课题基金 / 基金详情

ITR: Architecture for Surviving Denial-of-Service Attacks on Battery-powered Mobile Computers

ITR: Architecture for Surviving Denial-of-Service Attacks on Battery-powered Mobile Computers
ITR:抵御电池供电移动计算机拒绝服务攻击的架构
批准号:
0219801
负责人:
Thomas Martin
金额:
$41.17万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-09-15 至 2006-08-31

项目摘要

项目成果

Thomas Martin的其他基金

相似基金

相关文献

中文摘要
翻译
电池供电的计算设备的持续扩散已经产生了一种新型的“拒绝服务”攻击:如果攻击者可以耗尽设备的电池,例如,通过让它反复执行耗能程序,设备将无法操作。与其他拒绝服务攻击不同的是,攻击者必须保持攻击才能继续拒绝服务,攻击者可以在电池完全放电后停止攻击电池供电的设备,并继续攻击另一个设备。正如计算机网络的出现使得计算机病毒、特洛伊木马和其他计算机安全漏洞的数量增加一样,移动的计算设备的可用性的增加和对移动计算设备的依赖性的增加将导致“与电力相关的安全攻击”的产生和传播。“因此,移动的计算设备中的电池是一个脆弱点,必须加以保护。在一个典型的移动的计算机中,在一组使用条件下,用户在一小部分时间内积极使用设备,而设备在其余时间内处于空闲状态,期望电池提供一定的电池寿命。当设备空闲时,电源管理软件会将设备置于低功耗待机和睡眠模式,从而延长设备的电池寿命。 如果攻击者可以通过保持设备处于活动状态来阻止设备进入低功耗模式,则电池寿命可能会大幅缩短。攻击者消耗电池的方法主要有三种:(1)服务请求攻击,其中通常通过网络向受害者重复请求服务-即使不提供服务,受害者也必须花费能量来决定是否荣誉请求;(2)良性电源病毒,其中受害者重复执行有效但耗能的任务, (3)正在进行的研究通过定义(1)用于保证最小电池寿命的移动的计算设备的电源安全架构,以及(2)用于识别与电源相关的安全漏洞的设计流程来防御这些攻击。这项工作通过防止对设备电池的攻击(包括服务请求攻击、良性电源病毒和恶性电源病毒)来保证最低的电池寿命。整个电源安全架构在系统中采用了两个基本的安全功能,多层身份验证和能量签名监视器:多层身份验证确保所提供的所有不可信服务消耗少于一定量的能量。额外的资源只提交给那些已经获得更高信任级别的请求者。能量特征监视器捕获那些已经进入系统以执行高能耗应用程序或服务的入侵。该研究包括以下任务:* 分类的服务,以保证最小的使命时间 * 生成,捕获和验证的能源签名的可信服务请求 * 验证的架构,通过实施电源相关的安全攻击这个项目有一些直接的好处,在信息技术的最先进的。 第一,它保护电池供电的移动的计算系统(信息技术基础设施的一个日益重要的部分)免受潜在的破坏性形式的安全攻击。其次,它探索了一个新的问题,并吸引了人们对一个应该由大量研究人员共同研究的领域的关注。这项研究的更广泛的影响是确保移动的计算继续对不断增长的社区具有吸引力。 通过防止基于电池的安全攻击,这项工作确保了移动的计算被更广泛的社会群体持续采用。
英文摘要
The ongoing proliferation of battery-powered computing devices has created a new type of "denial of service" attack: If an attacker can drain a device's battery, for example, by having it repeatedly execute a energy-hungry program, the device will be rendered inoperable. Unlike other denial-of-service attacks where the attacker must keep up the attack in order to continue to deny the service, the attacker can quit attacking a battery-powered device once she has fully discharged thebattery, and move on to attack another device. Just as the advent of computer networks enabled an increase in the number of computer viruses, Trojan horses, and other computer security breaches, the rising availability of and increasing dependence on mobile computing devices will lead to the creation and spread of "power-related security attacks." The battery in a mobile computing device is thus a point of vulnerability and must be protected. The purpose of this research is to defend against attacks on the battery.In a typical mobile computer, the battery is expected to give a certain battery life under a set of usage conditions where the user is actively using the device for a small fractionof the time, and the device is idle the rest of the time. When the device is idle, power management software puts thedevice into low power standby and sleep modes, extending the device's battery life. If an attacker can prevent the device from entering low power modes by keeping it active, the battery life can be drastically shortened. There are three main methods for an attacker to drain the battery: (1)Service request attacks, where repeated requests are made to the victim for services, typically over a network--even if the service is not provided, the victim must expend energy deciding whether or not to honor the request; (2) benign power viruses, where the victim is made to execute a valid but energy-hungry task repeatedly, and (3) malignant power viruses, where an attacker modifies a program to make it consume more energy than it would otherwise.The ongoing research defends against these attacks by defining (1) a power-secure architecture for mobile computing devices that guarantees a minimum battery life, and (2) a design flow for identifying power-related security vulnerabilities. This work guarantees a minimum battery life by guarding against attacks on the device's battery, including service request attacks, benign power viruses, and malignant power viruses. The overall power-secure architecture employs twofundamental security features in the system, multi-layer authentication and energy signature monitor: The multi-layer authentication ensures that all untrusted services rendered consume less than a certain amount of energy. Additional resources are committed only to those requesters who have obtained further levels of trust. The energy signature monitor catches those intrusions that have entered the system to execute an energy-hungry application or service. The researchconsists of the following tasks:* Classification of services to guarantee minimum mission time* Generation, capture, and validation of energy signaturesfor trusted service requests* Validation of the architecture by implementing power-relatedsecurity attacksThis project has a number of direct benefits to the stateof the art in information technology. First, it protects battery-powered mobile computing systems, an increasingly important portion of the information technology infrastructure, from a potentially devastating form of security attack. Second, it explores a new problem and attracts attention to an areathat should be studied by a large community of researchers.The broader impact of the this research is to ensure that mobile computing continues to be attractive to a growing community. By protecting against battery-based security attacks, this work ensures the ongoing adoption of mobile computing by a wider segment of society.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
DISSERTATION RESEARCH: Survival and performance costs of phenotypic responses to predation risk
  • 批准号:
    1701672
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.87万
  • 财政年份:
    2017
  • 负责人:
    Thomas Martin
  • 依托单位:
Collaborative Research: Energetic consequences of rain and nest structure for ecology and evolution of songbirds in tropical rainforests
  • 批准号:
    1656120
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $82.43万
  • 财政年份:
    2017
  • 负责人:
    Thomas Martin
  • 依托单位:
SCH: INT: Collaborative Research: Smart Wearable Systems to Support and Measure Movement in Children With and Without Mobility Impairments
RAPID: Effects of a severe El Nino drought on survival, reproduction and population change across tropical songbird species that differ in average survival rates
  • 批准号:
    1651283
  • 项目类别:
    Standard Grant
  • 资助金额:
    $19.84万
  • 财政年份:
    2016
  • 负责人:
    Thomas Martin
  • 依托单位:
海外基金