课题基金 / 基金详情

NeTs-NBD: Maltraffic Analysis and Detection in Challenging and Aggregate Traffic (MADCAT)

NeTs-NBD: Maltraffic Analysis and Detection in Challenging and Aggregate Traffic (MADCAT)
NeTs-NBD:具有挑战性和聚合流量的恶意流量分析和检测 (MADCAT)
批准号:
0626696
负责人:
John Heidemann
金额:
$89.65万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-10-01 至 2010-09-30

项目摘要

项目成果

John Heidemann的其他基金

相似基金

相关文献

中文摘要
翻译
如今,许多被破坏的计算机都会产生恶意通信,例如拒绝服务(DoS)攻击、间谍软件报告、未经授权的应用程序、垃圾邮件和蠕虫。目前的防御正变得越来越脆弱。造成这一挑战的原因有以下几个:加密限制了对数据包内容的检查,网络边缘的聚合限制了过滤和黑名单的使用,因为有潜在的附带损害,增加的流量允许隐藏恶意流量,应用程序通常通过分层协议(HTTP上的SOAP或不同的端口分配)或主动隐藏来隐藏。该方案将信号处理和检测理论应用于网络流量中,以检测这些具有挑战性的场景中的恶意流量。我们将使用数据包定时和频率等特征,仔细设计测量和检测系统,以及研究协议中的固有行为来应对这些挑战。更广泛的影响:这项工作的结果将包括(a)开发一种系统的方法,将信号处理方法应用于网络流量;(b)分析针对不当通讯的新信号表示和检测方法;(c)识别、理解和建模不良流量的关键识别特征和固有行为,以及它们是如何被网络塑造的。我们的新方法将对网络流量产生更深入的理解,并将通过真实网络流量的痕迹进行测试,从而产生解决这些问题的新工具。
英文摘要
Many compromised computers today generate maltraffic, such as denial-of-service (DoS) attacks, spyware reporting home, unauthorized applications, spam, and worms. Current defenses are becoming increasingly brittle. There are several reasons for this challenge: encryption limits packet content inspecting, aggregation at network edge limits use of filtering and blacklisting due to potential collateral damage, increased traffic volumes allow maltraffic to hide, and applications are often cloaked through layered protocols (SOAP over HTTP or varying port allocation) or active concealment.This proposal applies signal processing and detection theory to network traffic to detect maltraffic in these challenging scenarios. We will use features such as packet timing and frequency, careful design of the measurement and detection systems, and study of inherent behaviors in protocols to address these challenges.Broader Impact: The results of this work will include (a) the development of a systematic methodology for applying signal processing methods to network traffic; (b) the analysis of new signal representation and detection methods specific to maltraffic; and (c) the identification, understanding, and modeling of key identifying features and inherent behaviors of maltraffic and how they are shaped by the network. Our new approaches will yield a deeper understanding of network traffic, and will be tested with traces of real network traffic, resulting in new tools to combat these problems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: IMR:MM-1B: Privacy in Internet Measurements Applied To WAN and Telematics
  • 批准号:
    2319409
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $26.91万
  • 财政年份:
    2023
  • 负责人:
    John Heidemann
  • 依托单位:
IMR: RI-P: Safe And Flexible Experimental Dataset Access and Sharing-Planning (SAFED-ASP)
  • 批准号:
    2224467
  • 项目类别:
    Standard Grant
  • 资助金额:
    $9.91万
  • 财政年份:
    2022
  • 负责人:
    John Heidemann
  • 依托单位:
Collaborative Research: CNS Core: Medium: A Traffic Map for the Internet
  • 批准号:
    2212480
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $39.8万
  • 财政年份:
    2022
  • 负责人:
    John Heidemann
  • 依托单位:
RAPID: Measuring the Internet during Novel Coronavirus to Evaluate Quarantine (RAPID-MINSEQ)
  • 批准号:
    2028279
  • 项目类别:
    Standard Grant
  • 资助金额:
    $9.9万
  • 财政年份:
    2020
  • 负责人:
    John Heidemann
  • 依托单位:
国内基金
海外基金
效应因子NBD在菰黑粉菌侵染中的作用机制
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    夏文强
  • 依托单位:
ABCC2基因NBD区突变影响MRP2亚细胞定位及降解在Dubin-Johnson综合征中的致病作用及机制
  • 批准号:
    82000543
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    24.0万元
  • 批准年份:
    2020
  • 负责人:
    武丽娜
  • 依托单位:
基于三维打印Sr-CaS/NBD多肽缓释微球支架材料修复感染性骨缺损的实验研究
  • 批准号:
    81601911
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    18.0万元
  • 批准年份:
    2016
  • 负责人:
    李雪
  • 依托单位:
炎症刺激下NBD多肽对成骨细胞分化作用的机制研究
  • 批准号:
    81272052
  • 项目类别:
    面上项目
  • 资助金额:
    70.0万元
  • 批准年份:
    2012
  • 负责人:
    余斌
  • 依托单位: