Collaborative Research: CNS Core: Small: Internet-Scale Measurement of TCP/IP Implementation Weaknesses
Collaborative Research: CNS Core: Small: Internet-Scale Measurement of TCP/IP Implementation Weaknesses
批准号:
2007741
负责人:
Jedidiah Crandall
金额:
$22.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2023-09-30
中文摘要
这个项目将揭示在互联网上常见的网络协议实现,并且容易受到侧信道攻击。 这可能会对虚拟专用网络(VPN)和域验证(DV)等应用程序产生严重的安全影响,DV证明组织在颁发证书之前拥有互联网域,例如www.example.com,组织可以将该证书作为身份验证提供给Web浏览器。 侧信道是一种机制,其中信息流根据系统的设计不打算流动。 一个类比可能是一个外国政府计算比萨饼交付到五角大楼的数量,并在比萨饼数量急剧增加时推断出最后一分钟的大型活动计划。 在其他情况下,侧通道导致了操作系统中分离进程的基本安全机制的根本故障(参见Meltdown和Spectre,这是计算机强制执行最基本的安全上下文分离方式的漏洞),并已被用于破解即使是最强的密码学。 TCP和IP协议为互联网奠定了基础,但如果不满足某些要求,则已知易受边信道的影响。 RFC(Request for Comments)(开发和定义Internet标准的文档)描述了如何以不可预测的方式选择某些数字,或者必须以特定的方式限制发送数据包的速率,以减轻TCP/IP侧通道的影响。 不遵守这些RFC会破坏互联网安全的最基本假设:为了让攻击者推断通信的存在,干扰或将自己的数据注入通信,攻击者必须控制通信双方之间的网络的一部分。违反这一基本假设可能对在美国活动的互联网用户造成毁灭性的影响。的利益,如记者,活动家和非政府组织(NGO)海外使用某种隧道绕过自己国家的互联网控制。 该项目将解决的一个主要技术挑战是探索研究人员发送的探测序列如何在不同互联网主机给出的响应中产生可预测模式的天文数字般巨大的可能性。 可预测的模式表明存在漏洞,因为安全模型假设攻击者无法猜测协议用于排序和其他目的的数字。该项目结合了网络安全和数据挖掘方面的专业知识,在互联网上搜索不应该存在的模式。 通过精心设计的实验来测量互联网主机如何响应不同的探测组合,时间数据挖掘以发现模式,以及用于纵向测量整个互联网的基础设施,该项目将揭示自定义网络堆栈如何创建一个情况,其中很大一部分互联网服务器不保护免受侧信道攻击。 这些自定义TCP/IP实现通常是为云、负载均衡器和防火墙等“中间设备”以及物联网开发的。 拟议的工作将通过道德披露过程,参与互联网标准机构,并教育研究人员和用户了解这些威胁来解决这种情况。 教育活动和外展将利用美国西南部独特的人口和PI的专业知识来支持该领域的多样化和劳动力发展。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project will uncover network protocol implementations that are common on the Internet and are susceptible to side channel attacks. This can have serious security implications for applications such as Virtual Private Networks (VPNs) and Domain Validation ((DV), that proves an organization owns an Internet domain such as www.example.com before issuing a certificate that the organization can present to web browsers as authentication). A side channel is a mechanism where information flows where it was not intended to flow according to the design of a system. An analogy might be a foreign government counting the number of pizza deliveries to the Pentagon and inferring last-minute planning for a big event when the number of pizzas increases sharply. In other contexts, side channels have led to fundamental breakdowns in the basic security mechanisms that separate processes in an operating system (see Meltdown and Spectre, which are vulnerabilities in the way computers enforce the most basic separation of security contexts), and have been used to crack even then strongest cryptography. The TCP and IP protocols lay the foundation for the Internet, but are known to be susceptible to side channels if certain requirements are not met. Requests for Comments (RFCs), (the documents that develop and define Internet standards) describe how, for example, certain numbers must be chosen in an unpredictable manner, or limiting the rate at which packets are sent must be applied in a specific way, in order to mitigate the effects of TCP/IP side channels. Failure to follow these RFCs undermines the most basic assumption of Internet security: that in order for an attacker to infer the existence of, interfere with, or inject their own data into a communication the attacker must control a part of the network in between the two parties that are communicating.Violating this basic assumption can be devastating for Internet users that are acting in the U.S.'s interest, such as journalists, activists, and non-governmental organizations (NGOs) overseas that use tunneling of some kind to bypass Internet controls in their own country. A major technical challenge that the project will address is to explore the astronomically large number of possibilities for how sequences of probes sent by researchers might result in predictable patterns in the responses given by different Internet hosts. Predictable patterns indicate a vulnerability because the security model assumes an attacker will not be able to guess the numbers that protocols use for sequencing and other purposes.This project combines expertise in network security and data mining to search the Internet for patterns where there should be none. Through a combination of carefully designed experiments to measure how Internet hosts respond to different combinations of probes, temporal data mining to uncover patterns, and an infrastructure for measuring the entire Internet longitudinally, the project will reveal how custom network stacks have created a situation where a significant fraction of Internet servers do not protect against side channel attacks. These custom TCP/IP implementations are commonly developed for the cloud, "middleboxes" such as load balancers and firewalls, and the Internet of Things. The proposed work will address this situation through the ethical disclosure process, engaging Internet standards bodies, and educating researchers and users about these threats. Educational activities and outreach will leverage the unique population of the Southwestern U.S. and the expertise of the PIs to support diversification of the field and workforce development.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
[William J. Tolley;Beau Kujath;Mohammad Taha Khan;Narseo Vallina-Rodriguez;Jedidiah R. Crandall]
通讯作者:
William J. Tolley;Beau Kujath;Mohammad Taha Khan;Narseo Vallina-Rodriguez;Jedidiah R. Crandall
Challenges and Opportunities for Practical and Effective Dynamic Information Flow Tracking
实用有效的动态信息流跟踪的挑战和机遇
DOI:
10.1145/3483790
发表时间:
2023
期刊:
ACM Computing Surveys
影响因子:
16.6
作者:
[Brant, Christopher, Shrestha, Prakash, Mixon-Baca, Benjamin, Chen, Kejun, Varlioglu, Said, Elsayed, Nelly, Jin, Yier, Crandall, Jedidiah, Oliveira, Daniela]
通讯作者:
Oliveira, Daniela
TSPU: Russia's decentralized censorship system
TSPU:俄罗斯的去中心化审查制度
DOI:
10.1145/3517745.3561461
发表时间:
2022
期刊:
ACM Internet Measurement Conference
影响因子:
--
作者:
[Xue, Diwen, Mixon-Baca, Benjamin, ValdikSS, Ablove, Anna, Kujath, Beau, Crandall, Jedidiah R., Ensafi, Roya]
通讯作者:
Ensafi, Roya
Collaborative Research: SaTC: CORE: Medium: Rethinking the Fundamentals of Tunneling Technologies for Security, Privacy, and Usability
-
批准号:2141547
-
项目类别:Continuing Grant
-
资助金额:$46.66万
-
财政年份:2022
-
负责人:Jedidiah Crandall
-
依托单位:
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
-
批准号:2042795
-
项目类别:Standard Grant
-
资助金额:$6.64万
-
财政年份:2020
-
负责人:Jedidiah Crandall
-
依托单位:
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
-
批准号:1801613
-
项目类别:Standard Grant
-
资助金额:$29.97万
-
财政年份:2018
-
负责人:Jedidiah Crandall
-
依托单位:
NeTS: Large: Measuring and Modeling Internet Choke Points as Threats to Online Freedom
-
批准号:1518878
-
项目类别:Standard Grant
-
资助金额:$140.0万
-
财政年份:2015
-
负责人:Jedidiah Crandall
-
依托单位:
TWC: TTP Option: Large: Collaborative: Towards a Science of Censorship Resistance
-
批准号:1518523
-
项目类别:Continuing Grant
-
资助金额:$37.78万
-
财政年份:2015
-
负责人:Jedidiah Crandall
-
依托单位:
TWC: Small: Developing Advanced Digital Forensic Tools Based on Network Stack Side Channels
-
批准号:1420716
-
项目类别:Standard Grant
-
资助金额:$45.8万
-
财政年份:2014
-
负责人:Jedidiah Crandall
-
依托单位:
TWC: Medium: Collaborative: Measurement and Analysis Techniques for Internet Freedom on IP and Social Networks
-
批准号:1314297
-
项目类别:Standard Grant
-
资助金额:$59.7万
-
财政年份:2013
-
负责人:Jedidiah Crandall
-
依托单位:
Realizing Full-System Dynamic Information Flow Tracking via Relaxed Static Stability
-
批准号:1017602
-
项目类别:Standard Grant
-
资助金额:$45.54万
-
财政年份:2010
-
负责人:Jedidiah Crandall
-
依托单位:
TC: Medium: Collaborative Research: Securing Concurrency in Modern Systems
-
批准号:0905177
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Jedidiah Crandall
-
依托单位:
CAREER: Internet Measurement in the Cat's Cradle of Global Internet Censorship
-
批准号:0844880
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Jedidiah Crandall
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: