课题基金 / 基金详情

EAGER: USBRCCR: Collaborative: Lightweight Policy Enforcement of Information Flows in IoT Infrastructures

EAGER: USBRCCR: Collaborative: Lightweight Policy Enforcement of Information Flows in IoT Infrastructures
EAGER:USBRCCR:协作:物联网基础设施中信息流的轻量级策略执行
批准号:
1740897
负责人:
Atul Prakash
金额:
$16.37万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-09-01 至 2020-08-31

项目摘要

项目成果

Atul Prakash的其他基金

相似基金

相关文献

中文摘要
翻译
随着物联网(IoT)系统的广泛部署,其安全性正在成为许多领域的一个严重问题,包括智能家居、自动驾驶汽车或工业控制系统。物联网系统中的安全漏洞可能导致隐私丢失、数据被盗、经济损失甚至人身伤害。拟议的工作将开发一种新的方法,通过跨层防御来加强物联网系统的安全性。该方法将由美国和巴西的三个参与机构合作开发和评估。该项目旨在为加强对物联网系统中几种安全攻击的防御提供技术基础,该项目还将通过传播结果和教育工作产生更广泛的影响。从技术上讲,所提出的方法考虑了物联网应用程序层、网络层和设备的跨层防御。核心概念是流策略:提出的工作从物联网应用程序中提取流策略,然后使用这些策略来执行所需的流,并在设备和网络层检测违规行为。与通用应用程序相比,物联网应用程序中的流通常是可预测的,并且具有足够的表现力,可以捕获重要的属性,这样检测到的流违规表明了真正的问题,而不是假警报。如果确实发现策略具有足够的表现力,并且在物联网系统中检查它们是轻量级的,那么该方法将为在实践中提高物联网系统的防御提供实质性的好处。
英文摘要
As Internet of Things (IoT) systems become deployed more widely, their security is becoming a serious concern in many domains, including smart homes, autonomous cars, or industrial control systems. Security exploits in IoT systems can lead to loss of privacy, data theft, financial losses, and even physical harm. The proposed work will develop a novel approach to harden security of IoT systems via cross-layer defense. The approach will be developed and evaluated in collaboration among three participating institutions in the US and Brazil. The project aims to provide technical foundations to harden the defense against several types of security attacks in IoT systems, and the project will also create broader impact through dissemination of results and education efforts.More technically, the proposed approach considers cross-layer defense at IoT app layer, network layer, and devices. The central concept is flow policies: the proposed work extracts flow policies from IoT apps, and then uses these policies to enforce desired flows and to detect violations at both the device and network layers. In contrast to general-purpose applications, the flows in IoT apps are expected to be often predictable and expressive enough to capture important properties such that detected flow violations indicate real problems and not false alarms. If policies are indeed found to be expressive enough, and checking them is lightweight in IoT systems, the approach will provide substantial benefits to improve defense of IoT systems in practice.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
Securing IoT Apps with Fine-grained Control of Information Flows
通过信息流的细粒度控制来保护物联网应用程序
DOI: --
发表时间: 2018
期刊: XVIII Brazilian Symposium On Information and Computational Systems Security
影响因子: --
作者: [Mauro Junior, Davino, Gama, Kiev, Prakash, Atul]
通讯作者: Prakash, Atul
Tyche: A Risk-Based Permission Model for Smart Homes
Tyche:智能家居基于风险的权限模型
DOI: 10.1109/secdev.2018.00012
发表时间: 2018
期刊: 2018 IEEE Cybersecurity Development (SecDev
影响因子: --
作者: [Rahmati, Amir, Fernandes, Earlence, Eykholt, Kevin, Prakash, Atul]
通讯作者: Prakash, Atul
DOI: 10.1007/978-3-030-20883-7_2
发表时间: 2019
期刊: Lenarduzzi V. (eds
影响因子: --
作者: [Carlson, Brandon, Leach, Kevin, Marinov, Darko, Nagappan, Meiyappan, Prakash, Atul]
通讯作者: Prakash, Atul
DOI: --
发表时间: 2018-07
期刊: ArXiv
影响因子: --
作者: [Kevin Eykholt;I. Evtimov;Earlence Fernandes;Bo Li;Amir Rahmati;Florian Tramèr;Atul Prakash;]
通讯作者: Kevin Eykholt;I. Evtimov;Earlence Fernandes;Bo Li;Amir Rahmati;Florian Tramèr;Atul Prakash;
EAGER: SaTC-EDU: Identifying Educational Conceptions and Challenges in Cybersecurity and Artificial Intelligence
CPS: Synergy: Collaborative Research: Support for Security and Safety of Programmable IoT Systems
TWC: Small: Discovering and Restricting Undesirable Information Flows Between Multiple Spheres of Activities
TC: Small: Capsule: Safely Accessing Confidential Data in a Low-Integrity Environment
海外基金