Forensix: Large-scale Tamper-resistant Computer Forensic Systems
Forensix:大规模防篡改计算机取证系统
基本信息
- 批准号:0529809
- 负责人:
- 金额:$ 39.9万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2004
- 资助国家:美国
- 起止时间:2004-10-15 至 2006-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Computer forensic systems are large-scale auditing systems that are complementary with on-line intrusion and anomaly detection and have been a relatively understudied field in network security. Whereas intrusion and anomaly detection systems attempt to do an active on-line analysis of events, forensic systems seek to log all of the information being processed for subsequent, off-line analysis. For the most part, computer forensics is still an ad-hoc activity that is applied to a system that has already been compromised.Leveraging the advances in computing, networking, and storage systems and building on the work within the IDS community, the project will build an experimental computer forensics system that will allow system administrators, law enforcement officials, and security experts to quickly and easily track down sources of security incidents after they have happened. There are a number of unique aspects of proposed approach including:(i) Actively tracking changes to the system being monitored at the operating system kernel level before an attack occurs to capture forensic data(ii) Backing the audit information to a locally connected logging host. This logging host exports only one service: the audit trail information from the host being monitored. All other access to the logging host is allowed only through the console. Thus, the logging host is a system that will provide extremely detailed system information.(iii) A database system to hold logging information. With an investigation of techniques for populating a database to allow advanced queries on the logging information. The goal of this is to allow complex queries to be performed while monitoring the system.The main questions to answer as a result of this research are:(i) Can a scalable proactive logging hosts be built to capture a large number of attacks?(ii) Can database technologies be used to actively mine fore malicious activities?(iii) How can file systems and database technologies be developed to support scalable logging?
计算机取证系统是与在线入侵和异常检测相辅相成的大规模审计系统,在网络安全领域一直是一个相对欠研究的领域。入侵和异常检测系统试图对事件进行主动的在线分析,而取证系统则试图记录正在处理的所有信息,以便进行后续的离线分析。在大多数情况下,计算机取证仍然是一个临时的活动,适用于一个系统,已经受到损害。利用先进的计算,网络和存储系统,并建立在IDS社区的工作,该项目将建立一个实验性的计算机取证系统,将允许系统管理员,执法官员,和安全专家,以便在安全事件发生后快速轻松地追踪其来源。所提出的方法有许多独特的方面,包括:(i)在攻击发生之前,在操作系统内核级别主动跟踪对被监视系统的更改,以捕获取证数据(ii)将审计信息备份到本地连接的日志主机。这个日志记录主机只导出一个服务:来自被监视主机的审计跟踪信息。对日志记录主机的所有其他访问只能通过控制台进行。因此,日志主机是将提供极其详细的系统信息的系统。(iii)保存日志信息的数据库系统。调查填充数据库以允许对日志信息进行高级查询的技术。这样做的目的是允许复杂的查询,同时监测system.The主要问题,以回答作为本研究的结果是:(i)可以建立一个可扩展的主动日志主机捕获大量的攻击?(ii)数据库技术可以用来主动挖掘恶意活动吗?(iii)如何开发文件系统和数据库技术来支持可伸缩日志记录?
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Wu-chang Feng其他文献
Wu-chang Feng的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Wu-chang Feng', 18)}}的其他基金
Education DCL: EAGER: Re-imagining the Role of Humans in Security Education
教育 DCL:EAGER:重新想象人类在安全教育中的角色
- 批准号:
2335633 - 财政年份:2023
- 资助金额:
$ 39.9万 - 项目类别:
Standard Grant
SaTC: EDU: Curricula and CTF Exercises for Teaching Smart Fuzzing and Symbolic Execution
SaTC:EDU:用于教授智能模糊测试和符号执行的课程和 CTF 练习
- 批准号:
1821841 - 财政年份:2018
- 资助金额:
$ 39.9万 - 项目类别:
Standard Grant
EDU: A Capture-the-Flag Service for Computer Security Courses
EDU:计算机安全课程的夺旗服务
- 批准号:
1623400 - 财政年份:2016
- 资助金额:
$ 39.9万 - 项目类别:
Standard Grant
TC: Small: Increasing The Cost of Malware
TC:小:增加恶意软件的成本
- 批准号:
1017034 - 财政年份:2010
- 资助金额:
$ 39.9万 - 项目类别:
Continuing Grant
Forensix: Large-scale Tamper-resistant Computer Forensic Systems
Forensix:大规模防篡改计算机取证系统
- 批准号:
0230960 - 财政年份:2002
- 资助金额:
$ 39.9万 - 项目类别:
Standard Grant
相似国自然基金
水稻穗粒数调控关键因子LARGE6的分子遗传网络解析
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
量子自旋液体中拓扑拟粒子的性质:量子蒙特卡罗和新的large-N理论
- 批准号:
- 批准年份:2020
- 资助金额:62 万元
- 项目类别:面上项目
甘蓝型油菜Large Grain基因调控粒重的分子机制研究
- 批准号:31972875
- 批准年份:2019
- 资助金额:58.0 万元
- 项目类别:面上项目
Large PB/PB小鼠 视网膜新生血管模型的研究
- 批准号:30971650
- 批准年份:2009
- 资助金额:8.0 万元
- 项目类别:面上项目
基因discs large在果蝇卵母细胞的后端定位及其体轴极性形成中的作用机制
- 批准号:30800648
- 批准年份:2008
- 资助金额:20.0 万元
- 项目类别:青年科学基金项目
LARGE基因对口腔癌细胞中α-DG糖基化及表达的分子调控
- 批准号:30772435
- 批准年份:2007
- 资助金额:29.0 万元
- 项目类别:面上项目
相似海外基金
Renewal application: How do ecological trade-offs drive ectomycorrhizal fungal community assembly? Fine- scale processes with large-scale implications
更新应用:生态权衡如何驱动外生菌根真菌群落组装?
- 批准号:
MR/Y011503/1 - 财政年份:2025
- 资助金额:
$ 39.9万 - 项目类别:
Fellowship
LSS_BeyondAverage: Probing cosmic large-scale structure beyond the average
LSS_BeyondAverage:探测超出平均水平的宇宙大尺度结构
- 批准号:
EP/Y027906/1 - 财政年份:2024
- 资助金额:
$ 39.9万 - 项目类别:
Research Grant
CSR: Small: Multi-FPGA System for Real-time Fraud Detection with Large-scale Dynamic Graphs
CSR:小型:利用大规模动态图进行实时欺诈检测的多 FPGA 系统
- 批准号:
2317251 - 财政年份:2024
- 资助金额:
$ 39.9万 - 项目类别:
Standard Grant
CRII: OAC: A Compressor-Assisted Collective Communication Framework for GPU-Based Large-Scale Deep Learning
CRII:OAC:基于 GPU 的大规模深度学习的压缩器辅助集体通信框架
- 批准号:
2348465 - 财政年份:2024
- 资助金额:
$ 39.9万 - 项目类别:
Standard Grant
Collaborative Research: OAC Core: Distributed Graph Learning Cyberinfrastructure for Large-scale Spatiotemporal Prediction
合作研究:OAC Core:用于大规模时空预测的分布式图学习网络基础设施
- 批准号:
2403312 - 财政年份:2024
- 资助金额:
$ 39.9万 - 项目类别:
Standard Grant
CAREER: Large scale geometry and negative curvature
职业:大规模几何和负曲率
- 批准号:
2340341 - 财政年份:2024
- 资助金额:
$ 39.9万 - 项目类别:
Continuing Grant
Continuous, Large-scale Manufacturing of Functionalized Silver Nanowire Transparent Conducting Films
功能化银纳米线透明导电薄膜的连续大规模制造
- 批准号:
2422696 - 财政年份:2024
- 资助金额:
$ 39.9万 - 项目类别:
Standard Grant
Collaborative Research: Large-Scale Wireless RF Networks of Microchip Sensors
合作研究:微芯片传感器的大规模无线射频网络
- 批准号:
2322601 - 财政年份:2024
- 资助金额:
$ 39.9万 - 项目类别:
Standard Grant
CAREER: A Multi-faceted Framework to Enable Computationally Efficient Evaluation and Automatic Design for Large-scale Economics-driven Transmission Planning
职业生涯:一个多方面的框架,可实现大规模经济驱动的输电规划的计算高效评估和自动设计
- 批准号:
2339956 - 财政年份:2024
- 资助金额:
$ 39.9万 - 项目类别:
Continuing Grant
CAREER: Strategic Interactions, Learning, and Dynamics in Large-Scale Multi-Agent Systems: Achieving Tractability via Graph Limits
职业:大规模多智能体系统中的战略交互、学习和动态:通过图限制实现可处理性
- 批准号:
2340289 - 财政年份:2024
- 资助金额:
$ 39.9万 - 项目类别:
Continuing Grant