CAREER: Securing and Evolving Internet Security Protocols for Naming and Routing
职业:保护和发展用于命名和路由的互联网安全协议
基本信息
- 批准号:2339378
- 负责人:
- 金额:$ 69.13万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2024
- 资助国家:美国
- 起止时间:2024-05-01 至 2029-04-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Internet's naming relies on the Domain Name System (DNS). Security Extensions of DNS (DNSSEC) and Resource Public Key Infrastructure (RPKI) safeguard the Internet's two critical aspects: naming through DNSSEC and routing through Border Gateway Protocol (BGP) using RPKI. Despite their pivotal importance, fully grasping the principles of RPKI and DNSSEC and managing them securely and effectively presents challenges, given their complexity and the diverse ways they are deployed and implemented across various entities. This project aims to improve the visibility, understanding, administration, and security of these essential components of Internet infrastructure.The project targets three main objectives. Firstly, it introduces a technique for evaluating DNS and RPKI clients at scale, leveraging residential virtual private network (VPN) proxies and perturbation techniques such as fuzzing and genetic algorithms to pinpoint and address security vulnerabilities. Secondly, it plans to analyze the causes of configuration errors from administrators' viewpoints, aiming to create machine learning-based tools for automatic correction of errors. Lastly, it plans to leverage RPKI and DNSSEC to improve the security of other network protocols, focusing on TLS revocation trust issues and the security assessment of critical infrastructure communication channels.By providing a clearer understanding and effective management tools for DNSSEC and RPKI, the project addresses fundamental challenges in ensuring the Internet remains a secure and trustworthy environment. This is important for maintaining the integrity and reliability of Internet naming and routing, which are foundational to the global digital ecosystem. The project's outcomes will be to help minimize mismanagement and vulnerabilities, towards enhancing the overall security and resilience of the Internet.The project's resources, including tools, datasets, and source code, will be made available at https://projects.netsecurelab.org, ensuring long-term access for researchers, practitioners, and policymakers interested in Internet security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
Internet的命名依赖于域名系统(DNS)。 DNS(DNSSEC)和资源公共密钥基础架构(RPKI)的安全扩展保护Internet的两个关键方面:通过DNSSEC命名和使用RPKI通过边界网关协议(BGP)进行路由。尽管它们的重要性至关重要,但鉴于它们的复杂性以及它们在各个实体中部署和实施的方式,完全掌握了RPKI和DNSSEC的原则,并安全有效地提出了挑战。该项目旨在提高互联网基础架构这些基本组成部分的可见性,理解,管理和安全性。该项目针对三个主要目标。首先,它引入了一种用于评估DNS和RPKI客户端的技术,利用住宅虚拟专用网络(VPN)代理和扰动技术(例如模糊和遗传算法)来确定和解决安全漏洞。其次,它计划从管理员的角度分析配置错误的原因,旨在创建基于机器学习的工具以自动校正错误。 Lastly, it plans to leverage RPKI and DNSSEC to improve the security of other network protocols, focusing on TLS revocation trust issues and the security assessment of critical infrastructure communication channels.By providing a clearer understanding and effective management tools for DNSSEC and RPKI, the project addresses fundamental challenges in ensuring the Internet remains a secure and trustworthy environment.这对于维持互联网命名和路由的完整性和可靠性很重要,这是全球数字生态系统的基础。 The project's outcomes will be to help minimize mismanagement and vulnerabilities, towards enhancing the overall security and resilience of the Internet.The project's resources, including tools, datasets, and source code, will be made available at https://projects.netsecurelab.org, ensuring long-term access for researchers, practitioners, and policymakers interested in Internet security.This award reflects NSF's statutory mission and has使用基金会的知识分子优点和更广泛的审查标准,被认为值得通过评估来支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Taejoong Chung其他文献
Privacy Guarantees of Bluetooth Low Energy Contact Tracing: A Case Study on COVIDWISE
低功耗蓝牙接触者追踪的隐私保证:COVIDWISE 案例研究
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:2.2
- 作者:
Salman Ahmed;Ya Xiao;Taejoong Chung;Carol J. Fung;M. Yung;D. Yao - 通讯作者:
D. Yao
Strategic bundling for content availability and fast distribution in BitTorrent
- DOI:
10.1016/j.comcom.2014.01.013 - 发表时间:
2014-05-01 - 期刊:
- 影响因子:
- 作者:
Jinyoung Han;Taejoong Chung;Seungbae Kim;Hyun-chul Kim;Jussi Kangasharju;Ted “Taekyoung” Kwon;Yanghee Choi - 通讯作者:
Yanghee Choi
RoVista: Measuring and Analyzing the Route Origin Validation (ROV) in RPKI
RoVista:测量和分析 RPKI 中的路线起点验证 (ROV)
- DOI:
10.1145/3618257.3624806 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Weitong Li;Zhexiao Lin;Md. Ishtiaq Ashiq;E. Aben;Romain Fontugne;Amreesh Phokeer;Taejoong Chung - 通讯作者:
Taejoong Chung
The Reality of Algorithm Agility: Studying the DNSSEC Algorithm Life-Cycle
算法敏捷性的现实:研究 DNSSEC 算法生命周期
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
M. Müller;W. Toorop;Taejoong Chung;J. Jansen;R. V. Rijswijk - 通讯作者:
R. V. Rijswijk
Delegation of TLS Authentication to CDNs using Revocable Delegated Credentials
使用可撤销委派凭证将 TLS 身份验证委派给 CDN
- DOI:
- 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Daegeun Yoon;Taejoong Chung;Yongdae Kim - 通讯作者:
Yongdae Kim
Taejoong Chung的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Taejoong Chung', 18)}}的其他基金
IMR: MT: Tools for Measuring Route Origin Validation in Resource Public Key Infrastructure (RPKI) at Scale
IMR:MT:用于大规模测量资源公钥基础设施 (RPKI) 中的路由源验证的工具
- 批准号:
2323137 - 财政年份:2023
- 资助金额:
$ 69.13万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Cryptographic accumulators and revocation of credentials
协作研究:SaTC:核心:中:加密累加器和凭证撤销
- 批准号:
2247306 - 财政年份:2023
- 资助金额:
$ 69.13万 - 项目类别:
Standard Grant
Travel: NSF Student Travel Grant for 2022 Internet Measurement Conference (IMC)
旅行:2022 年互联网测量会议 (IMC) 的 NSF 学生旅行补助金
- 批准号:
2234443 - 财政年份:2022
- 资助金额:
$ 69.13万 - 项目类别:
Standard Grant
CNS Core: Large: Collaborative Research: Towards an Evolvable Public Key Infrastructure
CNS 核心:大型:协作研究:迈向可进化的公钥基础设施
- 批准号:
2053363 - 财政年份:2020
- 资助金额:
$ 69.13万 - 项目类别:
Continuing Grant
CRII: SaTC: Measuring and Improving the Management of Resource Public Key Infrastructure (RPKI)
CRII:SaTC:衡量和改进资源公钥基础设施 (RPKI) 的管理
- 批准号:
2051166 - 财政年份:2020
- 资助金额:
$ 69.13万 - 项目类别:
Standard Grant
CRII: SaTC: Measuring and Improving the Management of Resource Public Key Infrastructure (RPKI)
CRII:SaTC:衡量和改进资源公钥基础设施 (RPKI) 的管理
- 批准号:
1850465 - 财政年份:2019
- 资助金额:
$ 69.13万 - 项目类别:
Standard Grant
CNS Core: Large: Collaborative Research: Towards an Evolvable Public Key Infrastructure
CNS 核心:大型:协作研究:迈向可进化的公钥基础设施
- 批准号:
1901090 - 财政年份:2019
- 资助金额:
$ 69.13万 - 项目类别:
Continuing Grant
相似国自然基金
恶劣条件下Web服务QoS预测与QoS确保的服务组合卸载方法研究
- 批准号:62172062
- 批准年份:2021
- 资助金额:58.00 万元
- 项目类别:面上项目
恶劣条件下Web服务QoS预测与QoS确保的服务组合卸载方法研究
- 批准号:
- 批准年份:2021
- 资助金额:58 万元
- 项目类别:面上项目
为明天城市的清洁空气融资: 通过土地增值回馈确保城市可持续发展、提高城市空气质量的潜力
- 批准号:71961137006
- 批准年份:2019
- 资助金额:190 万元
- 项目类别:国际(地区)合作与交流项目
反馈时延与丢包下确保事件触发线性系统稳定的反馈网络带宽条件研究
- 批准号:
- 批准年份:2019
- 资助金额:59 万元
- 项目类别:面上项目
确保人体安全的无线可充电传感器网络系统优化算法研究
- 批准号:61502229
- 批准年份:2015
- 资助金额:21.0 万元
- 项目类别:青年科学基金项目
相似海外基金
Securing the Future: Inclusive Cybersecurity Education for All
确保未来:全民包容性网络安全教育
- 批准号:
2350448 - 财政年份:2024
- 资助金额:
$ 69.13万 - 项目类别:
Standard Grant
CAREER: Securing Next-Generation Transportation Infrastructure: A Traffic Engineering Perspective
职业:保护下一代交通基础设施:交通工程视角
- 批准号:
2339753 - 财政年份:2024
- 资助金额:
$ 69.13万 - 项目类别:
Standard Grant
Ownership-based Alias Analysis for Securing Unsafe Rust Programs
用于保护不安全 Rust 程序的基于所有权的别名分析
- 批准号:
DP240103194 - 财政年份:2024
- 资助金额:
$ 69.13万 - 项目类别:
Discovery Projects
CAREER: Securing Off-premise Digital Services in the Presence of Strategic Incentives
职业:在战略激励的情况下确保场外数字服务的安全
- 批准号:
2337338 - 财政年份:2024
- 资助金额:
$ 69.13万 - 项目类别:
Continuing Grant
CAREER: Securing the Future of Electric Field Measurements in Space Physics
职业:确保空间物理电场测量的未来
- 批准号:
2338825 - 财政年份:2024
- 资助金额:
$ 69.13万 - 项目类别:
Continuing Grant