SHF: Medium: MEDITA - Multi-Layer Enterprise-Wide Dynamic Information-Flow Tracking and Assurance

SHF:中:MEDITA - 多层企业范围动态信息流跟踪和保证

基本信息

  • 批准号:
    0964647
  • 负责人:
  • 金额:
    $ 90万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2010
  • 资助国家:
    美国
  • 起止时间:
    2010-06-01 至 2014-05-31
  • 项目状态:
    已结题

项目摘要

Enterprise Information Systems (EIS) continually face attacks ranging from data leaks to the spread of malware; these attacks cost companies billions of dollars annually and can result in critical loss or leakage of data. Existing defenses typically either attempt to secure the hosts within the enterprise or add a security perimeter to the network. These conventional defenses are ineffective in the face of compromised hosts, mobile devices, and insider threats. Dynamic Information-Flow Tracking (DIFT) techniques maintain data provenance information about objects within the system and control information flow by defining and implementing policies that dictate how that information should be allowed to flow. Although powerful, existing DIFT approaches are limited by the fact of targeting only a single layer on a single physical host, which limits their effectiveness and practical applicability.This research will develop MEDITA, a multi-layer DIFT mechanism that can precisely, securely, and efficiently track data flowing within a networked EIS and across layers, and control the flow of such data based on the data provenance and the security policy in place. Multi-layer DIFT holds great promise for controlling information flow within an enterprise in many real-world scenarios. Despite its appeal, however, realizing a system that could implement such DIFT policies in practice is extremely challenging because of the wide variety of attacks that can be mounted, ranging from copying and pasting the sensitive data to writing the document to removable storage or a mobile device. To address these and other challenges, this research will (1) refine existing techniques for performing DIFT within the individual layers of an EIS, (2) design and implement the integration and inter-operation of DIFT techniques between layers, (3) define a language that can be used to express multi-layer security policies for the EIS and mechanisms for translating those policies to tainting and enforcement mechanisms; and (4) Develop a prototype implementation of MEDITA and perform experiments by using the prototype to apply MEDITA to realistic information-flow tracking control scenarios.
企业信息系统(EIS)不断面临从数据泄露到恶意软件传播的各种攻击;这些攻击每年使公司损失数十亿美元,并可能导致严重的数据丢失或泄露。 现有的防御措施通常要么试图保护企业内的主机,要么向网络添加安全边界。 这些常规防御在面对受损主机、移动的设备和内部威胁时是无效的。 动态信息流跟踪(DIFT)技术维护关于系统内的对象的数据起源信息,并通过定义和实现指示应该允许信息如何流动的策略来控制信息流。 现有的DIFT方法虽然功能强大,但由于只针对单个物理主机上的单个层,这限制了它们的有效性和实用性。本研究将开发MEDITA,一种多层DIFT机制,可以精确,安全,有效地跟踪网络EIS内和跨层的数据流,并基于数据起源和适当的安全策略来控制这种数据的流动。多层DIFT在许多现实场景中为控制企业内的信息流提供了很大的希望。 然而,尽管其具有吸引力,但实现可以在实践中实现这种DIFT策略的系统是极具挑战性的,因为可以安装各种各样的攻击,从复制和粘贴敏感数据到将文档写入可移动存储器或移动终端。 为了解决这些和其他挑战,本研究将(1)改进现有的在EIS的各个层内执行DIFT的技术,(2)设计和实现DIFT技术在层之间的集成和互操作,(3)定义一种可用于表达EIS的多层安全策略的语言以及将这些策略转换为污染和执行机制的机制;(4)开发了MEDITA的原型实现,并利用该原型将MEDITA应用于现实的信息流跟踪控制场景进行了实验。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Alessandro Orso其他文献

Alessandro Orso的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Alessandro Orso', 18)}}的其他基金

