Towards Scalable Computer Defenses
迈向可扩展的计算机防御
基本信息
- 批准号:RGPIN-2014-03782
- 负责人:
- 金额:$ 2.33万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Discovery Grants Program - Individual
- 财政年份:2018
- 资助国家:加拿大
- 起止时间:2018-01-01 至 2019-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
We seem to be losing the battle of computer security. Despite increasing investments in software security on all sides, attackers are still able to bypass defenses seemingly at will. The situation is so bad that large network administrators must assume that their networks have already been infiltrated no matter how much effort they put in to their defenses.**We assert that the key reason for this seemingly hopeless situation is that attacks are scalable while computer defenses are not. Attackers can make fixed-cost investments in attack development (e.g., finding a zero-day exploit, deveolping an exploit deployment mechanism) that can allow them to compromise millions of hosts. Defenders, however, can expend an unbounded amount of resources deploying firewalls, installing anti-malware software, running intrusion prevention systems, and manually auditing their software and configuration, only to find that their systems have still been compromised - assuming they are fortunate enough to even notice.**We propose to study the theory and practice behind making scalable defenses. The key insight for building scalable defenses is that attacker work should scale with the population size of the defenders: attackers should be required to expend effort proportional to the number of hosts that are to be compromised. The key questions addressed in this research are first, how can we define defense scalability in terms of software architecture and economics, and to what extent are current defenses scalable. If this research is successful it should provide a foundation for building and evaluating a new generation of scalable computer defenses.
我们似乎正在输掉这场计算机安全之战。尽管各方在软件安全方面的投资不断增加,但攻击者似乎仍然能够随意绕过防御。这种情况非常糟糕,以至于大型网络管理员必须假设他们的网络已经被渗透,无论他们投入多少努力进行防御。**我们断言,这种看似无望的情况的关键原因是攻击是可扩展的,而计算机防御是不可扩展的。攻击者可以在攻击开发上进行固定成本的投资(例如,找到一个零日漏洞,开发一个漏洞部署机制),这可以让他们危及数百万台主机。然而,防御者可能会花费大量资源部署防火墙、安装反恶意软件、运行入侵防御系统,并手动审核他们的软件和配置,结果却发现他们的系统仍然受到了威胁——假设他们足够幸运,甚至注意到了这一点。**我们建议研究可扩展防御背后的理论和实践。构建可扩展防御的关键观点是,攻击者的工作应该与防御者的数量一起扩展:应该要求攻击者花费与要破坏的主机数量成比例的精力。本研究解决的关键问题是,首先,我们如何根据软件架构和经济定义防御可伸缩性,以及当前防御可伸缩性的程度。如果这项研究取得成功,它将为构建和评估新一代可扩展的计算机防御提供基础。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Somayaji, Anil其他文献
Somayaji, Anil的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Somayaji, Anil', 18)}}的其他基金
Towards Scalable Computer Defenses
迈向可扩展的计算机防御
- 批准号:
RGPIN-2014-03782 - 财政年份:2017
- 资助金额:
$ 2.33万 - 项目类别:
Discovery Grants Program - Individual
Towards Scalable Computer Defenses
迈向可扩展的计算机防御
- 批准号:
RGPIN-2014-03782 - 财政年份:2016
- 资助金额:
$ 2.33万 - 项目类别:
Discovery Grants Program - Individual
Towards Scalable Computer Defenses
迈向可扩展的计算机防御
- 批准号:
RGPIN-2014-03782 - 财政年份:2015
- 资助金额:
$ 2.33万 - 项目类别:
Discovery Grants Program - Individual
Towards Scalable Computer Defenses
迈向可扩展的计算机防御
- 批准号:
RGPIN-2014-03782 - 财政年份:2014
- 资助金额:
$ 2.33万 - 项目类别:
Discovery Grants Program - Individual
Securing software with automated functional diversity
具有自动化功能多样性的软件安全
- 批准号:
298545-2009 - 财政年份:2013
- 资助金额:
$ 2.33万 - 项目类别:
Discovery Grants Program - Individual
Mobile Authentication & Fraud Detection
手机认证
- 批准号:
451552-2013 - 财政年份:2013
- 资助金额:
$ 2.33万 - 项目类别:
Collaborative Research and Development Grants
Swipe-based implicit authentication for smartphones
针对智能手机的基于滑动的隐式身份验证
- 批准号:
442654-2012 - 财政年份:2012
- 资助金额:
$ 2.33万 - 项目类别:
Engage Grants Program
Securing software with automated functional diversity
具有自动化功能多样性的软件安全
- 批准号:
298545-2009 - 财政年份:2012
- 资助金额:
$ 2.33万 - 项目类别:
Discovery Grants Program - Individual
Securing software with automated functional diversity
具有自动化功能多样性的软件安全
- 批准号:
298545-2009 - 财政年份:2011
- 资助金额:
$ 2.33万 - 项目类别:
Discovery Grants Program - Individual
Securing software with automated functional diversity
具有自动化功能多样性的软件安全
- 批准号:
298545-2009 - 财政年份:2010
- 资助金额:
$ 2.33万 - 项目类别:
Discovery Grants Program - Individual
相似国自然基金
Scalable Learning and Optimization: High-dimensional Models and Online Decision-Making Strategies for Big Data Analysis
- 批准号:
- 批准年份:2024
- 资助金额:万元
- 项目类别:合作创新研究团队
相似海外基金
Scalable and Automated Tuning of Spin-based Quantum Computer Architectures
基于自旋的量子计算机架构的可扩展和自动调整
- 批准号:
2887634 - 财政年份:2024
- 资助金额:
$ 2.33万 - 项目类别:
Studentship
CAREER: Building Scalable and Reliable Composable Computer Architectures
职业:构建可扩展且可靠的可组合计算机架构
- 批准号:
2341039 - 财政年份:2024
- 资助金额:
$ 2.33万 - 项目类别:
Continuing Grant
CAREER: Enabling Scalable and Resilient Quantum Computer Architectures through Synergistic Hardware-Software Co-Design
职业:通过协同硬件软件协同设计实现可扩展且有弹性的量子计算机架构
- 批准号:
2340267 - 财政年份:2024
- 资助金额:
$ 2.33万 - 项目类别:
Continuing Grant
Computer Vision for Analytical Chemistry (CVAC): Scalable Productivity for Chemical Manufacturing
分析化学计算机视觉 (CVAC):化学制造的可扩展生产力
- 批准号:
MR/T043458/1 - 财政年份:2021
- 资助金额:
$ 2.33万 - 项目类别:
Fellowship
Scalable Data-Driven Computer Vision
可扩展的数据驱动计算机视觉
- 批准号:
503063-2017 - 财政年份:2018
- 资助金额:
$ 2.33万 - 项目类别:
Postdoctoral Fellowships
Collaborative Research: CS4SF: A Scalable Model for Preparing High School Teachers to Provide Rigorous, Inclusive Computer Science Instruction
合作研究:CS4SF:一个可扩展的模型,帮助高中教师提供严格、包容的计算机科学教学
- 批准号:
1837699 - 财政年份:2018
- 资助金额:
$ 2.33万 - 项目类别:
Standard Grant
Collaborative Research: CS4SF: A Scalable Model for Preparing High School Teachers to Provide Rigorous, Inclusive Computer Science Instruction
合作研究:CS4SF:一个可扩展的模型,帮助高中教师提供严格、包容的计算机科学教学
- 批准号:
1837552 - 财政年份:2018
- 资助金额:
$ 2.33万 - 项目类别:
Standard Grant
Collaborative Research: Developing a Systemic, Scalable Model to Broaden Participation in Middle School Computer Science
合作研究:开发系统的、可扩展的模型以扩大中学计算机科学的参与
- 批准号:
1837240 - 财政年份:2018
- 资助金额:
$ 2.33万 - 项目类别:
Standard Grant
Collaborative Research: Developing a Systemic, Scalable Model to Broaden Participation in Middle School Computer Science
合作研究:开发系统的、可扩展的模型以扩大中学计算机科学的参与
- 批准号:
1837439 - 财政年份:2018
- 资助金额:
$ 2.33万 - 项目类别:
Standard Grant
Qubit state readout using tunnel diodes for the realisation of a scalable quantum computer
使用隧道二极管读出量子位状态以实现可扩展的量子计算机
- 批准号:
18K14081 - 财政年份:2018
- 资助金额:
$ 2.33万 - 项目类别:
Grant-in-Aid for Early-Career Scientists