TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
基本信息
- 批准号:1065130
- 负责人:
- 金额:$ 84.58万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2011
- 资助国家:美国
- 起止时间:2011-09-01 至 2017-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Operators of networks and distributed systems often find themselves needing to answer a diagnostic or forensic question -- some part of the system is found to be in an unexpected state, and the operators must decide whether the state is legitimate or a symptom of a clandestine attack. In such cases, it would be useful to ask the system for an 'explanation' of the observed state. In the absence of attacks, emerging network provenance techniques can construct such explanations by constructing a chain of events that links the observed state to its root causes. However, an attacker can cause the nodes under his control to forge or suppress information and thus produce a plausible (but incorrect) explanation. As a result, the operators may fail to notice the attack.This research develops secure network provenance techniques that can provide useful explanations even when the system is under attack by a powerful adversary. The project (i) substantially extends and generalizes the concept of network provenance by adding capabilities needed in a forensic setting; (ii) develops techniques for securely storing provenance without any trusted components; (iii) designs methods for efficiently querying secure provenance; (iv) introduces methods for protecting the confidentiality of provenance; and (v) evaluates these techniques in the context of concrete applications.The project's theme of provenance and forensics is integrated with Penn's new undergraduate program in Market and Social Systems Engineering. It will provide forensics support for a wide variety of distributed applications, including emerging cloud applications upon which critical infrastructure may soon be based.
网络和分布式系统的运营商经常发现自己需要回答一个诊断或取证问题-系统的某个部分被发现处于意外状态,运营商必须决定该状态是合法的还是秘密攻击的症状。在这种情况下,要求系统对观察到的状态进行“解释”将是有用的。在没有攻击的情况下,新兴的网络起源技术可以通过构建一系列事件来构建这样的解释,这些事件将观察到的状态与其根本原因联系起来。然而,攻击者可以使其控制下的节点伪造或隐藏信息,从而产生一个看似合理(但不正确)的解释。因此,运营商可能无法注意到的attack.This研究开发安全的网络起源技术,可以提供有用的解释,即使当系统受到攻击的一个强大的对手。该项目(一)通过增加法医环境所需的能力,大大扩展和推广了网络来源的概念;(二)开发了在没有任何可信组件的情况下安全存储来源的技术;(三)设计了有效查询安全来源的方法;(四)采用了保护来源机密性的方法;以及(v)在具体应用的背景下评估这些技术。该项目的起源和取证主题与宾夕法尼亚大学新的市场和社会系统工程本科课程相结合。它将为各种分布式应用程序提供取证支持,包括可能很快成为关键基础设施基础的新兴云应用程序。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Andreas Haeberlen其他文献
Addressing the provenance challenge using ZOOM
使用 ZOOM 解决来源挑战
- DOI:
10.1002/cpe.1232 - 发表时间:
2008 - 期刊:
- 影响因子:0
- 作者:
Arjun Narayan;Ariel J. Feldman;Antonis Papadimitriou;Andreas Haeberlen - 通讯作者:
Andreas Haeberlen
The Fault Detection Problem (Extended Abstract)
故障检测问题(扩展摘要)
- DOI:
- 发表时间:
2009 - 期刊:
- 影响因子:0
- 作者:
Andreas Haeberlen;P. Kuznetsov - 通讯作者:
P. Kuznetsov
2 Linear Dependent Types and Sensitivity Analysis : DFuzz
2 线性相关类型和敏感性分析:DFuzz
- DOI:
- 发表时间:
2013 - 期刊:
- 影响因子:0
- 作者:
Marco Gaboardi;E. J. G. Arias;Andreas Haeberlen;Justin Hsu;B. Pierce - 通讯作者:
B. Pierce
Fuzzi: a three-level logic for differential privacy
Fuzzi:差分隐私的三级逻辑
- DOI:
10.1145/3341697 - 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Hengchu Zhang;Edo Roth;Andreas Haeberlen;B. Pierce;Aaron Roth - 通讯作者:
Aaron Roth
THE UNIVERSITY OF CHICAGO HERMETIC: PRIVACY-PRESERVING DISTRIBUTED ANALYTICS WITHOUT (MOST) SIDE CHANNELS A THESIS SUBMITTED IN PARTIAL FULFILMENT OF THE REQUIREMENTS FOR THE DEGREE OF MASTER OF SCIENCE DEPARTMENT OF COMPUTER SCIENCE BY MIN XU
芝加哥大学 Hermetic:没有(大多数)侧通道的隐私保护分布式分析 部分满足计算机科学系理学硕士学位要求的论文,作者:Min Xu
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Min Xu;Antonis Papadimitriou;Ariel J. Feldman;Andreas Haeberlen - 通讯作者:
Andreas Haeberlen
Andreas Haeberlen的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Andreas Haeberlen', 18)}}的其他基金
CNS Core: Medium: The Synchronous Data Center
CNS 核心:媒介:同步数据中心
- 批准号:
1955670 - 财政年份:2020
- 资助金额:
$ 84.58万 - 项目类别:
Continuing Grant
CAREER: Evidence in Federated Distributed Systems
职业:联邦分布式系统的证据
- 批准号:
1054229 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Continuing Grant
相似海外基金
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1630037 - 财政年份:2015
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1064646 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
- 批准号:
1064944 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
- 批准号:
1065216 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
- 批准号:
1065537 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1064844 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
- 批准号:
1064986 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
- 批准号:
1064900 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
TC:媒介:协作研究:虚拟化环境中的随机数生成和使用
- 批准号:
1065288 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1064997 - 财政年份:2011
- 资助金额:
$ 84.58万 - 项目类别:
Standard Grant