课题基金 / 基金详情

CAREER:Towards Effective Identification of Application Behaviors in Encrypted Traffic

CAREER:Towards Effective Identification of Application Behaviors in Encrypted Traffic
职业:有效识别加密流量中的应用程序行为
批准号:
0852649
负责人:
Fabian Monrose
金额:
$24.12万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-08-19 至 2012-08-31

项目摘要

项目成果

Fabian Monrose的其他基金

相似基金

相关文献

中文摘要
翻译
Fabian Monrose John霍普金斯大学0546350摘要限制访问网络资源的几种基本安全机制依赖于引用监视器在流量通过网络时检查流量内容的能力。 然而,随着密码协议的日益普及,传统的检查数据包内容以执行安全策略的方法不再是可行的方法,因为消息内容被加密所隐藏.该项目包括第一个主要组成部分的原则性调查的可行性ofprotocol识别的基础上,完全的那些功能,即数据包的大小,到达间隔和方向后的加密。更具体地说,这项工作试图提供一个更好的理解协议识别的限制的基础上彻底的统计分析和信息理论评估的可用功能在协议行为观察在野外。具体而言,该项目通过构建用于检测具有多模态行为的协议的高效混合模型,设计用于可视化TCP序列中的行为基序的实用工具,为这些序列分配协议类标签提供新的信息理论决策策略,并为评估现实的伪装攻击和适当的防御提供新的概念,从而推进了当前的技术水平,并为科学界做出了贡献。
英文摘要
Fabian MonroseJohn Hopkins Unversity0546350AbstractSeveral fundamental security mechanisms for restricting access tonetwork resources rely on the ability of a reference monitor toinspect the contents of traffic as it traverses the network. However,with the increasing popularity of cryptographic protocols thetraditional means of inspecting packet contents to enforce securitypolicies is no longer a viable approach as message contents areconcealed by encryption. This project encompasses the first majorcomponent of a principled investigation into the feasibility ofprotocol identification based solely on those features that remainintact after encryption---namely, the packet size, inter-arrival anddirection. More specifically, this work attempts to provide a betterunderstanding of the limits of protocol recognition based on athorough statistical analysis and information theoretic assessment ofthe available features in protocol behaviors observed in thewild. Specifically, this project advances the current state of the artand contributes to the scientific community by building efficientmixture models for detecting protocols with multi-modal behaviors,designing practical tools for visualizing behavioral motifs in TCPsequences, providing new information-theoretic decision policies forassigning protocol class labels to these sequences, and imparting newnotions for assessing realistic masquerading attacks and theappropriate defenses.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Student Travel to the 2016 USENIX Security Symposium
NSF Support for the 2015 USENIX Security Symposium, Financial Aid; August 2015; Washington, D.C.
TWC: TTP Option: Small: Collaborative: Scalable Techniques for Better Situational Awareness: Algorithmic Frameworks and Large-Scale Empirical Analyses
NSF Support for the 2013 USENIX Security Symposium, Financial Aid; August 2013; Washington DC
海外基金