CRII: SaTC: Analyzing and verifying the security of TCP stacks under multi-entity interactions

CRII:SaTC:多实体交互下TCP协议栈的安全性分析与验证

基本信息

  • 批准号:
    1464410
  • 负责人:
  • 金额:
    $ 17.25万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2015
  • 资助国家:
    美国
  • 起止时间:
    2015-06-01 至 2018-05-31
  • 项目状态:
    已结题

项目摘要

The objective of this project is to strengthen the Transmission Control Protocol (TCP), a ubiquitous core Internet protocol, under emerging threat models to make it robust and secure enough to serve the needs of 'smart' technologies in communications, automobiles, medical devices, and other devices that touch our lives every day. It is terrifying to imagine that a smart car could fail to report an accident automatically due to a denial of service attack on its TCP connections, or a smart medical device could fail to report a patient's change in condition. This is not to mention the ever growing cyber attacks that leverage the global and powerful Internet. This project will systematically analyze the root causes of recent security vulnerabilities and generalize them. The results will offer valuable insights on how to avoid the problems. Further, the research is expected to lead to changes to the TCP implementations in major operating systems.Specifically, the research is motivated by the following observations. First, more subtle problems such as side channels have been overlooked in TCP stacks. Second, new threat models have merged, e.g., co-located entities that do not trust each other. Third, the end-to-end assumption of TCP is broken due to the prevalence of network middleboxes, host-based firewalls, and censorship firewalls. The research will leverage model checking to systematically search for vulnerabilities under a variety of threat models and network settings. The models will be constructed from popular operating systems (with recent and representative versions) as well as network middleboxes. They can serve as the basis for testing and verifying future TCP stack implementations.
该项目的目标是加强传输控制协议(TCP),一个无处不在的核心互联网协议,在新兴的威胁模型下,使其足够强大和安全,以满足通信,汽车,医疗设备和其他每天接触我们生活的设备中的“智能”技术的需求。想象一下,智能汽车可能由于TCP连接上的拒绝服务攻击而无法自动报告事故,或者智能医疗设备可能无法报告患者的病情变化,这是非常可怕的。更不用说利用全球强大互联网的日益增长的网络攻击。这个项目将系统地分析最近的安全漏洞的根本原因,并总结它们。结果将为如何避免问题提供有价值的见解。此外,该研究有望导致主要操作系统中TCP实现的变化。具体而言,该研究的动机是以下观察。首先,TCP协议栈中忽略了一些更微妙的问题,如侧信道。其次,新的威胁模型已经融合,例如,相互不信任的协同定位实体。第三,TCP的端到端假设由于网络中间盒、基于主机的防火墙和审查防火墙的流行而被打破。该研究将利用模型检查来系统地搜索各种威胁模型和网络设置下的漏洞。这些模型将从流行的操作系统(具有最新和代表性的版本)以及网络中间盒构建。它们可以作为测试和验证未来TCP堆栈实现的基础。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Zhiyun Qian其他文献

Used by device administration to set the maximum screen off timeout . *
由设备管理用来设置最大屏幕关闭超时。
  • DOI:
  • 发表时间:
    2015
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Yuru Shao;Jason Ott;Qi Alfred Chen;Zhiyun Qian;Z. Morley Mao
  • 通讯作者:
    Z. Morley Mao
Packet Header Obfuscation Using MIMO
使用 MIMO 进行数据包标头混淆
  • DOI:
    10.1109/tnet.2020.2998398
  • 发表时间:
    2020
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Yue Cao;A. Atya;Shailendra Singh;Zhiyun Qian;S. Krishnamurthy;T. L. Porta;P. Krishnamurthy;L. Marvel
  • 通讯作者:
    L. Marvel
Where Is the Weakest Link? A Study on Security Discrepancies Between Android Apps and Their Website Counterparts
最薄弱的环节在哪里?
  • DOI:
    10.1007/978-3-319-54328-4_8
  • 发表时间:
    2017
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Arash Alavi;Alan Quach;Hang Zhang;Bryan Marsh;Farhan ul Haq;Zhiyun Qian;Long Lu;Rajiv Gupta
  • 通讯作者:
    Rajiv Gupta
Who Moves My App Promotion Investment? A Systematic Study About App Distribution Fraud
Investigation of the 2016 Linux TCP Stack Vulnerability at Scale
对 2016 年 Linux TCP 堆栈漏洞的大规模调查

Zhiyun Qian的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Zhiyun Qian', 18)}}的其他基金

Collaborative Research: SaTC: CORE: Small: Self-Driving Continuous Fuzzing
协作研究:SaTC:核心:小型:自驱动连续模糊测试
  • 批准号:
    2247881
  • 财政年份:
    2023
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Small: Improving Decentralized Kernel Patch Ecosystems
协作研究:SaTC:CORE:小型:改善去中心化内核补丁生态系统
  • 批准号:
    2155213
  • 财政年份:
    2022
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Collaborative: Deep and Efficient Dynamic Analysis of Operating System Kernels
SaTC:核心:小型:协作:操作系统内核的深入有效的动态分析
  • 批准号:
    1953933
  • 财政年份:
    2020
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Collaborative: The Web Ad Technology Arms Race: Measurement, Analysis, and Countermeasures
SaTC:核心:小型:协作:网络广告技术军备竞赛:测量、分析和对策
  • 批准号:
    1719147
  • 财政年份:
    2017
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
CAREER: Empowering Attacker-Centric Security Analysis of Network Protocols
职业:支持以攻击者为中心的网络协议安全分析
  • 批准号:
    1652954
  • 财政年份:
    2017
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Continuing Grant
NeTS: Small: Collaborative Research: Practical HTTPS Traffic Manipulation At Middleboxes
NetS:小型:协作研究:中间盒的实用 HTTPS 流量操纵
  • 批准号:
    1619391
  • 财政年份:
    2016
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
TWC: Small: Cache-based Side Channel Attacks on Smartphone Graphics Buffers: New Vulnerabilities and Defenses
TWC:小型:针对智能手机图形缓冲区的基于缓存的侧通道攻击:新漏洞和防御
  • 批准号:
    1619450
  • 财政年份:
    2016
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
CSR: Small: Collaborative Research: Taming Mobile Hardware & OS Diversity for Comprehensive Software Analysis
CSR:小型:协作研究:驯服移动硬件
  • 批准号:
    1617573
  • 财政年份:
    2016
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
TWC: Small: Collaborative: Multipath TCP Side Channel Vulnerabilities and Defenses
TWC:小:协作:多路径 TCP 侧信道漏洞和防御
  • 批准号:
    1528114
  • 财政年份:
    2015
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant

相似海外基金

CRII: SaTC: Automated Knowledge Representation for IoT Cybersecurity Regulations
CRII:SaTC:物联网网络安全法规的自动化知识表示
  • 批准号:
    2348147
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
CRII: SaTC: Reliable Hardware Architectures Against Side-Channel Attacks for Post-Quantum Cryptographic Algorithms
CRII:SaTC:针对后量子密码算法的侧通道攻击的可靠硬件架构
  • 批准号:
    2348261
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
CRII: SaTC: Privacy vs. Accountability--Usable Deniability and Non-Repudiation for Encrypted Messaging Systems
CRII:SaTC:隐私与责任——加密消息系统的可用否认性和不可否认性
  • 批准号:
    2348181
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Continuing Grant
CRII: SaTC: Evolving I/O Protocols for Confidential Computing
CRII:SaTC:用于机密计算的不断发展的 I/O 协议
  • 批准号:
    2348130
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
  • 批准号:
    2327427
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Continuing Grant
CRII: SaTC: Enforcing Expressive Security Policies using Trusted Execution Environments
CRII:SaTC:使用可信执行环境执行表达性安全策略
  • 批准号:
    2348304
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Continuing Grant
CRII: SaTC: The Right to be Forgotten in Follow-ups of Machine Learning: When Privacy Meets Explanation and Efficiency
CRII:SaTC:机器学习后续中被遗忘的权利:当隐私遇到解释和效率时
  • 批准号:
    2348177
  • 财政年份:
    2024
  • 资助金额:
    $ 17.25万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了