EAGER: Exploring the Use of Deception to Enhance Cyber Security
EAGER: Exploring the Use of Deception to Enhance Cyber Security
批准号:
1548114
负责人:
Eugene Spafford
金额:
$18.23万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-08-01 至 2018-05-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Our computing systems are constantly under attack, by everyone from pranksters to agents of hostile nations. Many of those systems and networks make the task of the adversary easier by responding to attacks with useful information. This is because software and protocols have been written for decades to provide informative feedback for error detection and correction. It is precisely this behavior that enhances the chances of success by attackers, by allowing them to map networks and determine system flaws. This research addresses the question "Are there uses of deceptive responses that help prevent successful attacks?" Furthermore, the study investigates if it is possible to characterize and model the types of situations where deception may be useful. The result of this work provides cyber system designers with some new defensive measures, and guidance as to when they are useful to deploy.The project includes two related lines of research. The first of these is to explore some new applications of deceit in system defense. The researchers investigate presenting deceptive responses to attempts to exploit known vulnerabilities, and building a file system that "lies" about the creation and deletion of key files. Each of these mechanisms should support a system's security by providing early warning of bad behavior as well as blunting attacks. Deceitful responses to attacks can lead a perpetrator to employ ineffective attacks, thus wasting time and effort. A deceptive file system can capture forensic data about an attempted attack while only appearing to allow the installation of malicious files. The second line of research explores how to apply hypergame models to cyber defenses using deceptive techniques. Hypergames are an extension of game theory that includes incorrect and uncertain information. By constructing hypergame models we should be able to determine situations where there is a favorable result when deception is employed as a defense.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Preparing Cyber Security Leaders
-
批准号:1027493
-
项目类别:Continuing Grant
-
资助金额:$209.86万
-
财政年份:2011
-
负责人:Eugene Spafford
-
依托单位:
A Dual-Track Masters Degree Program for Information Security Specialists
-
批准号:0965780
-
项目类别:Standard Grant
-
资助金额:$4.75万
-
财政年份:2010
-
负责人:Eugene Spafford
-
依托单位:
SoD: Collaborative Research: Transparency and Legal Compliance in Software Systems
-
批准号:0725152
-
项目类别:Standard Grant
-
资助金额:$22.96万
-
财政年份:2007
-
负责人:Eugene Spafford
-
依托单位:
CT-ISG: Designing Next-Generation, Reliable Internet Servers
-
批准号:0523243
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Eugene Spafford
-
依托单位:
Exposing Grand Challenges in Information Security & Assurance
-
批准号:0335324
-
项目类别:Continuing Grant
-
资助金额:$8.91万
-
财政年份:2003
-
负责人:Eugene Spafford
-
依托单位:
A Dual-Track Masters Degree Program for Information Security Specialists
-
批准号:0113730
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2001
-
负责人:Eugene Spafford
-
依托单位:
CISE Experimental Partnerships: Audit Trails: Content, Storage and Processing
-
批准号:9903545
-
项目类别:Standard Grant
-
资助金额:$36.58万
-
财政年份:1999
-
负责人:Eugene Spafford
-
依托单位:
RIA: Debugging with Test-Based Information
-
批准号:8910306
-
项目类别:Standard Grant
-
资助金额:$6.7万
-
财政年份:1989
-
负责人:Eugene Spafford
-
依托单位:
国内基金
海外基金
Exploring Changing Fertility Intentions in China
-
批准号:--
-
项目类别:外国学者研究基金
-
资助金额:--
-
批准年份:2024
-
负责人:MINHEE CHAE
-
依托单位:
Exploring the Intrinsic Mechanisms of CEO Turnover and Market
-
批准号:--
-
项目类别:外国学者研究基金
-
资助金额:--
-
批准年份:2024
-
负责人:HAOFEI Z
-
依托单位:
Exploring the Intrinsic Mechanisms of CEO Turnover and Market Reaction: An Explanation Based on Information Asymmetry
-
批准号:W2433169
-
项目类别:外国学者研究基金项目
-
资助金额:--
-
批准年份:2024
-
负责人:HAOFEI ZHANG
-
依托单位: