INBOUNDS: The Integrated Network-Based Ohio University Network Detective Service

INBOUNDS:基于网络的综合俄亥俄大学网络侦探服务

基本信息

  • 批准号:
    0086642
  • 负责人:
  • 金额:
    $ 29.08万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2001
  • 资助国家:
    美国
  • 起止时间:
    2001-09-15 至 2004-08-31
  • 项目状态:
    已结题

项目摘要

This document describes a proposed software system, called INBOUNDS (IntegratedNetwork-Based Ohio University Network Detective Service), that will address thedifficult research problem of security in the dynamic real-time Internet environmentpopulated by both legitimate users and hostile intruders. Internet security is becoming more critical by the day. Successful attacks on banks,schools, government agencies, and corporations that do business online are becomingmore and more common, and the frequency of these attacks and the amount of damagedone is rising rapidly. Commercially available firewalls and intrusion detection systemsare currently the only weapons with which to defend against the threat, but they areobviously not capable of keeping up with the ever-changing attack strategies of hackers. Thus, we propose INBOUNDS a real-time network based intrusion detection andresponse system under development at Ohio University's Laboratory for Real-Time,Secure Systems and Applications. INBOUNDS detects and responds to suspiciousbehavior by using TCPTrace (a network traffic analysis tool) and DeSiDeRaTa (dynamic,real-time resource management middleware). INBOUNDS is intended to function in aheterogeneous environment with fault tolerance, very low overhead, and a high degree ofscalability. A prototype of INBOUNDS is currently being used for around-the-clockintrusion detection and response at Ohio University and we propose to add functionalitythat will enable INBOUNDS to deal with the following important types of attacks: Large-scale, distributed denial-of-service attacks Abnormal network protocol behavior including SYN and RESET attacks Suspicious keywords in interactive sessions/email Suspicious patterns of data, such as the fan-out patterns commonly seen with email viruses Communication over unusual network ports, which are common when attackers target seldom used and insecure servers Connections from unknown/unusual hosts Abnormal data patterns for a particular time of day Unusual data patterns on known ports, such as would be seen when at attacker installs programs using the fingerd port as in the Morris Worm
本文介绍了一个被称为INBOUNDS(IntegratedNetwork-Based俄亥俄州大学网络侦探服务)的软件系统,它将解决由合法用户和恶意入侵者组成的动态实时Internet环境中的安全性研究难题。 互联网安全日益重要。对银行、学校、政府机构和在网上开展业务的公司的成功攻击越来越普遍,这些攻击的频率和破坏的数量正在迅速上升。商用防火墙和入侵检测系统是目前防御威胁的唯一武器,但它们显然无法跟上黑客不断变化的攻击策略。 因此,我们建议INBOUNDS的实时网络为基础的入侵检测和响应系统正在开发中的俄亥俄州大学的实时,安全系统和应用实验室。INBOUNDS通过使用TCPTrace(网络流量分析工具)和DeSiDeRaTa(动态实时资源管理中间件)来检测和响应可疑行为。INBOUNDS旨在在具有容错性、非常低的开销和高度可伸缩性的异构环境中运行。INBOUNDS的原型目前正在俄亥俄州大学用于全天候的入侵检测和响应,我们建议增加功能,使INBOUNDS能够处理以下重要类型的攻击: 大规模分布式拒绝服务攻击 异常网络协议行为,包括SYN和RESET攻击 互动会话/电子邮件中的可疑关键字 可疑的数据模式,例如通常在 电子邮件病毒 通过不寻常的网络端口进行通信,当攻击者 针对很少使用和不安全的服务器 来自未知/异常主机的连接 一天中特定时间的异常数据模式 已知端口上的异常数据模式,例如在攻击者 使用fingerd端口安装程序,如Morris Worm

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Shawn Ostermann其他文献

Statistical analysis of malformed packets and their origins in the modern internet
现代互联网中畸形数据包及其起源的统计分析
Satellite Network Performance Measurements Using Simulated Multi-User Internet Traffic
使用模拟多用户互联网流量进行卫星网络性能测量
  • DOI:
  • 发表时间:
    1999
  • 期刊:
  • 影响因子:
    0
  • 作者:
    H. Kruse;M. Allman;J. Griner;Shawn Ostermann;E. Helvey
  • 通讯作者:
    E. Helvey
On the Impact of BER on Realistic TCP Traffic in Satellite Networks
BER 对卫星网络中实际 TCP 流量的影响
  • DOI:
  • 发表时间:
    2004
  • 期刊:
  • 影响因子:
    0
  • 作者:
    P. Narasimhan;H. Kruse;Shawn Ostermann;M. Allman
  • 通讯作者:
    M. Allman
One: the ohio network emulator
一:俄亥俄州网络模拟器
  • DOI:
  • 发表时间:
    1996
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Adam W. Caldwell;M. Allman;Shawn Ostermann
  • 通讯作者:
    Shawn Ostermann

