Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense

协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查

基本信息

项目摘要

This project delves into the emerging security risks associated with naming space hijacking attacks targeting Internet applications. In this type of attack, an adversary exploits similarities and confusion in names of domains and resources in cyber space (e.g., Amazon.com vs. Amazom.com) to target users and even software developers, leading to financial loss, intellectual property theft, reputation damage, and disruption of normal operations for unsuspecting users. The project’s novelty is the assessment of the security risks of these types of attacks systematically and quantitatively across vital platforms and applications, including software supply chain ecosystems, the Metaverse, and decentralized financial applications (Web3). This investigation also enables the development of effective defense mechanisms and provides a strong safety guarantee to Internet users. The project's broader significance and importance lie in securing current and future Internet applications, thereby enhancing the availability and reliability of Internet services. Additionally, educational efforts are devoted to the curriculum design of new cybersecurity courses with a focus on Web3 applications. Outreach activities are also conducted to promote the involvement of underrepresented minorities in computing and to enhance cybersecurity awareness and knowledge in the states of Virginia and Delaware (an EPSCoR state).This project develops multiple frameworks to continuously monitor and capture any suspicious activities and pinpoint potential naming space hijacking issues. The first task focuses on the identification and disclosure of vulnerabilities within software supply chain ecosystems that can be exploited by adversaries to hijack existing packages or distribute malicious code. The second task centers on exploring potential threats within user-specific worlds in emerging Metaverse platforms. The third task involves leveraging machine learning techniques to detect and mitigate fraudulent online activities within decentralized blockchain applications. Ultimately, the project aims to design and develop lightweight and robust defense systems that can effectively mitigate the potential security threats posed by naming space hijacking threats. The overall security risks are evaluated through long-term observation and large-scale measurement studies on real-world applications. The defense strategies are integrated in existing systems and protocols, and thoroughly evaluated on real-world scenarios to demonstrate their effectiveness.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该项目深入研究了与针对互联网应用程序的命名空间劫持攻击相关的新兴安全风险。在这种类型的攻击中,对手利用网络空间中的域和资源的名称的相似性和混淆(例如,Amazon.com vs. Amazom.com)以针对用户甚至软件开发人员,导致财务损失、知识产权盗窃、声誉损害以及对不知情用户的正常操作的破坏。该项目的新奇之处在于,系统地、定量地评估了这些类型的攻击在重要平台和应用程序中的安全风险,包括软件供应链生态系统、Metaverse和分散式金融应用程序(Web3)。这一调查也使有效的防御机制得以发展,为互联网用户提供了强有力的安全保障。该项目更广泛的意义和重要性在于确保当前和未来的互联网应用,从而提高互联网服务的可用性和可靠性。此外,教育工作致力于新的网络安全课程的课程设计,重点是Web3应用程序。还开展了推广活动,以促进代表性不足的少数民族参与计算,并提高弗吉尼亚州和特拉华州(EPSCoR州)的网络安全意识和知识。该项目开发了多个框架,以持续监控和捕获任何可疑活动,并查明潜在的命名空间劫持问题。第一项任务的重点是识别和披露软件供应链生态系统中的漏洞,这些漏洞可能被对手利用来劫持现有软件包或分发恶意代码。第二个任务是在新兴的Metaverse平台上探索用户特定世界中的潜在威胁。第三项任务涉及利用机器学习技术来检测和减轻分散式区块链应用程序中的欺诈性在线活动。最终,该项目旨在设计和开发轻量级和强大的防御系统,可以有效地减轻命名空间劫持威胁所带来的潜在安全威胁。通过对实际应用的长期观察和大规模测量研究来评估整体安全风险。这些防御策略被集成到现有的系统和协议中,并在真实世界的场景中进行了彻底的评估,以证明其有效性。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Haining Wang其他文献

A versatile platform of 2-(3,4-dihydroxyphenyl) pyrrolidine grafted graphene for preparation of various graphene-derived materials.
2-(3,4-二羟基苯基)吡咯烷接枝石墨烯的多功能平台,用于制备各种石墨烯衍生材料。
  • DOI:
    10.1002/asia.201403439
  • 发表时间:
    2015-05
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Haining Wang;Lanxia Xin;Jian Cui;Yehai Yan
  • 通讯作者:
    Yehai Yan
BDR-Net: Bhattacharyya Distance-Based Distribution Metric Modeling for Rotating Object Detection in Remote Sensing
BDR-Net:用于遥感中旋转物体检测的基于 Bhattacharyya 距离的分布度量建模
Smart modification of ZSM-5 with manganese species for the removal of mercury
用锰物质对 ZSM-5 进行智能改性以去除汞
  • DOI:
  • 发表时间:
  • 期刊:
  • 影响因子:
    4.1
  • 作者:
    Haining Wang;Wei Ma;Yingbin Zhang;Jiangbo Yan;Dong Ye
  • 通讯作者:
    Dong Ye
3D Digital Anthropometric Study on Chinese Head and Face
中国人头面部3D数字人体测量研究
RCB: A Simple and Practical Framework for Real-time Collaborative Browsing
RCB:一个简单实用的实时协作浏览框架
  • DOI:
  • 发表时间:
    2009
  • 期刊:
  • 影响因子:
    0
  • 作者:
    C. Yue;Zi Chu;Haining Wang
  • 通讯作者:
    Haining Wang

Haining Wang的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Haining Wang', 18)}}的其他基金

Phase II IUCRC Virginia Tech: Broadband Wireless Access and Applications Center (BWAC)
第二阶段 IUCRC 弗吉尼亚理工大学:宽带无线接入和应用中心 (BWAC)
  • 批准号:
    1822173
  • 财政年份:
    2018
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
SaTC: EDU: Integrating Cybersecurity Education with Cloud Computing
SaTC:EDU:将网络安全教育与云计算相结合
  • 批准号:
    1821744
  • 财政年份:
    2018
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TWC: Small: Collaborative: Reputation-Escalation-as-a-Service: Analyses and Defenses
TWC:小型:协作:声誉升级即服务:分析和防御
  • 批准号:
    1618117
  • 财政年份:
    2016
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
NeTS: Medium: Collaborative Research: Coexistence of Heterogeneous Wireless Access Technologies in the 5 GHz Bands
NeTS:媒介:协作研究:5 GHz 频段异构无线接入技术的共存
  • 批准号:
    1563832
  • 财政年份:
    2016
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: IHCS-Cybersystems: Integration of Protocol and Hardware Designs for Securing Internet Communications
合作研究:IHCS-Cyber​​systems:用于保护互联网通信的协议和硬件设计的集成
  • 批准号:
    0901537
  • 财政年份:
    2009
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
CSR: Small: An Efficient Framework for Real-Time Collaborative Browsing
CSR:小型:实时协作浏览的高效框架
  • 批准号:
    0916022
  • 财政年份:
    2009
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
CT-ISG: Collaborative Research: Intrusion Detection Techniques for Voice over IP
CT-ISG:协作研究:IP 语音入侵检测技术
  • 批准号:
    0627340
  • 财政年份:
    2006
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
CT-ER: Breaking Email Spam Laundering
CT-ER:打破电子邮件垃圾邮件洗钱活动
  • 批准号:
    0627339
  • 财政年份:
    2006
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant

相似国自然基金

Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 批准年份:
    2024
  • 资助金额:
    0.0 万元
  • 项目类别:
    省市级项目
Cell Research
  • 批准号:
    31224802
  • 批准年份:
    2012
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research
  • 批准号:
    31024804
  • 批准年份:
    2010
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research (细胞研究)
  • 批准号:
    30824808
  • 批准年份:
    2008
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
  • 批准号:
    10774081
  • 批准年份:
    2007
  • 资助金额:
    45.0 万元
  • 项目类别:
    面上项目

相似海外基金

Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317233
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338302
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330941
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
  • 批准号:
    2413046
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: EDU: Adversarial Malware Analysis - An Artificial Intelligence Driven Hands-On Curriculum for Next Generation Cyber Security Workforce
协作研究:SaTC:EDU:对抗性恶意软件分析 - 下一代网络安全劳动力的人工智能驱动实践课程
  • 批准号:
    2230609
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: EDU: RoCCeM: Bringing Robotics, Cybersecurity and Computer Science to the Middled School Classroom
合作研究:SaTC:EDU:RoCCeM:将机器人、网络安全和计算机科学带入中学课堂
  • 批准号:
    2312057
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Medium: Understanding the Impact of Privacy Interventions on the Online Publishing Ecosystem
协作研究:SaTC:核心:媒介:了解隐私干预对在线出版生态系统的影响
  • 批准号:
    2237329
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了