CRII: SaTC: Measuring and Improving the Management of Resource Public Key Infrastructure (RPKI)
CRII:SaTC:衡量和改进资源公钥基础设施 (RPKI) 的管理
基本信息
- 批准号:2051166
- 负责人:
- 金额:$ 14.94万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2020
- 资助国家:美国
- 起止时间:2020-08-01 至 2022-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The Border Gateway Protocol (BGP) is responsible for managing how packets are routed across the Internet by exchanging routing related messages (path announcements) between routers. While the Border Gateway Protocol plays a critical role in the Internet communications, it remains highly vulnerable to many attacks. This is because the protocol was originally designed for each BGP router to trust all protocol related messages, especially path announcements, sent by its neighboring routers. As a result, incorrect and malicious path information would be accepted by routers at face value, potentially leading to destination unreachable problems in the Internet. To address this issue, Resource Public Key Infrastructure (RPKI) was introduced in 2012 to allow routers to verify path announcements in the Border Gateway Protocol. However, today there is a dearth of information available about the vulnerability of the RPKI, and how routers in the Internet have actually deployed and managed it. This project will develop techniques to better understand and improve the management of RPKI, helping to better secure the Internet. Given the early stage of the RPKI protocol, the findings in this project stand a good chance of being integrated to improve the state of the system. The project would train students in related research. The findings of the project would identify what the current security problems of RPKI are and help spur a greater adoption of RPKI by releasing the codes, datasets and analysis tools developed in the project and presenting the research outcomes to other researchers, administrators, and Internet operations related working groups.This project has two research foci, each examining the management and improving security challenges of the Resource Public Key Infrastructure. First, the project will analyze existing RPKI repositories from multiple vantage points in an effort to understand how much of actual Border Gateway Protocol feeds in the Internet are verifiable. It will also determine what fraction of routers are actually using RPKI to validate paths. For this focus, the investigators will collaborate with one of the biggest network operators that have the most-peered global networks in existence. Second, the project will develop new techniques to detect misconfigurations of routers and potential security vulnerabilities. For this purpose, the project will host a custom RPKI repository that have multiple invalid routes, which will be used to test RPKI validators or routers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
边界网关协议(BGP)负责管理数据包如何通过路由器之间交换路由相关的消息(路径通告)在Internet上路由。虽然边界网关协议在互联网通信中起着至关重要的作用,但它仍然非常容易受到许多攻击。这是因为该协议最初是为每个BGP路由器设计的,以信任其相邻路由器发送的所有协议相关消息,特别是路径公告。因此,路由器会接受不正确和恶意的路径信息,从而可能导致Internet中的目的地不可达问题。为了解决这个问题,2012年引入了资源公钥基础设施(RPKI),允许路由器验证边界网关协议中的路径公告。然而,目前关于RPKI的脆弱性以及互联网上的路由器如何实际部署和管理它的信息非常缺乏。本项目将开发技术,以更好地了解和改进RPKI的管理,帮助更好地保护互联网。鉴于RPKI协议的早期阶段,在这个项目中的研究结果站在一个很好的机会被集成,以改善系统的状态。该项目将对学生进行相关研究方面的培训。该项目的研究结果将通过发布项目中开发的代码、数据集和分析工具,并将研究成果展示给其他研究人员、管理员和互联网运营相关工作组,来确定RPKI当前的安全问题,并帮助推动RPKI的更广泛采用。该项目有两个研究重点,每一个都检查资源公钥基础设施的管理和改进安全挑战。首先,该项目将从多个Vantage位置分析现有的RPKI存储库,以了解互联网上有多少实际的边界网关协议源是可验证的。它还将确定实际使用RPKI来验证路径的路由器的比例。为了实现这一目标,调查人员将与拥有现有全球对等网络最多的最大网络运营商之一合作。其次,该项目将开发新技术来检测路由器的错误配置和潜在的安全漏洞。为此,该项目将托管一个自定义RPKI存储库,其中包含多个无效路由,用于测试RPKI验证器或路由器。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Taejoong Chung其他文献
Privacy Guarantees of Bluetooth Low Energy Contact Tracing: A Case Study on COVIDWISE
低功耗蓝牙接触者追踪的隐私保证:COVIDWISE 案例研究
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:2.2
- 作者:
Salman Ahmed;Ya Xiao;Taejoong Chung;Carol J. Fung;M. Yung;D. Yao - 通讯作者:
D. Yao
Strategic bundling for content availability and fast distribution in BitTorrent
- DOI:
10.1016/j.comcom.2014.01.013 - 发表时间:
2014-05-01 - 期刊:
- 影响因子:
- 作者:
Jinyoung Han;Taejoong Chung;Seungbae Kim;Hyun-chul Kim;Jussi Kangasharju;Ted “Taekyoung” Kwon;Yanghee Choi - 通讯作者:
Yanghee Choi
RoVista: Measuring and Analyzing the Route Origin Validation (ROV) in RPKI
RoVista:测量和分析 RPKI 中的路线起点验证 (ROV)
- DOI:
10.1145/3618257.3624806 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Weitong Li;Zhexiao Lin;Md. Ishtiaq Ashiq;E. Aben;Romain Fontugne;Amreesh Phokeer;Taejoong Chung - 通讯作者:
Taejoong Chung
The Reality of Algorithm Agility: Studying the DNSSEC Algorithm Life-Cycle
算法敏捷性的现实:研究 DNSSEC 算法生命周期
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
M. Müller;W. Toorop;Taejoong Chung;J. Jansen;R. V. Rijswijk - 通讯作者:
R. V. Rijswijk
Under the Hood of DANE Mismanagement in SMTP
SMTP 中 DANE 管理不善的背后
- DOI:
- 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Hyeonmin Lee;Md. Ishtiaq Ashiq;M. Müller;R. V. Rijswijk;T. Kwon;Taejoong Chung - 通讯作者:
Taejoong Chung
Taejoong Chung的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Taejoong Chung', 18)}}的其他基金
CAREER: Securing and Evolving Internet Security Protocols for Naming and Routing
职业:保护和发展用于命名和路由的互联网安全协议
- 批准号:
2339378 - 财政年份:2024
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
IMR: MT: Tools for Measuring Route Origin Validation in Resource Public Key Infrastructure (RPKI) at Scale
IMR:MT:用于大规模测量资源公钥基础设施 (RPKI) 中的路由源验证的工具
- 批准号:
2323137 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Cryptographic accumulators and revocation of credentials
协作研究:SaTC:核心:中:加密累加器和凭证撤销
- 批准号:
2247306 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
Travel: NSF Student Travel Grant for 2022 Internet Measurement Conference (IMC)
旅行:2022 年互联网测量会议 (IMC) 的 NSF 学生旅行补助金
- 批准号:
2234443 - 财政年份:2022
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
CNS Core: Large: Collaborative Research: Towards an Evolvable Public Key Infrastructure
CNS 核心:大型:协作研究:迈向可进化的公钥基础设施
- 批准号:
2053363 - 财政年份:2020
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
CRII: SaTC: Measuring and Improving the Management of Resource Public Key Infrastructure (RPKI)
CRII:SaTC:衡量和改进资源公钥基础设施 (RPKI) 的管理
- 批准号:
1850465 - 财政年份:2019
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
CNS Core: Large: Collaborative Research: Towards an Evolvable Public Key Infrastructure
CNS 核心:大型:协作研究:迈向可进化的公钥基础设施
- 批准号:
1901090 - 财政年份:2019
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
相似海外基金
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
合作研究:SaTC:核心:小型:测量、验证和改进基于应用程序的隐私营养标签
- 批准号:
2247952 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: TTP: Medium: iDRAMA.cloud: A Platform for Measuring and Understanding Information Manipulation
协作研究:SaTC:TTP:中:iDRAMA.cloud:测量和理解信息操纵的平台
- 批准号:
2247867 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
合作研究:SaTC:核心:小型:测量、验证和改进基于应用程序的隐私营养标签
- 批准号:
2247953 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: TTP: Medium: iDRAMA.cloud: A Platform for Measuring and Understanding Information Manipulation
协作研究:SaTC:TTP:中:iDRAMA.cloud:测量和理解信息操纵的平台
- 批准号:
2247868 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
合作研究:SaTC:核心:小型:测量、验证和改进基于应用程序的隐私营养标签
- 批准号:
2247951 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Studying and Measuring the Consequence of Prototype Pollution Vulnerabilities Automatically via Joint Taintflow Analysis
SaTC:核心:小型:通过联合污染流分析自动研究和测量原型污染漏洞的后果
- 批准号:
2154404 - 财政年份:2022
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
CRII: SaTC: Measuring and Improving the Management of Resource Public Key Infrastructure (RPKI)
CRII:SaTC:衡量和改进资源公钥基础设施 (RPKI) 的管理
- 批准号:
1850465 - 财政年份:2019
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
SaTC: CORE: Medium: Collaborative: Measuring the Value of Anonymous Online Participation
SaTC:核心:媒介:协作:衡量匿名在线参与的价值
- 批准号:
2031951 - 财政年份:2019
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
CRII: SaTC: Techniques for Measuring and Characterizing Robocalls
CRII:SaTC:测量和表征 Robocalls 的技术
- 批准号:
1849994 - 财政年份:2019
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Understanding, Measuring, and Defending against Malicious Web Crawlers
SaTC:核心:小:理解、衡量和防御恶意网络爬虫
- 批准号:
1813974 - 财政年份:2018
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant