CRII: SaTC: Secure and Comprehensive Forensic Audit Infrastructure for Transparent Heterogeneous Computing
CRII:SaTC:用于透明异构计算的安全且全面的取证审计基础设施
基本信息
- 批准号:1850392
- 负责人:
- 金额:$ 17.44万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2019
- 资助国家:美国
- 起止时间:2019-03-01 至 2022-02-28
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Cyber attackers are increasingly targeting emerging smart devices (e.g., Internet of Things devices) causing devastating damages to various enterprises and government agencies. To combat these attacks, rapid and effective investigation is critical to understand attack paths and measure the damages. Unfortunately, forensic logging infrastructures are not efficient and effective enough. Many devices completely lack forensic logging systems and others rely on ineffective logging schemes, delaying or often completely preventing forensic investigation. This research aims to combat advanced cyber-attacks such as Advanced Persistent Threats (APTs) that actively leverage emerging devices. It would design and develop fundamental security primitives that improve state-of-the-art forensic logging in terms of accuracy, efficiency, effectiveness, reliability, and applicability. This research directly contributes to national security by advancing research in and developing techniques for the forensic investigation of advanced cyber-attacks exploiting emerging devices which have recently become a new major attack vector. The investigator is committed to the open and timely dissemination of the outcomes of the proposed research in order to encourage future research in this area. Also, the research will be integrated into new curriculum materials that the investigator will develop, including dedicated lab sessions on Internet of Things forensic analysis and associated APT investigation.This research aims to design and develop fundamental security primitives for forensic logging: (1) Improving the current ineffective forensic logging systems that generate confusing forensic logs which hinder the forensic investigation significantly. (2) Reducing the space overhead of forensic logging systems to increase its applicability. (3) Enabling forensic analysis on unmodifiable devices (e.g., proprietary devices) that cannot be modified and instrumented via a novel forensic causality inference technique. This research provides the following unique set of capabilities that were not previously possible. First is the design and implementation of a novel event-execution path encoding scheme that can precisely capture event execution context information. This will allow forensic analysts to disambiguate confusing event logs. Second is a technique for instrumentation-free forensic analysis via causality inference. Devices that do not allow any modification and instrumentation will be traced and analyzed via other devices that are connected to them leveraging a novel causality inference technique.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
网络攻击者越来越多地将目标对准新兴的智能设备(例如物联网设备),给各种企业和政府机构造成毁灭性的破坏。为了打击这些攻击,快速有效的调查对于了解攻击路径和测量危害至关重要。不幸的是,法医记录基础设施的效率和效力不够高。许多设备完全缺乏法医记录系统,其他设备依赖于无效的记录方案,推迟或经常完全阻止法医调查。这项研究旨在打击积极利用新兴设备的高级持续威胁(APT)等高级网络攻击。它将设计和开发基本的安全原语,在准确性、效率、有效性、可靠性和适用性方面改进最先进的法医记录。这项研究通过推进对利用新兴设备的高级网络攻击的法医调查技术的研究和开发,直接有助于国家安全,这些设备最近已成为新的主要攻击媒介。调查员致力于公开和及时地传播拟议研究的结果,以鼓励今后在这一领域进行研究。此外,这项研究还将被整合到调查者将开发的新课程中,包括物联网取证分析和相关APT调查的专门实验室会议。本研究旨在设计和开发法医日志记录的基本安全原语:(1)改进当前低效的法医日志记录系统,这些系统产生混乱的法医日志,严重阻碍法医调查。(2)减少取证录井系统的空间开销,增加其适用性。(3)允许对不可修改的设备(例如,专有设备)进行法医分析,这些设备不能通过新的法医因果关系推断技术进行修改和检测。这项研究提供了以下一组独特的功能,这是以前无法实现的。首先,设计并实现了一种新颖的事件执行路径编码方案,该方案能够准确地捕获事件执行上下文信息。这将使法医分析师能够消除令人困惑的事件日志。第二种是一种通过因果关系推断进行无需仪器的法医分析的技术。不允许任何修改和仪器的设备将通过利用新的因果推理技术连接到它们的其他设备进行跟踪和分析。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(13)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware Analysis
MalMax:自动动态 Web 服务器恶意软件分析的多方面执行
- DOI:10.1145/3319535.3363199
- 发表时间:2019
- 期刊:
- 影响因子:0
- 作者:Naderi-Afooshteh, Abbas;Kwon, Yonghwi;Nguyen-Tuong, Anh;Razmjoo-Qalaei, Ali;Zamiri-Gourabi, Mohammad-Reza;Davidson, Jack W.
- 通讯作者:Davidson, Jack W.
Security Analysis on Practices of Certificate Authorities in the HTTPS Phishing Ecosystem
HTTPS钓鱼生态系统中证书颁发机构的做法安全分析
- DOI:10.1145/3433210.3453100
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Kim, Doowon;Cho, Haehyun;Kwon, Yonghwi;Doupé, Adam;Son, Sooel;Ahn, Gail-Joon;Dumitras, Tudor
- 通讯作者:Dumitras, Tudor
Probabilistic Disassembly
- DOI:10.1109/icse.2019.00121
- 发表时间:2019-05
- 期刊:
- 影响因子:0
- 作者:Kenneth A. Miller;Yonghwi Kwon;Yi Sun;Zhuo Zhang;X. Zhang;Zhiqiang Lin
- 通讯作者:Kenneth A. Miller;Yonghwi Kwon;Yi Sun;Zhuo Zhang;X. Zhang;Zhiqiang Lin
SWARMFLAWFINDER: Discovering and Exploiting Logic Flaws of Swarm Algorithms
- DOI:10.1109/sp46214.2022.9833685
- 发表时间:2022-05
- 期刊:
- 影响因子:0
- 作者:Chi-Gon Jung;A. Ahad;Yuseok Jeon;Yonghwi Kwon
- 通讯作者:Chi-Gon Jung;A. Ahad;Yuseok Jeon;Yonghwi Kwon
PMP: Cost-effective Forced Execution with Probabilistic Memory Pre-planning
- DOI:10.1109/sp40000.2020.00035
- 发表时间:2020-05
- 期刊:
- 影响因子:0
- 作者:Wei You;Zhuo Zhang;Yonghwi Kwon;Yousra Aafer;Fei Peng;Yu Shi;C. Harmon;X. Zhang
- 通讯作者:Wei You;Zhuo Zhang;Yonghwi Kwon;Yousra Aafer;Fei Peng;Yu Shi;C. Harmon;X. Zhang
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Yonghwi Kwon其他文献
AdBudgetKiller: Online Advertising Budget Draining Attack
AdBudgetKiller:在线广告预算耗尽攻击
- DOI:
10.1145/3178876.3186096 - 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
I. L. Kim;Weihang Wang;Yonghwi Kwon;Yunhui Zheng;Yousra Aafer;Weijie Meng;X. Zhang - 通讯作者:
X. Zhang
PIEtrace: Platform independent executable trace
PIEtrace:平台独立的可执行跟踪
- DOI:
10.1109/ase.2013.6693065 - 发表时间:
2013 - 期刊:
- 影响因子:0
- 作者:
Yonghwi Kwon;X. Zhang;Dongyan Xu - 通讯作者:
Dongyan Xu
Understanding automated code review process and developer experience in industry
了解自动化代码审查流程和行业开发人员经验
- DOI:
- 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Hyungjin Kim;Yonghwi Kwon;Sangwoo Joh;Hyukin Kwon;Yeonhee Ryou;Taeksu Kim - 通讯作者:
Taeksu Kim
J-Force: Forced Execution on JavaScript
J-Force:强制执行 JavaScript
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Kyungtae Kim;I. L. Kim;C. Kim;Yonghwi Kwon;Yunhui Zheng;X. Zhang;Dongyan Xu - 通讯作者:
Dongyan Xu
Fast Prediction of Dynamic IR-Drop Using Recurrent U-Net Architecture
使用循环 U-Net 架构快速预测动态 IR 压降
- DOI:
10.1145/3551901.3556477 - 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Yonghwi Kwon;Youngsoo Shin - 通讯作者:
Youngsoo Shin
Yonghwi Kwon的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Yonghwi Kwon', 18)}}的其他基金
SaTC: CORE: Medium: Collaborative: Doctor WHO: Investigation and Prevention of Online Content Management System Abuse
SaTC:核心:媒介:协作:WHO 医生:在线内容管理系统滥用的调查和预防
- 批准号:
2426653 - 财政年份:2023
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CAREER: Automated Forensic-in-the-Loop Cyber Defense Infrastructure
职业:自动化环路取证网络防御基础设施
- 批准号:
2145616 - 财政年份:2022
- 资助金额:
$ 17.44万 - 项目类别:
Continuing Grant
OAC Core: Small: Collaborative Research: Data Provenance Infrastructure towards Robust andReliable Data Sharing and Analytics
OAC 核心:小型:协作研究:数据来源基础设施实现稳健可靠的数据共享和分析
- 批准号:
1908021 - 财政年份:2019
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
SaTC: CORE: Medium: Collaborative: Doctor WHO: Investigation and Prevention of Online Content Management System Abuse
SaTC:核心:媒介:协作:WHO 医生:在线内容管理系统滥用的调查和预防
- 批准号:
1916499 - 财政年份:2019
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
相似海外基金
CRII: SaTC: Towards a Secure and Efficient Ethereum P2P Network with Client Diversity
CRII:SaTC:迈向具有客户端多样性的安全高效的以太坊 P2P 网络
- 批准号:
2347486 - 财政年份:2024
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CRII: SaTC: Toward Secure, Privacy-Preserving, and Efficient Crowdsourcing Systems
CRII:SaTC:迈向安全、隐私保护和高效的众包系统
- 批准号:
2246143 - 财政年份:2023
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CRII: SaTC: Enabling Secure Machine Learning Queries over Encrypted Database in Cloud Computing
CRII:SaTC:在云计算中的加密数据库上启用安全机器学习查询
- 批准号:
2153393 - 财政年份:2022
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Secure and Privacy-preserving Input on Augmented Reality Systems
CRII:SaTC:增强现实系统的安全和隐私保护输入
- 批准号:
2153397 - 财政年份:2022
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Secure Wide-area Localization
CRII:SaTC:迈向安全的广域本地化
- 批准号:
1850264 - 财政年份:2019
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CRII: SaTC: Secure Branch Predictors for High Performance Processors
CRII:SaTC:高性能处理器的安全分支预测器
- 批准号:
1850365 - 财政年份:2019
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CRII: SaTC: Secure Instruction Set Extensions for Lattice-Based Post-Quantum Cryptosystems
CRII:SaTC:基于格的后量子密码系统的安全指令集扩展
- 批准号:
1850373 - 财政年份:2019
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CRII: SaTC: Mitigating Software-Based Microarchitectural Attacks via Secure Microcode Customization
CRII:SaTC:通过安全微代码定制缓解基于软件的微架构攻击
- 批准号:
1850436 - 财政年份:2019
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CRII: SaTC: Towards the Development of Stronger Memory-Hard Functions for Secure Password Hashing
CRII:SaTC:致力于开发更强的内存硬函数以实现安全密码散列
- 批准号:
1755708 - 财政年份:2018
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant
CRII: SaTC: Transparent Capture and Aggregation of Secure Data Provenance for Smart Devices
CRII:SaTC:智能设备安全数据来源的透明捕获和聚合
- 批准号:
1657534 - 财政年份:2017
- 资助金额:
$ 17.44万 - 项目类别:
Standard Grant