课题基金 / 基金详情

Collaborative Research NeTS-FIND: Privacy Preserving Attribution and Provenance

Collaborative Research NeTS-FIND: Privacy Preserving Attribution and Provenance
协作研究 NetS-FIND:隐私保护归属和出处
批准号:
0722000
负责人:
Tadayoshi Kohno
金额:
$23.4万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2007
资助国家:
美国
项目状态:
已结题
起止时间:
2007-09-01 至 2011-08-31

项目摘要

项目成果

Tadayoshi Kohno的其他基金

相似基金

相关文献

中文摘要
翻译
现实世界的安全策略总是涉及“谁”和“什么”的问题——谁是主体,他们寻求访问什么数据,等等。相比之下,当今的互联网体系结构主要关注“如何”和“在哪里”的问题——数据项通过什么协议传递,以及传递到哪些拓扑端点。这种内在的目的不协调使得Internet安全成为一种临时事务——抽象的访问控制策略被推到特定的应用程序中去实现,或者映射到由网络级抽象(例如,网络防火墙)提供的糟糕的近似上。此外,由于今天的互联网架构提供了一种功能匿名性,使攻击者免于承担任何有意义的责任,因此这些不完善的机制本身就可以免受攻击。这个项目正在开发两个关键的体系结构功能——主机归属(哪台物理机器发送了数据包)和数据来源(数据包中包含的数据的“来源”是什么)——以支持广泛的安全策略的直接表达。此外,这些属性正在以一种方式实现,这种方式要求网络(在很大程度上)使用它们,但设法保护最终用户的隐私。在这项工作中,pi专注于两个关键应用:用于攻击威慑的取证溯源和归因,以及用于对可能在网络中移动的数据进行精确控制的防御性数据泄露。更广泛的影响:这项研究正在开发关键的体系结构组件,以提高网络服务可用的安全性和保证级别。此外,pi正在研究人员和网络运营商之间发起关于网络安全关键政策方面的对话。特别是关于正常流量和攻击流量的来源信息,这些信息必须根据某些策略进行保护。
英文摘要
Real-world security policies invariably involve questions of ``who'' and ``what''--who are the principals, what data are they seeking to access, and so forth. By contrast, the present-day Internet architecture concerns itself primarily with issues of ``how'' and ``where''-- what are the protocols by which a data item is delivered and to which topological endpoints. This inherent dissonance of purpose makes Internet security a bolt-on affair---with abstract access control policies pushed off to be implemented by particular applications or mapped onto the poor approximations provided by network-level abstractions (e.g., network firewalls). Moreover, these imperfect mechanisms are themselves attacked with impunity since today's Internet architecture provides a functional anonymity that insulates attackers from any meaningful liability.This project is developing two key architectural capabilities--host attribution (which physical machine sent a packet) and data provenance (what is the ``origin'' of the data contained within a packet)--to enable the direct expression of a wide-range of security policies. Moreover, these properties are being implemented in a fashion that mandates their use (in a strong sense) by the network, but manages to preserve end-user privacy. The PIs are focusing on two key applications in this work: forensic trace-back and attribution for the purpose of attack deterrence, and defensive data-exfiltration to place precise controls over what kinds of data may move across a network.Broader Impacts: This research is developing key architectural components to improve the level of security and assurance available to network services. In addition, the PIs are initiating a dialogue among both researchers and network operators about critical policy aspects of network security. In particular, information about the sources of both normal and attack traffic that must be safeguarded according to some policy.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: Large: Collaborative: Living in the Internet of Things
  • 批准号:
    1565252
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $120.0万
  • 财政年份:
    2016
  • 负责人:
    Tadayoshi Kohno
  • 依托单位:
Student Travel Support for the 2013 Workshop on Health Information Technologies (HealthTech '13)
  • 批准号:
    1340616
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.5万
  • 财政年份:
    2013
  • 负责人:
    Tadayoshi Kohno
  • 依托单位:
Student Travel Support for the 21st USENIX Security Symposium 2012
  • 批准号:
    1246725
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.0万
  • 财政年份:
    2012
  • 负责人:
    Tadayoshi Kohno
  • 依托单位:
Student Travel Support for the First Workshop on Health Security and Privacy (HealthSec '10)
  • 批准号:
    1041547
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.5万
  • 财政年份:
    2010
  • 负责人:
    Tadayoshi Kohno
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)