CT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and Forensics
CT-T:建立跨机构合作安全监控和取证平台
基本信息
- 批准号:0716640
- 负责人:
- 金额:$ 69.98万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2007
- 资助国家:美国
- 起止时间:2007-10-01 至 2011-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
National Science FoundationCISE/CNSForm 7 Review Analysis and RecommendationProposal Number: 0716640PI: Vern PaxsonInstitution: International Computer Science Institute, University of California BerkeleyLeadProposal AbstractCT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and ForensicsAlthough there has been much research in developing systems for globally sharing security information, often these approaches are fundamentally limited because their broad scope limits the trust that participants can place in the system. This project instead seeks to reap significantly greater utility by considering a more restricted scope: a system for coordinated security analysis based on exchanging information between a set of sites who have explicitly decided to work with each other. This more limited scope optimizes for the common case that in such an environment the participating sites will usually (but not always) act in a responsible manner.A key focus of the project concerns automating the steps commonly involved in security monitoring and forensic analysis while still keeping an analyst "in the loop" for significant decisions. As security problems arise, a site detecting an incident codifies a description of the attack in an "analysis script" to export to other sites. Analysts receiving such scripts inspect them to determine whether they are of interest. If so, they can instruct the system to conduct both a retrospective search for the activity in the past, and refine the site's monitoring configurations to detect future instances.As validating such an approach requires operational deployment, the project seeks to demonstrate a working system for coordinating analysis between the Lawrence Berkeley National Laboratory, the National Energy Research Scientific Computing Center, and the University of California at Berkeley.
美国国家科学基金会CISE/CNSForm 7评审分析和建议提案编号:0716640 PI:Vern Paxson机构:加州伯克利大学国际计算机科学研究所领导提案摘要CT-T:建立一个跨机构的合作安全监测和法医平台虽然在开发全球共享安全信息的系统方面已经有了很多研究,这些方法往往从根本上受到限制,因为它们的范围很广,限制了参与者对系统的信任。 相反,该项目试图通过考虑更有限的范围来获得更大的效用:一个基于一组明确决定相互合作的网站之间交换信息的协调安全分析系统。 这种更有限的范围优化了常见情况,即在这种环境中,参与站点通常(但不总是)以负责任的方式行事。该项目的一个关键重点是自动化安全监控和取证分析中通常涉及的步骤,同时仍让分析师“参与”重大决策。 当安全问题出现时,检测到事件的站点将攻击描述编入“分析脚本”中,以导出到其他站点。 收到这些脚本的分析师会检查它们,以确定它们是否感兴趣。 如果是这样,他们可以指示系统对过去的活动进行回顾性搜索,并改进现场的监测配置以检测未来的情况。由于验证这种方法需要操作部署,该项目试图展示一个工作系统,用于协调劳伦斯伯克利国家实验室,国家能源研究科学计算中心,和位于伯克利的加州大学。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Vern Paxson其他文献
A Longitudinal View of HTTP Traffic
HTTP 流量的纵向视图
- DOI:
- 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
Tom Callahan;M. Allman;Vern Paxson - 通讯作者:
Vern Paxson
Vern Paxson的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Vern Paxson', 18)}}的其他基金
II-New: Enabling Security Analysis at Scale
II-新:实现大规模安全分析
- 批准号:
1406041 - 财政年份:2014
- 资助金额:
$ 69.98万 - 项目类别:
Standard Grant
TWC: Phase: Small: Censorship Counterstrike via Measurement, Filtering, Evasion, and Protocol Enhancement
TWC:阶段:小:通过测量、过滤、规避和协议增强进行审查反击
- 批准号:
1223717 - 财政年份:2012
- 资助金额:
$ 69.98万 - 项目类别:
Standard Grant
NeTS: Large: Collaborative Research: Measuring and Modeling the Dynamics of IPv4 Address Exhaustion
NeTS:大型:协作研究:IPv4 地址耗尽动态的测量和建模
- 批准号:
1111672 - 财政年份:2011
- 资助金额:
$ 69.98万 - 项目类别:
Continuing Grant
CT-L: Collaborative Research: Comprehensive Application Analysis and Control
CT-L:协作研究:综合应用分析与控制
- 批准号:
0831535 - 财政年份:2008
- 资助金额:
$ 69.98万 - 项目类别:
Continuing Grant
CT-T:Exploiting Multi-Core CPUs for Parallelizing Network Intrusion Prevention
CT-T:利用多核 CPU 并行化网络入侵防御
- 批准号:
0716636 - 财政年份:2007
- 资助金额:
$ 69.98万 - 项目类别:
Continuing Grant
CT-T: Approaches to Network Defense Proven in Open Scientific Environments
CT-T:在开放科学环境中经过验证的网络防御方法
- 批准号:
0627320 - 财政年份:2006
- 资助金额:
$ 69.98万 - 项目类别:
Standard Grant
NeTS-FIND: Collaborative Research: Network Fabric for Personal, Social, and Urban Sensing Applications
NeTS-FIND:协作研究:用于个人、社交和城市传感应用的网络结构
- 批准号:
0626539 - 财政年份:2006
- 资助金额:
$ 69.98万 - 项目类别:
Continuing Grant
Collaborative Proposal Cybertrust: Center for Internet Epidemiology and Defenses
协作提案 Cybertrust:互联网流行病学和防御中心
- 批准号:
0433702 - 财政年份:2004
- 资助金额:
$ 69.98万 - 项目类别:
Continuing Grant
STI: Viable Network Defense for Scientific Research Institutions
STI:科研机构可行的网络防御
- 批准号:
0334088 - 财政年份:2003
- 资助金额:
$ 69.98万 - 项目类别:
Continuing Grant
NRT: Collaborative Research: Testing and Benchmarking Methodologies for Future Network Security Mechanisms
NRT:协作研究:未来网络安全机制的测试和基准测试方法
- 批准号:
0335290 - 财政年份:2003
- 资助金额:
$ 69.98万 - 项目类别:
Cooperative Agreement
相似海外基金
Marine Soundscapes And EDNA For Assessing Biodiversity And Functioning Of Re-establishing European Flat Oyster Reefs, Ostrea Edulis
海洋声景和 EDNA 用于评估生物多样性和重建欧洲平牡蛎礁(Ostrea Edulis)的功能
- 批准号:
2727996 - 财政年份:2025
- 资助金额:
$ 69.98万 - 项目类别:
Studentship
BRC-BIO: Establishing Astrangia poculata as a study system to understand how multi-partner symbiotic interactions affect pathogen response in cnidarians
BRC-BIO:建立 Astrangia poculata 作为研究系统,以了解多伙伴共生相互作用如何影响刺胞动物的病原体反应
- 批准号:
2312555 - 财政年份:2024
- 资助金额:
$ 69.98万 - 项目类别:
Standard Grant
Postdoctoral Fellowship: EAR-PF: Establishing a new eruption classification with a multimethod approach
博士后奖学金:EAR-PF:用多种方法建立新的喷发分类
- 批准号:
2305462 - 财政年份:2024
- 资助金额:
$ 69.98万 - 项目类别:
Fellowship Award
Establishing a novel culture system for lymphoid-biased HSC expansion
建立用于淋巴偏向 HSC 扩增的新型培养系统
- 批准号:
24K19206 - 财政年份:2024
- 资助金额:
$ 69.98万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
Building Desirable and Resilient Public Media Futures: Establishing the Centre for Public Values, Technology & Society
建设理想且有弹性的公共媒体未来:建立公共价值观和技术中心
- 批准号:
MR/X033651/1 - 财政年份:2024
- 资助金额:
$ 69.98万 - 项目类别:
Fellowship
Establishing an Inter-institutional San Fernando Valley Collaborative to Improve STEM Transfer Student Support, Retention, and Graduation
建立圣费尔南多谷机构间合作,以改善 STEM 转学生的支持、保留和毕业
- 批准号:
2322433 - 财政年份:2024
- 资助金额:
$ 69.98万 - 项目类别:
Standard Grant
Establishing a High Impact Undergraduate STEM Summer Research Experience Early in College that Leads to Improved Student Outcomes
在大学早期建立高影响力的本科生 STEM 暑期研究体验,从而提高学生的学习成果
- 批准号:
2344975 - 财政年份:2024
- 资助金额:
$ 69.98万 - 项目类别:
Standard Grant
The impact and regulation of eIF4A-multimerisation in establishing translational programmes
eIF4A多聚化对建立转化项目的影响和监管
- 批准号:
BB/Y004248/1 - 财政年份:2024
- 资助金额:
$ 69.98万 - 项目类别:
Research Grant
M-PACE: Establishing an Urban PACE towards Cultivating Healthy Diets for All Communities
M-PACE:建立城市 PACE,为所有社区培养健康饮食
- 批准号:
BB/Z514408/1 - 财政年份:2024
- 资助金额:
$ 69.98万 - 项目类别:
Research Grant
Establishing a Partnership for Increasing Enrollment, Retention, and Graduation of Low-Income Information Technology Students in the National Capital Region
建立合作伙伴关系,提高国家首都地区低收入信息技术学生的入学率、保留率和毕业率
- 批准号:
2322698 - 财政年份:2024
- 资助金额:
$ 69.98万 - 项目类别:
Standard Grant