Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense

协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查

基本信息

项目摘要

This project delves into the emerging security risks associated with naming space hijacking attacks targeting Internet applications. In this type of attack, an adversary exploits similarities and confusion in names of domains and resources in cyber space (e.g., Amazon.com vs. Amazom.com) to target users and even software developers, leading to financial loss, intellectual property theft, reputation damage, and disruption of normal operations for unsuspecting users. The project’s novelty is the assessment of the security risks of these types of attacks systematically and quantitatively across vital platforms and applications, including software supply chain ecosystems, the Metaverse, and decentralized financial applications (Web3). This investigation also enables the development of effective defense mechanisms and provides a strong safety guarantee to Internet users. The project's broader significance and importance lie in securing current and future Internet applications, thereby enhancing the availability and reliability of Internet services. Additionally, educational efforts are devoted to the curriculum design of new cybersecurity courses with a focus on Web3 applications. Outreach activities are also conducted to promote the involvement of underrepresented minorities in computing and to enhance cybersecurity awareness and knowledge in the states of Virginia and Delaware (an EPSCoR state).This project develops multiple frameworks to continuously monitor and capture any suspicious activities and pinpoint potential naming space hijacking issues. The first task focuses on the identification and disclosure of vulnerabilities within software supply chain ecosystems that can be exploited by adversaries to hijack existing packages or distribute malicious code. The second task centers on exploring potential threats within user-specific worlds in emerging Metaverse platforms. The third task involves leveraging machine learning techniques to detect and mitigate fraudulent online activities within decentralized blockchain applications. Ultimately, the project aims to design and develop lightweight and robust defense systems that can effectively mitigate the potential security threats posed by naming space hijacking threats. The overall security risks are evaluated through long-term observation and large-scale measurement studies on real-world applications. The defense strategies are integrated in existing systems and protocols, and thoroughly evaluated on real-world scenarios to demonstrate their effectiveness.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该项目深入研究了针对Internet应用程序的空间劫持攻击的新兴安全风险。在这种类型的攻击中,对手在网络空间中的域名和资源的名称(例如Amazon.com vs. Amazon.com)中利用了相似性和混乱,向目标用户甚至软件开发人员造成了财务损失,知识产权盗用,声誉损害,以及对未替代用户的正常操作的破坏。项目的新颖性是对这些类型攻击的安全风险进行系统和定量的评估,包括软件供应链生态系统,元评估和分散的财务应用程序(WEB3)。这项投资还可以开发有效的防御机制,并为互联网用户提供强大的安全保证。该项目更广泛的意义和重要性在于确保当前和未来的互联网应用程序,从而增强互联网服务的可用性和可靠性。此外,教育工作将致力于新的网络安全课程的课程设计,重点是Web3应用程序。还开展了外展活动,以促进代表性不足的少数群体参与计算,并在弗吉尼亚州和特拉华州(EPSCOR国家)中提高网络安全意识和知识。该项目开发了多个框架,以连续监控和捕获任何可疑的活动,并捕获任何潜在的潜在命名空间劫持问题。第一个任务侧重于识别和披露软件供应链生态系统中漏洞,这些漏洞可以由对手劫持现有软件包或分布式恶意代码进行探索。第二个任务集中在探索新兴元平台中用户特定世界内的潜在威胁。第三个任务涉及利用机器学习技术来检测和减轻分散的区块链应用程序中的欺诈性在线活动。最终,该项目旨在设计和开发轻巧,强大的防御系统,这些系统可以有效地减轻命名太空劫持威胁所带来的潜在安全威胁。通过长期观察和关于现实世界应用的大规模测量研究来评估整体安全风险。国防策略集成到现有的系统和协议中,并在现实世界情景中进行了彻底评估以证明其有效性。该奖项反映了NSF的法定任务,并通过使用基金会的知识分子和更广泛的影响审查标准来通过评估来评估。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Haining Wang其他文献

3D Digital Anthropometric Study on Chinese Head and Face
中国人头面部3D数字人体测量研究
On the anticyclotomic Iwasawa main conjecture for Hilbert modular forms of parallel weights
关于并行权重的希尔伯特模形式的反圆剖分岩泽主要猜想
Smart modification of ZSM-5 with manganese species for the removal of mercury
用锰物质对 ZSM-5 进行智能改性以去除汞
  • DOI:
  • 发表时间:
  • 期刊:
  • 影响因子:
    4.1
  • 作者:
    Haining Wang;Wei Ma;Yingbin Zhang;Jiangbo Yan;Dong Ye
  • 通讯作者:
    Dong Ye
BDR-Net: Bhattacharyya Distance-Based Distribution Metric Modeling for Rotating Object Detection in Remote Sensing
BDR-Net:用于遥感中旋转物体检测的基于 Bhattacharyya 距离的分布度量建模
A versatile platform of 2-(3,4-dihydroxyphenyl) pyrrolidine grafted graphene for preparation of various graphene-derived materials.
2-(3,4-二羟基苯基)吡咯烷接枝石墨烯的多功能平台,用于制备各种石墨烯衍生材料。
  • DOI:
    10.1002/asia.201403439
  • 发表时间:
    2015-05
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Haining Wang;Lanxia Xin;Jian Cui;Yehai Yan
  • 通讯作者:
    Yehai Yan

Haining Wang的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Haining Wang', 18)}}的其他基金

Phase II IUCRC Virginia Tech: Broadband Wireless Access and Applications Center (BWAC)
第二阶段 IUCRC 弗吉尼亚理工大学:宽带无线接入和应用中心 (BWAC)
  • 批准号:
    1822173
  • 财政年份:
    2018
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
SaTC: EDU: Integrating Cybersecurity Education with Cloud Computing
SaTC:EDU:将网络安全教育与云计算相结合
  • 批准号:
    1821744
  • 财政年份:
    2018
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TWC: Small: Collaborative: Reputation-Escalation-as-a-Service: Analyses and Defenses
TWC:小型:协作:声誉升级即服务:分析和防御
  • 批准号:
    1618117
  • 财政年份:
    2016
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
NeTS: Medium: Collaborative Research: Coexistence of Heterogeneous Wireless Access Technologies in the 5 GHz Bands
NeTS:媒介:协作研究:5 GHz 频段异构无线接入技术的共存
  • 批准号:
    1563832
  • 财政年份:
    2016
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: IHCS-Cybersystems: Integration of Protocol and Hardware Designs for Securing Internet Communications
合作研究:IHCS-Cyber​​systems:用于保护互联网通信的协议和硬件设计的集成
  • 批准号:
    0901537
  • 财政年份:
    2009
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
CSR: Small: An Efficient Framework for Real-Time Collaborative Browsing
CSR:小型:实时协作浏览的高效框架
  • 批准号:
    0916022
  • 财政年份:
    2009
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
CT-ISG: Collaborative Research: Intrusion Detection Techniques for Voice over IP
CT-ISG:协作研究:IP 语音入侵检测技术
  • 批准号:
    0627340
  • 财政年份:
    2006
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
CT-ER: Breaking Email Spam Laundering
CT-ER:打破电子邮件垃圾邮件洗钱活动
  • 批准号:
    0627339
  • 财政年份:
    2006
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant

相似国自然基金

钛基骨植入物表面电沉积镁氢涂层及其促成骨性能研究
  • 批准号:
    52371195
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目
CLMP介导Connexin45-β-catenin复合体对先天性短肠综合征的致病机制研究
  • 批准号:
    82370525
  • 批准年份:
    2023
  • 资助金额:
    49 万元
  • 项目类别:
    面上项目
人工局域表面等离激元高灵敏传感及其系统小型化的关键技术研究
  • 批准号:
    62371132
  • 批准年份:
    2023
  • 资助金额:
    49 万元
  • 项目类别:
    面上项目
优先流对中俄原油管道沿线多年冻土水热稳定性的影响机制研究
  • 批准号:
    42301138
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
用于稳定锌负极的界面层/电解液双向调控研究
  • 批准号:
    52302289
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317233
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338302
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了