of the U.S. information infrastructure’s
susceptibility to catastrophic failure. The first study, published in 1998 by the United States President's Council of Advisors on Science and Technology (PCAST), recommended that a nongovernmental organization be formed to address national cyber security issues. Subsequent studies–by the Institute for Defense Analyses, as well as a white paper jointly produced by the National Security Council and the Office of Science and Technology Policy–agreed with the PCAST assessment, affirming the need for an organization dedicated to protecting the nation’s critical infrastructures.
In 2002, the I3P was founded at Dartmouth College
, with a grant from the federal government. Since its inception, the I3P has:
Funding for the I3P has come from various sources, including the Department of Homeland Security (DHS), the National Institute of Standards and Technology
(NIST) and the National Science Foundation
(NSF).
Researchers from five I3P academic institutions are engaged in a sweeping effort to understand privacy in the digital era. Over the course of 18 months, this research project will take a multidisciplinary look at privacy, examining the roles of human behavior, data exposure, and policy expression on the way people understand and protect their privacy.
Leveraging Human Behavior to Reduce Cyber Security Risk
This project brings a behavioral-sciences lens to security, examining the interface between human beings and computers through a set of rigorous empirical studies. The multi-disciplinary project draws together social scientists and information security professionals to illuminate the intricacies of human perceptions, cognitions, and biases, and how these impact computer security. The project’s goal is to leverage these new insights in a way that produces more secure systems and processes.
I3P researchers on this project have examined ways to quantify cyber risk by exploring the potential for a multi-factor scoring system, analogous to risk scoring in the insurance sector. Overall, the work takes into account the two key determinants of cyber risk: technologies that reduce the likelihood of attack and internal capabilities to respond to successful or potential attacks.
This project builds on an earlier I3P project in control-systems security to develop strategies for enhancing control-system resilience and allowing for rapid recovery in the event of a successful cyber attack.
Business Rationale for Cyber Security
This project, an offshoot of an earlier study on the economics of security, addresses the challenge of corporate decision-making when it comes to investing in cyber security. It attempted to answer questions such as, “How much is needed?” “How much is enough?” “And how does one measure the return on investment?” The study includes an investigation of investment strategies, including risks and vulnerabilities, supply-chain interdependencies and technological fixes.
Safeguarding Digital Identity
Multidisciplinary in scope, this project addresses the security of digital identities , emphasizing the development of technical approaches for managing digital identities that also meet political, social and legal needs. The work has focused primarily on the two sectors for which privacy and identity protection are paramount: financial services and healthcare.
Insider Threat
This project addresses the need to detect, monitor and prevent insider attacks, which can inflict serious harm on an organization. The researchers have undertaken a systematic analysis of insider threat, one that addresses technical challenges but also takes into account ethical, legal and economic dimensions.
Consortium
A consortium is an association of two or more individuals, companies, organizations or governments with the objective of participating in a common activity or pooling their resources for achieving a common goal....
of national cyber security institutions, including academic research centers, government laboratories and non-profit organizations, all of which have long-standing, widely recognized expertise in cyber security research and development (R&D). The I3P is managed by Dartmouth College
Dartmouth College
Dartmouth College is a private, Ivy League university in Hanover, New Hampshire, United States. The institution comprises a liberal arts college, Dartmouth Medical School, Thayer School of Engineering, and the Tuck School of Business, as well as 19 graduate programs in the arts and sciences...
, which is home to a small administrative staff that oversees and helps direct consortium activities.
The I3P coordinates and funds cyber security research in several areas related to critical infrastructure protection and hosts high-impact workshops that bring together thought leaders from both the public and private sectors. The I3P brings a multi-disciplinary and multi-institutional perspective to complex and difficult problems, and works collaboratively with stakeholders in seeking solutions. Since its founding, in 2002, more than 100 researchers from a wide variety of disciplines and backgrounds have worked together to better understand and mitigate critical risks in the field of cyber security.
History
History of the I3PThe I3P came into existence following several government assessments of the U.S. information infrastructure’s
Information Infrastructure
An information infrastructure is defined by Hanseth as "a shared, evolving, open, standardized, and heterogeneous installed base" and by Pironti as all of the people, processes, procedures, tools, facilities, and technology which supports the creation, use, transport, storage, and destruction of...
susceptibility to catastrophic failure. The first study, published in 1998 by the United States President's Council of Advisors on Science and Technology (PCAST), recommended that a nongovernmental organization be formed to address national cyber security issues. Subsequent studies–by the Institute for Defense Analyses, as well as a white paper jointly produced by the National Security Council and the Office of Science and Technology Policy–agreed with the PCAST assessment, affirming the need for an organization dedicated to protecting the nation’s critical infrastructures.
In 2002, the I3P was founded at Dartmouth College
Dartmouth College
Dartmouth College is a private, Ivy League university in Hanover, New Hampshire, United States. The institution comprises a liberal arts college, Dartmouth Medical School, Thayer School of Engineering, and the Tuck School of Business, as well as 19 graduate programs in the arts and sciences...
, with a grant from the federal government. Since its inception, the I3P has:
- coordinated a national cyber security research and development program
- built informational and research bridges among academic, industrial and government stakeholders
- developed and delivered technologies to address an array of vulnerabilities
Funding for the I3P has come from various sources, including the Department of Homeland Security (DHS), the National Institute of Standards and Technology
National Institute of Standards and Technology
The National Institute of Standards and Technology , known between 1901 and 1988 as the National Bureau of Standards , is a measurement standards laboratory, otherwise known as a National Metrological Institute , which is a non-regulatory agency of the United States Department of Commerce...
(NIST) and the National Science Foundation
National Science Foundation
The National Science Foundation is a United States government agency that supports fundamental research and education in all the non-medical fields of science and engineering. Its medical counterpart is the National Institutes of Health...
(NSF).
Members
An extensive list of I3P member institutions is as follows:- Purdue UniversityPurdue UniversityPurdue University, located in West Lafayette, Indiana, U.S., is the flagship university of the six-campus Purdue University system. Purdue was founded on May 6, 1869, as a land-grant university when the Indiana General Assembly, taking advantage of the Morrill Act, accepted a donation of land and...
- University of TulsaUniversity of TulsaThe University of Tulsa is a private university awarding bachelor's, master's, and doctoral degrees located in Tulsa, Oklahoma, USA. It is currently ranked 75th among doctoral degree granting universities in the nation by US News and World Report and is listed as one of the "Best 366 Colleges" by...
- University of IdahoUniversity of IdahoThe University of Idaho is the State of Idaho's flagship and oldest public university, located in the rural city of Moscow in Latah County in the northern portion of the state...
- Columbia UniversityColumbia UniversityColumbia University in the City of New York is a private, Ivy League university in Manhattan, New York City. Columbia is the oldest institution of higher learning in the state of New York, the fifth oldest in the United States, and one of the country's nine Colonial Colleges founded before the...
- UC Davis
- Cornell UniversityCornell UniversityCornell University is an Ivy League university located in Ithaca, New York, United States. It is a private land-grant university, receiving annual funding from the State of New York for certain educational missions...
- George Mason University School of LawGeorge Mason University School of LawGeorge Mason University School of Law is the law school of George Mason University, a state university in Virginia, United States...
- Georgia Tech
- H. John Heinz III School of Public Policy and Management, Carnegie Mellon University
- Idaho National LaboratoryIdaho National LaboratoryIdaho National Laboratory is an complex located in the high desert of eastern Idaho, between the town of Arco to the west and the cities of Idaho Falls and Blackfoot to the east. It lies within Butte, Bingham, Bonneville and Jefferson counties...
- Johns Hopkins UniversityJohns Hopkins UniversityThe Johns Hopkins University, commonly referred to as Johns Hopkins, JHU, or simply Hopkins, is a private research university based in Baltimore, Maryland, United States...
- United States Military AcademyUnited States Military AcademyThe United States Military Academy at West Point is a four-year coeducational federal service academy located at West Point, New York. The academy sits on scenic high ground overlooking the Hudson River, north of New York City...
- University of Illinois Urbana-Champaign
- New York UniversityNew York UniversityNew York University is a private, nonsectarian research university based in New York City. NYU's main campus is situated in the Greenwich Village section of Manhattan...
- Dartmouth CollegeDartmouth CollegeDartmouth College is a private, Ivy League university in Hanover, New Hampshire, United States. The institution comprises a liberal arts college, Dartmouth Medical School, Thayer School of Engineering, and the Tuck School of Business, as well as 19 graduate programs in the arts and sciences...
- Lawrence Berkeley National LaboratoryLawrence Berkeley National LaboratoryThe Lawrence Berkeley National Laboratory , is a U.S. Department of Energy national laboratory conducting unclassified scientific research. It is located on the grounds of the University of California, Berkeley, in the Berkeley Hills above the central campus...
- MIT Lincoln Laboratory
- MITRE Corporation
- Pacific Northwest National LaboratoryPacific Northwest National LaboratoryPacific Northwest National Laboratory is one of the United States Department of Energy National Laboratories, managed by the Department of Energy's Office of Science. The main campus of the laboratory is in Richland, Washington....
- RAND Corporation
- Sandia National LaboratoriesSandia National LaboratoriesThe Sandia National Laboratories, managed and operated by the Sandia Corporation , are two major United States Department of Energy research and development national laboratories....
- Indiana UniversityIndiana UniversityIndiana University is a multi-campus public university system in the state of Indiana, United States. Indiana University has a combined student body of more than 100,000 students, including approximately 42,000 students enrolled at the Indiana University Bloomington campus and approximately 37,000...
- Software Engineering Institute, Canegie Mellon University
- SRI InternationalSRI InternationalSRI International , founded as Stanford Research Institute, is one of the world's largest contract research institutes. Based in Menlo Park, California, the trustees of Stanford University established it in 1946 as a center of innovation to support economic development in the region. It was later...
- University of California at Berkeley
- University of Massachusetts AmherstUniversity of Massachusetts AmherstThe University of Massachusetts Amherst is a public research and land-grant university in Amherst, Massachusetts, United States and the flagship of the University of Massachusetts system...
- University of VirginiaUniversity of VirginiaThe University of Virginia is a public research university located in Charlottesville, Virginia, United States, founded by Thomas Jefferson...
2010-2011 Research Projects
Privacy in the Digital EraResearchers from five I3P academic institutions are engaged in a sweeping effort to understand privacy in the digital era. Over the course of 18 months, this research project will take a multidisciplinary look at privacy, examining the roles of human behavior, data exposure, and policy expression on the way people understand and protect their privacy.
Leveraging Human Behavior to Reduce Cyber Security Risk
This project brings a behavioral-sciences lens to security, examining the interface between human beings and computers through a set of rigorous empirical studies. The multi-disciplinary project draws together social scientists and information security professionals to illuminate the intricacies of human perceptions, cognitions, and biases, and how these impact computer security. The project’s goal is to leverage these new insights in a way that produces more secure systems and processes.
2008-2009 Research Projects
Better Security Through Risk PricingI3P researchers on this project have examined ways to quantify cyber risk by exploring the potential for a multi-factor scoring system, analogous to risk scoring in the insurance sector. Overall, the work takes into account the two key determinants of cyber risk: technologies that reduce the likelihood of attack and internal capabilities to respond to successful or potential attacks.
2007-2009 Research Projects
Survivability and Recovery of Process Control Systems ResearchThis project builds on an earlier I3P project in control-systems security to develop strategies for enhancing control-system resilience and allowing for rapid recovery in the event of a successful cyber attack.
Business Rationale for Cyber Security
This project, an offshoot of an earlier study on the economics of security, addresses the challenge of corporate decision-making when it comes to investing in cyber security. It attempted to answer questions such as, “How much is needed?” “How much is enough?” “And how does one measure the return on investment?” The study includes an investigation of investment strategies, including risks and vulnerabilities, supply-chain interdependencies and technological fixes.
Safeguarding Digital Identity
Multidisciplinary in scope, this project addresses the security of digital identities , emphasizing the development of technical approaches for managing digital identities that also meet political, social and legal needs. The work has focused primarily on the two sectors for which privacy and identity protection are paramount: financial services and healthcare.
Insider Threat
This project addresses the need to detect, monitor and prevent insider attacks, which can inflict serious harm on an organization. The researchers have undertaken a systematic analysis of insider threat, one that addresses technical challenges but also takes into account ethical, legal and economic dimensions.