课题基金 / 基金详情

Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense

Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
批准号:
2317829
负责人:
Haining Wang
金额:
$30.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-10-01 至 2026-09-30

项目摘要

项目成果

Haining Wang的其他基金

相似基金

相关文献

中文摘要
翻译
这个项目深入研究了与针对互联网应用程序的命名空间劫持攻击相关的新出现的安全风险。在这种类型的攻击中,对手利用网络空间(例如Amazon.com与Amazom.com)中域名和资源名称的相似和混淆来攻击用户甚至软件开发人员,从而导致经济损失、知识产权被盗、声誉受损,以及对毫无戒心的用户的正常运营中断。该项目的新奇之处在于对这些类型的攻击在重要平台和应用程序(包括软件供应链生态系统、Metverse和分散的金融应用程序(Web3))中的安全风险进行了系统和定量的评估。此次调查还使制定有效的防御机制成为可能,为互联网用户提供了强有力的安全保障。该项目的更广泛的意义和重要性在于确保当前和未来的互联网应用程序的安全,从而增强互联网服务的可用性和可靠性。此外,教育努力致力于新的网络安全课程的课程设计,重点是Web3应用。在弗吉尼亚州和特拉华州(EPSCoR的一个州),还开展了外联活动,以促进未被充分代表的少数群体参与计算,并提高网络安全意识和知识。该项目开发了多个框架,以持续监测和捕获任何可疑活动,并查明潜在的命名空间劫持问题。第一个任务集中在识别和披露软件供应链生态系统中的漏洞,这些漏洞可以被攻击者利用来劫持现有的包或分发恶意代码。第二项任务是探索新兴Metverse平台中特定于用户的世界中的潜在威胁。第三项任务涉及利用机器学习技术来检测和缓解分散的区块链应用程序中的欺诈性在线活动。最终,该项目的目标是设计和开发轻量级和强大的防御系统,可以有效地缓解命名空间劫持威胁带来的潜在安全威胁。通过对实际应用的长期观察和大规模测量研究来评估总体安全风险。防御战略被整合到现有的系统和协议中,并在现实世界的场景中进行了彻底的评估,以展示其有效性。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project delves into the emerging security risks associated with naming space hijacking attacks targeting Internet applications. In this type of attack, an adversary exploits similarities and confusion in names of domains and resources in cyber space (e.g., Amazon.com vs. Amazom.com) to target users and even software developers, leading to financial loss, intellectual property theft, reputation damage, and disruption of normal operations for unsuspecting users. The project’s novelty is the assessment of the security risks of these types of attacks systematically and quantitatively across vital platforms and applications, including software supply chain ecosystems, the Metaverse, and decentralized financial applications (Web3). This investigation also enables the development of effective defense mechanisms and provides a strong safety guarantee to Internet users. The project's broader significance and importance lie in securing current and future Internet applications, thereby enhancing the availability and reliability of Internet services. Additionally, educational efforts are devoted to the curriculum design of new cybersecurity courses with a focus on Web3 applications. Outreach activities are also conducted to promote the involvement of underrepresented minorities in computing and to enhance cybersecurity awareness and knowledge in the states of Virginia and Delaware (an EPSCoR state).This project develops multiple frameworks to continuously monitor and capture any suspicious activities and pinpoint potential naming space hijacking issues. The first task focuses on the identification and disclosure of vulnerabilities within software supply chain ecosystems that can be exploited by adversaries to hijack existing packages or distribute malicious code. The second task centers on exploring potential threats within user-specific worlds in emerging Metaverse platforms. The third task involves leveraging machine learning techniques to detect and mitigate fraudulent online activities within decentralized blockchain applications. Ultimately, the project aims to design and develop lightweight and robust defense systems that can effectively mitigate the potential security threats posed by naming space hijacking threats. The overall security risks are evaluated through long-term observation and large-scale measurement studies on real-world applications. The defense strategies are integrated in existing systems and protocols, and thoroughly evaluated on real-world scenarios to demonstrate their effectiveness.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Phase II IUCRC Virginia Tech: Broadband Wireless Access and Applications Center (BWAC)
SaTC: EDU: Integrating Cybersecurity Education with Cloud Computing
  • 批准号:
    1821744
  • 项目类别:
    Standard Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2018
  • 负责人:
    Haining Wang
  • 依托单位:
TWC: Small: Collaborative: Reputation-Escalation-as-a-Service: Analyses and Defenses
  • 批准号:
    1618117
  • 项目类别:
    Standard Grant
  • 资助金额:
    $20.0万
  • 财政年份:
    2016
  • 负责人:
    Haining Wang
  • 依托单位:
NeTS: Medium: Collaborative Research: Coexistence of Heterogeneous Wireless Access Technologies in the 5 GHz Bands
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)