课题基金 / 基金详情

SGER: Behavioral Authentication of Server Flows

SGER: Behavioral Authentication of Server Flows
SGER:服务器流的行为身份验证
批准号:
0335574
负责人:
Carla Brodley
金额:
$5.07万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-09-15 至 2005-06-30

项目摘要

项目成果

Carla Brodley的其他基金

相似基金

相关文献

中文摘要
翻译
SGER:服务器流的行为认证异常通信模式的检测本项目的目标是开发用于分析服务器流的流量行为以检测异常通信模式的方法。以前的工作,在数据挖掘应用于计算机安全是面向发现攻击数据包,而本研究的目的是找到模式的流量,表明异常行为的应用层协议。用于确定流量类型的传统方法依赖于TCP/UDP数据包报头中携带的端口标签。但是,如果存在重新映射端口号的代理服务器,或者存在已被破坏以充当后门或隐蔽通道的主机服务,则此方法可能会失败。这个探索性项目的基础是使用捕获流行为的特征对TCP服务器流流量进行分类。这些功能独立于端口标签,因此,在存在恶意活动的情况下提供更准确的流量类型分类。这项研究中一个令人兴奋的新方向是对服务器流进行身份验证,以检测异常和潜在的恶意行为。本研究解决了应用层协议的认证需求。由于大多数入侵检测系统和防火墙依赖于了解应用程序协议来确定是否允许流量和发现恶意行为,因此本研究填补了当前信息安全技术的关键空白。预期的结果将在广泛的应用程序中产生广泛的影响,这些应用程序严重依赖可靠,有效和高效的信息安全。该项目的成果可在项目网站http://mow.ecn.purdue.edu/cnlrn/上查阅,并在安全会议上分发。
英文摘要
SGER: Behavioral Authentication of Server Flows for Detection of Anomalous Communication PatternsThe goal of this project is to develop methods for analyzing traffic behavior of server flows to detect anomalous communication patterns. Prior work in data mining applied to computer security was geared at finding attack packets, whereas this research aims to find patterns of traffic that indicate anomalous behavior of an application-layer protocol. Traditional methods for determining traffic type rely on the port label carried in the TCP/UDP packet header. This method can fail, however, in the presence of proxy servers that re-map port numbers, or host services that have been compromised to act as back doors or covert channels. The basis for this exploratory project is the classification of TCP server stream traffic using features that capture stream behavior. The features are independent of port label, and therefore, provide a more accurate classification of traffic type in the presence of malicious activity. An exciting new direction in this research is the authentication of server flows to detect anomalous and potentially malicious behavior. This research addresses the need for authentication of the application-layer protocol. Because most intrusion detection systems and firewalls rely on knowing the application protocol for determining whether to permit the traffic and for discovering malicious behavior, this research fills a critical gap in current information security technology. The expected results will have broad impact in a wide range of applications that critically depend on reliable, effective and efficient information security. Results of this project will accessible on the project web site http://mow.ecn.purdue.edu/~lrn/, and disseminated at Security Conferences.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CUE-M: LEVEL UP: Charting a Pathway toward Inclusive Computing
  • 批准号:
    2246079
  • 项目类别:
    Standard Grant
  • 资助金额:
    $100.0万
  • 财政年份:
    2023
  • 负责人:
    Carla Brodley
  • 依托单位:
Broadening Participation in the CyberCorps(R) Scholarship for Service Program
  • 批准号:
    2208797
  • 项目类别:
    Standard Grant
  • 资助金额:
    $160.18万
  • 财政年份:
    2022
  • 负责人:
    Carla Brodley
  • 依托单位:
BPC-A: Data Alliance on Persistence and Perception in Computing (DAPPIC)
  • 批准号:
    2216629
  • 项目类别:
    Standard Grant
  • 资助金额:
    $132.3万
  • 财政年份:
    2022
  • 负责人:
    Carla Brodley
  • 依托单位:
BPC-AE: An Extension to Widening the Research Pipeline
  • 批准号:
    0739229
  • 项目类别:
    Standard Grant
  • 资助金额:
    $175.0万
  • 财政年份:
    2008
  • 负责人:
    Carla Brodley
  • 依托单位:
国内基金
海外基金
Behavioral Insights on Cooperation in Social Dilemmas
  • 批准号:
    --
  • 项目类别:
    外国优秀青年学者研究基金项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    LIEN,Jaimie Wei-Hung
  • 依托单位: