CCRI: Medium: DNS, Identity, and Internet Naming for Experimentation and Research (DIINER)
CCRI: Medium: DNS, Identity, and Internet Naming for Experimentation and Research (DIINER)
批准号:
1925737
负责人:
John Heidemann
金额:
$145.84万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2024-09-30
中文摘要
互联网中的命名和识别对于查找网站(例如www.nsf.gov)和其他服务至关重要。域名系统(DNS)、身份和互联网命名实验和研究(DIINER)项目建议通过提供研究基础设施、数据和社区建设来加快互联网命名、身份识别和域名系统的研究。该项目将提供(1)试验台和工具,以允许对域名系统数据进行实验,并支持新方法从研究逐步过渡到实验使用,并最终过渡到操作。(2)该项目将在注重隐私的匿名化和受控数据共享框架的背景下,提供有关如何使用域名系统以及域名系统和服务器的运行情况的数据。DIINER项目还将致力于(3)通过加强学术界的创造力和观点与关键基础设施的知识和现实世界问题以及运行数据之间的反馈循环,举办关于这些主题以及关于这些工具和新研究方法的研讨会,促进合作研究社区。DIINER项目建立在南加州大学(USC)信息科学研究所(ISI)运行B-Root等可操作的域名服务以及与研究社区合作共享数据和提供研究基础设施的经验基础上。Diiner的预期成果是在如何开展互联网命名、身份和域名系统的研究方面取得科学进展;改进目前互联网命名、身份和域名系统的性能、可靠性、安全性和私密性;支持南加州大学和社区的教育和研究。互联网的域名系统最常见的是将名称映射到地址(例如www.nsf.gov到128.150.4.107),它的使用已经增长到包括反垃圾邮件和内容分发网络等应用程序。使用DNSSEC(域名系统安全扩展),DNS可保护数据完整性,并可使信任系统、X.509通信和证书颁发机构接地。但互联网命名、识别和域名系统面临许多挑战。随着互联网从一个低风险的学术实验转变为一个价值万亿美元的市场,安全已经发生了变化,带来了来自有组织犯罪和民族国家的威胁。从数以百万计的家庭路由器到复杂的商业集群,DNS也积累了巨大的惯性,拥有庞大的、不会发生变化的安装基础。它被认定为“关键基础设施”增加了技术和政治上的惰性。这些要求加剧了技术挑战,如最大限度地减少延迟,往往使研究界远离运营现实,缺乏做出可信贡献所需的数据和基础设施。Diiner项目建议通过在互联网命名和信任方面进行新的研究,并在保持稳定性的同时简化从研究到运营部署的过渡,来应对这些挑战和扭转域名僵化。它的目标是通过围绕DIINER发展一个互联网命名和识别社区来团结孤立的研究人员,DIINER是一个新的共享研究基础设施,提供:(1)并行DNS解析评估(PRE),以支持实时、真实世界部署的DNS内的实验的安全测试,以及(2)实时工具和测量,以共享真实世界的DNS查询和性能数据,并由技术和法律方法支持。今天,研究人员的支持不足,可用的域名系统数据有限,通常是在收集很长时间之后,共享能力有限,而且不存在对真实世界规模实验的支持。南加州大学ISI为领导这项工作做好了独一无二的准备,负责B-Root DNS服务器的运营,长期参与网络研究和研究生教育,并独立于商业利益。DIINER方法跨越了从终端计算机(存根解析器)到组织级递归解析器,再到权威的DNS服务器的整个DNS生态系统。拟议的基础设施将与B-Root、二级域权威解析器以及递归解析器集成。利益相关者包括终端用户、互联网服务提供商(ISP)和其他类型的服务提供商,从公共域名服务运营商到商业域名服务提供商。Diiner项目将发布其开发的开源工具,通过第三方部署增强研究基础设施即服务。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Naming and identification in the Internet is essential to find websites (e.g. www.nsf.gov) and other services. The Domain Name System (DNS), Identity, and Internet Naming for Experimentation and Research (DIINER) project proposes to accelerate research on Internet naming, identification, and the DNS by providing research infrastructure, data, and community building. The project will provide (1) a testbed and tools to allow experimentation on DNS data and to support gradual transition of new approaches from research into experimental use and ultimately to operation. (2) The project will provide data about how DNS is used and how the DNS system and servers perform, in the context of a framework for privacy-sensitive anonymization and controlled data sharing. The DIINER project will also work to (3) foster a collaborative research community by tightening the feedback loop between the creativity and perspectives of academia and the knowledge and real-world problems and data of operation of critical infrastructure, holding workshops about these topics and about these tools and new research methods. The DIINER project builds on the University of Southern California (USC) Information Sciences Institute (ISI) experiences both running operational DNS services such as B-Root and working with the research community to share data and provide research infrastructure. The anticipated outcome of DIINER is scientific progress on how to carry out research on Internet naming, identity, and DNS; improvements to the performance, reliability, security, and privacy of how Internet naming, identity, and DNS are done today; and support of education and research at the USC and