CT-T: Approaches to Network Defense Proven in Open Scientific Environments
CT-T:在开放科学环境中经过验证的网络防御方法
基本信息
- 批准号:0627320
- 负责人:
- 金额:$ 23.61万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2006
- 资助国家:美国
- 起止时间:2006-10-01 至 2009-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Proposal Number: 0627320Panel: P060975PI: Vern Paxson Institution: International Computer Science Institute, University of California, Berkeley Title: CT-T: Approaches to Network Defense Proven in Open Scientific Experiments AbstractThis effort pursues research in network intrusion detection where the research is tied to large-scale operational settings in an exceptionally strong manner. The central component the work builds upon is the "Bro" network intrusion detection system previously developed by the PIs. The PIs participate in Bro's deployment for 24x7 operational cybersecurity monitoring at the Lawrence Berkeley National Laboratory (LBNL), the Berkeley campus of the University of California, and the Technical University of Munich.The theme of the research is to develop advances in technology for security monitoring of network traffic where the approaches are directly grounded in the pragmatics of network security at large institutes. The advances under investigation span a range of themes: (1) developing new ways of detecting attacks (detecting network "triggers" used by automated exploit software and by worms; drawing upon LBNL's immense archive of logs of past network traffic to devise robust anomaly detection algorithms; identifying possibly unknown malware by re-executing suspicious flows against a fully instrumented honeypot system); (2) new approaches to protocol analysis (exploiting dynamic analysis of protocols that avoid identification via standard ports; extending an abstract protocol description language for specifying analyzers that are then compiled into C++ classes); (3) integrating new sources of information into analyses (distributed monitors; flow records; honeynets; historic behavior; host-based context); and (4) addressing challenges in monitoring very high-speed, high-volume links (transparent load-balancing and cluster operation; hardware support for filtering, state management, normalization, and enabling intrusion prevention).
建议编号:0627320面板: P060975 PI:Vern Paxson 机构:国际计算机科学研究所,加州大学伯克利分校 CT-T:开放科学实验中的网络防御方法 AbstractThis的努力追求在网络入侵检测的研究是绑在一个非常强大的方式大规模的操作设置。 这项工作的核心组成部分是由PI先前开发的“Bro”网络入侵检测系统。 这些PI参与了Bro在劳伦斯伯克利国家实验室(LBNL)、加州大学伯克利分校和慕尼黑工业大学的24 x7操作网络安全监控部署。研究的主题是开发网络流量安全监控技术的进步,其中方法直接基于大型研究所的网络安全实用主义。 正在调查的进展跨越了一系列主题:(1)开发检测攻击的新方法(检测自动攻击软件和蠕虫使用的网络“触发器”;利用LBNL过去网络流量日志的巨大档案来设计强大的异常检测算法;通过对完全仪表化的蜜罐系统重新执行可疑流来识别可能未知的恶意软件);(2)协议分析的新方法(3)将新的信息源集成到分析中;(4)利用对避免通过标准端口识别的协议的动态分析;(5)扩展抽象协议描述语言以指定分析器,然后将分析器编译成C++类(分布式监控器;流记录;蜜网;历史行为;基于主机的上下文);以及(4)解决监控非常高速、高容量链路的挑战(透明的负载平衡和集群操作;对过滤、状态管理、规范化和启用入侵防御的硬件支持)。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Vern Paxson其他文献
A Longitudinal View of HTTP Traffic
HTTP 流量的纵向视图
- DOI:
- 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
Tom Callahan;M. Allman;Vern Paxson - 通讯作者:
Vern Paxson
Vern Paxson的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Vern Paxson', 18)}}的其他基金
II-New: Enabling Security Analysis at Scale
II-新:实现大规模安全分析
- 批准号:
1406041 - 财政年份:2014
- 资助金额:
$ 23.61万 - 项目类别:
Standard Grant
TWC: Phase: Small: Censorship Counterstrike via Measurement, Filtering, Evasion, and Protocol Enhancement
TWC:阶段:小:通过测量、过滤、规避和协议增强进行审查反击
- 批准号:
1223717 - 财政年份:2012
- 资助金额:
$ 23.61万 - 项目类别:
Standard Grant
NeTS: Large: Collaborative Research: Measuring and Modeling the Dynamics of IPv4 Address Exhaustion
NeTS:大型:协作研究:IPv4 地址耗尽动态的测量和建模
- 批准号:
1111672 - 财政年份:2011
- 资助金额:
$ 23.61万 - 项目类别:
Continuing Grant
CT-L: Collaborative Research: Comprehensive Application Analysis and Control
CT-L:协作研究:综合应用分析与控制
- 批准号:
0831535 - 财政年份:2008
- 资助金额:
$ 23.61万 - 项目类别:
Continuing Grant
CT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and Forensics
CT-T:建立跨机构合作安全监控和取证平台
- 批准号:
0716640 - 财政年份:2007
- 资助金额:
$ 23.61万 - 项目类别:
Standard Grant
CT-T:Exploiting Multi-Core CPUs for Parallelizing Network Intrusion Prevention
CT-T:利用多核 CPU 并行化网络入侵防御
- 批准号:
0716636 - 财政年份:2007
- 资助金额:
$ 23.61万 - 项目类别:
Continuing Grant
NeTS-FIND: Collaborative Research: Network Fabric for Personal, Social, and Urban Sensing Applications
NeTS-FIND:协作研究:用于个人、社交和城市传感应用的网络结构
- 批准号:
0626539 - 财政年份:2006
- 资助金额:
$ 23.61万 - 项目类别:
Continuing Grant
Collaborative Proposal Cybertrust: Center for Internet Epidemiology and Defenses
协作提案 Cybertrust:互联网流行病学和防御中心
- 批准号:
0433702 - 财政年份:2004
- 资助金额:
$ 23.61万 - 项目类别:
Continuing Grant
STI: Viable Network Defense for Scientific Research Institutions
STI:科研机构可行的网络防御
- 批准号:
0334088 - 财政年份:2003
- 资助金额:
$ 23.61万 - 项目类别:
Continuing Grant
NRT: Collaborative Research: Testing and Benchmarking Methodologies for Future Network Security Mechanisms
NRT:协作研究:未来网络安全机制的测试和基准测试方法
- 批准号:
0335290 - 财政年份:2003
- 资助金额:
$ 23.61万 - 项目类别:
Cooperative Agreement
相似国自然基金
Lagrangian origin of geometric approaches to scattering amplitudes
- 批准号:24ZR1450600
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
相似海外基金
Reveal of thermal transport in disordered materials with local order and hierarchical structure by topological and network approaches
通过拓扑和网络方法揭示具有局部有序和分层结构的无序材料中的热传输
- 批准号:
23H01360 - 财政年份:2023
- 资助金额:
$ 23.61万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
BENCHMARKS: Building a European Network for the Characterisation and Harmonisation of Monitoring Approaches for Research and Knowledge on Soils
基准:建立欧洲网络,以表征和协调土壤研究和知识监测方法
- 批准号:
10064786 - 财政年份:2023
- 资助金额:
$ 23.61万 - 项目类别:
EU-Funded
Building a European Network for the Characterisation and Harmonisation of Monitoring Approaches for Research and Knowledge on Soils (BENCHMARKS)
建立欧洲土壤研究和知识监测方法特征和协调网络(BENCMARKS)
- 批准号:
10062462 - 财政年份:2023
- 资助金额:
$ 23.61万 - 项目类别:
EU-Funded
Statistical physics and network-based approaches for elucidating molecular biomarkers of COPD
阐明 COPD 分子生物标志物的统计物理学和基于网络的方法
- 批准号:
10559835 - 财政年份:2023
- 资助金额:
$ 23.61万 - 项目类别:
Innovative biostatistical approaches to network level analyses of connectome-behavior relationships
连接组-行为关系网络级分析的创新生物统计方法
- 批准号:
10700129 - 财政年份:2022
- 资助金额:
$ 23.61万 - 项目类别:
Network Interdiction and Fortification Planning Under Uncertainty: Models, Solution Approaches and Applications
不确定性下的网络拦截和设防规划:模型、解决方法和应用
- 批准号:
RGPIN-2017-06732 - 财政年份:2022
- 资助金额:
$ 23.61万 - 项目类别:
Discovery Grants Program - Individual
Constructive approaches for network source coding
网络源编码的建设性方法
- 批准号:
RGPIN-2018-05719 - 财政年份:2022
- 资助金额:
$ 23.61万 - 项目类别:
Discovery Grants Program - Individual
Innovative biostatistical approaches to network level analyses of connectome-behavior relationships
连接组-行为关系网络级分析的创新生物统计方法
- 批准号:
10630851 - 财政年份:2022
- 资助金额:
$ 23.61万 - 项目类别:
Machine learning approaches for multi-organ neuronal network mapping and modulation
用于多器官神经元网络映射和调制的机器学习方法
- 批准号:
10746766 - 财政年份:2022
- 资助金额:
$ 23.61万 - 项目类别:
Dynamic approaches to understanding social cognitive aging: A social network neuroscience approach
理解社会认知衰老的动态方法:社交网络神经科学方法
- 批准号:
10342805 - 财政年份:2022
- 资助金额:
$ 23.61万 - 项目类别:














{{item.name}}会员




