Collaborative Research: CT-L: CLEANSE: Cross-Layer Large-Scale Efficient Analysis of Network Activities to Secure the Internet
Collaborative Research: CT-L: CLEANSE: Cross-Layer Large-Scale Efficient Analysis of Network Activities to Secure the Internet
批准号:
0831300
负责人:
Wenke Lee
金额:
$66.89万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-10-01 至 2015-09-30
中文摘要
第 8 层攻击(例如垃圾邮件和网络钓鱼)是从恶意服务平台(例如僵尸网络)发起的,该平台由大量受感染的机器(或机器人)组成。这种攻击平台依赖于下层网络服务来实现通信和攻击活动的高效、鲁棒性和隐蔽性。这些服务包括查找(例如 DNS)、托管(例如 Web 服务器)和传输(例如 BGP)。 CLEANSE 项目的主要研究目标和方法是: 1. 控制平面监控。用于发起第 8 层攻击的大部分基础设施都涉及滥用核心网络服务(例如 DNS 和 BGP)中的控制平面。CLEANSE 项目开发分布式、在线和实时的控制平面异常检测传感器。 2. 数据平面监控。该项目开发基于流量采样和聚类的新型通用网络异常检测算法,用于监控高速流量。 3.提升安全审计能力。 CLEANSE 项目开发数据包“标记/污染”技术,以实现网络流量的跟踪和集群(例如,由同一机器人程序生成)。该项目还开发了改进的流量采样功能,具有攻击感知能力和全网络分布式能力。通过专注于核心网络服务的监控,CLEANSE框架可以检测未来的第8层攻击和新形式的大规模恶意软件感染。该项目还创建了教育内容,包括新教科书和在线课程材料,这些内容直接受益于研究活动。 CLEANSE 项目团队还与行业合作伙伴(包括 ISP)合作组织重点研讨会,将学术界的研究人员和行业/ISP、政府和执法机构的从业者聚集在一起,以促进思想、数据和技术的交流。
英文摘要
Layer-8 attacks (e.g., spam and phishing) are launched from a malicious service platform, e.g., botnet, which consists of a large number of infected machines (or bots). Such an attack platform relies on lower-layer network services to achieve efficiency, robustness, and stealth in communication and attack activities. These services include look-up (e.g., DNS), hosting (e.g., Web servers), and transport (e.g., BGP).The main research goals and approaches of the CLEANSE project are: 1. Control-plane monitoring. Much of the infrastructure for mounting layer-8 attacks involves abuse of the control plane in core network services (e.g., DNS and BGP).The CLEANSE project develops control-plane anomaly detection sensors that are distributed, online, and real-time. 2. Data-plane monitoring. The project develops new and general network anomaly detection algorithms based on traffic sampling and clustering for monitoring high-speed traffic. 3. Improved security auditing capabilities. The CLEANSE project develops packet "tagging/tainting" techniques to enable tracking and clustering of network traffic flows (e.g., that are generated by the same bot program). The project also develops improved traffic sampling capabilities that are attack-aware and distributed network-wide.By focusing on monitoring of core network services, the CLEANSE framework can detect future layer-8 attacks and new forms of large-scale malware infections. The project also creates educational contents, including new textbooks and on-line course materials, which directly benefit from the research activities. The CLEANSE project team also work with industry partners (including the ISPs) to organize focused workshops that bring together researchers from academia and practitioners from the industry/ISP, government, and law enforcement agencies to foster the exchange of ideas, data, and technologies.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
2015 Cyber Security Education Workshop
-
批准号:1544099
-
项目类别:Standard Grant
-
资助金额:$3.5万
-
财政年份:2015
-
负责人:Wenke Lee
-
依托单位:
TWC: Medium: Collaborative: Automated Reverse Engineering of Commodity Software
-
批准号:1409807
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2014
-
负责人:Wenke Lee
-
依托单位:
TWC SBE: TTP Option: Medium: Collaborative: EPICA: Empowering People to Overcome Information Controls and Attacks
-
批准号:1409635
-
项目类别:Standard Grant
-
资助金额:$110.0万
-
财政年份:2014
-
负责人:Wenke Lee
-
依托单位:
EAGER: The Conceptual Landscape of Information Manipulation
-
批准号:1255453
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2012
-
负责人:Wenke Lee
-
依托单位:
SaTC Cyber Cafe
-
批准号:1304678
-
项目类别:Standard Grant
-
资助金额:$5.34万
-
财政年份:2012
-
负责人:Wenke Lee
-
依托单位:
TC: Small: A Foundational and Practical Platform for Host Security Applications
-
批准号:1017265
-
项目类别:Standard Grant
-
资助金额:$42.96万
-
财政年份:2010
-
负责人:Wenke Lee
-
依托单位:
Collaborative Research: CT-T: Logic and Data Flow Extraction for Live and Informed Malware Execution
-
批准号:0716570
-
项目类别:Continuing Grant
-
资助金额:$22.0万
-
财政年份:2007
-
负责人:Wenke Lee
-
依托单位:
Collaborative Research: CT-ISG: Modeling and Measuring Botnets
-
批准号:0627477
-
项目类别:Continuing Grant
-
资助金额:$17.5万
-
财政年份:2006
-
负责人:Wenke Lee
-
依托单位:
Intrusion Detection Techniques for Mobile Ad Hoc Networks
-
批准号:0311024
-
项目类别:Continuing Grant
-
资助金额:$27.5万
-
财政年份:2003
-
负责人:Wenke Lee
-
依托单位:
CAREER: Adaptive Intrusion Detection Systems
-
批准号:0133629
-
项目类别:Continuing Grant
-
资助金额:$35.0万
-
财政年份:2002
-
负责人:Wenke Lee
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: