SaTC: CORE: Medium: Large-Scale Characterization of DNS Abuse
SaTC:核心:中:DNS 滥用的大规模特征
基本信息
- 批准号:1705050
- 负责人:
- 金额:$ 120万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2017
- 资助国家:美国
- 起止时间:2017-07-15 至 2021-06-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The domain name system (DNS) is one of the most critical pieces of Internet infrastructure in use today. It underlies how we name nearly all Internet resources, such as "nsf.gov", and its correct operation is implicitly assumed both by end users and in the design of many important applications such as email and the World Wide Web. Unfortunately, DNS is also abused in a wide variety of ways to support criminal activities such as spam, phishing, fraud, and host compromise. The goal of this research is to develop infrastructure for the comprehensive and frequent auditing of the domain name system as a basis for discovering and understanding the impact of abuse and attacks on the health of the DNS and the Internet as a whole, and how changes in the domain name system facilitate new kinds of abuse and attacks. Given the indiscriminate nature of Internet abuse, ensuring the vitality of the DNS ecosystem can positively benefit virtually all Internet users. The project itself will also create educational opportunities for students at a variety of levels, expanding the research skills of postdoc, graduate, and undergraduate students.This research will perform large-scale measurement of many sources of data which, when combined, will provide a global perspective on the health of the DNS, and develop analysis techniques for scalably identifying and characterizing the nature of DNS abuse. We will comprehensively survey DNS to capture the bindings of all key records. We will crawl registered domains in all top-level domains for which we can obtain data, and regularly repeat this survey over time to look for changes. We will scan resources linked to domains, including Web sites, mail servers, login and application servers, any certificates that they provide, linked registration records, results of search engine queries and contemporaneous data from both a range of threat intelligence and passive DNS feeds. We will perform such measurements from a variety of geographically diverse IP addresses to capture differences due to national DNS infrastructure and cache poisoning attacks. We will build tools to process this considerable amount of data to efficiently identify changes in DNS mapping state and characterize abusive behavior. Finally, we will produce an overall analysis of DNS abuse Internet-wide, as revealed by our measurements, in which we capture the prevalence of different kinds of abuse, and what the abusers are using it for.
域名系统(DNS)是当今使用的互联网基础设施中最关键的部分之一。 它是我们如何命名几乎所有互联网资源的基础,例如“nsf.gov“,其正确操作被最终用户和许多重要应用程序(如电子邮件和万维网)的设计隐含地假定。不幸的是,DNS也以各种方式被滥用,以支持垃圾邮件、网络钓鱼、欺诈和主机入侵等犯罪活动。 本研究的目标是开发对域名系统进行全面和频繁审计的基础设施,作为发现和了解滥用和攻击对DNS和整个互联网健康状况的影响以及域名系统的变化如何促进新类型滥用和攻击的基础。 鉴于互联网滥用的不分青红皂白的性质,确保DNS生态系统的活力可以使几乎所有互联网用户受益。 该项目本身也将为不同层次的学生创造教育机会,扩展博士后、研究生和本科生的研究技能。该研究将对多种数据源进行大规模测量,当这些数据结合在一起时,将提供DNS健康状况的全球视角,并开发分析技术,以可扩展地识别和表征DNS滥用的性质。 我们将全面调查DNS以捕获所有关键记录的绑定。我们将抓取所有顶级域名中的注册域名,我们可以获得这些域名的数据,并随着时间的推移定期重复这项调查,以寻找变化。 我们将扫描链接到域的资源,包括网站、邮件服务器、登录和应用程序服务器、它们提供的任何证书、链接的注册记录、搜索引擎查询结果以及来自一系列威胁情报和被动DNS源的同期数据。 我们将从各种地理位置不同的IP地址执行此类测量,以捕获由于国家DNS基础设施和缓存中毒攻击而导致的差异。 我们将构建工具来处理大量数据,以有效地识别DNS映射状态的变化并描述滥用行为。 最后,我们将对整个互联网范围内的DNS滥用进行全面分析,正如我们的测量所揭示的那样,我们在其中捕获了不同类型滥用的流行程度以及滥用者使用它的目的。
项目成果
期刊论文数量(10)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Reading the Tea leaves: A Comparative Analysis of Threat Intelligence
- DOI:
- 发表时间:2019
- 期刊:
- 影响因子:0
- 作者:Vector Guo Li;M. Dunn;P. Pearce;Damon McCoy;G. Voelker;S. Savage
- 通讯作者:Vector Guo Li;M. Dunn;P. Pearce;Damon McCoy;G. Voelker;S. Savage
Characterization of Anycast Adoption in the DNS Authoritative Infrastructure
DNS 权威基础设施中选播采用的特征
- DOI:
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Sommese, Raffaele;Akiwate, Gautam;Jonker, Mattijs;Moura, Giovane C.;Davids, Marco;Rijswijk-Deij, Roland van;Voelker, Geoffrey M.;Savage, Stefan;Claffy, kc;Sperotto, Anna
- 通讯作者:Sperotto, Anna
Detecting and Characterizing Lateral Phishing at Scale
- DOI:
- 发表时间:2019-10
- 期刊:
- 影响因子:0
- 作者:Grant Ho;Asaf Cidon;Lior Gavish;M. Schweighauser;V. Paxson;S. Savage;G. Voelker;D. Wagner
- 通讯作者:Grant Ho;Asaf Cidon;Lior Gavish;M. Schweighauser;V. Paxson;S. Savage;G. Voelker;D. Wagner
Hack for Hire: Exploring the Emerging Market for Account Hijacking
