课题基金 / 基金详情

CAREER: Securing Critical Infrastructure with Autonomously Secure Storage

CAREER: Securing Critical Infrastructure with Autonomously Secure Storage
职业:通过自主安全存储保护关键基础设施
批准号:
1540217
负责人:
Kevin Butler
金额:
$32.2万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-08-15 至 2019-03-31

项目摘要

项目成果

Kevin Butler的其他基金

相似基金

相关文献

中文摘要
翻译
嵌入式系统目前依赖于本地且通常不安全的状态保留来进行过程控制和后续取证分析。随着关键嵌入式控制系统(例如智能电网、SCADA)生成越来越多的数据并与其他系统的连接越来越紧密,需要安全地保留和管理这些数据。 Stuxnet 等攻击表明,SCADA 和其他构成关键基础设施的系统很容易受到控制器和传感设备的损害,以及伪造数据以规避异常检测机制。该项目开发用于安全存储和监控关键基础设施中的嵌入式系统状态的技术和架构。我们正在检查与关键嵌入式系统中生成和存储数据相关的漏洞,这些系统通常是资源受限的环境。我们建议设计和部署“自主安全存储设备”,作为嵌入式设备的弹性存储。 我们正在设计日志记录、审计和管理架构,以便在面对恶意和受损设备时弹性存储系统数据和来源。此外,我们探索如何将这些数据传播到其他系统和云等环境,旨在通过隐私保护通信和查询接口来保护数据,并尝试对系统操作进行数据驱动的推断以检测异常行为。通过对生成的数据和元数据进行这些主动保护,我们的目标是为生成和存储关键基础设施中生成的数据提供新的基准。
英文摘要
Embedded systems currently rely on local and often insecure state retention for process control and subsequent forensic analysis. As critical embedded control systems (e.g., smart grids, SCADA) generate increasing amounts of data and become ever more connected to other systems, secure retention and management of that data is required. Attacks such as Stuxnet show that SCADA and other systems comprising critical infrastructure are vulnerable to the compromise of controllers and sensing devices, as well as falsification of data to circumvent anomaly detection mechanisms. This project develops techniques and architectures for securely storing and monitoring embedded system state in critical infrastructure. We are examining vulnerabilities relating to generating and storing data in critical embedded systems, which are often resource-constrained environments. We propose the design and deployment of 'autonomously secure storage devices' that act as resilient storage for embedded devices. We are designing logging, audit, and management architectures for resiliently storing system data and provenance in the face of malicious and compromised devices. Additionally, we explore how this data may be disseminated to other systems and to environments such as the cloud and aim to protect data through privacy-preserving communication and querying interfaces, and attempt to make data-driven inferences about system operation to detect anomalous behavior. Through these active protections to generated data and metadata, we aim to provide a new baseline for producing and storing data generated within critical infrastructures.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Enabling Practically Secure Cellular Infrastructure
  • 批准号:
    2055014
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.8万
  • 财政年份:
    2022
  • 负责人:
    Kevin Butler
  • 依托单位:
Collaborative Proposal: SaTC: Frontiers: Securing the Future of Computing for Marginalized and Vulnerable Populations
  • 批准号:
    2206950
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $403.58万
  • 财政年份:
    2022
  • 负责人:
    Kevin Butler
  • 依托单位:
SaTC: STARSS: Small: Domain Informed Techniques for Detecting and Defending Against Malicious Firmware
  • 批准号:
    1815883
  • 项目类别:
    Standard Grant
  • 资助金额:
    $33.33万
  • 财政年份:
    2018
  • 负责人:
    Kevin Butler
  • 依托单位:
Travel Grant Support for Association for Computing Machinery (AC) WiSec 2018
  • 批准号:
    1823067
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.9万
  • 财政年份:
    2018
  • 负责人:
    Kevin Butler
  • 依托单位:
海外基金