课题基金 / 基金详情

CAREER: Dependable Network Communication

CAREER: Dependable Network Communication
职业:可靠的网络通信
批准号:
0133495
负责人:
David Wetherall
金额:
$35.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-08-15 至 2008-07-31

项目摘要

项目成果

David Wetherall的其他基金

相似基金

相关文献

中文摘要
翻译
研究人员在下一个十年的议程是提高网络通信服务的健壮性,使其适用于依赖于保证连接的应用。在这个提议中,研究人员关注的关键目标是包含路由器错误配置的影响,路由协议中的实现错误,以及其他内部错误,如果不加以检查,可能导致广泛的连接损失。随着航空、医疗服务、应急服务、公用事业和国防等领域的关键应用与互联网相结合,可靠的通信显然具有重要意义。然而,今天的互联网不能依赖,因为提供连接的路由协议本身就很脆弱。它们采用双模安全性方法:使用成熟的加密技术对受信任的实体进行身份验证,并保护协议免受不受信任的攻击者的攻击,但是一旦实体通过身份验证,就不会对其提供的信息进行进一步检查。结果是,一旦出现无意的错误或攻击者,错误的范围可能是无限的。1997年4月,弗吉尼亚州一家ISP的错误配置导致大多数互联网骨干流量被错误引导长达两个小时,这是一个众所周知的重大失败的例子。一项关于互联网故障的研究数据显示,内部故障造成的故障数量大约是恶意攻击(如拒绝服务)的五倍。研究人员建议朝着能够有效容忍上述内部故障的路由协议设计方向努力。检测和控制这些故障是一个具有挑战性的问题,因为传统的安全技术通常是无效的。例如,身份验证可以验证哪个实体发送了哪个消息,但不能验证实体的行为是否正确。他的方法的关键是用参与者可以使用的信息来扩展路由协议,以一致性检查彼此的行为。这是一种新颖的策略,与大多数先前的工作不同,这些工作的重点是在现有路由协议的上下文中增加安全性。研究人员通过描述他对鲁棒拥塞信令协议的研究来说明该方法,该协议在相关领域中应用于实质性优势。为了开始这项工作,研究人员将对BGP配置错误进行测量研究,BGP是跨互联网骨干网使用的路由协议。我已经开始了这项工作,并在提案中包含了一些初步的结果。这样的研究很重要,因为很少有数据可以量化内部断层的种类、流行程度或影响。有了这些结果,研究人员将设计路由协议,以限制由常见故障引起的连接丢失。研究人员的理念是首先把部署方面的考虑放在一边,把重点放在通过一个全新的设计可以实现的更基本的结果上,然后将设计映射到现有路由协议的上下文中。具体地说,他将推断处理不同类型故障所需的最小机制,并通过结合使用实现、模拟和与文献中的替代方案进行比较来评估该机制的成本。研究人员的方法也是首先解决最简单的、非恶意的内部故障,然后逐步解决更复杂的故障类别,而不是从设计一个。拜占庭健壮。协议。这样做的优点是,既可以将已知的困难问题分解为多个部分,又可以暴露容忍更复杂故障所增加的计算成本。在上述所有阶段,研究人员将交叉施肥我的研究和教育活动,如提案中所述。研究人员将把他的研究带到课堂上,使讲座生动起来,并把学生、他们的项目和重叠的基础设施(如拟议的动画)带回他的研究中。如果成功,这项工作将加深对可靠网络通信以及路由协议如何有效地包含故障的理解。这反过来将为可靠的分布式系统的研究和教育奠定基础,这些系统依赖于路由协议与其他组件(如传输协议和名称解析)的组合。
英文摘要
The researcher's agenda over the next decade is to improve the robustness of network communication services to the point that they are suitable for applications that depend on assured connectivity. In this proposal, the researcher focuses on the key goal of containing the effects of router misconfigurations, implementation bugs in routing protocols, and other insider faults that, if left unchecked, can cause widespread loss of connectivity. Dependable communications are of clear importance as critical applications in the areas of aviation, medical services, emergency services, utilities and defense become integrated with the Internet. Yet the Internet today cannot be depended on because the routing protocols that provide connectivity are themselves fragile. They take a bimodal approach to security: well-developed cryptographic techniques are used to authenticate trusted entities and protect the protocol from untrusted attackers, but no further checks are placed on the information provided by an entity once it has been authenticated. The result is that once an inadvertent error or attacker slips in, the scope of error is potentially unbounded. As one example of a well-known, spectacular failure, misconfiguration at a Virginia-based ISP caused most Internet backbone traffic to be misdirected for up to two hours in April 1997. Data from one study of Internet failures suggests that insider faults account for roughly five times more trouble tickets than malicious attacks, such as denial-of-service. The researcher proposes to work towards the design of routing protocols that are able to efficiently tolerate the above kind of insider faults. Detecting and containing these faults is a challenging problem because traditional security techniques are often ineffective. For example, authentication can validate what entity sent which message, but not that the entity is behaving correctly. The key to his approach is to extend routing protocols with information that can be used by the participants to consistency-check the behavior of each other. This is a novel strategy that differs from most of the prior work, which is focused on adding security in the context of existing routing protocols. The researcher illustrates the approach in this proposal by describing his research on a robust congestion signaling protocol, where it was applied to substantial advantage in a related domain. To begin this work, the researcher will conduct a measurement study of configuration errors in BGP, the routing protocol used across the backbone of the Internet. I have already started this task, and include some preliminary results in the proposal. Such a study is important because there is little data to quantify the kind, prevalence or impact of insider faults. Armed with these results, the researcher will design routing protocols that limit the loss of connectivity caused by common faults. the researchers philosophy is to first put aside deployment considerations to focus on what can be achieved as a more fundamental result with a clean-slate design, and then map the designs into the context of existing routing protocols. Specifically, he will reason about the minimal mechanism required to handle different kinds of faults, and evaluate the costs of that mechanism by using a combination of implementation, simulation, and comparison to alternatives in the literature. The researcher's approach is also to tackle the simplest, non-malicious insider faults first and work towards progressively more complex classes of faults, rather than beginning with the design of a .Byzantine robust. protocol. This has the advantages of both breaking a known, hard problem into pieces, and exposing the increased computational costs of tolerating more complex faults. At all of the above stages, the researcher will cross-fertilize my research and education activities as described in the proposal. The researcher will bring his research into the classroom to enliven lectures, and bring students, their projects, and overlapping infrastructure such as the proposed animations back into his research. If successful, this work will deepen the understanding of dependable network communication and how routing protocols can efficiently contain faults. This in turn will lay a foundation for research and education on dependable distributed systems that rely on the composition of routing protocols with other components such as transport protocols and name resolution.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NeTS: Small: RFID-Based Networking
  • 批准号:
    1016487
  • 项目类别:
    Standard Grant
  • 资助金额:
    $45.0万
  • 财政年份:
    2010
  • 负责人:
    David Wetherall
  • 依托单位:
TC:Small:Informing Users of Their Privacy in Practice
  • 批准号:
    0917341
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $49.74万
  • 财政年份:
    2009
  • 负责人:
    David Wetherall
  • 依托单位:
Collaborative Research NeTS-FIND: Protecting User Privacy in a Network with Ubiquitous Computing Devices
  • 批准号:
    0722004
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2007
  • 负责人:
    David Wetherall
  • 依托单位:
Student Travel Support for the Second USENIX/ACM Symposium on Networked Systems Design and Implementation
  • 批准号:
    0530882
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2005
  • 负责人:
    David Wetherall
  • 依托单位:
海外基金