课题基金 / 基金详情

ITR/SY: Mandatory Human Participation: A New Paradigm for Building Secure Systems

ITR/SY: Mandatory Human Participation: A New Paradigm for Building Secure Systems
ITR/SY:强制人类参与:构建安全系统的新范式
批准号:
0113933
负责人:
Jun Xu
金额:
$28.8万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2001
资助国家:
美国
项目状态:
已结题
起止时间:
2001-09-15 至 2004-08-31

项目摘要

项目成果

Jun Xu的其他基金

相似基金

相关文献

中文摘要
翻译
目前,自动攻击是对计算机安全的主要威胁。例如,最便宜的家用PC可以对目标系统进行数千次“探测”。强力密码(或PIN码)猜测程序每秒可以生成并尝试数万个候选密码。或者,一台家用电脑可能会试图用数千个“虚假”请求淹没一个网站。虽然有一些方法试图阻止这种攻击,但它们都可以在某种程度上被击败。我们提出了一种基于技术的新方法,可以区分机器人和人类之间的差异。因此,我们可以禁止自动攻击。我们的技术允许一种新的限制:现在系统可以坚持只有人类才能访问它们的宝贵资源,它们可以禁止机器人。这个问题的解决方案是受到图灵人工智能测试的启发。该解决方案的基本思想是,计算机系统在接受或执行交易之前,首先要求每个交易的作者解决一个谜题。谜题的内容将基于模式识别、视觉解释和自然语言理解领域的重大挑战问题。这些问题的本质属性是,人们可以很容易地解决它们,而计算机在可预见的未来不太可能解决它们。一个典型的谜题包括计算机系统向代理发送一个位图图像,代理用一个ascii字符串回复。图像可能包括一张图片和一个问题,以及一个关于这张图片的问题,比如“请键入下面的手写单词”或“这张图片中的哪些物体是可食用的?”计算机系统根据所提供的答案确定事务作者是否为人类。这一解决难题的过程引出了构建安全计算机系统的新框架。在这个框架中,人类必须直接参与(通过解决谜题并输入答案)身份验证或其他容易受到自动攻击的过程,这些过程被称为强制性人类参与(Mandatory human Participation, MHP)。显然,在此框架下不可能对受保护进程进行自动攻击。我们提出的研究是建立一个试点系统,可以用来证明MHP的基本思想。这将主要基于基于角色的方法。然后,我们计划仔细地测试和测量我们的系统的性能以及用户对它的接受程度。
英文摘要
Currently, automatic attacks are a major threat to computer security. For example, the cheapest home PC can try thousands of "probes" against a targeted system. A brute-force password (or PIN number) guessing program can generate and try tens of thousands of candidate passwords each second. Or a home PC could attempt to flood a web site with thousands of "bogus" requests. While there methods that attempt to stop such attacks they all can be defeated to some degree. We propose a new approach to this security based on technology that can tell the difference between robots and humans. Thus, we can disallow automatic attacks. Our technology allows a new kind of restriction: now systems can insist that only humans have access to their valuable resources and they can disallow robots.The proposed solution to the problem is inspired by Turing's test for artificial intelligence. The fundamental idea of the solution is for a computer system to first ask the author of every transaction to solve a puzzle before accepting or executing the transaction. The content of the puzzle will be based on grand challenge problems in the domains of pattern recognition, visual interpretation, and natural language understanding. These problems have the essential property that people can solve them easily while computers are not likely to solve them in the foreseeable future. A typical puzzle would consist of the computer system sending the agent a bit-mapped image and the agent replying with an ascii string. The image might include a picture and a question and a question about that picture, such as "Please type the following handwritten word" or "Which of the objects in this picture are edible?" The computer system determines whether the transaction author is a human based on the answer supplied.This puzzle-solving process leads to a new framework for building secure computer systems. In this framework, a human being has to be directly involved (by solving the puzzle and typing in the answer) in the authentication or other processes that are vulnerable to automatic attacks, referred to as Mandatory Human Participation (MHP). Apparently, no automatic attack to the protected process would be possible under this framework.Our proposed research is to build a pilot system that can be used to demonstrate the basic idea of MHP. This will be based mostly on character based methods. We then, plan to carefuly test and measure how well our system performs and how well it is received by users.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Fuzzing Large Software: Principles, Methods, and Tools
  • 批准号:
    2340198
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $55.55万
  • 财政年份:
    2024
  • 负责人:
    Jun Xu
  • 依托单位:
Travel: NSF Student Travel Grant for 2023 ACM Conference on Computer and Communications Security (CCS)
  • 批准号:
    2341773
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.5万
  • 财政年份:
    2023
  • 负责人:
    Jun Xu
  • 依托单位:
CICI: TCR: Prompt, Reliable, and Safe Security Update for Cyberinfrastructure
  • 批准号:
    2319880
  • 项目类别:
    Standard Grant
  • 资助金额:
    $119.81万
  • 财政年份:
    2023
  • 负责人:
    Jun Xu
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
  • 批准号:
    2213727
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.6万
  • 财政年份:
    2022
  • 负责人:
    Jun Xu
  • 依托单位:
国内基金
海外基金
基于Nurr1调节YAP-INF2-线粒体分裂途径探讨龙琥醒脑颗粒在SH-SY5Y细胞氧糖剥夺再灌注诱发的神经元损伤的保护作用研究
SY4835通过WEE1/DDR1双靶点抑制胰腺癌的作用及机制
  • 批准号:
    82373136
  • 项目类别:
    面上项目
  • 资助金额:
    48万元
  • 批准年份:
    2023
  • 负责人:
    张晓飞
  • 依托单位:
米糠黄酮抑制Aβ诱导的SH-SY5Y细胞中Tau蛋白过度磷酸化的分子机制研究
  • 批准号:
    2022JJ31009
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2022
  • 负责人:
    张琳
  • 依托单位:
天目山来源链霉菌Streptomyces sp. SY1322中morindolestatin类新颖咔唑生物碱获取及其铁死亡抑制活性研究
  • 批准号:
    LY21H300001
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2020
  • 负责人:
    马列峰
  • 依托单位: