课题基金 / 基金详情

CT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and Forensics

CT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and Forensics
CT-T:建立跨机构合作安全监控和取证平台
批准号:
0716640
负责人:
Vern Paxson
金额:
$69.98万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2007
资助国家:
美国
项目状态:
已结题
起止时间:
2007-10-01 至 2011-09-30

项目摘要

项目成果

Vern Paxson的其他基金

相似基金

相关文献

中文摘要
翻译
国家科学基金cise /CNSForm 7综述分析与建议提案编号:0716640PI: Vern paxson机构:加州大学伯克利分校国际计算机科学研究所领导提案摘要ct - t:建立合作安全监测和取证的跨机构平台尽管在开发全球共享安全信息的系统方面已经有了很多研究,但这些方法往往从根本上受到限制,因为它们的范围太广,限制了参与者对系统的信任。相反,这个项目寻求通过考虑一个更有限的范围来获得更大的效用:一个基于在一组明确决定彼此合作的站点之间交换信息的协调安全分析系统。在这种环境中,参与站点通常(但并非总是)以负责任的方式行事,这种更有限的范围优化了常见情况。该项目的一个关键焦点是自动化安全监控和取证分析中通常涉及的步骤,同时仍然保持分析师“在循环中”做出重大决策。当安全问题出现时,检测到事件的站点将攻击描述写入“分析脚本”,以导出到其他站点。分析师收到这类脚本后会检查它们,以确定它们是否值得关注。如果是这样,他们可以指示系统对过去的活动进行回顾性搜索,并改进站点的监控配置以检测未来的实例。由于验证这种方法需要可操作的部署,该项目寻求演示一个工作系统,用于在劳伦斯伯克利国家实验室、国家能源研究科学计算中心和加州大学伯克利分校之间协调分析。
英文摘要
National Science FoundationCISE/CNSForm 7 Review Analysis and RecommendationProposal Number: 0716640PI: Vern PaxsonInstitution: International Computer Science Institute, University of California BerkeleyLeadProposal AbstractCT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and ForensicsAlthough there has been much research in developing systems for globally sharing security information, often these approaches are fundamentally limited because their broad scope limits the trust that participants can place in the system. This project instead seeks to reap significantly greater utility by considering a more restricted scope: a system for coordinated security analysis based on exchanging information between a set of sites who have explicitly decided to work with each other. This more limited scope optimizes for the common case that in such an environment the participating sites will usually (but not always) act in a responsible manner.A key focus of the project concerns automating the steps commonly involved in security monitoring and forensic analysis while still keeping an analyst "in the loop" for significant decisions. As security problems arise, a site detecting an incident codifies a description of the attack in an "analysis script" to export to other sites. Analysts receiving such scripts inspect them to determine whether they are of interest. If so, they can instruct the system to conduct both a retrospective search for the activity in the past, and refine the site's monitoring configurations to detect future instances.As validating such an approach requires operational deployment, the project seeks to demonstrate a working system for coordinating analysis between the Lawrence Berkeley National Laboratory, the National Energy Research Scientific Computing Center, and the University of California at Berkeley.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
II-New: Enabling Security Analysis at Scale
TWC: Phase: Small: Censorship Counterstrike via Measurement, Filtering, Evasion, and Protocol Enhancement
NeTS: Large: Collaborative Research: Measuring and Modeling the Dynamics of IPv4 Address Exhaustion
CT-L: Collaborative Research: Comprehensive Application Analysis and Control
海外基金