课题基金 / 基金详情

CT-T: Approaches to Network Defense Proven in Open Scientific Environments

CT-T: Approaches to Network Defense Proven in Open Scientific Environments
CT-T:在开放科学环境中经过验证的网络防御方法
批准号:
0627320
负责人:
Vern Paxson
金额:
$23.61万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-10-01 至 2009-09-30

项目摘要

项目成果

Vern Paxson的其他基金

相似基金

相关文献

中文摘要
翻译
提案编号:0627320小组:P060975PI:Vern Paxson Institution:国际计算机科学研究所,加州大学伯克利分校标题:CT-T:开放式科学实验中证明的网络防御方法摘要这项工作致力于网络入侵检测的研究,该研究以一种异常强大的方式与大规模操作环境相联系。这项工作的中心组件是由私人投资机构先前开发的“Bro”网络入侵检测系统。PIs参与了Bro在劳伦斯伯克利国家实验室(LBNL)、加州大学伯克利校区和慕尼黑技术大学部署的24x7操作网络安全监控。研究的主题是开发网络流量安全监控的技术进步,其中方法直接基于大型机构的网络安全实用。调查中的进展涉及一系列主题:(1)开发检测攻击的新方法(检测自动利用软件和蠕虫使用的网络“触发器”;利用LBNL过去网络流量的巨大日志档案来设计健壮的异常检测算法;通过针对完全装备的蜜罐系统重新执行可疑流来识别可能未知的恶意软件);(2)协议分析的新方法(利用通过标准端口避免识别的协议的动态分析;扩展用于指定分析器的抽象协议描述语言,然后将其编译成C++类);(3)将新的信息源集成到分析中(分布式监视器;流记录;蜜网;历史行为;基于主机的上下文);以及(4)应对监控超高速、大容量链路的挑战(透明负载平衡和集群操作;对过滤、状态管理、标准化和启用入侵防御的硬件支持)。
英文摘要
Proposal Number: 0627320Panel: P060975PI: Vern Paxson Institution: International Computer Science Institute, University of California, Berkeley Title: CT-T: Approaches to Network Defense Proven in Open Scientific Experiments AbstractThis effort pursues research in network intrusion detection where the research is tied to large-scale operational settings in an exceptionally strong manner. The central component the work builds upon is the "Bro" network intrusion detection system previously developed by the PIs. The PIs participate in Bro's deployment for 24x7 operational cybersecurity monitoring at the Lawrence Berkeley National Laboratory (LBNL), the Berkeley campus of the University of California, and the Technical University of Munich.The theme of the research is to develop advances in technology for security monitoring of network traffic where the approaches are directly grounded in the pragmatics of network security at large institutes. The advances under investigation span a range of themes: (1) developing new ways of detecting attacks (detecting network "triggers" used by automated exploit software and by worms; drawing upon LBNL's immense archive of logs of past network traffic to devise robust anomaly detection algorithms; identifying possibly unknown malware by re-executing suspicious flows against a fully instrumented honeypot system); (2) new approaches to protocol analysis (exploiting dynamic analysis of protocols that avoid identification via standard ports; extending an abstract protocol description language for specifying analyzers that are then compiled into C++ classes); (3) integrating new sources of information into analyses (distributed monitors; flow records; honeynets; historic behavior; host-based context); and (4) addressing challenges in monitoring very high-speed, high-volume links (transparent load-balancing and cluster operation; hardware support for filtering, state management, normalization, and enabling intrusion prevention).
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
II-New: Enabling Security Analysis at Scale
TWC: Phase: Small: Censorship Counterstrike via Measurement, Filtering, Evasion, and Protocol Enhancement
NeTS: Large: Collaborative Research: Measuring and Modeling the Dynamics of IPv4 Address Exhaustion
CT-L: Collaborative Research: Comprehensive Application Analysis and Control
国内基金
海外基金
Lagrangian origin of geometric approaches to scattering amplitudes
  • 批准号:
    24ZR1450600
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    ALEXANDER OCHIROV
  • 依托单位: