课题基金 / 基金详情

EAGER: Collaborative: Towards Understanding the Attack Vector of Privacy Technologies

EAGER: Collaborative: Towards Understanding the Attack Vector of Privacy Technologies
EAGER:协作:了解隐私技术的攻击向量
批准号:
1809000
负责人:
David Mohaisen
金额:
$10.22万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-11-10 至 2019-08-31

项目摘要

项目成果

David Mohaisen的其他基金

相似基金

相关文献

中文摘要
翻译
隐私增强技术的进步,包括加密机制、标准化安全协议和基础设施,显著改善了隐私,并通过保护用户对社会产生了重大影响。与此同时,这种基础设施的成功吸引了包括复杂的僵尸网络和勒索软件在内的非法活动的滥用,并已成为毒品和违禁品的市场;僵尸网络上升为网络犯罪的主要工具,其开发者被证明是高度足智多谋的。有人认为,下一波僵尸网络将广泛试图颠覆隐私基础设施和加密机制,这可能会破坏它们的法律基础和未来的性能。该项目将为分析、监测和缓解颠覆隐私增强技术的下一代僵尸网络奠定理论和实验基础。为了实现这一目标,该项目将为以下方面开发工具:1)分析框架:该项目制定了一项具体战略,通过明确关于此类僵尸网络的推理的分析框架,来接近检测、表征和减轻滥用隐私基础设施的问题。这包括其关键属性的识别和正规化(例如,回溯和断层扫描弹性、隐蔽货币化)、启用机制(例如,IP地址分离、控制/数据流量不可区分)、基本限制和评估指标。该项目将探索未来互联网架构中类似的滥用场景,在这些架构中,匿名性通过设计来促进。2)监测和分析:该项目开发了一个实验框架,以跟踪下一代僵尸网络的活动,以实现可扩展和有效的缓解。这样的框架将利用它们的理想设计和行为特性,并借鉴相关上下文中的各种初步测量结果。3)缓解:该项目的最终目标是主动开发基于坚实的理论基础、在理论框架内进行分析并在实验框架内进行评估的各种缓解技术。缓解技术的范围从增加运营此类僵尸网络的成本,到积极遏制和中和僵尸程序,再到提出对隐私增强协议的修改。该项目的结果将与有关社区进行沟通,以便对现有和未来的隐私基础设施产生直接和即时的影响。该项目还将开发教育材料,培训学生使用增强隐私技术的基础和系统。
英文摘要
Advances in privacy-enhancing technologies, including cryptographic mechanisms, standardized security protocols, and infrastructure, significantly improved privacy and had a significant impact on society by protecting users. At the same time, the success of such infrastructure has attracted abuse from illegal activities, including sophisticated botnets and ransomware, and has become a marketplace for drugs and contraband; botnets rose to be a major tool for cybercrime and their developers proved to be highly resourceful. It is contended that the next waves of botnets will extensively attempt to subvert privacy infrastructure and cryptographic mechanisms, which has the potential of both undermining their legal basis and future performance. This project will develop the theoretical and experimental foundations for analyzing, monitoring and mitigating the next generation of botnets that subvert privacy-enhancing technologies. Towards that goal, the project will develop tools for: 1) Analytical framework: the project develops a concrete strategy for approaching the detection, characterization, and mitigation of abuse of privacy infrastructure by crystallizing an analytical framework for reasoning about such botnets. This includes the identification
and formalization of their key properties (e.g., traceback and tomography resiliency, stealthy monetization), enabling mechanisms (e.g., IP address de-coupling, control/data traffic indistinguishability), fundamental limitations, and evaluation metrics. The project will explore analogous scenarios of abuse in future Internet architectures where anonymity is facilitated by design. 2) Monitoring and analysis: the project develops an experimental framework to track activities of the next generation of botnets for scalable and effective mitigation. Such framework will exploit their ideal design and behavioral properties, and draws on various preliminary measurement results in related contexts. 3) Mitigation: The project has the ultimate
goal of proactively developing an arsenal of mitigation techniques grounded in a sound theoretical foundation, analyzed within the theoretical framework, and evaluated within the experimental framework. The mitigation techniques span the gamut of increasing the cost of operating such botnets, to actively containing
and neutralizing bots, to proposing modifications to the privacy-enhancing protocols. The results of this project will be communicated with the concerned communities for having a direct and immediate impact on existing and future privacy infrastructure. The project will also develop educational material to train students in the foundations and systems for enabling privacy enhancing technologies.
期刊论文(12)
专著(0)
科研奖励(0)
会议论文
Digitalseal: a Transaction Authentication Tool for Online and Offline Transactions
Digitalseal:线上线下交易的交易认证工具
DOI: 10.1109/icassp.2018.8462341
发表时间: 2018
期刊: Speech and Signal Processing (ICASSP
影响因子: --
作者: [Jung, Changhun, Kang, Jeonil, Mohaisen, Aziz, Nyang, DaeHun]
通讯作者: Nyang, DaeHun
DOI: 10.1109/dsn.2019.00057
发表时间: 2019-06
期刊: 2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子: --
作者: [Jeman Park;Aminollah Khormali;Manar Mohaisen;Aziz Mohaisen]
通讯作者: Jeman Park;Aminollah Khormali;Manar Mohaisen;Aziz Mohaisen
DOI: --
发表时间: 2018
期刊: International Conference on Security and Privacy in Communication Systems
影响因子: --
作者: [Anwar, Afsah, Khormali, Aminollah, Nyang, DaeHun, Mohaisen, Aziz]
通讯作者: Mohaisen, Aziz
DOI: 10.1109/tnet.2018.2874896
发表时间: 2018-12-01
期刊: IEEE-ACM TRANSACTIONS ON NETWORKING
影响因子: 3.7
作者: [Wang, An, Chang, Wentao, Mohaisen, Aziz]
通讯作者: Mohaisen, Aziz
10
    NSF Student Travel Grant for 2021 ACM CCS
    SaTC: Student Travel Support for IEEE CNS 2016
    • 批准号:
      1606354
    • 项目类别:
      Standard Grant
    • 资助金额:
      $1.0万
    • 财政年份:
      2016
    • 负责人:
      David Mohaisen
    • 依托单位:
    EAGER: Collaborative: Towards Understanding the Attack Vector of Privacy Technologies
    • 批准号:
      1643207
    • 项目类别:
      Standard Grant
    • 资助金额:
      $12.5万
    • 财政年份:
      2016
    • 负责人:
      David Mohaisen
    • 依托单位:
    海外基金