Completed Computing & AI Public Health & Healthcare

Interdisciplinary Centre for Finding, Understanding and Countering Crime in the Cloud

In plain English

AI plain-English summary

A new Cambridge centre will mine the largest non-classified dataset ever assembled on online abuse—including millions of spam emails and cloud-service logs—to detect and understand crime happening inside cloud infrastructure. Most cybercrime research is hamstrung because academics cannot get real data from the companies that host criminal activity. Law enforcement, meanwhile, lacks the forensic tools and statistical baselines needed to investigate cloud-based crime at scale. This centre solves both problems by negotiating access to massive, diverse data feeds from major cloud providers and public bodies, then correlating them to extract patterns of abuse. If the centre succeeds, police will gain automated tools to search terabytes of cloud data, preserve evidence with tamper-proof chain-of-custody mechanisms, and produce reliable national cybercrime statistics. Cloud providers will receive actionable intelligence on how and when abuse occurs, allowing them to shut down criminal accounts faster. The centre will also release sanitised datasets to the wider research community, breaking the data-access bottleneck that has stalled academic progress in this field. The result could be a measurable reduction in fraud, data theft, and other crimes that currently exploit the anonymity and scale of cloud services.

View original technical description
The Cambridge Interdisciplinary Centre for Crime in the Cloud (CICCC) will combine the diverse range of skills available in the Institute of Criminology, the Faculty of Law and the Computer Laboratory at the University of Cambridge. Our approach will be multidisciplinary, including researchers with expertise in computer science, criminology, cybersecurity, economics, psychology, forensics and law. Our approach will be data driven. We have negotiated access to some very substantial datasets including large feeds of data such as spam email messages and technical information about the operation of cloud services from several major cloud providers and public bodies. Together, they will constitute the largest data resource available anywhere outside of classified systems on abuse online; we will have more, and more diverse, data than almost all service firms or law enforcement agencies, creating a unique opportunity for research to develop new tools for cloud crime detection and forensics. We will mine and correlate these datasets to extract information about criminal activity. Our analysis will enhance our understanding of crime in the cloud, enable us to devise identifiers of such criminality, allow us to build systems to detect crime when it occurs, and ensure we collect evidence of wrongdoing to a high standard. We will work closely with law enforcement to ensure appropriate interventions can be undertaken. Our overall objective is to create a sustainable and internationally competitive centre for academic research into cybercrime. The primary aim of the centre is to improve the security of users of cloud services, and to improve outcomes for those who would be affected by their misuse. We will develop a strong legal framework to operate in, and maintain high ethical standards in everything we do. We will incorporate this into APIs for abuse data sharing that support appropriate authentication, nonrepudiation and privacy mechanisms, and feed these back to the industry. We aim to provide the police with an enhanced ability to search large amounts of data related to cybercrime in the cloud, improved forensics, better chain-of-custody mechanisms for evidence, additional training, and meaningful statistics on cybercrime. We have strong relationships with industry, and we will provide them with important data and insights on how, when and why criminality in the cloud occurs, thus enabling cloud providers to improve security for the users of cloud services by cracking down swiftly on abuse. We will also work closely with other academics, providing sanitised datasets to researchers generally, and enable trustworthy researchers access to our full dataset on the same basis as ourselves. This will solve the main problem faced by most academics who want to do research on cybercrime, namely the difficulty of getting access to real data on actual abuse.

View the original record at the funder ↗

Researchers

Alastair Beresford (Co-Investigator)Alice Hutchings (Co-Investigator)Lawrence Sherman (Co-Investigator)Ross Anderson (Principal Investigator)Simon Deakin (Co-Investigator)

Related Research

Grants with similar aims, by meaning.

CRITiCaL - Combatting cRiminals In The CLoud
Tracking Covid Cybercrime and Abuse
Interdisciplinary Cybercrime Project
CybercrimeNLP (CC-NLP): A natural language processing toolkit for the interdisciplinary analysis of underground online forums
Identifying and Modelling Victim, Business, Regulatory and Malware Behaviours in a Changing Cyberthreat Landscape

Original classification

Research Grant

Plain English summaries and category classifications on this site are generated by AI and may not perfectly reflect the original research.