课题基金 / 基金详情

Secure Virtually Isolated Networks to Avoid and Tolerate Denial of Service

Secure Virtually Isolated Networks to Avoid and Tolerate Denial of Service
保护虚拟隔离的网络以避免和容忍拒绝服务
批准号:
0087609
负责人:
Daniel Mosse
金额:
$30.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2001
资助国家:
美国
项目状态:
已结题
起止时间:
2001-10-01 至 2005-09-30

项目摘要

项目成果

Daniel Mosse的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The widespread need and ability to connect machines across the Internet, in a world where intelligent objects rather than documents are exchanged, has caused the network to be more vulnerable to intrusions and has facilitated break-ins of a variety of types. Most of the methods currently available to deal with networkvulnerability to abuse and attacks are either inadequate, inefficient oroverly restrictive. Compounding theproblem is the need to maintain an acceptable level of quality of service (QoS). The proposed research project considers a heterogeneous network environment where servers, whichprovide different levels of QoS support to clients through a contract protocol, are prone to faults and denialof service attacks. The research project assumes the existence of intrusion detection mechanisms, and aimsat investigating new and potentially revolutionary approaches for the development of scalable and efficientservice deployment strategies and network resource management schemes to maintain acceptable levels ofQoS and security, despite faults. Two types of faults, namely, benign malfunctions and malicious intrusions,will be considered. The former can be caused by a faulty, yet legitimate client that accidentally loses controlover its behavior, while the latter occurs with the intent to cause damage, such asDenial of Service (DoS).Both types of faults can severely affect the performance of the network and compromise the integrity andsecurity of its services. These faults can manifest themselves in the form of a protocol breach or a contract violation. The formeris exemplified by an authorized clients (impersonation may take place) who attempt to deliberately breachthe contract protocol and impact the behavior of the server to eventually cause its failure. Contract violationoccurs when a client attempts to acquire a level of service beyond what has been agreed upon in the servicecontract. In order to protect the servers and the network, we propose two new techniques: fault avoidance,based on the concept of replicated elusive servers, and fault tolerance, based on resource management schemes through the creation of a Virtually Isolated Network (VIN). The concept of replicated elusive servers espouses ideas such as roaming addresses and frequent frequencychanges in wireless networks. Replication is coordinated through group communication supported by anunderlying multicast mechanism. VINs, on the other hand, provide the basis to achieve both physical andlogical separation (in space and time) of the resources reserved for each service, client, or class of clients. Efficient management of network resources is achieved based on an integrative approach which considersnetwork performance, fault tolerance and security asintegral components of a multi-dimensional QoS space.QoS support can then be perceived as a multi-layered optimization process which considers security, fault-tolerance, resource allocation, communication protocol optimization and user level application managementas inhabitants of the same QoS spectrum and seeks to exploit tradeoffs in order to reach anoptimal operatingpoint. The techniques developed will be designed to handle multiple coordinated intrusions, clustered inboth space and time. A coordinated/clustered fault model will be developed and a study of its effect on thedeveloped techniques and algorithms will be conducted. The proposed research will build on a foundation of prior work developed by the PIs which have astrong track record of success in a wide range of research topics related to fault-tolerance, operating systemdevelopment and resource management for QoS support in wired and wireless networks. It is anticipatedthat through algorithms development and analysis, simulation and testbed implementations, the results ofthis project will lead to a better understanding of how to provide efficient support to QoS performance,fault-tolerance and securityin an integrated manner, both in wired and wireless environments. An equallyimportant contribution of this project will be the training of high quality students in a field where expertiseis scarce.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CSR-PDOS: Hardening Distributed Data Stores for Disaster Recovery
  • 批准号:
    0720578
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2007
  • 负责人:
    Daniel Mosse
  • 依托单位:
Travel Support Grant for Graduate Students/Junior Faculty to Attend IEEE 7th Real-Time Systems Symposium in Brazil
  • 批准号:
    0640162
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.04万
  • 财政年份:
    2006
  • 负责人:
    Daniel Mosse
  • 依托单位:
Collaborative Research: CT-ISG: Fault-Tolerant and Secure Infrastructure for Time Critical Embedded Systems
  • 批准号:
    0524634
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2005
  • 负责人:
    Daniel Mosse
  • 依托单位:
SGER: Exploratory Research on Sensor Based Infrastructure for Early Tsunami Detection
  • 批准号:
    0549119
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2005
  • 负责人:
    Daniel Mosse
  • 依托单位:
国内基金
海外基金
Gorenstein投射模与virtually Gorenstein代数
  • 批准号:
    11801141
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    22.0万元
  • 批准年份:
    2018
  • 负责人:
    沈大伟
  • 依托单位:
Haken流形的判定及virtually Haken猜想
  • 批准号:
    11101103
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    22.0万元
  • 批准年份:
    2011
  • 负责人:
    张宇
  • 依托单位: