CAREER: Tools and Techniques for Preserving Integrity on the Web
职业:维护网络完整性的工具和技术
基本信息
- 批准号:1941617
- 负责人:
- 金额:$ 55.11万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2020
- 资助国家:美国
- 起止时间:2020-10-01 至 2025-09-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
The web, the Internet's most successful and recognizable application, has become part of peoples' daily lives and is relied upon by billions of users for news, entertainment, communications, and work. This reliance is constantly taken advantage of by attackers who appear to have an inexhaustible collection of diverse attacks targeting popular web services and end users. This project views a large number of seemingly unrelated attacks as mere instances of the problem of integrity violation. Due to the absence of integrity checks and guarantees, web applications have no way of gauging whether the content that their users will receive today when clicking on a remote link or loading a remote resource, is the same content that they linked to in the past. This project focuses on better understanding this issue of content integrity on the web, gathering data about how attackers abuse it, and developing defenses against integrity violations.The project proposes to design, implement, and evaluate tools and techniques for preserving integrity on the web by enabling web developers to discover the remote resources on which their web applications rely and make explicit statements about these resources through new policy systems. Next to developer-authored policies, this project will use anomaly detection to automatically discover when remote resources behave in an uncharacteristic fashion by extracting attributes and combining them in integrity signatures. To quantify how popular web applications depend on remote resources and to evaluate how different types of websites would react to different policies, the project includes the longitudinal collection of linking data and the use of this data to simulate the effects of the proposed systems. Finally, the project proposes collaborative, client-server resource-integrity schemes to further protect web users and strengthen the security of existing services. The outcomes of this research effort are expected to improve the research community's understanding of content integrity on the web and to achieve substantial practical impact in protecting websites and users against integrity-violating attacks on the web.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
网络是互联网最成功和最知名的应用,已经成为人们日常生活的一部分,数十亿用户依赖于它来获取新闻、娱乐、通信和工作。这种依赖性不断被攻击者利用,他们似乎拥有针对流行Web服务和最终用户的各种攻击的无穷无尽的集合。该项目将大量看似无关的攻击视为违反完整性问题的实例。由于缺乏完整性检查和保证,Web应用程序无法衡量用户在点击远程链接或加载远程资源时今天将收到的内容是否与他们过去链接的内容相同。该项目的重点是更好地了解网络上的内容完整性问题,收集有关攻击者如何滥用它的数据,并开发针对完整性侵犯的防御措施。该项目建议设计,实施,并评估通过使Web开发人员能够发现其Web应用程序所依赖的远程资源并通过新的政策体系除了开发人员编写的策略之外,该项目还将使用异常检测,通过提取属性并将其组合到完整性签名中,自动发现远程资源何时以不典型的方式运行。为了量化流行的网络应用程序对远程资源的依赖程度,并评估不同类型的网站对不同政策的反应,该项目包括纵向收集链接数据,并使用这些数据来模拟拟议系统的效果。最后,该项目提出了协作,客户端-服务器资源完整性计划,以进一步保护Web用户和加强现有服务的安全性。这项研究工作的成果有望提高研究界对网络内容完整性的理解,并在保护网站和用户免受网络上违反完整性的攻击方面产生实质性的实际影响。该奖项反映了NSF的法定使命,并被认为值得通过使用基金会的智力价值和更广泛的影响审查标准进行评估来支持。
项目成果
期刊论文数量(17)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Navigating Murky Waters: Automated Browser Feature Testing for Uncovering Tracking Vectors
航行浑水:用于发现跟踪向量的自动浏览器功能测试
- DOI:10.14722/ndss.2023.24072
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Ali, Mir Masood;Chitale, Binoy;Ghasemisharif, Mohammad;Kanich, Chris;Nikiforakis, Nick;Polakis, Jason
- 通讯作者:Polakis, Jason
Click This, Not That: Extending Web Authentication with Deception
点击这个,而不是那个:通过欺骗扩展 Web 身份验证
- DOI:10.1145/3433210.3453088
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Barron, Timothy;So, Johnny;Nikiforakis, Nick
- 通讯作者:Nikiforakis, Nick
To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media
- DOI:10.14722/ndss.2021.24322
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Beliz Kaleli;Brian Kondracki;Manuel Egele;Nick Nikiforakis;G. Stringhini
- 通讯作者:Beliz Kaleli;Brian Kondracki;Manuel Egele;Nick Nikiforakis;G. Stringhini
Escaping the Confines of Time: Continuous Browser Extension Fingerprinting Through Ephemeral Modifications
逃离时间的限制:通过短暂修改进行连续浏览器扩展指纹识别
- DOI:10.1145/3548606.3560576
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Solomos, Konstantinos;Ilia, Panagiotis;Nikiforakis, Nick;Polakis, Jason
- 通讯作者:Polakis, Jason
The More Things Change, the More They Stay the Same: Integrity of Modern JavaScript
事物变化越多,它们就越保持不变:现代 JavaScript 的完整性
- DOI:10.1145/3543507.3583395
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:So, Johnny;Ferdman, Michael;Nikiforakis, Nick
- 通讯作者:Nikiforakis, Nick
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Nick Nikiforakis其他文献
PriVaricator: Deceiving Fingerprinters with Little White Lies
PriVricator:用善意的小谎言欺骗指纹采集者
- DOI:
10.1145/2736277.2741090 - 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Nick Nikiforakis;W. Joosen;B. Livshits - 通讯作者:
B. Livshits
Panning for gold.com: Understanding the Dynamics of Domain Dropcatching
淘金金网:了解域名丢弃的动态
- DOI:
10.1145/3178876.3186092 - 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
N. Miramirkhani;Timothy Barron;M. Ferdman;Nick Nikiforakis - 通讯作者:
Nick Nikiforakis
PrivacyMeter: Designing and Developing a Privacy-Preserving Browser Extension
PrivacyMeter:设计和开发隐私保护浏览器扩展
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Oleksii Starov;Nick Nikiforakis - 通讯作者:
Nick Nikiforakis
Secure multi-execution of web scripts: Theory and practice
Web 脚本的安全多重执行:理论与实践
- DOI:
10.3233/jcs-130495 - 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Willem De Groef;Dominique Devriese;Nick Nikiforakis;Frank Piessens - 通讯作者:
Frank Piessens
By Hook or by Crook: Exposing the Diverse Abuse Tactics of Technical Support Scammers
不择手段:揭露技术支持诈骗者的各种滥用策略
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Bharat Srinivasan;Athanasios Kountouras;N. Miramirkhani;Monjur Alam;Nick Nikiforakis;M. Antonakakis;M. Ahamad - 通讯作者:
M. Ahamad
Nick Nikiforakis的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Nick Nikiforakis', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Medium: App-driven Web Browsing: Novel Risks, Vulnerabilities, and Defenses
协作研究:SaTC:核心:中:应用程序驱动的网络浏览:新的风险、漏洞和防御
- 批准号:
2211575 - 财政年份:2022
- 资助金额:
$ 55.11万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI
协作研究:SaTC:核心:中:利用浏览器内人工智能防御社会工程攻击
- 批准号:
2126654 - 财政年份:2021
- 资助金额:
$ 55.11万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Understanding, Measuring, and Defending against Malicious Web Crawlers
SaTC:核心:小:理解、衡量和防御恶意网络爬虫
- 批准号:
1813974 - 财政年份:2018
- 资助金额:
$ 55.11万 - 项目类别:
Standard Grant
EAGER: ISN: Detecting and Disrupting Illicit Supply Networks via Traffic Distribution Systems
EAGER:ISN:通过流量分配系统检测和破坏非法供应网络
- 批准号:
1842020 - 财政年份:2018
- 资助金额:
$ 55.11万 - 项目类别:
Standard Grant
EAGER: Measuring the Stability of Web Links
EAGER:测量网络链接的稳定性
- 批准号:
1735396 - 财政年份:2017
- 资助金额:
$ 55.11万 - 项目类别:
Standard Grant
TWC: Small: Emerging Attacks Against the Mobile Web and Novel Proxy Technologies for Their Containment
TWC:小型:针对移动网络的新兴攻击和新型代理技术的遏制
- 批准号:
1617593 - 财政年份:2016
- 资助金额:
$ 55.11万 - 项目类别:
Standard Grant
TWC: Small: Cross-Application and Cross-Platform Tracking of Web Users: Techniques and Countermeasures
TWC:小:Web用户的跨应用和跨平台跟踪:技术和对策
- 批准号:
1527086 - 财政年份:2015
- 资助金额:
$ 55.11万 - 项目类别:
Standard Grant
相似海外基金
ERI: SDR Beyond Radio: Enabling Experimental Research in Multi-Node Optical Wireless Networks via Software Defined Radio Tools and Techniques
ERI:超越无线电的 SDR:通过软件定义无线电工具和技术实现多节点光无线网络的实验研究
- 批准号:
2347514 - 财政年份:2024
- 资助金额:
$ 55.11万 - 项目类别:
Standard Grant
REU Site: High Performance Computing (HPC) Tools, Techniques, and Research across the Physical Sciences
REU 网站:跨物理科学领域的高性能计算 (HPC) 工具、技术和研究
- 批准号:
2348782 - 财政年份:2024
- 资助金额:
$ 55.11万 - 项目类别:
Standard Grant
Development of tools and techniques that foster graphicacy skills in STEM education among students with visual impairment in mainstream school settings
开发工具和技术,培养主流学校环境中视力障碍学生 STEM 教育中的图形技能
- 批准号:
23KK0038 - 财政年份:2023
- 资助金额:
$ 55.11万 - 项目类别:
Fund for the Promotion of Joint International Research (International Collaborative Research)
Comparison Study on Japanese and Chinese Building Tools and Processing Traces Aimed to Establish the Foundation of the History of East Asian Wooden Building Construction Techniques
中日建筑工具及加工痕迹比较研究,为东亚木建筑建造技术史奠定基础
- 批准号:
23H01597 - 财政年份:2023
- 资助金额:
$ 55.11万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
Tools and Techniques for Operational Technology Cyber Security Compliance in Rail
铁路运营技术网络安全合规性工具和技术
- 批准号:
10073292 - 财政年份:2023
- 资助金额:
$ 55.11万 - 项目类别:
Collaborative R&D
Tools and Techniques to Perform Comprehensive Security Assessments
执行全面安全评估的工具和技术
- 批准号:
577519-2022 - 财政年份:2022
- 资助金额:
$ 55.11万 - 项目类别:
Idea to Innovation
Multi-Robot Tools and Techniques for Exploration and Mobile Surveying
用于勘探和移动测量的多机器人工具和技术
- 批准号:
RGPIN-2015-04025 - 财政年份:2022
- 资助金额:
$ 55.11万 - 项目类别:
Discovery Grants Program - Individual
Integrating Imaging and Motion Tracking Tools and Techniques for Assessing and Surgically Treating Musculoskeletal Disorders
整合成像和运动跟踪工具和技术来评估和手术治疗肌肉骨骼疾病
- 批准号:
RGPIN-2019-05542 - 财政年份:2022
- 资助金额:
$ 55.11万 - 项目类别:
Discovery Grants Program - Individual
Tools and Techniques for Electrical and Optical Stimulation and Recording from the Nervous System
神经系统电和光刺激和记录的工具和技术
- 批准号:
RGPIN-2018-04323 - 财政年份:2022
- 资助金额:
$ 55.11万 - 项目类别:
Discovery Grants Program - Individual
Development of new tools and techniques for the analysis and risk management of landslides and related geohazards
开发滑坡及相关地质灾害分析和风险管理的新工具和技术
- 批准号:
RGPIN-2017-03916 - 财政年份:2022
- 资助金额:
$ 55.11万 - 项目类别:
Discovery Grants Program - Individual