2007.02.01 - To Review and To Re-org
Time to Review, and then Re-org
Michael Kao 2007/2/1
After the midterm review and the 1st iCAST working conference, it is time to evaluate all the projects; including their progress and structure, and re-organize them if necessary. The most important goals for now are: to propose the 2nd year project and to lay out a long-term roadmap. Currently, iCAST has four project groups: III (Institute for Information Industry), ITRI (Industrial Technology Research Institute of Taiwan), Academia, and NDU (National Defense University). Each are assigned with project numbers 100s, 200s, 300s, and 400s. While the III, ITRI, and NDU focus on “Network Security Assessment Technology Development”, “Wireless & Sensor Security”, and “Military Security Operation Center (M-SOC)”; the Academia projects, mostly proposed and delivered by TWISC (TaiWan Information Security Center) members, cover various fields in Information Security Core Technologies. Because of its complexity and wide coverage, the Academia 300s projects should be reviewed first, then the others. In this memorandum, Section 1 outlines all iCAST topic groups. Then, Section 2 focuses on 300 series projects and reviews their current status, new partners and topics, recommended policies and procedures, and other pertinent issues. Finally, more alliance issues of all projects are addressed in Section 3. Most works of this memorandum are based on consulting with iCAST PIs.
1. Three iCAST Research Areas
To make ourselves easier to observe the interrelationship among iCAST projects and then to re-org them if needed, we divide their research into the following three areas:
(1). Authentication, Vulnerability Analysis and Verification
(2). Wireless and Sensor Security
(3). Intrusion Detection and Management
While both III and NDS focus on area (3), ITRI on (2), 300 series projects cover all three areas as shown in Chart 1.
Chart 1 - Three iCAST Research Areas

2. 300 Series Projects
2.1. New Partners and Tasks
In 300 series projects, the majority of first year iCAST members: Investigators, Professors, Engineers, and Students, are from organizations based in northern Taiwan. They would like to have wider coverage for the next year and after. For now, we are glad to have new potential members from TWISC@NCTU and TWSSC@NCKU as well as potential coverage in both central and southern Taiwan. Currently, NCTU teams are interested in Information Security Topics in wireless sensor network areas, especially WiFi and WiMAX, while NCKU teams focus on Information Security Systems of Intrusion Detection.
2.2. Tasks, Investigators and Students
The following table summarizes all tasks of current 300 series and new tasks proposed by NCTU and NCKU teams. These tasks are listed according to the research areas. Each row represents a task with the task title, US collaboration team campus, and the Taiwanese team information in Columns 1, 2, and 3, respectively. The Taiwanese team information consists of professors’ names and the numbers of their Ph.D., master students, and the Assistants (RA) in this project. These Assistants, research assistants, are assigned to coordinate the administrative works in the corresponding project. The number of students marked with * are sent or will be sent to the U.S. study. Most of them have stayed in the US for two to three months (minimum: 13 days; average: 70 days; maximum: 142 days; total: 1265 days). If only one part of the group is sent to US study, we put the number of “US study” students inside the parenthesis. Please note that the number of professors’ visits is not included in this study since they have different characteristics.
Table 1 - Tasks and Their Teams of 300s in the 1st & 2nd Project Year
|
Task |
US |
Taiwanese Team |
|||
|
|
Team |
PI |
Students |
||
|
|
|
|
Ph.D. |
Master |
RA |
|
(1). Authentication, Vulnerability Analysis and Verification (303 & 305) |
|||||
|
Remote Authentication |
CMU |
|
|
|
2 |
|
吳宗成 |
1* |
1 |
|
||
|
呂及人 |
|
|
|
||
|
楊柏因 |
|
|
|
||
|
徐讚昇 |
|
|
|
||
|
王旭正 |
1* |
|
|
||
|
莊文勝 |
|
1 |
|
||
|
Combining Model Checking and Theorem Proving |
CMU |
莊庭瑞 |
|
|
|
|
王柏堯 |
|
1 |
|
||
|
蔡益坤 |
2* |
|
|
||
|
Programs/Software Security Evaluation Systems |
UCB |
李德財 |
|
|
1* |
|
(2). Wireless and Sensor Security (301, 302, and NCTU) |
|||||
|
Wireless Sensor Networks |
UCB |
|
|
|
1 |
|
雷欽隆 |
2* |
2 |
|
||
|
謝續平 |
|
3 |
|
||
|
黃仁俊 |
|
5 |
|
||
|
邱舉明@ |
|
3(2*) |
|
||
|
項天瑞 |
|
3(1*) |
|
||
|
鄧惟中 |
|
3(1*) |
|
||
|
RFID Applications |
UCB |
|
|
|
1 |
|
賴源正 |
1* |
2 |
|
||
|
邱榮輝 |
2 |
|
|
||
|
羅乃維 |
1* |
2 |
|
||
|
楊傳凱 |
|
1* |
|
||
|
王大為 |
|
|
|
||
|
WiFi & WiMax Applications |
UCB? |
謝續平 |
|
|
|
|
NCTU** |
2 |
|
|
||
|
NCTU** NCTU** |
1 1 |
|
|
||
|
(3) Intrusion Detection and Management (304, 306, & NCKU) |
|||||
|
Kernel |
CMU |
|
|
|
1* |
|
李漢銘 |
1* |
2 |
|
||
|
李育杰 |
|
2 |
|
||
|
何正信# |
|
|
|
||
|
鮑興國 |
|
1 |
|
||
|
吳怡樂 |
|
3 |
|
||
|
Systems - incl. Testbed, Sniffer, Data Collection, etc. |
? |
|
|
|
|
|
賴溪松 |
2 |
|
|
||
|
NCKU** |
2 |
|
|
||
|
Network Security and Forensics |
CMU |
|
|
|
2(1*) |
|
孫雅麗 |
1* |
1 |
|
||
|
陳孟彰 |
|
1 |
|
||
|
Privacy-preserving Information Protection Management System |
UCB |
|
|
|
|
|
曹承礎 |
|
4(1*) |
|
||
|
|
|
|
|
||
|
(total - 1st year) |
|
29 |
12 |
41 |
8 |
|
(total - 2nd year estimate) |
33 |
20 |
40 |
8 |
|
Notes: 1. NCTU may also involve with RFID & Wireless Sensor Network projects.
