课题基金 / 基金详情

Collaborative Research: CNS Core: Small: Internet-Scale Measurement of TCP/IP Implementation Weaknesses

Collaborative Research: CNS Core: Small: Internet-Scale Measurement of TCP/IP Implementation Weaknesses
合作研究:CNS 核心:小型:TCP/IP 实施弱点的互联网规模测量
批准号:
2007741
负责人:
Jedidiah Crandall
金额:
$22.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2023-09-30

项目摘要

项目成果

Jedidiah Crandall的其他基金

相似基金

相关文献

中文摘要
翻译
该项目将揭示互联网上常见的网络协议实现,并且容易受到侧信道攻击。这可能会对虚拟专用网(vpn)和域验证(DV)等应用程序产生严重的安全影响,域验证(DV)在颁发组织可以向web浏览器提供作为身份验证的证书之前证明组织拥有Internet域(如www.example.com)。侧通道是一种机制,它使信息流向根据系统设计不打算流向的地方。打个比方,一个外国政府计算了向五角大楼运送披萨的数量,并在披萨数量急剧增加时推断出最后一刻的重大活动计划。在其他情况下,侧通道导致了操作系统中分离进程的基本安全机制的根本崩溃(参见Meltdown和Spectre,它们是计算机强制安全上下文最基本分离的方式中的漏洞),并且被用来破解最强的加密技术。TCP和IP协议为Internet奠定了基础,但众所周知,如果不满足某些要求,它们很容易受到侧信道的影响。评论请求(rfc)(开发和定义Internet标准的文档)描述了如何,例如,必须以不可预测的方式选择某些数字,或者必须以特定的方式限制发送数据包的速率,以减轻TCP/IP侧通道的影响。不遵守这些rfc破坏了Internet安全的最基本假设:为了让攻击者推断存在、干扰或将自己的数据注入通信,攻击者必须控制通信双方之间的一部分网络。违反这一基本假设对在美国的互联网用户来说可能是毁灭性的例如海外的记者、活动人士和非政府组织(ngo),他们利用某种形式的隧道绕过本国的互联网控制。该项目的一个主要技术挑战是探索大量的可能性,研究人员发送的探测序列如何导致不同互联网主机给出的可预测的响应模式。可预测的模式表明存在漏洞,因为安全模型假设攻击者无法猜测协议用于排序和其他目的的数字。这个项目结合了网络安全和数据挖掘方面的专业知识,在Internet上搜索不应该存在的模式。通过精心设计的实验来测量互联网主机如何响应不同的探针组合,时间数据挖掘以揭示模式,以及纵向测量整个互联网的基础设施,该项目将揭示自定义网络堆栈如何创造了一种情况,即很大一部分互联网服务器无法抵御侧信道攻击。这些自定义TCP/IP实现通常是为云、“中间设备”(如负载平衡器和防火墙)以及物联网开发的。拟议的工作将通过伦理披露过程、互联网标准机构参与以及对研究人员和用户进行有关这些威胁的教育来解决这种情况。教育活动和推广将利用美国西南部独特的人口和pi的专业知识来支持该领域的多样化和劳动力发展。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project will uncover network protocol implementations that are common on the Internet and are susceptible to side channel attacks. This can have serious security implications for applications such as Virtual Private Networks (VPNs) and Domain Validation ((DV), that proves an organization owns an Internet domain such as www.example.com before issuing a certificate that the organization can present to web browsers as authentication). A side channel is a mechanism where information flows where it was not intended to flow according to the design of a system. An analogy might be a foreign government counting the number of pizza deliveries to the Pentagon and inferring last-minute planning for a big event when the number of pizzas increases sharply. In other contexts, side channels have led to fundamental breakdowns in the basic security mechanisms that separate processes in an operating system (see Meltdown and Spectre, which are vulnerabilities in the way computers enforce the most basic separation of security contexts), and have been used to crack even then strongest cryptography. The TCP and IP protocols lay the foundation for the Internet, but are known to be susceptible to side channels if certain requirements are not met. Requests for Comments (RFCs), (the documents that develop and define Internet standards) describe how, for example, certain numbers must be chosen in an unpredictable manner, or limiting the rate at which packets are sent must be applied in a specific way, in order to mitigate the effects of TCP/IP side channels. Failure to follow these RFCs undermines the most basic assumption of Internet security: that in order for an attacker to infer the existence of, interfere with, or inject their own data into a communication the attacker must control a part of the network in between the two parties that are communicating.Violating this basic assumption can be devastating for Internet users that are acting in the U.S.'s interest, such as journalists, activists, and non-governmental organizations (NGOs) overseas that use tunneling of some kind to bypass Internet controls in their own country. A major technical challenge that the project will address is to explore the astronomically large number of possibilities for how sequences of probes sent by researchers might result in predictable patterns in the responses given by different Internet hosts. Predictable patterns indicate a vulnerability because the security model assumes an attacker will not be able to guess the numbers that protocols use for sequencing and other purposes.This project combines expertise in network security and data mining to search the Internet for patterns where there should be none. Through a combination of carefully designed experiments to measure how Internet hosts respond to different combinations of probes, temporal data mining to uncover patterns, and an infrastructure for measuring the entire Internet longitudinally, the project will reveal how custom network stacks have created a situation where a significant fraction of Internet servers do not protect against side channel attacks. These custom TCP/IP implementations are commonly developed for the cloud, "middleboxes" such as load balancers and firewalls, and the Internet of Things. The proposed work will address this situation through the ethical disclosure process, engaging Internet standards bodies, and educating researchers and users about these threats. Educational activities and outreach will leverage the unique population of the Southwestern U.S. and the expertise of the PIs to support diversification of the field and workforce development.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2021
期刊:
影响因子: --
作者: [William J. Tolley;Beau Kujath;Mohammad Taha Khan;Narseo Vallina-Rodriguez;Jedidiah R. Crandall]
通讯作者: William J. Tolley;Beau Kujath;Mohammad Taha Khan;Narseo Vallina-Rodriguez;Jedidiah R. Crandall
DOI: 10.1145/3483790
发表时间: 2023
期刊: ACM Computing Surveys
影响因子: 16.6
作者: [Brant, Christopher, Shrestha, Prakash, Mixon-Baca, Benjamin, Chen, Kejun, Varlioglu, Said, Elsayed, Nelly, Jin, Yier, Crandall, Jedidiah, Oliveira, Daniela]
通讯作者: Oliveira, Daniela
TSPU: Russia's decentralized censorship system
TSPU:俄罗斯的去中心化审查制度
DOI: 10.1145/3517745.3561461
发表时间: 2022
期刊: ACM Internet Measurement Conference
影响因子: --
作者: [Xue, Diwen, Mixon-Baca, Benjamin, ValdikSS, Ablove, Anna, Kujath, Beau, Crandall, Jedidiah R., Ensafi, Roya]
通讯作者: Ensafi, Roya
Collaborative Research: SaTC: CORE: Medium: Rethinking the Fundamentals of Tunneling Technologies for Security, Privacy, and Usability
  • 批准号:
    2141547
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $46.66万
  • 财政年份:
    2022
  • 负责人:
    Jedidiah Crandall
  • 依托单位:
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
  • 批准号:
    2042795
  • 项目类别:
    Standard Grant
  • 资助金额:
    $6.64万
  • 财政年份:
    2020
  • 负责人:
    Jedidiah Crandall
  • 依托单位:
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
  • 批准号:
    1801613
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.97万
  • 财政年份:
    2018
  • 负责人:
    Jedidiah Crandall
  • 依托单位:
NeTS: Large: Measuring and Modeling Internet Choke Points as Threats to Online Freedom
  • 批准号:
    1518878
  • 项目类别:
    Standard Grant
  • 资助金额:
    $140.0万
  • 财政年份:
    2015
  • 负责人:
    Jedidiah Crandall
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)