Architectural Solutions for Preventing Distributed Denial of Service Attacks
Architectural Solutions for Preventing Distributed Denial of Service Attacks
批准号:
0208946
负责人:
Ruby Lee
金额:
$19.63万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-08-01 至 2005-07-31
中文摘要
拒绝服务攻击使网站充斥着如此之多的请求,以至于它再也无法响应。连接到Internet的计算机容易在不知不觉中被用于对受害者网站发动分布式拒绝服务(DDoS)攻击。过去基于软件补丁或重新编译的对策往往被用户忽视,导致许多系统容易受到攻击。本研究首先提出了各种拒绝服务攻击的分类和对策,然后在未来机器的核心(非可选)硬件和软件中定义了体系结构解决方案。研究了允许建立DDoS攻击网络的计算机的脆弱性。研究了计算机核心硬件中的低开销体系结构特征,这些特征首先阻碍了攻击网络的建立,或者检测和防止潜在恶意代码的执行。恶意方经常使用缓冲区溢出攻击,通过破坏过程返回地址来获得进入计算机的权限。这项研究调查了处理器体系结构中的安全返回地址堆栈(SRAS)等功能,以此作为对此类缓冲区溢出利用的新防御。所提出的研究方法的独特之处在于在客户端平台而不是仅在服务器或路由器中提供防御,在核心硬件而不是仅在软件层中构建更可信的体系结构。由于应用程序代码不需要更改或重新编译,因此遗留软件和未来软件都可以享受硬件架构解决方案的安全优势。由于DDoS攻击对关键互联网服务的可用性构成严重威胁,这项研究可以促进互联网的整体安全,同时增加所有者对其互联信息设备的信任。
英文摘要
Denial of service attacks flood a web-site with so many requests that it can no longer respond. Computers connected to the Internet are vulnerable to being used unwittingly in mounting a distributed denial of service (DDoS) attack on a victim web-site. Past countermeasures based on software patches or re-compilation are often ignored by users, leaving many systems vulnerable. This research first proposes a classification of the various denial of service attacks and countermeasures, then defines architectural solutions in the core (non-optional) hardware and software of future machines. The vulnerabilities of computers, which allow DDoS attack networks to be set up, are studied. Low overhead architectural features in the core hardware of computers are investigated which hinder attack networks from being set up in the first place, or detect and prevent the execution of potentially hostile code. Malicious parties often employ buffer overflow attacks to gain entry to a computer by corrupting procedure return addresses. This research investigates features like a secure return address stack (SRAS) in the processor architecture as a new defense against such buffer overflow exploits. The proposed research approach is unique in providing defenses in the client platforms rather than only in the servers or routers, and in building more trusted architecture in the core hardware, rather than only in software layers. Since application code need not be changed nor re-compiled, both legacy and future software can enjoy the security benefits of hardware architectural solutions. Since DDoS attacks pose a serious threat to the availability of critical Internet services, this research can contribute to the overall security of the Internet while increasing the trust that owners may have in their interconnected information appliances.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: STARSS: Small: Collaborative: Design and Security Verification of Next-Generation Open-Source Processors
-
批准号:1814190
-
项目类别:Standard Grant
-
资助金额:$16.56万
-
财政年份:2018
-
负责人:Ruby Lee
-
依托单位:
STARSS: Small: Collaborative: Practical and Scalable Security Verification of Security-Aware Hardware Architectures
-
批准号:1526493
-
项目类别:Standard Grant
-
资助金额:$13.33万
-
财政年份:2015
-
负责人:Ruby Lee
-
依托单位:
CSR: Small: Cloud Security on Demand
-
批准号:1218817
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2012
-
负责人:Ruby Lee
-
依托单位:
SHF: Small: Rethinking Computer Architecture for Secure and Resilient Systems
-
批准号:0917134
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Ruby Lee
-
依托单位:
Collaborative Research: SecureCore for Trustworthy Commodity Computing and Communications
-
批准号:0430487
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Ruby Lee
-
依托单位:
ITR: Architectures and Design Methodologies for Secure Low-Power Embedded Systems
-
批准号:0326372
-
项目类别:Standard Grant
-
资助金额:$52.5万
-
财政年份:2003
-
负责人:Ruby Lee
-
依托单位:
Instruction Set Architecture for Pervasive Security
-
批准号:0105677
-
项目类别:Continuing Grant
-
资助金额:$25.66万
-
财政年份:2001
-
负责人:Ruby Lee
-
依托单位:
海外基金