STI: Viable Network Defense for Scientific Research Institutions

STI:科研机构可行的网络防御

基本信息

  • 批准号:
    0334088
  • 负责人:
  • 金额:
    $ 90万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2003
  • 资助国家:
    美国
  • 起止时间:
    2003-11-01 至 2007-10-31
  • 项目状态:
    已结题

项目摘要

Modern science makes heavy use of the Internet for collaborations that draw upon the network in ways far beyond simple uses such as email for discussion and Web access for sharing data in some cases several hundred distinct services. This access also opens the doors to incessant network attacks and research institutes find themselves under growing pressure to place significant restrictions on such access in the form of firewalls, limited permitted applications, and mandatory proxies. These issues threaten to diminish the effectiveness of how modern science is conducted across a broad range of disciplines. A key tool to maintain openness is intrusion detection: detecting in real-time that an attack is underway and, if warranted, initiating a response in order to thwart it. However, there is a world of difference between detecting attackers in a small-scale environment such as a researcher's LAN and doing so at a large scale such as for an entire open site. Both the much higher required performance and the greatly increased traffic diversity present major challenges. But intrusion detection for large, open sites also sees very little in the way of academic research, because of the great difficulties many researchers face in acquiring the necessary access.The PI of this proposal, however, is in a unique position for developing and validating network intrusion detection research at such sites, by virtue of his joint appointment at ICSI and LBNL. LBNL's operational cyber security is centered around use of BRO- the intrusion detection system developed by the PI. The PI has full monitoring access to the Laboratory's network traffic, and participation in the realities of network security at a large institute. In addition, BRO is used operationally at the University of California, Berkeley, where the PI likewise has full monitoring access. The proposed efforts will be firmly grounded in the realities of defending large research institutions. The work will not be abstract; it will validate mechanisms developed against actual in situ attacks and actual operational needs, avoiding the pitfall of devising attractive solutions that fail in practice when actually deployed. The research will be spanning a number of areas: (i) developing new ways of detecting attacks (detecting network "triggers" used by automated exploit software and by worms; attempting to "finger print" users by their keystroke timing; drawing upon LBNL's immense archive of TCP connection summaries to devise robust anomaly detection algorithms); (ii) addressing challenges in monitoring very high-speed, high volume links (distributing monitoring across multiple machines; coordinating monitors with border routers that will "shunt" a portion of the traffic to the monitor and cut through the rest; devising robust mechanisms for dealing with massive traffic floods); and (iii) addressing the realities of managing large-scale security policies (understanding the relationship between individual alerts and the complex policies that lead to them; automatically locating "stale" policy elements no longer relevant). The work will advance development in two key areas: (iv) refining and applying the trace anonymization framework developed in earlier in order to address the major shortcoming in network intrusion detection research of a complete lack of traffic traces that include packet contents; and (v) bringing the BRO software system up to the level of support necessary for it to become the open-source monitoring system of choice for operational deployment at large scientific research institutes.
现代科学大量利用互联网进行协作,其利用网络的方式远远超出了简单的用途,例如用于讨论的电子邮件和用于共享数据的网络访问,在某些情况下还有数百种不同的服务。这种访问也为持续不断的网络攻击打开了大门,研究机构发现自己面临着越来越大的压力,需要以防火墙、有限允许的应用程序和强制代理的形式对此类访问进行严格限制。这些问题可能会降低现代科学在广泛学科中开展的有效性。 保持开放性的一个关键工具是入侵检测:实时检测正在进行的攻击,如果有必要,则启动响应以阻止攻击。然而,在小规模环境(例如研究人员的 LAN)中检测攻击者与在大规模环境(例如整个开放站点)中检测攻击者之间存在天壤之别。更高的性能要求和大大增加的流量多样性都带来了重大挑战。但大型、开放站点的入侵检测在学术研究中也很少见,因为许多研究人员在获得必要的访问权限方面面临着巨大的困难。然而,该提案的 PI 由于在 ICSI 和 LBNL 的联合任命,在开发和验证此类站点的网络入侵检测研究方面处于独特的地位。 LBNL 的运营网络安全以 BRO(由 PI 开发的入侵检测系统)的使用为中心。 PI可以全面监控实验室的网络流量,并参与大型研究所的网络安全实践。此外,BRO 还在加州大学伯克利分校投入使用,PI 同样拥有完全的监控访问权限。拟议的努力将牢牢扎根于保卫大型研究机构的现实。这项工作不会是抽象的;它将验证针对实际原位攻击和实际操作需求而开发的机制,避免设计有吸引力的解决方案但在实际部署时却失败的陷阱。该研究将涵盖多个领域:(i)开发检测攻击的新方法(检测自动漏洞软件和蠕虫使用的网络“触发器”;尝试通过击键时间“指纹”用户;利用劳伦斯伯克利国家实验室庞大的 TCP 连接摘要档案来设计强大的异常检测算法); (ii) 解决监控超高速、大容量链路方面的挑战(跨多台机器分布监控;协调监控器与边界路由器,将一部分流量“分流”到监控器并切断其余流量;设计强大的机制来处理大规模流量洪流); (iii) 解决管理大规模安全策略的现实问题(了解单个警报与导致这些警报的复杂策略之间的关系;自动定位不再相关的“过时”策略元素)。这项工作将推动两个关键领域的发展:(iv)完善和应用早期开发的跟踪匿名化框架,以解决网络入侵检测研究中完全缺乏包括数据包内容的流量跟踪的主要缺点; (v) 将 BRO 软件系统提升到必要的支持水平,使其成为大型科研机构运行部署的首选开源监控系统。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Vern Paxson其他文献

