Skip to content
Cyber Science Lab

Securing Canada’s Critical Infrastructure

A Canada Research Chair program advancing cyber threat intelligence for Canada’s critical infrastructure — automated incident response, forensics, and cyber risk quantification against state-sponsored threats.

2025–2030Natural Sciences and Engineering Research Council of Canada (NSERC)PI: Dr. Ali Dehghantanha

State-sponsored hacking groups, commonly known as advanced persistent threats (APTs), are increasingly directing their cyber activities towards Canada’s national critical infrastructure (CI). Statistics Canada reveals that critical infrastructure operators reported over 45% of the country’s cyber incidents. While the average cost of recovery per cyber incident for Canadian businesses stands at $16,000, the critical infrastructure sector faces significantly higher costs. Notably, the pipeline transportation sector bears the highest average recovery cost per cyber incident in Canada, amounting to $131,000, followed by the natural gas distribution sector at $118,000.

This Canada Research Chair program is centered on advancing cyber threat intelligence (CTI) within the national CI landscape, specifically addressing the elevated risk posed by APTs. The program focuses on automating post-compromise activities, aiming to create robust solutions for incident response (IR), forensic examination, and quantitative risk assessment. Given the escalating vulnerability of Industrial Control Systems (ICSs) and the Industrial Internet of Things (IIoT) within CI, a swift and automated response becomes imperative.

The program unfolds over a five-year period, organized into three WPs. The first WP emphasizes the development of an automated fuzzy-deep reinforcement learning IIoT incident response system, encompassing the formulation of fuzzy risk estimation models, compilation of threat intelligence, and collaboration with industry partners for asset categorization. The second WP addresses the challenges of interpretability and explainability in deep learning (DL) systems, focusing on an autonomous forensics triage system. It involves simulating APT attacks, surveying the forensics community, and developing deep Reinforcement Learning (RL)-based systems for automated forensics investigations. The third WP concentrates on a deep RL-based cyber risk quantification framework, involving data processing, DL model training, and the formulation of a comprehensive risk assessment approach.

Overall, the program provides CI owners and operators with reliable tools for timely response and forensics examination of cyber incidents. Additionally, the program aims to offer frameworks for quantifying cyber risks, contributing to enhanced cybersecurity measures for Canada’s critical infrastructure.