课题基金 / 基金详情

CT-T: Approaches to Network Defense Proven in Open Scientific Environments

CT-T: Approaches to Network Defense Proven in Open Scientific Environments
CT-T:在开放科学环境中经过验证的网络防御方法
批准号:
0627320
负责人:
Vern Paxson
金额:
$23.61万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-10-01 至 2009-09-30

项目摘要

项目成果

Vern Paxson的其他基金

相似基金

相关文献

中文摘要
翻译
提案编号:0627320Panel: P060975PI: Vern Paxson机构:国际计算机科学研究所,加州大学伯克利分校标题:CT-T:在开放科学实验中证明的网络防御方法摘要这项工作致力于网络入侵检测的研究,该研究以一种非常强大的方式与大规模操作设置联系在一起。这项工作的核心组成部分是先前由pi开发的“Bro”网络入侵检测系统。这些pi参与了Bro在劳伦斯伯克利国家实验室(LBNL)、加州大学伯克利分校和慕尼黑工业大学的24x7运营网络安全监控部署。该研究的主题是发展网络流量安全监控技术的进步,这些方法直接基于大型研究所的网络安全语用学。正在研究的进展跨越了一系列主题:(1)开发检测攻击的新方法(检测自动利用软件和蠕虫使用的网络“触发器”;利用LBNL过去网络流量的大量日志来设计强大的异常检测算法;通过对完全仪器化的蜜罐系统重新执行可疑流量来识别可能未知的恶意软件);(2)协议分析的新方法(利用协议的动态分析,避免通过标准端口进行识别;扩展抽象协议描述语言,用于指定分析器,然后将其编译成c++类);(3)将新的信息源整合到分析中(分布式监视器、流量记录、蜜网、历史行为、基于主机的上下文);(4)解决监控高速、大容量链路方面的挑战(透明负载平衡和集群操作;过滤、状态管理、规范化和启用入侵防御的硬件支持)。
英文摘要
Proposal Number: 0627320Panel: P060975PI: Vern Paxson Institution: International Computer Science Institute, University of California, Berkeley Title: CT-T: Approaches to Network Defense Proven in Open Scientific Experiments AbstractThis effort pursues research in network intrusion detection where the research is tied to large-scale operational settings in an exceptionally strong manner. The central component the work builds upon is the "Bro" network intrusion detection system previously developed by the PIs. The PIs participate in Bro's deployment for 24x7 operational cybersecurity monitoring at the Lawrence Berkeley National Laboratory (LBNL), the Berkeley campus of the University of California, and the Technical University of Munich.The theme of the research is to develop advances in technology for security monitoring of network traffic where the approaches are directly grounded in the pragmatics of network security at large institutes. The advances under investigation span a range of themes: (1) developing new ways of detecting attacks (detecting network "triggers" used by automated exploit software and by worms; drawing upon LBNL's immense archive of logs of past network traffic to devise robust anomaly detection algorithms; identifying possibly unknown malware by re-executing suspicious flows against a fully instrumented honeypot system); (2) new approaches to protocol analysis (exploiting dynamic analysis of protocols that avoid identification via standard ports; extending an abstract protocol description language for specifying analyzers that are then compiled into C++ classes); (3) integrating new sources of information into analyses (distributed monitors; flow records; honeynets; historic behavior; host-based context); and (4) addressing challenges in monitoring very high-speed, high-volume links (transparent load-balancing and cluster operation; hardware support for filtering, state management, normalization, and enabling intrusion prevention).
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
II-New: Enabling Security Analysis at Scale
TWC: Phase: Small: Censorship Counterstrike via Measurement, Filtering, Evasion, and Protocol Enhancement
NeTS: Large: Collaborative Research: Measuring and Modeling the Dynamics of IPv4 Address Exhaustion
CT-L: Collaborative Research: Comprehensive Application Analysis and Control
国内基金
海外基金
Lagrangian origin of geometric approaches to scattering amplitudes
  • 批准号:
    24ZR1450600
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    ALEXANDER OCHIROV
  • 依托单位: