CAREER: Resilient Execution with Bounded-Time Recovery (REBOUND)

职业生涯:具有有限时间恢复(REBOUND)的弹性执行

基本信息

  • 批准号:
    1750158
  • 负责人:
  • 金额:
    $ 47.54万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2018
  • 资助国家:
    美国
  • 起止时间:
    2018-09-01 至 2024-08-31
  • 项目状态:
    已结题

项目摘要

This project develops new ways to defend critical infrastructure systems, such as factory control networks, medical devices, or power plants, against attacks. These systems directly interact with the physical world, so a successful attack can have serious consequences: for instance, a compromised chemical plant could have severe environmental consequences, and a compromised medical device could result in injury or death. Contemporary security mechanisms, however, can be inadequate for at two reasons. First, current defenses tend to be quite heavyweight, which makes them difficult to apply to resource-constrained infrastructure systems. And second, timing is critical: current defenses tend to focus on preventing systems from 'doing the wrong thing' or 'failing to do the right thing', as opposed to preventing systems from 'doing the right thing at the wrong time', which is often just as damaging. To address this problem, this project creates stronger defense mechanisms tailored specifically for infrastructure systems. The new mechanisms explicitly take timing into account, are expected to have lower cost, and will initially be applied to automotive systems in collaboration with a major car manufacturer. The principal investigator will organize tutorials for practitioners, and will enhance the curriculum of the Master's in Embedded Systems program at the University of Pennsylvania with more coverage of Internet-of-Things security. She is also developing a series of outreach activities to improve the representation of women and minorities in the real-time systems community. Collaborations with the law school and the medical school at the University of Pennsylvania will investigate how to use the new techniques to improve the legal framework for infrastructure systems, by offering better accountability for product defects, for example, and how to apply them to improve the security of medical systems. This project pursues an approach called bounded-time recovery. Unlike many existing techniques, bounded time recovery does not attempt to mask all symptoms of an attack, which existing defenses do at great cost; rather, it leverages the fact that many systems cannot change their state arbitrarily quickly, due to properties such as inertia or thermal capacity, and can thus already tolerate brief disruptions, provided the system quickly returns to a correct state. This approach seeks guarantees that 1) the system will meet its timing requirements in the absence of an attack, and that 2) when under attack, the system will return to a correct state within a bounded amount of time, potentially after reconfiguring itself to exclude compromised nodes. The goal is to provide these guarantees in the Byzantine model, that is, without a priori knowledge of what the attacks will look like, or which nodes will be attacked. To achieve this goal, the project will construct practical algorithms for (provably) detecting attacks within bounded time, based on techniques such as tamper-evident logs and cryptographic evidence; create methods for recovering from detected attacks within bounded time, using ideas from multi-mode systems; and produce reusable implementations of the new techniques that will be widely disseminated and made available under an open-source license.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该项目开发了保护关键基础设施系统(如工厂控制网络、医疗设备或发电厂)免受攻击的新方法。这些系统直接与物理世界交互,因此成功的攻击可能会产生严重的后果:例如,受损的化工厂可能会产生严重的环境后果,受损的医疗设备可能会导致受伤或死亡。然而,当代安全机制可能由于两个原因而不足。首先,当前的防御往往是相当重量级的,这使得它们难以应用于资源受限的基础设施系统。其次,时机至关重要:当前的防御往往侧重于防止系统“做错误的事情”或“未能做正确的事情”,而不是防止系统“在错误的时间做正确的事情”,这通常同样具有破坏性。为了解决这个问题,该项目创建了专门为基础设施系统量身定制的更强大的防御机制。新机制明确考虑了时间,预计成本较低,最初将与一家大型汽车制造商合作应用于汽车系统。首席研究员将为从业人员组织教程,并将加强宾夕法尼亚大学嵌入式系统硕士课程的课程,更多地覆盖物联网安全。她还在开展一系列外联活动,以提高妇女和少数群体在实时系统社区中的代表性。与宾夕法尼亚大学法学院和医学院的合作将研究如何使用新技术来改善基础设施系统的法律的框架,例如,通过为产品缺陷提供更好的问责制,以及如何应用它们来提高医疗系统的安全性。该项目采用一种称为有限时间恢复的方法。与许多现有技术不同,有界时间恢复并不试图掩盖攻击的所有症状,现有的防御措施需要付出巨大的代价;相反,它利用了许多系统由于惯性或热容量等属性而无法任意快速改变其状态的事实,因此可以容忍短暂的中断,只要系统快速返回到正确的状态。这种方法寻求保证:1)系统将在没有攻击的情况下满足其定时要求,以及2)当受到攻击时,系统将在有限的时间内返回到正确的状态,可能是在重新配置自身以排除受损节点之后。我们的目标是在拜占庭模型中提供这些保证,也就是说,没有关于攻击会是什么样子或哪些节点将被攻击的先验知识。为了实现这一目标,该项目将构建实用的算法,基于防篡改日志和加密证据等技术,在有限时间内(可证明地)检测攻击;使用多模式系统的思想,创建在有限时间内从检测到的攻击中恢复的方法;并产生新技术的可重复使用的实现,这些实现将在一个开放的该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(18)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
REBOUND: defending distributed systems against attacks with bounded-time recovery
DNA: Dynamic Resource Allocation for Soft Real-Time Multicore Systems
DNA:软实时多核系统的动态资源分配
Real-Time Packet-Based Intrusion Detection on Edge Devices
边缘设备上基于数据包的实时入侵检测
Mitigating Computational Constraints via Adaptive Control and Resource Allocation Co-design.
通过自适应控制和资源分配协同设计减轻计算约束。
IGOR: Accelerating Byzantine Fault Tolerance for Real-Time Systems with Eager Execution
IGOR:通过 Eager Execution 加速实时系统的拜占庭容错
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Linh Thi Xuan Phan其他文献

A view of the sustainable computing landscape
  • DOI:
    10.1016/j.patter.2025.101296
  • 发表时间:
    2025-07-11
  • 期刊:
  • 影响因子:
    7.400
  • 作者:
    Benjamin C. Lee;David Brooks;Arthur van Benthem;Mariam Elgamal;Udit Gupta;Gage Hills;Vincent Liu;Linh Thi Xuan Phan;Benjamin Pierce;Christopher Stewart;Emma Strubell;Gu-Yeon Wei;Adam Wierman;Yuan Yao;Minlan Yu
  • 通讯作者:
    Minlan Yu
A convolutional autoencoder architecture for robust network intrusion detection in embedded systems
  • DOI:
    10.1016/j.sysarc.2024.103283
  • 发表时间:
    2024-11-01
  • 期刊:
  • 影响因子:
  • 作者:
    Niccolò Borgioli;Federico Aromolo;Linh Thi Xuan Phan;Giorgio Buttazzo
  • 通讯作者:
    Giorgio Buttazzo

Linh Thi Xuan Phan的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Linh Thi Xuan Phan', 18)}}的其他基金

NeTS: Medium: Collaborative Research: Diagnosing Datacenter Networks with Quantitative Provenance
NeTS:媒介:协作研究:通过定量来源诊断数据中心网络
  • 批准号:
    1703936
  • 财政年份:
    2017
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Continuing Grant
NeTS: CSR: Medium: Network Functions Virtualization With Timing Guarantees
NeTS:CSR:媒介:具有时序保证的网络功能虚拟化
  • 批准号:
    1563873
  • 财政年份:
    2016
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Continuing Grant
CSR: Small: Resource Management for Real-time Cloud Computing
CSR:小型:实时云计算的资源管理
  • 批准号:
    1117185
  • 财政年份:
    2011
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Standard Grant

相似海外基金

INSPIRE- Intersectional Spaces of Participation: Inclusive, Resilient, Embedded
INSPIRE-交叉参与空间:包容性、弹性、嵌入式
  • 批准号:
    10106857
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    EU-Funded
Wildfire Resilient Cultural Heritage
野火复原力文化遗产
  • 批准号:
    AH/Z00005X/1
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Research Grant
Building Desirable and Resilient Public Media Futures: Establishing the Centre for Public Values, Technology & Society
建设理想且有弹性的公共媒体未来:建立公共价值观和技术中心
  • 批准号:
    MR/X033651/1
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Fellowship
Resilient and Equitable Nature-based Pathways in Southern African Rangelands (REPAiR)
南部非洲牧场弹性且公平的基于自然的途径 (REPAiR)
  • 批准号:
    NE/Z503459/1
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Research Grant
NSF Engines Development Award: Creating climate-resilient opportunities for plant systems (NC)
NSF 发动机开发奖:为工厂系统创造气候适应机会 (NC)
  • 批准号:
    2315399
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Cooperative Agreement
CAREER: Resilient and Efficient Automatic Control in Energy Infrastructure: An Expert-Guided Policy Optimization Framework
职业:能源基础设施中的弹性和高效自动控制:专家指导的政策优化框架
  • 批准号:
    2338559
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Standard Grant
REU Site: Ecology and Management for Resilient and Adapted Forests
REU 网站:弹性和适应性森林的生态和管理
  • 批准号:
    2348895
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Continuing Grant
Development of an entirely Lagrangian hydro-elastoviscoplastic FSI solver for design of resilient ocean/coastal structures
开发完全拉格朗日水弹粘塑性 FSI 求解器,用于弹性海洋/沿海结构的设计
  • 批准号:
    24K07680
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
Are family firms in Japan resilient to economic shock? Digging further by family types, management strategies, and earnings quality.
日本的家族企业能否抵御经济冲击?
  • 批准号:
    24K00297
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 47.54万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了