Shawn Ostermann的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Shawn Ostermann', 18)}}的其他基金

Networking Education: How to Educate the Educators?; Karlsruhe, Germany
网络教育:如何教育教育工作者?
  • 批准号:
    0349407
  • 财政年份:
    2003
  • 资助金额:
    $ 29.08万
  • 项目类别:
    Standard Grant
Tcptrace: Instrumenting and Visualizing Network Dynamics
Tcptrace:检测和可视化网络动态
  • 批准号:
    9981927
  • 财政年份:
    2000
  • 资助金额:
    $ 29.08万
  • 项目类别:
    Standard Grant

相似国自然基金

greenwashing behavior in China:Basedon an integrated view of reconfiguration of environmental authority and decoupling logic
  • 批准号:
  • 批准年份:
    2024
  • 资助金额:
    万元
  • 项目类别:
    外国学者研究基金项目
焦虑症小鼠模型整合模式(Integrated) 行为和精细行为评价体系的构建
  • 批准号:
  • 批准年份:
    2024
  • 资助金额:
    0.0 万元
  • 项目类别:
    省市级项目

相似海外基金

CC* Integration-Small: M2- NET: An Integrated Access and Backhaul Millimeter-wave Wireless Network for Campus Connectivity and Research
CC* Integration-Small:M2-NET:用于校园连接和研究的集成接入和回程毫米波无线网络
  • 批准号:
    2346621
  • 财政年份:
    2024
  • 资助金额:
    $ 29.08万
  • 项目类别:
    Standard Grant
Network for Integrated Care Excellence (NICE) Canada: Transforming Health with Integrated Care Knowledge Mobilization and Impact Hub
加拿大卓越综合护理网络 (NICE):通过综合护理知识动员和影响力中心改变健康状况
  • 批准号:
    485405
  • 财政年份:
    2023
  • 资助金额:
    $ 29.08万
  • 项目类别:
    Operating Grants
An eHealth Technology Intervention Pragmatic trials Platform integrated in the Canadian Primary Care Sentinel Surveillance Network: The eTIPP-CPCSSN
纳入加拿大初级保健哨点监测网络的电子健康技术干预实用试验平台:eTIPP-CPCSSN
  • 批准号:
    487643
  • 财政年份:
    2023
  • 资助金额:
    $ 29.08万
  • 项目类别:
    Operating Grants
Integrated, Individualized, and Intelligent Prescribing (I3P) Clinical Trial Network
一体化、个体化、智能处方(I3P)临床试验网络
  • 批准号:
    10822651
  • 财政年份:
    2023
  • 资助金额:
    $ 29.08万
  • 项目类别:
Integrated Network Analysis of RADx-UP Data to Increase COVID-19 Testing and Vaccination Among Persons Involved with Criminal Legal Systems (PCLS)
RADx-UP 数据的综合网络分析可提高刑事法律系统 (PCLS) 相关人员的 COVID-19 检测和疫苗接种率
  • 批准号:
    10879972
  • 财政年份:
    2023
  • 资助金额:
    $ 29.08万
  • 项目类别:
NSF-IITP: AI/ML-Enabled Scalable and Privacy-Preserving 6G Space-Air-Ground Integrated Network Operation
NSF-IITP:支持 AI/ML 的可扩展且保护隐私的 6G 天地一体化网络运营
  • 批准号:
    2242412
  • 财政年份:
    2023
  • 资助金额:
    $ 29.08万
  • 项目类别:
    Standard Grant
RCN-SC: Research Coordination Network for Design and Testing of Neuromorphic Integrated Circuits
RCN-SC:神经形态集成电路设计和测试的研究协调网络
  • 批准号:
    2332166
  • 财政年份:
    2023
  • 资助金额:
    $ 29.08万
  • 项目类别:
    Continuing Grant
AccelNet-Design: A Global Network of Networks of Integrated Urban Services (GNNIUS) for Healthy and Smart Cities
AccelNet-Design:面向健康和智慧城市的全球综合城市服务网络 (GNNIUS)
  • 批准号:
    2301858
  • 财政年份:
    2023
  • 资助金额:
    $ 29.08万
  • 项目类别:
    Standard Grant
TMJ SYMPHONY Systems-integrated model and mechanisms of patient-centered holistic outcomes and network-supported training and therapy
TMJ SYMPHONY 系统集成模型和以患者为中心的整体结果机制以及网络支持的培训和治疗
  • 批准号:
    10829112
  • 财政年份:
    2023
  • 资助金额:
    $ 29.08万
  • 项目类别:
EAGER: Quantum Manufacturing: Enabling Integrated Quantum Network Nodes
EAGER:量子制造:实现集成量子网络节点
  • 批准号:
    2240267
  • 财政年份:
    2023
  • 资助金额:
    $ 29.08万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了