NSF Convergence Accelerator Track G: AVOID 5G: Automated Verification Of Internet Data-paths for 5G
NSF Convergence Accelerator Track G: AVOID 5G: Automated Verification Of Internet Data-paths for 5G
批准号:
2326928
负责人:
Alexander Marder
金额:
$500.0万
依托单位:
依托单位国家:
美国
项目类别:
Cooperative Agreement
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-09-01 至 2025-08-31
中文摘要
美国国防部(DOD)使用商用第五代(5G)网络,需要前所未有地依赖不受信任的第三方通信基础设施,包括直接连接到5G设备的5G基站和5G通信基础的互联网基础设施。通过非合作商业5G基础设施运行时的核心问题是,未知的基础设施可能会将通信暴露给对手。穿越对手控制的基础设施,使国防部的对手能够识别、破坏或提取情报,甚至是从加密通信中提取情报。越来越复杂的混淆技术已经与检测混淆的网络智能技术形成了军备竞赛。随着每一次新的混淆,国防部永远无法知道它是否愚弄了对手,或者对手是否只是在欺骗国防部进入一种虚假的安全感。通过5G网络运营的下一个重大能力飞跃可能来自于复杂的分析,这些分析提供了通信基础设施内威胁的态势感知,以及沿着良性路径动态路由通信的实施。通过一个结合了跨学科和部门专业知识的团队,该项目将追求这种变革性的能力,并加速新的国防部5G防御的融合:重组通信路径,以避免对手控制的基站,网络和位置,从而保持国防部通信不被对手观察到。该项目提出了一个系统-互联网数据路径自动验证(AVOID)-通过两个可交付成果创建这种前所未有的能力,以解决5G通信的两个高风险攻击向量。攻击1的目标是潜在的对手控制商业基站在世界任何地方,使他们能够破坏国防部的通信在进入点介绍无线网络。AVOID将识别恶意和监视基站,并为国防部设备提供连接到特定良性基站的机制。可扩展2打击我们的对手将复杂的网络分析应用于任何穿越他们控制的网络或领土的国防部通信的能力。AVOID将在路由系统中嵌入拓扑和地理感知,并为国防部的通信提供一种机制,以避免全球互联网上的敌对控制区域,并为国防部控制的网络提供安全路径。结合起来,这些交付成果将提供端到端的对手规避,而不需要修改国防部网络中的现有应用程序或路由器,也不需要任何第三方网络的合作。其智力优势来自于解决一个长期未解决的国家安全挑战,这需要七个专业领域的融合:5G通信和网络管理;互联网路径分析;覆盖路由;运营网络安全;测试和评估目标国防部的情况下,技术过渡和专业项目管理。避免5G也将广泛影响社会。这些可交付成果补充了零信任架构、安全5G实施和正在进行的混淆技术开发的更广泛领域。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Department of Defense (DOD) use of commercial 5th Generation (5G) networks entails unprecedented reliance on untrusted third-party communications infrastructure, including the 5G base stations that connect directly to 5G devices and the Internet infrastructure that underlies 5G communications. The core problem when operating through non-cooperative commercial 5G infrastructure is that the unknown infrastructure potentially exposes communications to an adversary. Traversing adversary-controlled infrastructure allows DOD’s adversaries to recognize, disrupt, or extract intelligence even from encrypted communications. Increasingly complex obfuscation techniques have created an arms race against network intelligence techniques to detect the obfuscation. With each new obfuscation, DOD can never know if it fools the adversary, or if the adversary is simply lulling DOD into a false sense of security.The next great capability leap for operating through 5G networks will likely come from sophisticated analytics that provide situational awareness of threats within the communications infrastructure, and an implementation that dynamically routes communications along benign paths. Through a team that combines expertise across disciplines and sectors, this project will pursue this transformative capability and accelerate convergence on a new DOD 5G defense: restructuring communication paths to avoid adversary-controlled base stations, networks, and locations, thereby keeping DOD communications unobservable by the adversary. This project proposes a system—Automated Verification Of Internet Data-paths (AVOID)—that creates this unprecedented capability through two deliverables that tackle two high risk attack vectors for 5G communications. Deliverable 1 targets the potential for adversaries to control commercial base stations anywhere in the world, allowing them to subvert DOD communications at the point of entry intro the wireless network. AVOID will recognize malicious and surveillance base stations, and provide a mechanism for DOD devices to connect to specific benign base stations. Deliverable 2 combats the ability of our adversaries to apply sophisticated and complex network analytics to any DOD communications that traverse networks or territory they control. AVOID will embed topologic and geographic awareness into a routing system, and provide a mechanism for DOD’s communications to avoid adversary-controlled territory across the global Internet and provide safe paths to DOD-controlled networks. Combined, these deliverables will provide end-to-end adversary avoidance without requiring modification to existing applications or routers in DOD networks, or cooperation by any third-party network.The intellectual merit comes from addressing a persistently unsolved national security challenge which requires convergence across seven areas of expertise: 5G communication and network management; Internet path analytics; overlay routing; operational network security; test and evaluation that targets DOD scenarios; technology transition; and professional project management. AVOID 5G will also broadly impact society. The deliverables complement the broader landscape of zero-trust architectures, secure 5G implementations, and ongoing obfuscation technique development. Government partners included in the team provide a channel for research and education outcomes, including cybersecurity workforce training.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF Convergence Accelerator Track G: 5G Traffic Sovereignty: Operating Through an Adversarial Internet
-
批准号:2226460
-
项目类别:Standard Grant
-
资助金额:$75.0万
-
财政年份:2022
-
负责人:Alexander Marder
-
依托单位:
CRII: CNS: Cloud Cartography: Measurement Capabilities for the Modern Internet
-
批准号:2105393
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2021
-
负责人:Alexander Marder
-
依托单位:
海外基金