课题基金 / 基金详情

CT-ISG: Protection Against Malicious Attacks via Quarantine-Tolerant Service Partitioning

CT-ISG: Protection Against Malicious Attacks via Quarantine-Tolerant Service Partitioning
CT-ISG:通过隔离容忍服务分区防止恶意攻击
批准号:
0523932
负责人:
Kang Shin
金额:
$40.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2005
资助国家:
美国
项目状态:
已结题
起止时间:
2005-09-01 至 2012-08-31

项目摘要

项目成果

Kang Shin的其他基金

相似基金

相关文献

中文摘要
翻译
摘要本项目旨在为企业网络开发一套针对蠕虫、病毒和间谍软件等恶意代码攻击的自动化防御系统。该系统通过动态和有选择地隔离主机、服务和其他联网设备来响应攻击。基于防火墙和单个主机隔离的传统遏制系统不足以遏制新一代的本地扫描、拓扑、元服务器和传染蠕虫,这些蠕虫可以在企业中迅速传播。此外,这些系统不能在隔离期间为企业提供基本服务的保护。为了解决这些缺点,正在开发、实施和评估一个名为SeQuEN(企业网络中的服务隔离)的综合企业防御框架。SeQuEN根据主机、路由器和交换机的服务交互(“行为”)而不是网络的物理拓扑来自动识别隔离主机、路由器和交换机。由于大多数病毒和蠕虫针对特定的服务和潜在的漏洞,因此SeQuEN中以服务为中心的隔离有望实现对恶意攻击的快速遏制。此外,在检测到攻击后激活网络范围隔离时,SeQuEN通过维持基本服务来增强可操作网络的生存能力。这是通过在提供服务分发和复制的同时将服务拓扑划分为多个隔离区来实现的。SeQuEN还被集成到攻击模拟引擎(ASE)中,以模拟不同类型的恶意代码攻击,如拓扑、本地扫描蠕虫和间谍机器人。SeQuEN中隔离算法的有效性正在使用从二级IP网络收集的网络痕迹进行评估。
英文摘要
Shin - AbstractThis project is developing an automated defense system for enterprise networks against malicious code attacks such as worms, viruses and spyware. This system responds to attacks by dynamically and selectively quarantining hosts, services, and other networked devices. Traditional containment systems based on firewalls and individual host isolation are not adequate for containing the new generation of local-scanning, topological, metaserver and contagion worms that can spread very quickly through an enterprise. Further, these systems do not provide enterprise-wide protection of essential services during such quarantine. To address these shortcomings, a comprehensive enterprise defense framework, called SeQuEN (Service Quarantine in Enterprise Networks) is being developed, implemented and evaluated. SeQuEN automatically identifies hosts, routers and switches forquarantine based on their service interactions ("behaviors") instead of the physical topology of the network. Since most viruses and worms target specific services and the underlying vulnerabilities, the service-centric quarantine in SeQuEN is expected to achieve fast containment of malicious attacks. Further, SeQuEN enhances the survivability of an operational network by maintaining essential services when a network-wide quarantine is activated upon attack detection. This is achieved by partitioning the service topology into a number of quarantine zones while providing service distribution and replication. SeQuEN is also being integrated within an Attack Simulation Engine (ASE) to simulate different types of malicious code attacks, such as topological, local-scanning worms and spybots. The effectiveness of the quarantine algorithms in SeQuEN is being evaluated using network traces collected from a class-2 IP network.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Securing Interactions between Driver and Vehicle Using Batteries
CPS:Small: Imposing Recovery Period for Battery Health Monitoring, Prognosis, and Optimization
CPS: Breakthrough: Secure Interactions with Internet of Things
CPS: Synergy: Adaptive Management of Large Energy Storage Systems for Vehicle Electrification
国内基金
海外基金
甘草苷通过IFN-I/ISG15信号通路促进卵巢颗粒细胞外泌体分泌延缓卵巢衰老的作用机制
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    李璐邑
  • 依托单位:
ISG15/LFA-1调控肿瘤相关巨噬细胞浸润促进胆囊癌免疫逃逸的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    蔡炜龙
  • 依托单位:
ISG15类泛素化修饰多囊泡小体介导KNG1-PI3K/Akt信号轴在葡萄膜炎内皮屏障损伤中的作用机制研究
  • 批准号:
    JCZRQN202500743
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
  • 依托单位:
肾周脂肪M2 巨噬细胞通过ISG15/LFA-1轴调控传入神经活性在肥 胖相关高血压中的作用及机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    郭静
  • 依托单位: