Skip to main content
Close shot of Software Engineering Institute building sign

Where Cybersecurity Research Could Make the Biggest Difference

CMU’s Software Engineering Institute identifies the most impactful opportunities across national security missions and systems

Media Inquiries
Name
University Communications and Marketing, Media Relations

Cyber threats are evolving and expanding as increasingly complex systems and artificial intelligence create new security challenges. For cybersecurity researchers, that raises a fundamental question: Which problems are most important to solve? 

Researchers at Carnegie Mellon University’s Software Engineering Institute have developed a framework to help answer that question. “Advancing Cybersecurity: A Framework of Cyber Research Priorities(opens in new window)” identifies seven enduring areas of cybersecurity research and 37 specific research opportunities with the potential to improve cyber operations and strengthen national security. 

Bill Scherlis

Bill Scherlis

Within the complex, rapidly changing landscape of cybersecurity, the researchers argue, there are enduring subjects where research and development can drive significant operational improvements even as particular technologies, systems and threats continue to change. 

“There is greater urgency than ever before to take considered action to improve the nation’s cybersecurity posture — and in a way that accelerates the delivery of capability to the mission,” said Bill Scherlis(opens in new window), the framework’s editor and a special adviser to the director of the SEI.

More than 25 SEI technical experts, led by Scherlis and Greg Touhill(opens in new window), director of the SEI’s CERT Division(opens in new window), selected seven topic areas based on their potential impact on cyber operations and envisioned capabilities across national security missions. 

Seven enduring cybersecurity challenges

The framework identifies seven areas where research and development has the greatest potential to improve cyber operations and capabilities across national security missions:

  • Analytic and Operational Tradecraft for Cybersecurity
  • Securing AI-Based Systems and Workflows
  • Cyber-Physical System Security
  • Cybersecurity for Complex Integrated Systems
  • Insider Threat and Human–Systems Interaction
  • Secure Engineering and Mission Confidence for Critical Software-Reliant Systems
  • Modeling and Simulation in Support of Security

Within those areas, the framework identifies high-priority research opportunities and recommends both near- and long-term actions. 

For example, AI systems present a particular cybersecurity challenge. An AI model may offer capabilities that are useful for a mission while still containing weaknesses that cannot easily be eliminated. The framework identifies research into ways to design larger systems that can safely incorporate vulnerable AI models, as well as better methods for testing AI systems, identifying weaknesses and determining if safeguards actually work. 

The framework also recommends that organizations structure their cybersecurity research around three elements of cyber risk: the characteristics of potential threats, the consequences a cyber event could have for a mission and the vulnerabilities in the systems involved. 

Research focused on mission

Broader cybersecurity research, including work(opens in new window) by the National Academies of Sciences, Engineering and Medicine(opens in new window), informed the framework, which focuses specifically on the needs of national security operations. 

The SEI brings leading-edge research in all seven topic areas to bear on the most pressing mission problems. 

Greg Touhill

Greg Touhill

“We benefit from an extraordinary range and depth of expertise and experience in our core areas of cybersecurity, software and AI,” said Scherlis.

The researchers hope the framework can help research organizations, government agencies and technology developers make decisions not only about today’s cybersecurity needs, but about the capabilities they will need in the future. 

“Our collective security depends on our ability to out-innovate and act with greater velocity and precision than those who seek to exploit our vulnerabilities,” said Touhill. “We call on leaders in the research, operations and product development communities to use this framework to set vision-driven cyber research agendas. In today’s rapidly evolving digital environment, we must work together to engineer the future of national security in the digital age.”

— Related Content —