STI: Viable Network Defense for Scientific Research Institutions
STI: Viable Network Defense for Scientific Research Institutions
批准号:
0334088
负责人:
Vern Paxson
金额:
$90.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-11-01 至 2007-10-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Modern science makes heavy use of the Internet for collaborations that draw upon the network in ways far beyond simple uses such as email for discussion and Web access for sharing data in some cases several hundred distinct services. This access also opens the doors to incessant network attacks and research institutes find themselves under growing pressure to place significant restrictions on such access in the form of firewalls, limited permitted applications, and mandatory proxies. These issues threaten to diminish the effectiveness of how modern science is conducted across a broad range of disciplines. A key tool to maintain openness is intrusion detection: detecting in real-time that an attack is underway and, if warranted, initiating a response in order to thwart it. However, there is a world of difference between detecting attackers in a small-scale environment such as a researcher's LAN and doing so at a large scale such as for an entire open site. Both the much higher required performance and the greatly increased traffic diversity present major challenges. But intrusion detection for large, open sites also sees very little in the way of academic research, because of the great difficulties many researchers face in acquiring the necessary access.The PI of this proposal, however, is in a unique position for developing and validating network intrusion detection research at such sites, by virtue of his joint appointment at ICSI and LBNL. LBNL's operational cyber security is centered around use of BRO- the intrusion detection system developed by the PI. The PI has full monitoring access to the Laboratory's network traffic, and participation in the realities of network security at a large institute. In addition, BRO is used operationally at the University of California, Berkeley, where the PI likewise has full monitoring access. The proposed efforts will be firmly grounded in the realities of defending large research institutions. The work will not be abstract; it will validate mechanisms developed against actual in situ attacks and actual operational needs, avoiding the pitfall of devising attractive solutions that fail in practice when actually deployed. The research will be spanning a number of areas: (i) developing new ways of detecting attacks (detecting network "triggers" used by automated exploit software and by worms; attempting to "finger print" users by their keystroke timing; drawing upon LBNL's immense archive of TCP connection summaries to devise robust anomaly detection algorithms); (ii) addressing challenges in monitoring very high-speed, high volume links (distributing monitoring across multiple machines; coordinating monitors with border routers that will "shunt" a portion of the traffic to the monitor and cut through the rest; devising robust mechanisms for dealing with massive traffic floods); and (iii) addressing the realities of managing large-scale security policies (understanding the relationship between individual alerts and the complex policies that lead to them; automatically locating "stale" policy elements no longer relevant). The work will advance development in two key areas: (iv) refining and applying the trace anonymization framework developed in earlier in order to address the major shortcoming in network intrusion detection research of a complete lack of traffic traces that include packet contents; and (v) bringing the BRO software system up to the level of support necessary for it to become the open-source monitoring system of choice for operational deployment at large scientific research institutes.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
II-New: Enabling Security Analysis at Scale
-
批准号:1406041
-
项目类别:Standard Grant
-
资助金额:$59.38万
-
财政年份:2014
-
负责人:Vern Paxson
-
依托单位:
TWC: Phase: Small: Censorship Counterstrike via Measurement, Filtering, Evasion, and Protocol Enhancement
-
批准号:1223717
-
项目类别:Standard Grant
-
资助金额:$66.66万
-
财政年份:2012
-
负责人:Vern Paxson
-
依托单位:
NeTS: Large: Collaborative Research: Measuring and Modeling the Dynamics of IPv4 Address Exhaustion
-
批准号:1111672
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2011
-
负责人:Vern Paxson
-
依托单位:
CT-L: Collaborative Research: Comprehensive Application Analysis and Control
-
批准号:0831535
-
项目类别:Continuing Grant
-
资助金额:$127.75万
-
财政年份:2008
-
负责人:Vern Paxson
-
依托单位:
CT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and Forensics
-
批准号:0716640
-
项目类别:Standard Grant
-
资助金额:$69.98万
-
财政年份:2007
-
负责人:Vern Paxson
-
依托单位:
CT-T:Exploiting Multi-Core CPUs for Parallelizing Network Intrusion Prevention
-
批准号:0716636
-
项目类别:Continuing Grant
-
资助金额:$49.94万
-
财政年份:2007
-
负责人:Vern Paxson
-
依托单位:
CT-T: Approaches to Network Defense Proven in Open Scientific Environments
-
批准号:0627320
-
项目类别:Standard Grant
-
资助金额:$23.61万
-
财政年份:2006
-
负责人:Vern Paxson
-
依托单位:
NeTS-FIND: Collaborative Research: Network Fabric for Personal, Social, and Urban Sensing Applications
-
批准号:0626539
-
项目类别:Continuing Grant
-
资助金额:$22.01万
-
财政年份:2006
-
负责人:Vern Paxson
-
依托单位:
Collaborative Proposal Cybertrust: Center for Internet Epidemiology and Defenses
-
批准号:0433702
-
项目类别:Continuing Grant
-
资助金额:$309.75万
-
财政年份:2004
-
负责人:Vern Paxson
-
依托单位:
NRT: Collaborative Research: Testing and Benchmarking Methodologies for Future Network Security Mechanisms
-
批准号:0335290
-
项目类别:Cooperative Agreement
-
资助金额:$0.0万
-
财政年份:2003
-
负责人:Vern Paxson
-
依托单位:
国内基金
海外基金
再生水系统中VBNC(Viable but nonculturable)病原菌复活机制与控制方法研究
-
批准号:51178242
-
项目类别:面上项目
-
资助金额:61.0万元
-
批准年份:2011
-
负责人:李丹
-
依托单位: