CCRI: Medium: DNS, Identity, and Internet Naming for Experimentation and Research (DIINER)
CCRI:媒介:用于实验和研究的 DNS、身份和互联网命名 (DINER)
基本信息
- 批准号:1925737
- 负责人:
- 金额:$ 145.84万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2019
- 资助国家:美国
- 起止时间:2019-10-01 至 2024-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Naming and identification in the Internet is essential to find websites (e.g. www.nsf.gov) and other services. The Domain Name System (DNS), Identity, and Internet Naming for Experimentation and Research (DIINER) project proposes to accelerate research on Internet naming, identification, and the DNS by providing research infrastructure, data, and community building. The project will provide (1) a testbed and tools to allow experimentation on DNS data and to support gradual transition of new approaches from research into experimental use and ultimately to operation. (2) The project will provide data about how DNS is used and how the DNS system and servers perform, in the context of a framework for privacy-sensitive anonymization and controlled data sharing. The DIINER project will also work to (3) foster a collaborative research community by tightening the feedback loop between the creativity and perspectives of academia and the knowledge and real-world problems and data of operation of critical infrastructure, holding workshops about these topics and about these tools and new research methods. The DIINER project builds on the University of Southern California (USC) Information Sciences Institute (ISI) experiences both running operational DNS services such as B-Root and working with the research community to share data and provide research infrastructure. The anticipated outcome of DIINER is scientific progress on how to carry out research on Internet naming, identity, and DNS; improvements to the performance, reliability, security, and privacy of how Internet naming, identity, and DNS are done today; and support of education and research at the USC and in the community.The Internet's DNS most commonly maps names to addresses (e.g. www.nsf.gov to 128.150.4.107), and its use has grown to include applications like anti-spam and Content Delivery Networks. With DNSSEC (Domain Name System Security Extensions), DNS protects data integrity and can ground trust systems, X.509 communications and Certificate Authorities. But Internet naming, identification, and DNS face many challenges. Security has changed as the Internet has moved from a low-risk academic experiment to a trillion-dollar marketplace, bringing threats from organized crime and nation states. DNS has also gathered great inertia, with a huge, change-resistant installed base, from millions of home routers to sophisticated commercial clusters. Its identification as "critical infrastructure" adds both technical and political inertia. These requirements compound technical challenges, such as minimizing latency, and often leave the research community distant from operational reality, without the data and infrastructure they need to make credible contributions.The DIINER project proposes to meet these challenges and reverse DNS ossification by enabling new research in Internet naming and trust, and easing transition from research to operational deployment, while preserving stability. Its goal is to unite isolated researchers by growing an Internet naming and identification community around DIINER, a new shared research infrastructure providing: (1) parallel DNS resolution evaluation (PRE) to support safe testing of experiments within live, real-world deployed DNS, and (2) live instrumentation and measurement to share real-world DNS query and performance data, with responsibility supported by technical and legal methods. Today researchers are under-supported, with only limited DNS data available, often long after collection and with limited ability to share, and no support exists for real-world experiments at scale. USC ISI is uniquely prepared to lead this effort with operational responsibility for the B-Root DNS server, long-term involvement in networking research and graduate education, and independence from commercial interests. The DIINER approach spans the DNS ecosystem, from end-computers (stub resolvers), to organization-level recursive resolvers, and to authoritative DNS servers. The proposed infrastructure will integrate with B-Root, second-level-domain authoritative resolvers, and with a recursive resolver. Stakeholders include end users, Internet services providers (ISPs), and other kinds of service providers, from operators of public DNS services, to commercial DNS providers. The DIINER project will release tools it develops as open source, augmenting research-infrastructure-as-service with third-party deployments.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
互联网上的命名和识别对于查找网站(例如www.nsf.gov)和其他服务至关重要。域名系统(DNS)、身份和互联网命名实验与研究(DIINER)项目建议通过提供研究基础设施、数据和社区建设来加速互联网命名、身份和DNS的研究。该项目将提供(1)一个测试平台和工具,允许对DNS数据进行实验,并支持新方法从研究逐步过渡到实验使用并最终投入运营。(2)该项目将在隐私敏感匿名化和受控数据共享框架的背景下,提供有关如何使用DNS以及DNS系统和服务器如何执行的数据。DIINER项目还将致力于(3)通过加强学术界的创造力和观点与知识、现实世界问题和关键基础设施运行数据之间的反馈循环,举办关于这些主题、这些工具和新研究方法的研讨会,促进合作研究社区。DIINER项目建立在南加州大学(USC)信息科学研究所(ISI)运行运营DNS服务(如B-Root)以及与研究社区合作共享数据和提供研究基础设施的经验基础上。DIINER的预期成果是在如何开展互联网命名、身份和DNS研究方面取得科学进展;改进当今互联网命名、身份和DNS的性能、可靠性、安全性和隐私性;以及对南加州大学和社区教育和研究的支持。互联网的DNS最常见的是将名称映射到地址(例如www.nsf.gov到128.150.4.107),它的使用已经发展到包括反垃圾邮件和内容交付网络等应用程序。通过DNSSEC(域名系统安全扩展),DNS保护数据完整性,并可以建立信任系统、X.509通信和证书颁发机构。但是Internet命名、识别和DNS面临许多挑战。随着互联网从一个低风险的学术实验变成一个价值数万亿美元的市场,安全已经发生了变化,带来了有组织犯罪和民族国家的威胁。DNS也积累了巨大的惯性,从数以百万计的家庭路由器到复杂的商业集群,它的安装基础庞大且不受变化的影响。将其定义为“关键基础设施”增加了技术和政治上的惰性。这些需求加剧了技术挑战,例如最小化延迟,并且经常使研究界远离实际操作,没有他们需要的数据和基础设施来做出可信的贡献。DIINER项目建议通过启用互联网命名和信任方面的新研究,以及在保持稳定性的同时简化从研究到运营部署的过渡,来应对这些挑战并逆转DNS僵化。DIINER是一种新的共享研究基础设施,它提供:(1)并行DNS解析评估(PRE),以支持在真实世界部署的实时DNS中进行实验的安全测试;(2)实时仪器和测量,以共享真实世界的DNS查询和性能数据,并提供技术和法律方法的支持。今天的研究人员缺乏支持,只有有限的DNS数据可用,通常在收集后很长时间,共享能力有限,并且没有大规模的现实世界实验支持。USC ISI是唯一准备领导这项工作的B-Root DNS服务器的运营责任,长期参与网络研究和研究生教育,并独立于商业利益。DIINER方法横跨DNS生态系统,从终端计算机(存根解析器)到组织级递归解析器,再到权威DNS服务器。提议的基础设施将与B-Root、二级域权威解析器和递归解析器集成。利益相关者包括最终用户、互联网服务提供商(isp)和其他类型的服务提供商,从公共DNS服务运营商到商业DNS提供商。DIINER项目将发布其开发的开源工具,通过第三方部署增强研究基础设施即服务。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(5)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Old but Gold: Prospecting TCP to Engineer and Live Monitor DNS Anycast
老而黄金:勘探 TCP 来设计和实时监控 DNS 选播
- DOI:
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Moura, Giovane C.;Heidemann, John;Hardaker, Wes;Charnsethikul, Pithayuth;Bulten, Jeroen;Ceron, João M.;Hesselman, Cristian
- 通讯作者:Hesselman, Cristian
Do You Really Like Me? Anycast Latency and Root DNS Popularity
你真的喜欢我吗?
- DOI:
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Heidemann, John;Moura, Giovane C.;Hardaker, Wes
- 通讯作者:Hardaker, Wes
TsuNAME: exploiting misconfiguration and vulnerability to DDoS DNS
TsuNAME:利用 DDoS DNS 的错误配置和漏洞
- DOI:10.1145/3487552.3487824
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Moura, Giovane C.;Castro, Sebastian;Heidemann, John;Hardaker, Wes
- 通讯作者:Hardaker, Wes
Anycast Agility: Network Playbooks to Fight DDoS
Anycast Agility:对抗 DDoS 的网络手册
- DOI:
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Rizvi, A S;Bertholdo, Leandro;Ceron, João;Heidemann, John
- 通讯作者:Heidemann, John
Institutional privacy risks in sharing DNS data
共享 DNS 数据的机构隐私风险
- DOI:10.1145/3472305.3472324
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Imana, Basileal;Korolova, Aleksandra;Heidemann, John
- 通讯作者:Heidemann, John
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
John Heidemann其他文献
Auditing for Racial Discrimination in the Delivery of Education Ads
教育广告投放中的种族歧视审核
- DOI:
10.1145/3630106.3659041 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Basileal Imana;A. Korolova;John Heidemann - 通讯作者:
John Heidemann
Detecting Malicious Activities with DNS Backscatter
使用 DNS 反向散射检测恶意活动
- DOI:
10.1145/2815675.2815706 - 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Kensuke Fukuda;John Heidemann - 通讯作者:
John Heidemann
Deep Dive into NTP Pool's Popularity and Mapping
深入探讨 NTP 池的流行度和映射
- DOI:
10.1145/3639041 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
G. Moura;Marco Davids;C. Schutijser;Cristian Hesselman;John Heidemann;Georgios Smaragdakis - 通讯作者:
Georgios Smaragdakis
Anycast Polarization in the Wild
野外任播极化
- DOI:
- 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
A. Rizvi;Tingshan Huang;R. Esrefoglu;John Heidemann - 通讯作者:
John Heidemann
Privacy protection technologies: From protecting questioner to personal data anonymization
隐私保护技术:从保护提问者到个人数据匿名化
- DOI:
10.1241/johokanri.60.710 - 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Kensuke Fukuda;John Heidemann;Abudul Qadrer;中川裕志 - 通讯作者:
中川裕志
John Heidemann的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('John Heidemann', 18)}}的其他基金
Collaborative Research: IMR:MM-1B: Privacy in Internet Measurements Applied To WAN and Telematics
合作研究:IMR:MM-1B:应用于广域网和远程信息处理的互联网测量隐私
- 批准号:
2319409 - 财政年份:2023
- 资助金额:
$ 145.84万 - 项目类别:
Continuing Grant
IMR: RI-P: Safe And Flexible Experimental Dataset Access and Sharing-Planning (SAFED-ASP)
IMR:RI-P:安全灵活的实验数据集访问和共享规划 (SAFED-ASP)
- 批准号:
2224467 - 财政年份:2022
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Medium: A Traffic Map for the Internet
合作研究:CNS 核心:媒介:互联网流量地图
- 批准号:
2212480 - 财政年份:2022
- 资助金额:
$ 145.84万 - 项目类别:
Continuing Grant
RAPID: Measuring the Internet during Novel Coronavirus to Evaluate Quarantine (RAPID-MINSEQ)
RAPID:测量新型冠状病毒期间的互联网以评估隔离情况 (RAPID-MINSEQ)
- 批准号:
2028279 - 财政年份:2020
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
CNS Core: Small: Event Identification in Evaluation of Internet Outages
CNS 核心:小型:互联网中断评估中的事件识别
- 批准号:
2007106 - 财政年份:2020
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
RAPID: Interactive Internet Outages Visualization to Assess Disaster Recovery
RAPID:用于评估灾难恢复的交互式互联网中断可视化
- 批准号:
1806785 - 财政年份:2018
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
CICI: RSARC: DDoS Defense In Depth for DNS
CICI:RSARC:DNS 深度 DDoS 防御
- 批准号:
1739034 - 财政年份:2017
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
CI-P: Planning for Identity and Naming Experimentation Shared Testbed
CI-P:规划身份和命名实验共享测试台
- 批准号:
1513213 - 财政年份:2015
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
MRI: Development of an Always-Available Testbed for Underwater Networking Research
MRI:开发用于水下网络研究的始终可用的测试台
- 批准号:
0821750 - 财政年份:2008
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
NeTS-NBD-SGER: Map/Reduce for Network Traffic Analysis (MR-Net Sger)
NeTS-NBD-SGER:用于网络流量分析的 Map/Reduce (MR-Net Sger)
- 批准号:
0823774 - 财政年份:2008
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
相似海外基金
Collaborative Research: CyberTraining: Implementation: Medium: Training Users, Developers, and Instructors at the Chemistry/Physics/Materials Science Interface
协作研究:网络培训:实施:媒介:在化学/物理/材料科学界面培训用户、开发人员和讲师
- 批准号:
2321102 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
RII Track-4:@NASA: Bluer and Hotter: From Ultraviolet to X-ray Diagnostics of the Circumgalactic Medium
RII Track-4:@NASA:更蓝更热:从紫外到 X 射线对环绕银河系介质的诊断
- 批准号:
2327438 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
Collaborative Research: Topological Defects and Dynamic Motion of Symmetry-breaking Tadpole Particles in Liquid Crystal Medium
合作研究:液晶介质中对称破缺蝌蚪粒子的拓扑缺陷与动态运动
- 批准号:
2344489 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
Collaborative Research: AF: Medium: The Communication Cost of Distributed Computation
合作研究:AF:媒介:分布式计算的通信成本
- 批准号:
2402836 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Continuing Grant
Collaborative Research: AF: Medium: Foundations of Oblivious Reconfigurable Networks
合作研究:AF:媒介:遗忘可重构网络的基础
- 批准号:
2402851 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Continuing Grant
Collaborative Research: CIF: Medium: Snapshot Computational Imaging with Metaoptics
合作研究:CIF:Medium:Metaoptics 快照计算成像
- 批准号:
2403122 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
Collaborative Research: SHF: Medium: Differentiable Hardware Synthesis
合作研究:SHF:媒介:可微分硬件合成
- 批准号:
2403134 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
Collaborative Research: SHF: Medium: Enabling Graphics Processing Unit Performance Simulation for Large-Scale Workloads with Lightweight Simulation Methods
合作研究:SHF:中:通过轻量级仿真方法实现大规模工作负载的图形处理单元性能仿真
- 批准号:
2402804 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
Collaborative Research: CIF-Medium: Privacy-preserving Machine Learning on Graphs
合作研究:CIF-Medium:图上的隐私保护机器学习
- 批准号:
2402815 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant
Collaborative Research: SHF: Medium: Tiny Chiplets for Big AI: A Reconfigurable-On-Package System
合作研究:SHF:中:用于大人工智能的微型芯片:可重新配置的封装系统
- 批准号:
2403408 - 财政年份:2024
- 资助金额:
$ 145.84万 - 项目类别:
Standard Grant