CAREER: Dependable Network Communication
CAREER: Dependable Network Communication
批准号:
0133495
负责人:
David Wetherall
金额:
$35.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-08-15 至 2008-07-31
中文摘要
研究人员在未来十年的议程是提高网络通信服务的健壮性,使其适用于依赖于确保连接的应用程序。在本提案中,研究人员将重点放在控制路由器错误配置、路由协议中的实施错误和其他内部故障的影响这一关键目标上,如果不加以控制,这些内部故障可能会导致广泛的连接中断。随着航空、医疗服务、紧急服务、公用事业和国防等领域的关键应用与互联网相结合,可靠的通信显然具有重要意义。然而,今天的互联网不能依赖,因为提供连接的路由协议本身就很脆弱。它们采用双模式安全方法:使用成熟的加密技术来验证受信任的实体并保护协议免受不受信任的攻击者的攻击,但一旦实体通过身份验证,就不会对其提供的信息进行进一步的检查。其结果是,一旦无意中出现错误或攻击者偷偷进入,错误的范围可能是无限的。作为众所周知的严重故障的一个例子,总部位于弗吉尼亚州的一家ISP的错误配置导致大多数Internet主干流量在1997年4月被误导了长达两个小时。一项关于互联网故障的研究数据显示,内部故障造成的麻烦票大约是拒绝服务等恶意攻击的五倍。研究人员建议致力于设计能够有效容忍上述内部错误的路由协议。检测和控制这些漏洞是一个具有挑战性的问题,因为传统的安全技术往往无效。例如,身份验证可以验证哪个实体发送了哪条消息,但不能验证该实体的行为是否正确。他的方法的关键是使用参与者可以使用的信息来扩展路由协议,以检查彼此的行为是否一致。这是一种新的策略,不同于大多数以前的工作,后者专注于在现有路由协议的上下文中增加安全性。这位研究人员通过描述他对一个健壮的拥塞信令协议的研究来说明这个建议中的方法,在这个协议中,该协议在相关领域得到了实质性的优势。为了开始这项工作,研究人员将对BGP中的配置错误进行测量研究,BGP是跨互联网主干使用的路由协议。我已经开始了这项任务,并在提案中包括了一些初步结果。这样的研究很重要,因为几乎没有数据来量化内部失误的种类、流行程度或影响。有了这些结果,研究人员将设计限制由常见故障导致的连接丢失的路由协议。研究人员的理念是,首先将部署考虑放在一边,专注于通过从头设计可以实现的更基本的结果,然后将设计映射到现有路由协议的环境中。具体地说,他将推理处理不同类型故障所需的最小机制,并通过结合实施、模拟和与文献中的替代方案进行比较来评估该机制的成本。研究人员的方法也是首先解决最简单、非恶意的内部故障,并致力于逐步解决更复杂的故障类别,而不是从设计.拜占庭健壮型故障开始。协议。这样做的好处是既可以将已知的困难问题分解为碎片,又可以暴露出容忍更复杂错误所增加的计算成本。在上述所有阶段,研究人员将按照提案中的描述对我的研究和教育活动进行交叉培养。研究人员将把他的研究带入课堂,以活跃课堂,并将学生、他们的项目和重叠的基础设施(如拟议的动画)带回他的研究中。如果成功,这项工作将加深对可靠网络通信以及路由协议如何有效地遏制故障的理解。这反过来将为研究和教育可靠的分布式系统奠定基础,这些系统依赖于路由协议与其他组件(如传输协议和名称解析)的组合。
英文摘要
The researcher's agenda over the next decade is to improve the robustness of network communication services to the point that they are suitable for applications that depend on assured connectivity. In this proposal, the researcher focuses on the key goal of containing the effects of router misconfigurations, implementation bugs in routing protocols, and other insider faults that, if left unchecked, can cause widespread loss of connectivity. Dependable communications are of clear importance as critical applications in the areas of aviation, medical services, emergency services, utilities and defense become integrated with the Internet. Yet the Internet today cannot be depended on because the routing protocols that provide connectivity are themselves fragile. They take a bimodal approach to security: well-developed cryptographic techniques are used to authenticate trusted entities and protect the protocol from untrusted attackers, but no further checks are placed on the information provided by an entity once it has been authenticated. The result is that once an inadvertent error or attacker slips in, the scope of error is potentially unbounded. As one example of a well-known, spectacular failure, misconfiguration at a Virginia-based ISP caused most Internet backbone traffic to be misdirected for up to two hours in April 1997. Data from one study of Internet failures suggests that insider faults account for roughly five times more trouble tickets than malicious attacks, such as denial-of-service. The researcher proposes to work towards the design of routing protocols that are able to efficiently tolerate the above kind of insider faults. Detecting and containing these faults is a challenging problem because traditional security techniques are often ineffective. For example, authentication can validate what entity sent which message, but not that the entity is behaving correctly. The key to his approach is to extend routing protocols with information that can be used by the participants to consistency-check the behavior of each other. This is a novel strategy that differs from most of the prior work, which is focused on adding security in the context of existing routing protocols. The researcher illustrates the approach in this proposal by describing his research on a robust congestion signaling protocol, where it was applied to substantial advantage in a related domain. To begin this work, the researcher will conduct a measurement study of configuration errors in BGP, the routing protocol used across the backbone of the Internet. I have already started this task, and include some preliminary results in the proposal. Such a study is important because there is little data to quantify the kind, prevalence or impact of insider faults. Armed with these results, the researcher will design routing protocols that limit the loss of connectivity caused by common faults. the researchers philosophy is to first put aside deployment considerations to focus on what can be achieved as a more fundamental result with a clean-slate design, and then map the designs into the context of existing routing protocols. Specifically, he will reason about the minimal mechanism required to handle different kinds of faults, and evaluate the costs of that mechanism by using a combination of implementation, simulation, and comparison to alternatives in the literature. The researcher's approach is also to tackle the simplest, non-malicious insider faults first and work towards progressively more complex classes of faults, rather than beginning with the design of a .Byzantine robust. protocol. This has the advantages of both breaking a known, hard problem into pieces, and exposing the increased computational costs of tolerating more complex faults. At all of the above stages, the researcher will cross-fertilize my research and education activities as described in the proposal. The researcher will bring his research into the classroom to enliven lectures, and bring students, their projects, and overlapping infrastructure such as the proposed animations back into his research. If successful, this work will deepen the understanding of dependable network communication and how routing protocols can efficiently contain faults. This in turn will lay a foundation for research and education on dependable distributed systems that rely on the composition of routing protocols with other components such as transport protocols and name resolution.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NeTS: Small: RFID-Based Networking
-
批准号:1016487
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2010
-
负责人:David Wetherall
-
依托单位:
TC:Small:Informing Users of Their Privacy in Practice
-
批准号:0917341
-
项目类别:Continuing Grant
-
资助金额:$49.74万
-
财政年份:2009
-
负责人:David Wetherall
-
依托单位:
Collaborative Research NeTS-FIND: Protecting User Privacy in a Network with Ubiquitous Computing Devices
-
批准号:0722004
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:David Wetherall
-
依托单位:
Student Travel Support for the Second USENIX/ACM Symposium on Networked Systems Design and Implementation
-
批准号:0530882
-
项目类别:Standard Grant
-
资助金额:$1.5万
-
财政年份:2005
-
负责人:David Wetherall
-
依托单位:
Cyber Trust: Controlling Internet Denial-of-Service with Capabilities
-
批准号:0430304
-
项目类别:Continuing Grant
-
资助金额:$33.0万
-
财政年份:2004
-
负责人:David Wetherall
-
依托单位:
SP: Collaborative Research: Rapid Evolution of Transport Protocols
-
批准号:0338837
-
项目类别:Standard Grant
-
资助金额:$40.86万
-
财政年份:2003
-
负责人:David Wetherall
-
依托单位:
海外基金