in the community.The Internet's DNS most commonly maps names to addresses (e.g. www.nsf.gov to 128.150.4.107), and its use has grown to include applications like anti-spam and Content Delivery Networks. With DNSSEC (Domain Name System Security Extensions), DNS protects data integrity and can ground trust systems, X.509 communications and Certificate Authorities. But Internet naming, identification, and DNS face many challenges. Security has changed as the Internet has moved from a low-risk academic experiment to a trillion-dollar marketplace, bringing threats from organized crime and nation states. DNS has also gathered great inertia, with a huge, change-resistant installed base, from millions of home routers to sophisticated commercial clusters. Its identification as "critical infrastructure" adds both technical and political inertia. These requirements compound technical challenges, such as minimizing latency, and often leave the research community distant from operational reality, without the data and infrastructure they need to make credible contributions.The DIINER project proposes to meet these challenges and reverse DNS ossification by enabling new research in Internet naming and trust, and easing transition from research to operational deployment, while preserving stability. Its goal is to unite isolated researchers by growing an Internet naming and identification community around DIINER, a new shared research infrastructure providing: (1) parallel DNS resolution evaluation (PRE) to support safe testing of experiments within live, real-world deployed DNS, and (2) live instrumentation and measurement to share real-world DNS query and performance data, with responsibility supported by technical and legal methods. Today researchers are under-supported, with only limited DNS data available, often long after collection and with limited ability to share, and no support exists for real-world experiments at scale. USC ISI is uniquely prepared to lead this effort with operational responsibility for the B-Root DNS server, long-term involvement in networking research and graduate education, and independence from commercial interests. The DIINER approach spans the DNS ecosystem, from end-computers (stub resolvers), to organization-level recursive resolvers, and to authoritative DNS servers. The proposed infrastructure will integrate with B-Root, second-level-domain authoritative resolvers, and with a recursive resolver. Stakeholders include end users, Internet services providers (ISPs), and other kinds of service providers, from operators of public DNS services, to commercial DNS providers. The DIINER project will release tools it develops as open source, augmenting research-infrastructure-as-service with third-party deployments.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(5)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Old but Gold: Prospecting TCP to Engineer and Live Monitor DNS Anycast
老而黄金:勘探 TCP 来设计和实时监控 DNS 选播
DOI:
--
发表时间:
2022
期刊:
Passive and Active Measurement Conference"
影响因子:
--
作者:
[Moura, Giovane C., Heidemann, John, Hardaker, Wes, Charnsethikul, Pithayuth, Bulten, Jeroen, Ceron, João M., Hesselman, Cristian]
通讯作者:
Hesselman, Cristian
DOI:
--
发表时间:
2021
期刊:
Workshop on DNS and Internet Naming Research Directions
影响因子:
--
作者:
[Heidemann, John, Moura, Giovane C., Hardaker, Wes]
通讯作者:
Hardaker, Wes
TsuNAME: exploiting misconfiguration and vulnerability to DDoS DNS