- DOI:10.1145/3308558.3313489
- 发表时间:2019-05
- 期刊:
- 影响因子:0
- 作者:A. Mirian;Joe DeBlasio;S. Savage;G. Voelker;Kurt Thomas
- 通讯作者:A. Mirian;Joe DeBlasio;S. Savage;G. Voelker;Kurt Thomas
Hopper: Modeling and Detecting Lateral Movement
料斗:建模和检测横向运动
- DOI:
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Ho, Grant;Dhiman, Mayank;Akhawe, Devdatta;Paxson, Vern;Savage, Stefan;Voelker, Geoffrey M.;Wagner, David
- 通讯作者:Wagner, David
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Stefan Savage其他文献
Protocol design in an uncooperative internet
不合作互联网中的协议设计
- DOI:
- 发表时间:
2002 - 期刊:
- 影响因子:0
- 作者:
Stefan Savage;Thomas E. Anderson;B. Bershad - 通讯作者:
B. Bershad
Using Honeybuckets to Characterize Cloud Storage Scanning in the Wild
使用 Honeybuckets 表征云存储的野外扫描
- DOI:
10.48550/arxiv.2312.00580 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Katherine Izhikevich;Geoff Voelker;Stefan Savage;Liz Izhikevich - 通讯作者:
Liz Izhikevich
Safety and performance in the SPIN operating system
SPIN 操作系统的安全性和性能
- DOI:
- 发表时间:
1994 - 期刊:
- 影响因子:0
- 作者:
B. Bershad;Stefan Savage;P. Pardyak;E. F. Sirer;M. Fiuczynski;D. Becker;Craig Chambers;S. Eggers - 通讯作者:
S. Eggers
Stefan Savage的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Stefan Savage', 18)}}的其他基金
SaTC: CORE: Medium: After the Breach: Detecting Lateral Movement, Reconnaissance, and Exfiltration in Enterprise Networks
SaTC:核心:中:违规后:检测企业网络中的横向移动、侦察和渗透
- 批准号:
2152644 - 财政年份:2022
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
TWC: Frontier: Collaborative: Beyond Technical Security: Developing an Empirical Basis for Socio-Economic Perspectives
TWC:前沿:协作:超越技术安全:为社会经济视角建立实证基础
- 批准号:
1237264 - 财政年份:2012
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
TC: Medium: Collaborative Research:Foundations, Architectures, and Methodologies for Secure and Private Cyber-physical Vehicles
TC:媒介:协作研究:安全和私有网络物理车辆的基础、架构和方法
- 批准号:
0963702 - 财政年份:2010
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CT-M: Understanding and Exploiting Economic Incentives in Internet-based Scams
合作研究:CT-M:理解和利用网络诈骗中的经济激励
- 批准号:
0831138 - 财政年份:2008
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Collaborative Research: Cybertrust Center for Internet Epidemiology and Defenses
合作研究:网络流行病学和防御网络信任中心
- 批准号:
0433668 - 财政年份:2004
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
相似国自然基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
- 批准号:82371765
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
锕系元素5f-in-core的GTH赝势和基组的开发
- 批准号:22303037
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:52 万元
- 项目类别:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
- 批准号:
- 批准年份:2020
- 资助金额:55 万元
- 项目类别:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
- 批准号:92053110
- 批准年份:2020
- 资助金额:70.0 万元
- 项目类别:重大研究计划
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
- 批准号:81902805
- 批准年份:2019
- 资助金额:20.5 万元
- 项目类别:青年科学基金项目
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
- 批准号:41973063
- 批准年份:2019
- 资助金额:65.0 万元
- 项目类别:面上项目
CORDEX-CORE区域气候模拟与预估研讨会
- 批准号:41981240365
- 批准年份:2019
- 资助金额:1.5 万元
- 项目类别:国际(地区)合作与交流项目
RBM38通过协助Pol-ε结合、招募core调控HBV复制
- 批准号:31900138
- 批准年份:2019
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Testing the causal influence of social media on well-being and animosity
SaTC:核心:中:测试社交媒体对幸福感和敌意的因果影响
- 批准号:
2334148 - 财政年份:2024
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330941 - 财政年份:2024
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Increasing user autonomy and advertiser and platform responsibility in online advertising
SaTC:核心:中:增加在线广告中的用户自主权以及广告商和平台责任
- 批准号:
2318290 - 财政年份:2024
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Collaborative: Hardening Off-the-Shelf Software Against Side Channel Attacks
SaTC:核心:媒介:协作:强化现成软件以抵御侧通道攻击
- 批准号:
2425665 - 财政年份:2024
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Understanding the Impact of Privacy Interventions on the Online Publishing Ecosystem
协作研究:SaTC:核心:媒介:了解隐私干预对在线出版生态系统的影响
- 批准号:
2237329 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Securing Interactions between Driver and Vehicle Using Batteries
合作研究:SaTC:核心:中:使用电池确保驾驶员和车辆之间的交互安全
- 批准号:
2245224 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Understanding and Combatting Impersonation Attacks and Data Leakage in Online Advertising
协作研究:SaTC:核心:媒介:理解和打击在线广告中的冒充攻击和数据泄露
- 批准号:
2247516 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant














{{item.name}}会员




