NRT: Collaborative Research: Testing and Benchmarking Methodologies for Future Network Security Mechanisms
NRT: Collaborative Research: Testing and Benchmarking Methodologies for Future Network Security Mechanisms
批准号:
0335290
负责人:
Vern Paxson
金额:
$0.0万
依托单位国家:
美国
项目类别:
Cooperative Agreement
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-09-01 至 2007-08-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Networks and computer systems are becoming increasingly attractive targets to large-scale programmedattacks such as worms and Distributed Denial of Service attacks (DDoS), which can compromise a vastnumber of vulnerable targets in a few minutes. Critical end-user applications vulnerable to such attacksinclude e-commerce, e-medicine, command-and-control applications, video surveillance and tracking, andmany other applications. While there is a growing body of research techniques, prototypes, and commercialproducts that purport to protect these applications and the network infrastructure on which they rely, thereis little existing scientific methodology by which to objectively evaluate the merits of such claims. Moreover,thorough testing of a defense system for worms or for attacks on the infrastructure cannot be evaluatedsafely on a live network without affecting its operation.To make rapid advancements in defending against these and future attacks, the state of the art in theevaluation of network security mechanisms must be improved. This will require the emergence of large-scalesecurity testbeds coupled with new standards for testing and benchmarking that can make these testbedstruly useful. Current shortcomings and impediments to evaluating network security mechanisms include lackof scientific rigor;lack of relevant and representative network data;inadequate models of defense mechanisms;and inadequate models of both the network and the transmitted data (benign and attack traffic). The latteris challenging because of the complexity of interactions among traffic, topology and protocols.The researchers propose to develop thorough, realistic,and scientifically rigorous testing frameworks and methodologies for particular classes of network attacks and defense mechanisms. These testing frameworks will be adapted for different kinds of testbeds, including simulators such as NS, emulation facilities such as Emulab, and both small and large hardware testbeds. They will include attack scenarios; attack simulators;generators for topology and background traffic; data sets derived from live traffic; and tools to monitor andsummarize test results. These frameworks will allow researchers to experiment with a variety of parameters representing the network environment, attack behaviors, and the configuration of the mechanisms under test.In addition to developing testing frameworks, the researchers propose to validate them by conducting tests on representative network defense mechanisms. Defense mechanisms of interest include network-based Intrusion Detection Systems (IDS); automated attack traceback mechanisms;t raffic rate-limiting to control DDoS attacks; and mechanisms to detect large-scale worm attacks. Conducting these tests will require incorporating real defense mechanisms into a testbed, and applying and evaluating frameworks and methodologies. Conducting these tests will also help us to ensure that the testbed framework allows other researchers to easily integrate and test network defense echanisms of their own.The research team includes experts in security, networking, data analysis, software engineering, and operating systems who are committed to developing these challenging integrated testing frameworks.Intellectual Merit: The development of testing methodologies for network defense mechanisms requiressignificant advances in our understanding of network attacks and the interactions between attacks and theirenvironment including:deployed defense technology, traffic, topology, protocols, and applications. It willalso require advances in our understanding of metrics for evaluating defenses.Education: The research into testing methodologies for network defense mechanisms will involve graduate students and provide new curriculum material for universities.Broader Impact: By providing new testing frameworks, the work will accelerate improvements innetwork defense mechanisms and facilitate their evaluation and deployment. The researchers will hold yearly workshops to disseminate results and obtain community feedback.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
II-New: Enabling Security Analysis at Scale
-
批准号:1406041
-
项目类别:Standard Grant
-
资助金额:$59.38万
-
财政年份:2014
-
负责人:Vern Paxson
-
依托单位:
TWC: Phase: Small: Censorship Counterstrike via Measurement, Filtering, Evasion, and Protocol Enhancement
-
批准号:1223717
-
项目类别:Standard Grant
-
资助金额:$66.66万
-
财政年份:2012
-
负责人:Vern Paxson
-
依托单位:
NeTS: Large: Collaborative Research: Measuring and Modeling the Dynamics of IPv4 Address Exhaustion
-
批准号:1111672
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2011
-
负责人:Vern Paxson
-
依托单位:
CT-L: Collaborative Research: Comprehensive Application Analysis and Control
-
批准号:0831535
-
项目类别:Continuing Grant
-
资助金额:$127.75万
-
财政年份:2008
-
负责人:Vern Paxson
-
依托单位:
CT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and Forensics
-
批准号:0716640
-
项目类别:Standard Grant
-
资助金额:$69.98万
-
财政年份:2007
-
负责人:Vern Paxson
-
依托单位:
CT-T:Exploiting Multi-Core CPUs for Parallelizing Network Intrusion Prevention
-
批准号:0716636
-
项目类别:Continuing Grant
-
资助金额:$49.94万
-
财政年份:2007
-
负责人:Vern Paxson
-
依托单位:
CT-T: Approaches to Network Defense Proven in Open Scientific Environments
-
批准号:0627320
-
项目类别:Standard Grant
-
资助金额:$23.61万
-
财政年份:2006
-
负责人:Vern Paxson
-
依托单位:
NeTS-FIND: Collaborative Research: Network Fabric for Personal, Social, and Urban Sensing Applications
-
批准号:0626539
-
项目类别:Continuing Grant
-
资助金额:$22.01万
-
财政年份:2006
-
负责人:Vern Paxson
-
依托单位:
Collaborative Proposal Cybertrust: Center for Internet Epidemiology and Defenses
-
批准号:0433702
-
项目类别:Continuing Grant
-
资助金额:$309.75万
-
财政年份:2004
-
负责人:Vern Paxson
-
依托单位:
STI: Viable Network Defense for Scientific Research Institutions
-
批准号:0334088
-
项目类别:Continuing Grant
-
资助金额:$90.0万
-
财政年份:2003
-
负责人:Vern Paxson
-
依托单位:
海外基金