Collaborative Research: SHF: Medium: A General Framework for Automated Test Transfer
合作研究:SHF:Medium:自动化测试传输的通用框架
  • 批准号:
    2107125
  • 财政年份:
    2021
  • 资助金额:
    $ 90万
  • 项目类别:
    Continuing Grant
SHF: Medium: Spectral Profiling: Understanding Software Performance without Code Instrumentation
SHF:中:频谱分析:无需代码检测即可了解软件性能
  • 批准号:
    1563991
  • 财政年份:
    2016
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
EAGER: Collaborative Research: Leveraging Graph Databases for Incremental and Scalable Symbolic Analysis and Verification of Web Applications
EAGER:协作研究:利用图形数据库进行增量和可扩展的 Web 应用程序符号分析和验证
  • 批准号:
    1548856
  • 财政年份:
    2015
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
I-Corps: Capturing Field Data for Mobile Applications
I-Corps:捕获移动应用程序的现场数据
  • 批准号:
    1522518
  • 财政年份:
    2015
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
SHF: Small: BugX: In-house Debugging of Field Failures to Improve Software Quality
SHF:小:BugX:现场故障的内部调试以提高软件质量
  • 批准号:
    1320783
  • 财政年份:
    2013
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
SHF: Medium: Collaborative Research: Regression Testing Techniques for Real-world Software Systems
SHF:媒介:协作研究:现实世界软件系统的回归测试技术
  • 批准号:
    1161821
  • 财政年份:
    2012
  • 资助金额:
    $ 90万
  • 项目类别:
    Continuing Grant
TC: Small: Collaborative Research: Viewpoints: Discovering Client- and Server-side Input Validation Inconsistencies to Improve Web Application Security
TC:小型:协作研究:观点:发现客户端和服务器端输入验证不一致以提高 Web 应用程序安全性
  • 批准号:
    1117167
  • 财政年份:
    2011
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
SHF: Small: Automated Debugging Techniques for Modern Software Systems
SHF:小型:现代软件系统的自动调试技术
  • 批准号:
    0916605
  • 财政年份:
    2009
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
Collaborative Research: SoD-TEAM: Designing Tests for Evolving Software Systems
协作研究:SoD-TEAM:为不断发展的软件系统设计测试
  • 批准号:
    0725202
  • 财政年份:
    2008
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
Collaborative Research: Software and Hardware Support for Efficient Monitoring of Program Behavior
协作研究:高效监控程序行为的软硬件支持
  • 批准号:
    0541080
  • 财政年份:
    2006
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant

相似海外基金

RII Track-4:@NASA: Bluer and Hotter: From Ultraviolet to X-ray Diagnostics of the Circumgalactic Medium
RII Track-4:@NASA:更蓝更热:从紫外到 X 射线对环绕银河系介质的诊断
  • 批准号:
    2327438
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
Collaborative Research: Topological Defects and Dynamic Motion of Symmetry-breaking Tadpole Particles in Liquid Crystal Medium
合作研究:液晶介质中对称破缺蝌蚪粒子的拓扑缺陷与动态运动
  • 批准号:
    2344489
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
Collaborative Research: AF: Medium: The Communication Cost of Distributed Computation
合作研究:AF:媒介:分布式计算的通信成本
  • 批准号:
    2402836
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Continuing Grant
Collaborative Research: AF: Medium: Foundations of Oblivious Reconfigurable Networks
合作研究:AF:媒介:遗忘可重构网络的基础
  • 批准号:
    2402851
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Continuing Grant
Collaborative Research: CIF: Medium: Snapshot Computational Imaging with Metaoptics
合作研究:CIF:Medium:Metaoptics 快照计算成像
  • 批准号:
    2403122
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
Collaborative Research: SHF: Medium: Differentiable Hardware Synthesis
合作研究:SHF:媒介:可微分硬件合成
  • 批准号:
    2403134
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
Collaborative Research: CyberTraining: Implementation: Medium: Training Users, Developers, and Instructors at the Chemistry/Physics/Materials Science Interface
协作研究:网络培训:实施:媒介:在化学/物理/材料科学界面培训用户、开发人员和讲师
  • 批准号:
    2321102
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
Collaborative Research: SHF: Medium: Enabling Graphics Processing Unit Performance Simulation for Large-Scale Workloads with Lightweight Simulation Methods
合作研究:SHF:中:通过轻量级仿真方法实现大规模工作负载的图形处理单元性能仿真
  • 批准号:
    2402804
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
Collaborative Research: CIF-Medium: Privacy-preserving Machine Learning on Graphs
合作研究:CIF-Medium:图上的隐私保护机器学习
  • 批准号:
    2402815
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
Collaborative Research: SHF: Medium: Tiny Chiplets for Big AI: A Reconfigurable-On-Package System
合作研究:SHF:中:用于大人工智能的微型芯片:可重新配置的封装系统
  • 批准号:
    2403408
  • 财政年份:
    2024
  • 资助金额:
    $ 90万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了