2. ** Investigators and students of NCTU & NCKU will be identified later.
3. @ One of邱舉明 students is undergraduate, but at different funding.
4. 楊傳凱student has already left iCAST project.
5. # 何正信 will no longer with iCAST project next year.
In summary, during the first project year, we have 29 professors and 62 students in the 300 series projects and will sent a total of 18 students to the US for long-term study. In the second year, we expect to have about 33 professors and 70 students and send 20 to 24 students per year. The second year of iCAST project will start from 2007/05/01 and end 2007/12/31 to fit it into the calendar year of 2007, while the collaboration part will start from 2007/07/01; therefore, we expect to send a total of 10 to 12 students to the US in the 2nd half year of 2007.
The 2nd year proposal will continuously use "Projects 301 to 306" scheme, which is the same as the 1st year, except for slight modifications to include new members and tasks. The PI assignments are listed below. The second year will also act as a transition year to the 3rd year (2008) when we will focus more on research areas and their interrelationship.
(1). Authentication, Vulnerability Analysis and Verification
Project 303 - 吳宗成
Project 305 - 莊庭瑞
(2). Wireless and Sensor Security
Project 301 - 謝續平
Project 302 - 雷欽隆
(3). Intrusion Detection and Management
Project 304 - 賴溪松
Project 306 - 孫雅麗
In general, almost all 1st year tasks will be carried on to the 2nd year under the same project, and with the same project number as in the 1st year unless better arrangements are proposed and agreed by all PIs.
2.3. Research Area Principle Investigators
Additionally, Professors吳宗成, 謝續平, and賴溪松, are nominated as the Lead principle investigators of research areas 1, 2, and 3, respectively, to coordinate the strategic issues intra- and inter- organizations. They are also the directors of TWISC @NTUST, @NCTU, and @NCKU respectively, and the coordinators of the cross-organization review teams which are outlined in Section 3.2.
2.4. Second Year Funding
Currently, for 300 projects we propose a budget with 46 percent growth, i.e. NT$46,000,000/year for 2nd year comparing NT$31,500,000/year for the 1st year. This increment will be used to cover the following growth:
(1). Have more projects,
(2). Send more students to US with longer stay,
(3). Set up with dialogue and collaboration with industries.
2.5. Guidelines and Policies
We recommend adapting the following guidelines for next year. Part of the guidelines was formulated in recent iCAST meetings, while the rest were recommended by iCAST PIs.
(1). Projects with Ph.D. and Master Students are selected first unless junior professors themselves are ready to conduct the extensive collaboration research study.
(2). Selected students should meet an agreed-upon standard of English proficiency such as a minimum TOFEL score or passing “certification” tests.
(3). Selection of students should take place months ahead of the project start date. For CMU and UCB international offices to process J visa paperwork, we have to give them at least 45 days advance.
(4). The student study period in the US should use the American school calendar as a base - one semester per stay, and those attending UCB should apply for housing as early as possible (UCB will reimburse this cost).
2.6. More Recommendation
Additionally, the followings are recommended:
(1). Set up review criteria for both output and outcome.
(2). Assign students and research assistants to assist the PI in writing reports and handling administrative issues, especially, one single contact window to interact with Heiwen and Maggie of the TWISC office and the staff of iCAST project office.
(3). Set up a fair compensation mechanism of all US-long-stay students to different regions and with different lengths of stay.
3. Overall Review and Re-org
Our goals should include building a roadmap, maximizing the outcome and minimizing the cost which can be accomplished through continuously review and tune up.
3.1. Overall Review and Collaboration
In order to build up the complete iCAST long-term roadmap, we have to outline all iCAST projects as an integrated unit, and treat each project as an important iCAST component. Moreover, all projects should complement each other and minimize the potential overlap during the process, and be ready working together and conducting technology transfer in the future. Currently, both III and NDS projects are in group (3) “Intrusion Detection and Management”, and ITRI projects are in (2) “Wireless and Sensor Security”. Their statements of work and goals are outlines below:
Group (2) - Wireless and Sensor Security
Project 201(ITRI): Secure Wireless City in WiFi/WiMAX environment (UCB)
4 researchers
(1). Authentication mechanism
(2). Threat model analysis
(3). Seamless roaming