CT: New Techniques for Attack Detection, Prevention and Immunization
CT:攻击检测、预防和免疫的新技术
基本信息
- 批准号:0627687
- 负责人:
- 金额:$ 35万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2006
- 资助国家:美国
- 起止时间:2006-09-01 至 2010-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Software vulnerabilities have been the biggest culprit behind cyberattacks in the past several years. A handful of vulnerabilities, such asbuffer overflows, format string, SQL injection, command injection,cross-site scripting, and directory traversals, have come to dominate,accounting for about 70% of the CVE vulnerabilities reported in the lasttwo years. Although that these vulnerabilities are well understood anddocumented, their number continues to escalate from one year to the next.New vulnerabilities continue to be discovered in recently releasedsoftware, as well as established software.This will develop novel techniques for defending applications from knownas well as unknown attacks, and for immunizing applications from futureattack instances. The proposed approach can thus protect the integrity aswell as the availability of vulnerable applications. A central componentof the proposed approach is an efficient fine-grained dynamic taintanalysis that tracks the flow of untrusted information through avulnerable program. Both specification-based and anomaly-based attackdetection techniques can be made highly versatile and accurate by usingfine-grained taint, and can stop the wide range of attacks mentionedabove. Taint analysis will also form the basis of an immunizationtechnique that is based on learning input filters that characterizeattack-bearing inputs, and selectively discarding such inputs.The proposed work can address multi-billion dollar losses experienced dueto cyber attacks, since it can stop most types of exploits before theycause damage. To maximize impact, the techniques developed in the projectwill be implemented into open-source software prototypes.
过去几年,软件漏洞一直是网络攻击的罪魁祸首。缓冲区溢出、格式字符串、SQL注入、命令注入、跨站点脚本和目录遍历等少数漏洞已经占据主导地位,在过去两年中报告的CVE漏洞中约占70%。尽管这些漏洞被很好地理解和记录,但它们的数量仍在逐年上升。在最近发布的软件以及已建立的软件中不断发现新的漏洞。这将开发新的技术来保护应用程序免受已知和未知的攻击,并使应用程序免受未来的攻击实例。因此,所提出的方法可以保护易受攻击应用程序的完整性和可用性。该方法的一个核心组件是一种有效的细粒度动态污染分析,用于跟踪通过易受攻击程序的不可信信息流。基于规范和基于异常的攻击检测技术都可以通过使用细粒度的污染来实现高度通用性和准确性,并且可以阻止上述广泛的攻击。污染分析也将构成免疫技术的基础,该技术基于学习输入过滤器,该过滤器表征攻击承受输入,并有选择地丢弃这些输入。这项提议的工作可以解决网络攻击造成的数十亿美元损失,因为它可以在大多数类型的攻击造成损害之前阻止它们。为了最大限度地发挥作用,项目中开发的技术将被实现到开源软件原型中。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Ramasubramanian Sekar其他文献
Ramasubramanian Sekar的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Ramasubramanian Sekar', 18)}}的其他基金
SaTC: CORE: Medium: WebSheets: A New Privacy-Centric Framework for Web Applications
SaTC:核心:媒介:WebSheets:一种新的以隐私为中心的 Web 应用程序框架
- 批准号:
2153056 - 财政年份:2022
- 资助金额:
$ 35万 - 项目类别:
Standard Grant
SaTC: CORE: Medium: Collaborative: RADAR: Real-time Advanced Detection and Attack Reconstruction
SaTC:核心:中等:协作:雷达:实时高级检测和攻击重建
- 批准号:
1918667 - 财政年份:2019
- 资助金额:
$ 35万 - 项目类别:
Standard Grant
TWC: Small: A platform for enhancing security of binary code
TWC:小型:增强二进制代码安全性的平台
- 批准号:
1319137 - 财政年份:2013
- 资助金额:
$ 35万 - 项目类别:
Standard Grant
Collaborative Project: An Extensible Software Platform for a Virtual Cyber Security Laboratory
合作项目:虚拟网络安全实验室的可扩展软件平台
- 批准号:
0817188 - 财政年份:2008
- 资助金额:
$ 35万 - 项目类别:
Standard Grant
CT-T: Proactive Techniques for Preserving System Integrity: A Basis for Robust Defense Against Malware
CT-T:保护系统完整性的主动技术:强大防御恶意软件的基础
- 批准号:
0831298 - 财政年份:2008
- 资助金额:
$ 35万 - 项目类别:
Continuing Grant
Center for Information Protection: A Multi-University Industry/University Collaborative Research Center
信息保护中心:多大学产学合作研究中心
- 批准号:
0733935 - 财政年份:2007
- 资助金额:
$ 35万 - 项目类别:
Continuing Grant
A Plan for Developing a Multi-University Industry/University Collaborative Research Center on Cyber Security
建立多所大学网络安全产学合作研究中心计划
- 批准号:
0532030 - 财政年份:2005
- 资助金额:
$ 35万 - 项目类别:
Standard Grant
Scholarship for Service in Information Assurance
信息保障服务奖学金
- 批准号:
0417103 - 财政年份:2004
- 资助金额:
$ 35万 - 项目类别:
Continuing Grant
Collaborative Research: Capacity Expansion in Information Assurance
合作研究:信息保障能力扩展
- 批准号:
0313858 - 财政年份:2003
- 资助金额:
$ 35万 - 项目类别:
Standard Grant
A New Approach for Securing Systems Using Automated Adaptive Intrusion Response
使用自动自适应入侵响应保护系统安全的新方法
- 批准号:
0208877 - 财政年份:2002
- 资助金额:
$ 35万 - 项目类别:
Continuing Grant
相似海外基金
Development of new molecular self-temperature sensing techniques using luminescence-absorption hybrid thermometry
利用发光-吸收混合测温法开发新型分子自温度传感技术
- 批准号:
24K17691 - 财政年份:2024
- 资助金额:
$ 35万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
Enabling solid state metal recycling with new numerical techniques
利用新的数值技术实现固态金属回收
- 批准号:
DE230100338 - 财政年份:2023
- 资助金额:
$ 35万 - 项目类别:
Discovery Early Career Researcher Award
Investigating Bacterial Dynamics and Developing New Antimicrobial Agents in Cambodia Using Innovative Genome Analysis Techniques
利用创新的基因组分析技术研究柬埔寨的细菌动力学并开发新的抗菌剂
- 批准号:
23KK0151 - 财政年份:2023
- 资助金额:
$ 35万 - 项目类别:
Fund for the Promotion of Joint International Research (International Collaborative Research)
New Techniques for Resolving Boundary Problems in Total Search
解决全搜索中边界问题的新技术
- 批准号:
EP/W014750/1 - 财政年份:2023
- 资助金额:
$ 35万 - 项目类别:
Research Grant
Development of new shoot diagnosis techniques to increase the propagation efficiency of softwood cutting and clarification of rooting mechanism in persimmon dwarf rootstocks
开发新的芽诊断技术以提高软木切割的繁殖效率并阐明柿矮砧木的生根机制
- 批准号:
23K13950 - 财政年份:2023
- 资助金额:
$ 35万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
New techniques and invariants in low-dimensional topology
低维拓扑中的新技术和不变量
- 批准号:
FT230100092 - 财政年份:2023
- 资助金额:
$ 35万 - 项目类别:
ARC Future Fellowships
Performance Improvement of Meteor Burst Communications by New Element Techniques and its Installment in Soft Defined RadioPer
通过新元件技术改进流星爆发通信的性能及其在软定义RadioPer中的安装
- 批准号:
23K03836 - 财政年份:2023
- 资助金额:
$ 35万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
Vision-led and Accessibility-oriented Urban Transportation Planning Techniques Adapted to New Mobility Era
适应新出行时代的以视觉为主导、以可达性为导向的城市交通规划技术
- 批准号:
23H01526 - 财政年份:2023
- 资助金额:
$ 35万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
DDRIG in DRMS: Measuring Persuasion Without Measuring a Prior Belief: A New Application of Planned Missing Data Techniques
DRMS 中的 DDRIG:在不衡量先验信念的情况下衡量说服力:计划丢失数据技术的新应用
- 批准号:
2242100 - 财政年份:2023
- 资助金额:
$ 35万 - 项目类别:
Standard Grant
Novel microwave devices based on new materials and new manufacturing techniques
基于新材料和新制造技术的新型微波器件
- 批准号:
2883004 - 财政年份:2023
- 资助金额:
$ 35万 - 项目类别:
Studentship