A New Approach for Securing Systems Using Automated Adaptive Intrusion Response
A New Approach for Securing Systems Using Automated Adaptive Intrusion Response
批准号:
0208877
负责人:
Ramasubramanian Sekar
金额:
$0.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-08-01 至 2007-07-31
中文摘要
网络信息系统在发电和配电、交通、商业和国家安全等关键基础设施中发挥着越来越重要的作用。CERT协调中心等组织报告的持续不断的安全事件表明,尽管在保护系统方面做出了最大的努力,但“黑客”攻击甚至会渗透到最好的防御机制中。为了科普这种攻击,需要开发能够检测和响应这种攻击的新技术。不幸的是,现有的方法主要集中在事后检测这种攻击。此外,入侵响应主要依赖于人的参与。这两个因素意味着快速进展的攻击(例如,程序化攻击)可以在任何保护性反应启动之前造成重大损害。从这种损坏中恢复是一项劳动密集型工作,并且会使目标系统在数小时内(如果不是数天的话)不可用。该项目将开发新的方法,自动入侵响应,使目标系统可以保护自己免受攻击造成的严重损害。它将建立在提出者的成功研究,基于规范的入侵检测。该项目的关键技术组件包括:规范语言增强以表达响应动作,隔离受损进程的技术,使它们不会干扰系统的其余部分,以及欺骗技术,可以在保护目标系统的同时为攻击者提供成功的假象。
英文摘要
Networked information systems play an increasingly important role in critical infrastructures such as power generation and distribution, transportation, commerce, and national security. The continuing spate of security incidents reported by organizations such as CERT Coordination Center demonstrates that in spite of best efforts in securing systems, "hacker" attacks will penetrate even the best defense mechanisms. To cope with such attacks, new techniques need to be developed that can detect and respond to such attacks. Unfortunately, existing approaches focus primarily on after-the-fact detection of such attacks. Moreover, intrusion response relies primarily on human involvement. These two factors mean that fast-progressing attacks (e.g., programmed attacks) can effect significant damage before any protective response is launched. Recovery from such damage is labor-intensive, and will render the target system unavailable for hours if not days. This project will develop new approach that automates intrusion responses so that the target system can defend itself from serious damage due to attacks. It will build on the proposer's successful research in specification-based intrusion detection. Key technical components of this project include: specification language enhancements to express response actions, techniques for isolating compromised processes so that they do not interfere with the rest of the system, and deception techniques that can provide an illusion of success to attacker while protecting the target the system.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: WebSheets: A New Privacy-Centric Framework for Web Applications
-
批准号:2153056
-
项目类别:Standard Grant
-
资助金额:$101.93万
-
财政年份:2022
-
负责人:Ramasubramanian Sekar
-
依托单位:
SaTC: CORE: Medium: Collaborative: RADAR: Real-time Advanced Detection and Attack Reconstruction
-
批准号:1918667
-
项目类别:Standard Grant
-
资助金额:$59.99万
-
财政年份:2019
-
负责人:Ramasubramanian Sekar
-
依托单位:
TWC: Small: A platform for enhancing security of binary code
-
批准号:1319137
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2013
-
负责人:Ramasubramanian Sekar
-
依托单位:
CT-T: Proactive Techniques for Preserving System Integrity: A Basis for Robust Defense Against Malware
-
批准号:0831298
-
项目类别:Continuing Grant
-
资助金额:$100.0万
-
财政年份:2008
-
负责人:Ramasubramanian Sekar
-
依托单位:
Collaborative Project: An Extensible Software Platform for a Virtual Cyber Security Laboratory
-
批准号:0817188
-
项目类别:Standard Grant
-
资助金额:$19.1万
-
财政年份:2008
-
负责人:Ramasubramanian Sekar
-
依托单位:
Center for Information Protection: A Multi-University Industry/University Collaborative Research Center
-
批准号:0733935
-
项目类别:Continuing Grant
-
资助金额:$25.0万
-
财政年份:2007
-
负责人:Ramasubramanian Sekar
-
依托单位:
CT: New Techniques for Attack Detection, Prevention and Immunization
-
批准号:0627687
-
项目类别:Continuing Grant
-
资助金额:$35.0万
-
财政年份:2006
-
负责人:Ramasubramanian Sekar
-
依托单位:
A Plan for Developing a Multi-University Industry/University Collaborative Research Center on Cyber Security
-
批准号:0532030
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2005
-
负责人:Ramasubramanian Sekar
-
依托单位:
Scholarship for Service in Information Assurance
-
批准号:0417103
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Ramasubramanian Sekar
-
依托单位:
Collaborative Research: Capacity Expansion in Information Assurance
-
批准号:0313858
-
项目类别:Standard Grant
-
资助金额:$19.99万
-
财政年份:2003
-
负责人:Ramasubramanian Sekar
-
依托单位:
A Model-Based Approach for Securing Software Systems
-
批准号:0098154
-
项目类别:Continuing Grant
-
资助金额:$19.98万
-
财政年份:2001
-
负责人:Ramasubramanian Sekar
-
依托单位:
国内基金
海外基金
EnSite array指导下对Stepwise approach无效的慢性房颤机制及消融径线设计的实验研究
-
批准号:81070152
-
项目类别:面上项目
-
资助金额:10.0万元
-
批准年份:2010
-
负责人:唐恺
-
依托单位: