Collaborative Research: CNS Core: Small: Internet-Scale Measurement of TCP/IP Implementation Weaknesses
Collaborative Research: CNS Core: Small: Internet-Scale Measurement of TCP/IP Implementation Weaknesses
批准号:
2007741
负责人:
Jedidiah Crandall
金额:
$22.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2023-09-30
中文摘要
该项目将发现在Internet上常见且容易受到侧通道攻击的网络协议实现。这可能会对虚拟专用网络(VPN)和域验证(DV)等应用程序产生严重的安全影响,域验证(DV)在颁发证书(该组织可以向Web浏览器提供该证书作为身份验证)之前证明组织拥有诸如www.Example.com之类的Internet域。侧通道是一种机制,在该机制中,根据系统的设计,信息在不打算流动的地方流动。一个类比可能是,外国政府计算向五角大楼递送披萨的数量,并在披萨数量急剧增加的情况下,推断最后一刻为一项重大活动做的计划。在其他环境中,侧通道导致了在操作系统中分隔进程的基本安全机制的根本崩溃(参见Meltdown和Spectre,这是计算机实施最基本的安全上下文隔离方式中的漏洞),并被用来破解即使是最强的加密技术。TCP和IP协议为互联网奠定了基础,但众所周知,如果不满足某些要求,就容易受到旁路信道的影响。请求注解(RFC)(制定和定义互联网标准的文档)描述了如何例如以不可预测的方式选择某些数字,或者必须以特定的方式应用限制分组发送的速率,以减轻TCP/IP侧通道的影响。未能遵循这些RFC破坏了互联网安全的最基本假设:为了让攻击者推断通信的存在、干扰他们自己的数据或将他们自己的数据注入通信,攻击者必须控制通信双方之间的网络的一部分。破坏这一基本假设可能会对为美国S利益行事的互联网用户造成毁灭性的打击,例如使用某种隧道技术绕过本国互联网控制的记者、活动人士和海外非政府组织(NGO)。该项目将解决的一个主要技术挑战是探索天文数字的大量可能性,即研究人员发送的探测器序列如何在不同的互联网主机给出的响应中产生可预测的模式。可预测的模式表明了一个漏洞,因为安全模型假设攻击者将无法猜测协议用于排序和其他目的的数字。这个项目结合了网络安全和数据挖掘方面的专业知识,在互联网上搜索本不应该存在的模式。通过一系列精心设计的实验来衡量互联网主机如何对不同的探测组合做出反应,通过时态数据挖掘来发现模式,以及一个用于纵向测量整个互联网的基础设施,该项目将揭示自定义网络堆栈是如何造成很大一部分互联网服务器无法防御侧通道攻击的情况。这些定制的TCP/IP实现通常是为云、负载均衡器和防火墙等“中间盒”以及物联网开发的。拟议的工作将通过道德披露过程、让互联网标准机构参与并教育研究人员和用户了解这些威胁来解决这种情况。教育活动和外展活动将利用美国西南部独特的人口和私人投资机构的专业知识来支持领域和劳动力发展的多样化。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project will uncover network protocol implementations that are common on the Internet and are susceptible to side channel attacks. This can have serious security implications for applications such as Virtual Private Networks (VPNs) and Domain Validation ((DV), that proves an organization owns an Internet domain such as www.example.com before issuing a certificate that the organization can present to web browsers as authentication). A side channel is a mechanism where information flows where it was not intended to flow according to the design of a system. An analogy might be a foreign government counting the number of pizza deliveries to the Pentagon and inferring last-minute planning for a big event when the number of pizzas increases sharply. In other contexts, side channels have led to fundamental breakdowns in the basic security mechanisms that separate processes in an operating system (see Meltdown and Spectre, which are vulnerabilities in the way computers enforce the most basic separation of security contexts), and have been used to crack even then strongest cryptography. The TCP and IP protocols lay the foundation for the Internet, but are known to be susceptible to side channels if certain requirements are not met. Requests for Comments (RFCs), (the documents that develop and define Internet standards) describe how, for example, certain numbers must be chosen in an unpredictable manner, or limiting the rate at which packets are sent must be applied in a specific way, in order to mitigate the effects of TCP/IP side channels. Failure to follow these RFCs undermines the most basic assumption of Internet security: that in order for an attacker to infer the existence of, interfere with, or inject their own data into a communication the attacker must control a part of the network in between the two parties that are communicating.Violating this basic assumption can be devastating for Internet users that are acting in the U.S.'s interest, such as journalists, activists, and non-governmental organizations (NGOs) overseas that use tunneling of some kind to bypass Internet controls in their own country. A major technical challenge that the project will address is to explore the astronomically large number of possibilities for how sequences of probes sent by researchers might result in predictable patterns in the responses given by different Internet hosts. Predictable patterns indicate a vulnerability because the security model assumes an attacker will not be able to guess the numbers that protocols use for sequencing and other purposes.This project combines expertise in network security and data mining to search the Internet for patterns where there should be none. Through a combination of carefully designed experiments to measure how Internet hosts respond to different combinations of probes, temporal data mining to uncover patterns, and an infrastructure for measuring the entire Internet longitudinally, the project will reveal how custom network stacks have created a situation where a significant fraction of Internet servers do not protect against side channel attacks. These custom TCP/IP implementations are commonly developed for the cloud, "middleboxes" such as load balancers and firewalls, and the Internet of Things. The proposed work will address this situation through the ethical disclosure process, engaging Internet standards bodies, and educating researchers and users about these threats. Educational activities and outreach will leverage the unique population of the Southwestern U.S. and the expertise of the PIs to support diversification of the field and workforce development.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
[William J. Tolley;Beau Kujath;Mohammad Taha Khan;Narseo Vallina-Rodriguez;Jedidiah R. Crandall]
通讯作者:
William J. Tolley;Beau Kujath;Mohammad Taha Khan;Narseo Vallina-Rodriguez;Jedidiah R. Crandall
Challenges and Opportunities for Practical and Effective Dynamic Information Flow Tracking
实用有效的动态信息流跟踪的挑战和机遇
DOI:
10.1145/3483790
发表时间:
2023
期刊:
ACM Computing Surveys
影响因子:
16.6
作者:
[Brant, Christopher, Shrestha, Prakash, Mixon-Baca, Benjamin, Chen, Kejun, Varlioglu, Said, Elsayed, Nelly, Jin, Yier, Crandall, Jedidiah, Oliveira, Daniela]
通讯作者:
Oliveira, Daniela
TSPU: Russia's decentralized censorship system
TSPU:俄罗斯的去中心化审查制度
DOI:
10.1145/3517745.3561461
发表时间:
2022
期刊:
ACM Internet Measurement Conference
影响因子:
--
作者:
[Xue, Diwen, Mixon-Baca, Benjamin, ValdikSS, Ablove, Anna, Kujath, Beau, Crandall, Jedidiah R., Ensafi, Roya]
通讯作者:
Ensafi, Roya
Collaborative Research: SaTC: CORE: Medium: Rethinking the Fundamentals of Tunneling Technologies for Security, Privacy, and Usability
-
批准号:2141547
-
项目类别:Continuing Grant
-
资助金额:$46.66万
-
财政年份:2022
-
负责人:Jedidiah Crandall
-
依托单位:
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
-
批准号:2042795
-
项目类别:Standard Grant
-
资助金额:$6.64万
-
财政年份:2020
-
负责人:Jedidiah Crandall
-
依托单位:
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
-
批准号:1801613
-
项目类别:Standard Grant
-
资助金额:$29.97万
-
财政年份:2018
-
负责人:Jedidiah Crandall
-
依托单位:
NeTS: Large: Measuring and Modeling Internet Choke Points as Threats to Online Freedom
-
批准号:1518878
-
项目类别:Standard Grant
-
资助金额:$140.0万
-
财政年份:2015
-
负责人:Jedidiah Crandall
-
依托单位:
TWC: TTP Option: Large: Collaborative: Towards a Science of Censorship Resistance
-
批准号:1518523
-
项目类别:Continuing Grant
-
资助金额:$37.78万
-
财政年份:2015
-
负责人:Jedidiah Crandall
-
依托单位:
TWC: Small: Developing Advanced Digital Forensic Tools Based on Network Stack Side Channels
-
批准号:1420716
-
项目类别:Standard Grant
-
资助金额:$45.8万
-
财政年份:2014
-
负责人:Jedidiah Crandall
-
依托单位:
TWC: Medium: Collaborative: Measurement and Analysis Techniques for Internet Freedom on IP and Social Networks
-
批准号:1314297
-
项目类别:Standard Grant
-
资助金额:$59.7万
-
财政年份:2013
-
负责人:Jedidiah Crandall
-
依托单位:
Realizing Full-System Dynamic Information Flow Tracking via Relaxed Static Stability
-
批准号:1017602
-
项目类别:Standard Grant
-
资助金额:$45.54万
-
财政年份:2010
-
负责人:Jedidiah Crandall
-
依托单位:
TC: Medium: Collaborative Research: Securing Concurrency in Modern Systems
-
批准号:0905177
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Jedidiah Crandall
-
依托单位:
CAREER: Internet Measurement in the Cat's Cradle of Global Internet Censorship
-
批准号:0844880
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Jedidiah Crandall
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: