EDU: Collaborative: Using Virtual Machine Introspection for Deep Cyber Security Education
EDU: Collaborative: Using Virtual Machine Introspection for Deep Cyber Security Education
批准号:
1844136
负责人:
Irfan Ahmed
金额:
$13.98万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-06-15 至 2020-08-31
中文摘要
网络安全是计算机科学中最具战略意义的领域之一,也是最难有效教学的学科之一。从历史上看,动手网络安全练习帮助学生加强基本概念,但大多数都集中在用户层面的攻击和防御。由于操作系统内核为应用程序提供了基础,因此对操作系统内核的任何妥协都将导致完全不可信的计算。因此,对学生进行内核级攻击与防御的实践教学势在必行。在过去的十年中,人们对使用虚拟化来分析、描述和观察内核事件(包括安全事件)产生了浓厚的兴趣。受虚拟机自省(VMI)巨大成功的启发,该项目旨在通过在虚拟化之上直接构建实用的VMI工具和库(或工具包),并将其应用于深度网络安全教育,从而提供一种进步。深度来自于对底层系统内部的研究,如操作系统内核。该项目将进一步提供一些种子内容,教授教师和学生如何利用该工具包,不仅用于研究传统的用户级攻击(如缓冲区溢出),还用于研究操作系统内核内部的防御。该项目的成果(即,工具包和网络安全演习)将有助于提高网络安全教育的先进水平,特别是有效执行实际操作的网络安全演习,从而为我们社会的健康、安全和经济福祉做出贡献。
英文摘要
Cybersecurity is one of the most strategically important areas in computer science, and also one of the most difficult disciplines to teach effectively. Historically, hands-on cyber security exercises helped students reinforce basic concepts, but most of them focused on user level attacks and defenses. Since OS kernels provide the foundations to the applications, any compromise to OS kernels will lead to an entirely untrusted computing. Therefore, it is imperative to teach students the practice of kernel level attacks and defenses.Over the past decade, there has been great interest in using virtualization to profile, characterize, and observe kernel events including the security incidents. Inspired by the great success from virtual machine introspection (VMI), this project aims to provide an advancement by directly building practical VMI tools and libraries (or toolkit) on top of virtualization, and applying them for deep cybersecurity education. The deepness comes from the study of the lower level system internals such as OS kernels. The project will further provide a number of seed contents to teach both instructors and students on utilizing the toolkit to be used for studying not only traditional user level attacks such as buffer overflow, but also defenses inside the OS kernels. The outcome of this project (i.e., the toolkit and the cybersecurity exercises) will contribute to the health, safety, and economic well-being of our society by helping to improve the state-of-the-art in cybersecurity education, especially for effectively performing hands-on cybersecurity exercises.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Travel: NSF Student Travel Grant for 2024 Digital Forensics Research Conference (DFRWS)
-
批准号:2409934
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2024
-
负责人:Irfan Ahmed
-
依托单位:
CyberTraining: Implementation: Small: Using Problem-Based Learning for Vocational Training in Cyberinfrastructure Security at Community Colleges
-
批准号:2017337
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2020
-
负责人:Irfan Ahmed
-
依托单位:
SaTC-EDU: EAGER: Peer Instruction for Cybersecurity Education
-
批准号:1901733
-
项目类别:Standard Grant
-
资助金额:$4.38万
-
财政年份:2018
-
负责人:Irfan Ahmed
-
依托单位:
EDU: Collaborative: Using Virtual Machine Introspection for Deep Cyber Security Education
-
批准号:1623276
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2016
-
负责人:Irfan Ahmed
-
依托单位:
SaTC-EDU: EAGER: Peer Instruction for Cybersecurity Education
-
批准号:1500101
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2015
-
负责人:Irfan Ahmed
-
依托单位:
EAGER: Integrating Cognitive and Computer Science to Improve Cyber Security: Selective Attention and Personality Traits for the Detection and Prevention of Risk
-
批准号:1358723
-
项目类别:Standard Grant
-
资助金额:$22.3万
-
财政年份:2014
-
负责人:Irfan Ahmed
-
依托单位:
海外基金