TsuNAME:利用 DDoS DNS 的错误配置和漏洞
DOI:
10.1145/3487552.3487824
发表时间:
2021
期刊:
ACM Internet Measurements Conference
影响因子:
--
作者:
[Moura, Giovane C., Castro, Sebastian, Heidemann, John, Hardaker, Wes]
通讯作者:
Hardaker, Wes
Anycast Agility: Network Playbooks to Fight DDoS
Anycast Agility:对抗 DDoS 的网络手册
DOI:
--
发表时间:
2022
期刊:
31st USENIX Security Symposium
影响因子:
--
作者:
[Rizvi, A S, Bertholdo, Leandro, Ceron, João, Heidemann, John]
通讯作者:
Heidemann, John
Institutional privacy risks in sharing DNS data
共享 DNS 数据的机构隐私风险
DOI:
10.1145/3472305.3472324
发表时间:
2021
期刊:
Proceedings of the Applied Networking Research Workshop (ANRW
影响因子:
--
作者:
[Imana, Basileal, Korolova, Aleksandra, Heidemann, John]
通讯作者:
Heidemann, John
Collaborative Research: IMR:MM-1B: Privacy in Internet Measurements Applied To WAN and Telematics
-
批准号:2319409
-
项目类别:Continuing Grant
-
资助金额:$26.91万
-
财政年份:2023
-
负责人:John Heidemann
-
依托单位:
IMR: RI-P: Safe And Flexible Experimental Dataset Access and Sharing-Planning (SAFED-ASP)
-
批准号:2224467
-
项目类别:Standard Grant
-
资助金额:$9.91万
-
财政年份:2022
-
负责人:John Heidemann
-
依托单位:
Collaborative Research: CNS Core: Medium: A Traffic Map for the Internet
-
批准号:2212480
-
项目类别:Continuing Grant
-
资助金额:$39.8万
-
财政年份:2022
-
负责人:John Heidemann
-
依托单位:
RAPID: Measuring the Internet during Novel Coronavirus to Evaluate Quarantine (RAPID-MINSEQ)
-
批准号:2028279
-
项目类别:Standard Grant
-
资助金额:$9.9万
-
财政年份:2020
-
负责人:John Heidemann
-
依托单位:
CNS Core: Small: Event Identification in Evaluation of Internet Outages
-
批准号:2007106
-
项目类别:Standard Grant
-
资助金额:$48.33万
-
财政年份:2020
-
负责人:John Heidemann
-
依托单位:
RAPID: Interactive Internet Outages Visualization to Assess Disaster Recovery
-
批准号:1806785
-
项目类别:Standard Grant
-
资助金额:$19.89万
-
财政年份:2018
-
负责人:John Heidemann
-
依托单位:
CICI: RSARC: DDoS Defense In Depth for DNS
-
批准号:1739034
-
项目类别:Standard Grant
-
资助金额:$99.72万
-
财政年份:2017
-
负责人:John Heidemann
-
依托单位:
CI-P: Planning for Identity and Naming Experimentation Shared Testbed
-
批准号:1513213
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2015
-
负责人:John Heidemann
-
依托单位:
MRI: Development of an Always-Available Testbed for Underwater Networking Research
-
批准号:0821750
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2008
-
负责人:John Heidemann
-
依托单位:
NeTS-NBD-SGER: Map/Reduce for Network Traffic Analysis (MR-Net Sger)
-
批准号:0823774
-
项目类别:Standard Grant
-
资助金额:$10.02万
-
财政年份:2008
-
负责人:John Heidemann
-
依托单位:
CRI: CRD: Collaborative Research: Open Research Testbed for Underwater Ad Hoc and Sensor Networks
-
批准号:0708946
-
项目类别:Continuing Grant
-
资助金额:$15.0万
-
财政年份:2007
-
负责人:John Heidemann
-
依托单位:
NeTS-FIND: Sensor-Internet Sharing and Search
-
批准号:0626702
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:John Heidemann
-
依托单位:
NeTs-NBD: Maltraffic Analysis and Detection in Challenging and Aggregate Traffic (MADCAT)
-
批准号:0626696
-
项目类别:Standard Grant
-
资助金额:$89.65万
-
财政年份:2006
-
负责人:John Heidemann
-
依托单位:
NeTS-NOSS: Sensor Networks for Undersea Seismic Experimentation (SNUSE)
-
批准号:0435517
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:John Heidemann
-
依托单位:
ITR: MAC Protocols Specific for Sensor Networks (MACSS)
-
批准号:0220026
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2002
-
负责人:John Heidemann
-
依托单位:
Collaborative Simulation for Education and Research
-
批准号:9986208
-
项目类别:Continuing Grant
-
资助金额:$150.51万
-
财政年份:2000
-
负责人:John Heidemann
-
依托单位:
海外基金