NeTS-ANET: SSL Misuse, Web Bugs, and Open Redirects: Prevalence, Implications, and Defense
NeTS-ANET: SSL Misuse, Web Bugs, and Open Redirects: Prevalence, Implications, and Defense
批准号:
0831988
负责人:
Minaxi Gupta
金额:
$10.01万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-09-01 至 2010-08-31
中文摘要
从以用户为中心的角度来看,在理解强大的网络功能对用户的风险方面存在的研究很少。这个项目试图通过研究三类已知(和紧急的)威胁来填补这一空白,该框架通过研究三类已知的(和紧急的)威胁:滥用安全套接字层(SSL)、网络错误(一种用于监视网页用户的技术)和开放重定向(一种将用户转移到不同网页的技术,可能不会被检测到)。这些都是代价高昂且迫在眉睫的当前威胁;初步研究结果已在USENIX2008攻击性技术研讨会上公布,本报于2008年7月16日在《华盛顿邮报》上发表了一篇文章。该项目设想这三个具体问题代表用户的网络风险的三个主要类别,从而导致一个以用户为中心的安全框架。广泛的研究活动包括:1.测量:通过结合主动网络爬行和被动观察,研究正在量化这三种威胁的性质和程度,并在此过程中开发准确识别其发生的技术。2.以用户为中心的相关性研究:当多个网站订阅同一网络漏洞托管公司时,该(恶意)公司可以跟踪多个网站的用户行为。这是关联威胁的一个例子。该项目还研究了对用户安全和隐私的相关威胁。该项目的更广泛影响包括:1.网络上的用户安全和隐私:该项目推进了以用户为中心的网络安全和隐私观点。这是当前和迫切的社会需求。该研究小组已经开发了几个用户端工具,有助于防止或至少揭示问题,并将继续开发这些工具并将其发布到公共领域。2.开放访问数据:抓取网络是非常耗费资源的,而且很少有来源公开这些数据。该组织将其数据提供给研究界。
英文摘要
Very little research exists in understanding the risks to users of powerful web features, as seen from a user-centric point of view. This project seeks to fill this void by creating a framework for this understanding by studying three classes of known (and urgent) threat: misuses of secure socket layer (SSL), web bugs (a technique for spying on the user of web page), and open redirects (a technique for transferring the user to a different web page perhaps without detection). These are costly and urgent current threats; results of preliminary research were presented at the USENIX 2008 Workshop on Offensive Technologies and an article in the Washington Post on July 16, 2008 reported on this paper. The project envisions the three specific problems as representing three major classes of the users' web risks and thus leading to a user-centric security framework. The broad research activities include: 1. Measurement: through a combination of active Web crawling and passive observation, the research is quantifying the nature and extent of the three threats, and in the process developing techniques for accurately identifying their occurrences. 2. User-centric correlation studies: When multiple web sites subscribe to the same web bug hosting company, that (malicious) company can track user behavior across multiple sites. This is one example of a correlation threat. The project also studies the correlated threats to user security and privacy. The broader impacts of the project include:1. User security and privacy on the Web: The project advances a user-centric view of security and privacy on the Web. This is a current and urgent social need. The research group has already developed several user-side tools that help prevent or at least reveal problem, and it will continue to develop and publish these to the public domain. 2. Open access to data: crawling the Web is very resource intensive and few sources make this data publicly available. The group makes its data available to the research community.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SDCI Sec: Metadata Management Software Tools to Support Research and Development of Cyberinfrastructure
-
批准号:1127406
-
项目类别:Standard Grant
-
资助金额:$18.2万
-
财政年份:2011
-
负责人:Minaxi Gupta
-
依托单位:
RAPID: Understanding and Preventing Scam on Craigslist
-
批准号:1110079
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2011
-
负责人:Minaxi Gupta
-
依托单位:
TC: Small: Collaborative Research: Predictive Blacklisting for Detecting Phishing Attacks
-
批准号:1018617
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2010
-
负责人:Minaxi Gupta
-
依托单位:
海外基金