A Longitudinal View of HTTP Traffic
HTTP 流量的纵向视图

Vern Paxson的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Vern Paxson', 18)}}的其他基金

II-New: Enabling Security Analysis at Scale
II-新:实现大规模安全分析
  • 批准号:
    1406041
  • 财政年份:
    2014
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
TWC: Phase: Small: Censorship Counterstrike via Measurement, Filtering, Evasion, and Protocol Enhancement
TWC:阶段:小:通过测量、过滤、规避和协议增强进行审查反击
  • 批准号:
    1223717
  • 财政年份:
    2012
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
NeTS: Large: Collaborative Research: Measuring and Modeling the Dynamics of IPv4 Address Exhaustion
NeTS:大型:协作研究:IPv4 地址耗尽动态的测量和建模
  • 批准号:
    1111672
  • 财政年份:
    2011
  • 资助金额:
    $ 90万
  • 项目类别:
    Continuing Grant
CT-L: Collaborative Research: Comprehensive Application Analysis and Control
CT-L:协作研究:综合应用分析与控制
  • 批准号:
    0831535
  • 财政年份:
    2008
  • 资助金额:
    $ 90万
  • 项目类别:
    Continuing Grant
CT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and Forensics
CT-T:建立跨机构合作安全监控和取证平台
  • 批准号:
    0716640
  • 财政年份:
    2007
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
CT-T:Exploiting Multi-Core CPUs for Parallelizing Network Intrusion Prevention
CT-T:利用多核 CPU 并行化网络入侵防御
  • 批准号:
    0716636
  • 财政年份:
    2007
  • 资助金额:
    $ 90万
  • 项目类别:
    Continuing Grant
CT-T: Approaches to Network Defense Proven in Open Scientific Environments
CT-T:在开放科学环境中经过验证的网络防御方法
  • 批准号:
    0627320
  • 财政年份:
    2006
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
NeTS-FIND: Collaborative Research: Network Fabric for Personal, Social, and Urban Sensing Applications
NeTS-FIND:协作研究:用于个人、社交和城市传感应用的网络结构
  • 批准号:
    0626539
  • 财政年份:
    2006
  • 资助金额:
    $ 90万
  • 项目类别:
    Continuing Grant
Collaborative Proposal Cybertrust: Center for Internet Epidemiology and Defenses
协作提案 Cyber​​trust:互联网流行病学和防御中心
  • 批准号:
    0433702
  • 财政年份:
    2004
  • 资助金额:
    $ 90万
  • 项目类别:
    Continuing Grant
NRT: Collaborative Research: Testing and Benchmarking Methodologies for Future Network Security Mechanisms
NRT:协作研究:未来网络安全机制的测试和基准测试方法
  • 批准号:
    0335290
  • 财政年份:
    2003
  • 资助金额:
    $ 90万
  • 项目类别:
    Cooperative Agreement

相似国自然基金

再生水系统中VBNC(Viable but nonculturable)病原菌复活机制与控制方法研究
  • 批准号:
    51178242
  • 批准年份:
    2011
  • 资助金额:
    61.0 万元
  • 项目类别:
    面上项目

相似海外基金

TUBERSCAN-VENTURE: Delivering a commercially-viable, non-destructive, data driven pipeline to quantify root crops during growth to realise maximum marketable yield and help reduce waste, contributing to net zero emissions
TUBERSCAN-VENTURE:提供商业上可行的、非破坏性的、数据驱动的管道,以量化生长过程中的块根作物,以实现最大的市场产量并帮助减少浪费,从而实现净零排放
  • 批准号:
    10092039
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Collaborative R&D
Developing commercially viable Quasi-Solid-State Li-S batteries for the Automotive market
为汽车市场开发商业上可行的准固态锂硫电池
  • 批准号:
    10040939
  • 财政年份:
    2023
  • 资助金额:
    $ 90万
  • 项目类别:
    Collaborative R&D
BBconnect - a people-centred, system aware design feasibility investigation that aims to define innovation opportunities, generate and evaluate viable ideas for more accessible, effective and integrated bladder and bowel healthcare services.
BBconnect - 一项以人为本、系统意识的设计可行性调查,旨在定义创新机会,生成和评估可行的想法,以提供更方便、有效和综合的膀胱和肠道医疗保健服务。
  • 批准号:
    10089501
  • 财政年份:
    2023
  • 资助金额:
    $ 90万
  • 项目类别:
    Collaborative R&D
REFINE - From solar energy to fuel: A holistic artificial photosynthesis platform for the production of viable solar fuels
REFINE - 从太阳能到燃料:用于生产可行太阳能燃料的整体人工光合作用平台
  • 批准号:
    10106958
  • 财政年份:
    2023
  • 资助金额:
    $ 90万
  • 项目类别:
    EU-Funded
From solar energy to fuel: A holistic artificial photosynthesis platform to produce viable solar fuels (REFINE)
从太阳能到燃料:生产可行太阳能燃料的整体人工光合作用平台 (REFINE)
  • 批准号:
    10095746
  • 财政年份:
    2023
  • 资助金额:
    $ 90万
  • 项目类别:
    EU-Funded
Accelerating VRbit to Minimum Viable Product Launch
加速 VRbit 最小可行产品的发布
  • 批准号:
    10069696
  • 财政年份:
    2023
  • 资助金额:
    $ 90万
  • 项目类别:
    Collaborative R&D
Coastal Workboats: E-LUV, a UK-first, MCA certified, fully electric inter-island workboat demonstration supported by Shore Power Storage to prove commercially viable, including in remote locations
沿海工作船:E-LUV是英国首创、MCA认证的全电动岛间工作船演示,由岸电存储支持,以证明商业可行性,包括在偏远地区
  • 批准号:
    10060694
  • 财政年份:
    2023
  • 资助金额:
    $ 90万
  • 项目类别:
    Collaborative R&D
Electrowetting-enhanced sustainable liquid films for collection of viable airborne pathogens
用于收集活空气传播病原体的电润湿可持续液膜
  • 批准号:
    EP/X017591/1
  • 财政年份:
    2023
  • 资助金额:
    $ 90万
  • 项目类别:
    Research Grant
Regenerative Fibre Networks: Designing viable traceable UK supply chains through nature-positive farming and novel digital systems, supporting livelihoods, climate action, and biodiversity to achieve net-zero.
再生纤维网络:通过自然积极型农业和新颖的数字系统设计可行的可追溯的英国供应链,支持生计、气候行动和生物多样性,以实现净零排放。
  • 批准号:
    10088542
  • 财政年份:
    2023
  • 资助金额:
    $ 90万
  • 项目类别:
    Collaborative R&D
Building confidence in non-protected zebrafish embryo-larvae as a viable alternative to mammalian DART assessment. (Ref 4649)
建立对非受保护斑马鱼胚胎幼虫作为哺乳动物 DART 评估的可行替代方案的信心。
  • 批准号:
    2867639
  • 财政年份:
    2023
  • 资助金额:
    $ 90万
  • 项目类别:
    Studentship
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了