TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
批准号:
1064986
负责人:
Micah Sherr
金额:
$35.24万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-09-01 至 2016-08-31
中文摘要
网络和分布式系统的运营商经常发现自己需要回答一个诊断或取证问题——系统的某些部分被发现处于意外状态,运营商必须确定这种状态是合法的还是秘密攻击的症状。在这种情况下,要求系统对观察到的状态作出“解释”将是有用的。在没有攻击的情况下,新兴的网络溯源技术可以通过构建将观察到的状态与其根本原因联系起来的事件链来构建这样的解释。然而,攻击者可以使其控制下的节点伪造或压制信息,从而产生一个似是而非的解释。因此,运营商可能没有注意到攻击。本研究开发了安全的网络来源技术,即使系统受到强大对手的攻击,也可以提供有用的解释。该项目(i)通过增加法医环境中所需的功能,大大扩展和概括了网络来源的概念;(ii)开发无需任何可信组件的安全存储来源的技术;(iii)设计有效查询安全来源的方法;(iv)介绍保护来源机密性的方法;(v)在具体应用的背景下评估这些技术。该项目的起源和取证主题与宾夕法尼亚大学市场和社会系统工程的新本科课程相结合。它将为各种分布式应用程序提供取证支持,包括关键基础设施可能很快就会基于的新兴云应用程序。
英文摘要
Operators of networks and distributed systems often find themselves needing to answer a diagnostic or forensic question -- some part of the system is found to be in an unexpected state, and the operators must decide whether the state is legitimate or a symptom of a clandestine attack. In such cases, it would be useful to ask the system for an 'explanation' of the observed state. In the absence of attacks, emerging network provenance techniques can construct such explanations by constructing a chain of events that links the observed state to its root causes. However, an attacker can cause the nodes under his control to forge or suppress information and thus produce a plausible (but incorrect) explanation. As a result, the operators may fail to notice the attack.This research develops secure network provenance techniques that can provide useful explanations even when the system is under attack by a powerful adversary. The project (i) substantially extends and generalizes the concept of network provenance by adding capabilities needed in a forensic setting; (ii) develops techniques for securely storing provenance without any trusted components; (iii) designs methods for efficiently querying secure provenance; (iv) introduces methods for protecting the confidentiality of provenance; and (v) evaluates these techniques in the context of concrete applications.The project's theme of provenance and forensics is integrated with Penn's new undergraduate program in Market and Social Systems Engineering. It will provide forensics support for a wide variety of distributed applications, including emerging cloud applications upon which critical infrastructure may soon be based.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: EDU: Security and Privacy Implications of Remote Proctoring for School Policies and Practices
-
批准号:2138078
-
项目类别:Standard Grant
-
资助金额:$19.07万
-
财政年份:2022
-
负责人:Micah Sherr
-
依托单位:
SaTC: Expanding Research Frontiers with a Next-Generation Anonymous Communication Experimentation (ACE) Framework
-
批准号:1925497
-
项目类别:Standard Grant
-
资助金额:$149.9万
-
财政年份:2019
-
负责人:Micah Sherr
-
依托单位:
SaTC: CORE: Small: Practical and Robust Hidden Voice Commands
-
批准号:1718498
-
项目类别:Standard Grant
-
资助金额:$50.63万
-
财政年份:2017
-
负责人:Micah Sherr
-
依托单位:
TWC: TTP Option: Small: Collaborative: Enhancing Anonymity Network Resilience against Pervasive Internet Attacks
-
批准号:1527401
-
项目类别:Standard Grant
-
资助金额:$44.98万
-
财政年份:2015
-
负责人:Micah Sherr
-
依托单位:
EAGER: Collaborative: Secure and Efficient Data Provenance
-
批准号:1445967
-
项目类别:Standard Grant
-
资助金额:$9.67万
-
财政年份:2014
-
负责人:Micah Sherr
-
依托单位:
CAREER: Private Communication in Strongly Adversarial Networks
-
批准号:1149832
-
项目类别:Continuing Grant
-
资助金额:$31.26万
-
财政年份:2012
-
负责人:Micah Sherr
-
依托单位:
海外基金