课题基金 / 基金详情

Architectural Solutions for Preventing Distributed Denial of Service Attacks

Architectural Solutions for Preventing Distributed Denial of Service Attacks
防止分布式拒绝服务攻击的架构解决方案
批准号:
0208946
负责人:
Ruby Lee
金额:
$19.63万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-08-01 至 2005-07-31

项目摘要

项目成果

Ruby Lee的其他基金

相似基金

相关文献

中文摘要
翻译
拒绝服务攻击会向网站发送大量请求,使其无法再响应。连接到互联网的计算机很容易在无意中被用来对受害网站进行分布式拒绝服务(DDoS)攻击。过去基于软件补丁或重新编译的对策经常被用户忽略,导致许多系统容易受到攻击。本研究首先提出了各种拒绝服务攻击的分类和对策,然后定义了未来机器的核心(非可选)硬件和软件的架构解决方案。研究了计算机的漏洞,使DDoS攻击网络得以建立。研究了计算机核心硬件中的低开销架构特征,这些特征首先会阻碍攻击网络的建立,或者检测和防止潜在恶意代码的执行。恶意方通常采用缓冲区溢出攻击,通过破坏过程返回地址来进入计算机。本研究调查了处理器架构中的安全返回地址堆栈(SRAS)等特性,作为防止此类缓冲区溢出漏洞的新防御。所提出的研究方法的独特之处在于在客户端平台中提供防御,而不仅仅是在服务器或路由器中,并且在核心硬件中构建更可信的体系结构,而不仅仅是在软件层中。由于应用程序代码不需要更改或重新编译,因此遗留和未来的软件都可以享受硬件体系结构解决方案的安全性优势。由于DDoS攻击对关键互联网服务的可用性构成严重威胁,因此这项研究可以有助于提高互联网的整体安全性,同时增加所有者对其互联信息设备的信任。
英文摘要
Denial of service attacks flood a web-site with so many requests that it can no longer respond. Computers connected to the Internet are vulnerable to being used unwittingly in mounting a distributed denial of service (DDoS) attack on a victim web-site. Past countermeasures based on software patches or re-compilation are often ignored by users, leaving many systems vulnerable. This research first proposes a classification of the various denial of service attacks and countermeasures, then defines architectural solutions in the core (non-optional) hardware and software of future machines. The vulnerabilities of computers, which allow DDoS attack networks to be set up, are studied. Low overhead architectural features in the core hardware of computers are investigated which hinder attack networks from being set up in the first place, or detect and prevent the execution of potentially hostile code. Malicious parties often employ buffer overflow attacks to gain entry to a computer by corrupting procedure return addresses. This research investigates features like a secure return address stack (SRAS) in the processor architecture as a new defense against such buffer overflow exploits. The proposed research approach is unique in providing defenses in the client platforms rather than only in the servers or routers, and in building more trusted architecture in the core hardware, rather than only in software layers. Since application code need not be changed nor re-compiled, both legacy and future software can enjoy the security benefits of hardware architectural solutions. Since DDoS attacks pose a serious threat to the availability of critical Internet services, this research can contribute to the overall security of the Internet while increasing the trust that owners may have in their interconnected information appliances.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: STARSS: Small: Collaborative: Design and Security Verification of Next-Generation Open-Source Processors
  • 批准号:
    1814190
  • 项目类别:
    Standard Grant
  • 资助金额:
    $16.56万
  • 财政年份:
    2018
  • 负责人:
    Ruby Lee
  • 依托单位:
STARSS: Small: Collaborative: Practical and Scalable Security Verification of Security-Aware Hardware Architectures
  • 批准号:
    1526493
  • 项目类别:
    Standard Grant
  • 资助金额:
    $13.33万
  • 财政年份:
    2015
  • 负责人:
    Ruby Lee
  • 依托单位:
CSR: Small: Cloud Security on Demand
  • 批准号:
    1218817
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2012
  • 负责人:
    Ruby Lee
  • 依托单位:
SHF: Small: Rethinking Computer Architecture for Secure and Resilient Systems
  • 批准号:
    0917134
  • 项目类别:
    Standard Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2009
  • 负责人:
    Ruby Lee
  • 依托单位:
海外基金