STI: A Security Architecture for IP Telephony

STI:IP 电话安全架构

基本信息

  • 批准号:
    0334177
  • 负责人:
  • 金额:
    $ 15.85万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2003
  • 资助国家:
    美国
  • 起止时间:
    2003-09-01 至 2006-08-31
  • 项目状态:
    已结题

项目摘要

IP telephony is a complex application involving multiple layers of the protocols stack and interactions among multiple network devices. The complexity is exacerbated by two additional factors . 1) the requirement that IP telephony interoperate with the Public Switched Telephone Network (PSTN) and 2) the requirement that IP telephony functions with existing network middle-boxes such as network address translators (NATs) and firewalls. These complexities introduce vulnerabilities that are prone to both known and perhaps, new forms of attacks. The goals of this proposed focused research are 1) to perform a comprehensive vulnerability analysis of IP telephony and 2) to design a security architecture to counter various types of denial-of-service (DoS) attacks in IP telephony. The work will proceed as follows: first carry out a detailed vulnerability analysis of IP telephony using a property driven approach. In this approach, define a set of properties that an IP telephony application must satisfy for a specific type of deployment. Then the vulnerabilities will be then enumerated and classified as potential ways to violate these properties using a corresponding attack. This vulnerability analysis will form the basis for designing the security architecture. In developing the security architecture, our focus will be in the design and analysis of sensors to detect and control DoS attacks. While DoS attacks have been studied, IP telephony presents significant new challenges. Next will be an investigation of both signature-based and statistical anomaly detection algorithms. The detection algorithms are complex because the attacks can occur at multiple layers involving multiple network devices and attack both the control and data plane of the protocol architecture. Finally, in a converged network, an attack to the IP telephony system can be made from both the Internet as well as the PSTN. Recovery algorithms that can quickly recover once the attack has ceased will be designed. The overall architecture will involve cross-layer introspection, i.e., the data from the various sensors at the different protocol layers and at the different network elements will have to correlated to determine the type of attack and hence the desired response.
IP 电话是一种复杂的应用,涉及多层协议栈以及多个网络设备之间的交互。 另外两个因素加剧了复杂性。 1) IP 电话与公共交换电话网络 (PSTN) 互操作的要求,以及 2) IP 电话与现有网络中间件(例如网络地址转换器 (NAT) 和防火墙)配合使用的要求。这些复杂性引入了容易遭受已知攻击或新形式攻击的漏洞。本次重点研究的目标是 1) 对 IP 电话进行全面的漏洞分析,2) 设计一个安全架构来应对 IP 电话中各种类型的拒绝服务 (DoS) 攻击。 工作将按如下方式进行:首先使用属性驱动方法对 IP 电话进行详细的漏洞分析。 在此方法中,定义 IP 电话应用程序必须满足特定类型部署的一组属性。然后,将枚举这些漏洞并将其分类为使用相应攻击来违反这些属性的潜在方法。 该漏洞分析将构成设计安全架构的基础。在开发安全架构时,我们的重点是传感器的设计和分析,以检测和控制 DoS 攻击。 虽然 DoS 攻击已得到研究,但 IP 电话提出了重大的新挑战。 接下来将研究基于签名和统计异常检测算法。检测算法很复杂,因为攻击可能发生在涉及多个网络设备的多个层,并且攻击协议架构的控制平面和数据平面。 最后,在融合网络中,可以从互联网和 PSTN 对 IP 电话系统进行攻击。 将设计一旦攻击停止就可以快速恢复的恢复算法。 整体架构将涉及跨层自省,即来自不同协议层和不同网络元件的各种传感器的数据必须相互关联,以确定攻击类型,从而确定所需的响应。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Dipak Ghosal其他文献

Calibers: A bandwidth calendaring paradigm for science workflows
  • DOI:
    10.1016/j.future.2018.07.030
  • 发表时间:
    2018-12-01
  • 期刊:
  • 影响因子:
  • 作者:
    Fatma Alali;Nathan Hanford;Eric Pouyoul;Raj Kettimuthu;Mariam Kiran;Ben Mack-Crane;Brian Tierney;Yatish Kumar;Dipak Ghosal
  • 通讯作者:
    Dipak Ghosal
Call admission and handoff control in multi-tier cellular networks: algorithms and analysis
  • DOI:
    10.1007/s11277-007-9307-y
  • 发表时间:
    2007-06-06
  • 期刊:
  • 影响因子:
    2.200
  • 作者:
    Vijoy Pandey;Dipak Ghosal;Biswanath Mukherjee;Xiaoxin Wu
  • 通讯作者:
    Xiaoxin Wu

Dipak Ghosal的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Dipak Ghosal', 18)}}的其他基金

NeTS: Small: Addressing End-system Bottlenecks in High-speed Networks
NeTS:小型:解决高速网络中的终端系统瓶颈
  • 批准号:
    1528087
  • 财政年份:
    2015
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Standard Grant
DC: Small: Scaling the Performance of Network Security Applications Using Massively Parallel Processing Array (MPPA) Architectures
DC:小型:使用大规模并行处理阵列 (MPPA) 架构扩展网络安全应用程序的性能
  • 批准号:
    1018886
  • 财政年份:
    2010
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Standard Grant
CSR:Small:Estimating the End-system Network I/O Bottleneck Rate to Optimize Transport Layer Performance
CSR:小:估计终端系统网络 I/O 瓶颈率以优化传输层性能
  • 批准号:
    0917315
  • 财政年份:
    2009
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Standard Grant
Colloborative Research: CRI: A Testbed for Research and Development of Secure IP Multimedia Communication Services
合作研究:CRI:安全 IP 多媒体通信服务研究和开发的测试平台
  • 批准号:
    0551654
  • 财政年份:
    2006
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Continuing Grant
Complimenting Internet Caching With Pseudo-Serving to Mitigate Network Congestion
通过伪服务补充互联网缓存以缓解网络拥塞
  • 批准号:
    9714668
  • 财政年份:
    1998
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Continuing Grant
CAREER: A Career Development Plan for Research and Education in High Speed Networks
职业:高速网络研究和教育的职业发展计划
  • 批准号:
    9703275
  • 财政年份:
    1997
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Standard Grant

相似海外基金

Edge computing from space via aerial platforms: enabling technologies, system architecture, security mechanisms, and offloading strategies.
通过空中平台进行太空边缘计算:支持技术、系统架构、安全机制和卸载策略。
  • 批准号:
    24K14918
  • 财政年份:
    2024
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
NHLBI ENTERPRISE ARCHITECTURE AND CYBER SECURITY SUPPORT FOR DATA SCIENCE PROGRAMS
NHLBI 数据科学项目的企业架构和网络安全支持
  • 批准号:
    10974010
  • 财政年份:
    2023
  • 资助金额:
    $ 15.85万
  • 项目类别:
Ontology-based Approach to Enhance Security in Network Architecture and in System Design
基于本体的方法增强网络架构和系统设计的安全性
  • 批准号:
    RGPIN-2020-06859
  • 财政年份:
    2022
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Discovery Grants Program - Individual
Unified Architecture for Security, Reliability, and Trust in Internet of Things
物联网安全性、可靠性和信任的统一架构
  • 批准号:
    RGPIN-2020-06573
  • 财政年份:
    2022
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Discovery Grants Program - Individual
Ontology-based Approach to Enhance Security in Network Architecture and in System Design
基于本体的方法增强网络架构和系统设计的安全性
  • 批准号:
    RGPIN-2020-06859
  • 财政年份:
    2021
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Discovery Grants Program - Individual
CNS Core: Small: Rethinking Runtime Software Security Hardening in the Context of Hybrid Instruction Set Architecture
CNS 核心:小型:重新思考混合指令集架构背景下的运行时软件安全强化
  • 批准号:
    2127491
  • 财政年份:
    2021
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Standard Grant
CICI: UCSS: ACSP4HR: Assuring Cyber Security and Privacy for Human Resilience Research: Requirements, Framework, Architecture, Mechanisms and Prototype
CICI:UCSS:ACSP4HR:确保人类复原力研究的网络安全和隐私:要求、框架、架构、机制和原型
  • 批准号:
    2115134
  • 财政年份:
    2021
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    2128607
  • 财政年份:
    2021
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Standard Grant
Unified Architecture for Security, Reliability, and Trust in Internet of Things
物联网安全性、可靠性和信任的统一架构
  • 批准号:
    RGPIN-2020-06573
  • 财政年份:
    2021
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Discovery Grants Program - Individual
Security Architecture for Supervisory Control and Data Acquisition (SCADA) Networks
监控和数据采集 (SCADA) 网络的安全架构
  • 批准号:
    533183-2018
  • 财政年份:
    2020
  • 资助金额:
    $ 15.85万
  • 项目类别:
    Collaborative Research and Development Grants
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了