课题基金 / 基金详情

SGER: Behavioral Authentication of Server Flows

SGER: Behavioral Authentication of Server Flows
SGER:服务器流的行为身份验证
批准号:
0335574
负责人:
Carla Brodley
金额:
$5.07万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-09-15 至 2005-06-30

项目摘要

项目成果

Carla Brodley的其他基金

相似基金

相关文献

中文摘要
翻译
SGER:用于检测异常通信模式的服务器流行为认证本项目的目标是开发分析服务器流的流量行为以检测异常通信模式的方法。先前应用于计算机安全的数据挖掘工作旨在发现攻击数据包,而本研究旨在找到表明应用层协议异常行为的流量模式。传统的确定流量类型的方法依赖于TCP/UDP包头中携带的端口标签。但是,如果存在重新映射端口号的代理服务器,或者存在已被破坏为充当后门或隐蔽通道的主机服务,则此方法可能失败。这个探索性项目的基础是使用捕获流行为的特性对TCP服务器流流量进行分类。这些特性独立于端口标签,因此,在存在恶意活动时提供更准确的流量类型分类。该研究的一个令人兴奋的新方向是服务器流的身份验证,以检测异常和潜在的恶意行为。本研究解决了应用层协议认证的需求。由于大多数入侵检测系统和防火墙依赖于了解应用协议来确定是否允许流量和发现恶意行为,因此本研究填补了当前信息安全技术的关键空白。预期的结果将对广泛的应用产生广泛的影响,这些应用严重依赖于可靠、有效和高效的信息安全。该项目的成果可在项目网站http://mow.ecn.purdue.edu/~lrn/上查阅,并在安全会议上传播。
英文摘要
SGER: Behavioral Authentication of Server Flows for Detection of Anomalous Communication PatternsThe goal of this project is to develop methods for analyzing traffic behavior of server flows to detect anomalous communication patterns. Prior work in data mining applied to computer security was geared at finding attack packets, whereas this research aims to find patterns of traffic that indicate anomalous behavior of an application-layer protocol. Traditional methods for determining traffic type rely on the port label carried in the TCP/UDP packet header. This method can fail, however, in the presence of proxy servers that re-map port numbers, or host services that have been compromised to act as back doors or covert channels. The basis for this exploratory project is the classification of TCP server stream traffic using features that capture stream behavior. The features are independent of port label, and therefore, provide a more accurate classification of traffic type in the presence of malicious activity. An exciting new direction in this research is the authentication of server flows to detect anomalous and potentially malicious behavior. This research addresses the need for authentication of the application-layer protocol. Because most intrusion detection systems and firewalls rely on knowing the application protocol for determining whether to permit the traffic and for discovering malicious behavior, this research fills a critical gap in current information security technology. The expected results will have broad impact in a wide range of applications that critically depend on reliable, effective and efficient information security. Results of this project will accessible on the project web site http://mow.ecn.purdue.edu/~lrn/, and disseminated at Security Conferences.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CUE-M: LEVEL UP: Charting a Pathway toward Inclusive Computing
  • 批准号:
    2246079
  • 项目类别:
    Standard Grant
  • 资助金额:
    $100.0万
  • 财政年份:
    2023
  • 负责人:
    Carla Brodley
  • 依托单位:
Broadening Participation in the CyberCorps(R) Scholarship for Service Program
  • 批准号:
    2208797
  • 项目类别:
    Standard Grant
  • 资助金额:
    $160.18万
  • 财政年份:
    2022
  • 负责人:
    Carla Brodley
  • 依托单位:
BPC-A: Data Alliance on Persistence and Perception in Computing (DAPPIC)
  • 批准号:
    2216629
  • 项目类别:
    Standard Grant
  • 资助金额:
    $132.3万
  • 财政年份:
    2022
  • 负责人:
    Carla Brodley
  • 依托单位:
BPC-AE: An Extension to Widening the Research Pipeline
  • 批准号:
    0739229
  • 项目类别:
    Standard Grant
  • 资助金额:
    $175.0万
  • 财政年份:
    2008
  • 负责人:
    Carla Brodley
  • 依托单位:
国内基金
海外基金
Behavioral Insights on Cooperation in Social Dilemmas
  • 批准号:
    --
  • 项目类别:
    外国优秀青年学者研究基金项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    LIEN,Jaimie Wei-Hung
  • 依托单位: