课题基金 / 基金详情

TC: Small: Collaborative Research: Symbiosis in Byzantine Fault Tolerance and Intrusion Detection

TC: Small: Collaborative Research: Symbiosis in Byzantine Fault Tolerance and Intrusion Detection
TC:小型:协作研究:拜占庭容错和入侵检测的共生
批准号:
1018871
负责人:
Karl Levitt
金额:
$25.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-08-15 至 2015-07-31

项目摘要

项目成果

Karl Levitt的其他基金

相似基金

相关文献

中文摘要
翻译
在大规模分布式系统中提供保护的两个主要组成部分是拜占庭容错(BFT)和入侵检测系统(IDS)。BFT用于在面对任意故障(包括恶意软件和互联网病原体引入的故障)时实现严格一致的状态复制。入侵检测涉及一组广泛的服务,这些服务检测可能指示正在进行的攻击是否存在的事件。入侵防御系统远非完美——它们既可能错过攻击,也可能将事件误解为恶意攻击。此外,ids本身也容易受到攻击。这两个组件处理系统安全性的不同部分。然而,每一个都有可能改善另一个,这就是这个项目的主题。事实证明,在基础和系统两级上将这两项工作结合起来是难以实现的。容错分布式算法被设计为使用故障检测器已经有一段时间了,但只是作为一种抽象。入侵检测在很大程度上是一种对系统安全性进行一般性改进的服务。尝试将这两种方法结合起来,可以使BFT成为多站点系统中真正实用的方法,并提供一种集成多个ids的新方法,以提高具有非统一和可变信任的多站点系统的安全性。这种好处的一些例子是:(1)BFT收集的关于可疑行为的任何证据都可能对IDS有用,因为它可能表明系统已被破坏。BFT可以使用来自IDS的信息来影响其对复制服务服务器的行为。例如,这可以允许BFT在服务尚未受到影响的情况下停止使用一个站点,或者为一个看起来管理良好的站点假定一组更温和的故障。(3) BFT对可疑行为的反应方式是一个复杂的策略,至少部分可以转移到IDS。这样做将允许对策略进行调整。(4)进一步的检测方法是将BFT的内部怀疑与IDS的外部怀疑进行比较。(5) BFT可用于检测和应对针对IDS的攻击。(6) IDS可以确认BFT集合中各方的行为是否符合BFT协议,这样可以提高BFT系统的性能。本研究通过开发用于广域网的BFT版本来探索合并系统的这种潜力,该版本设计了几个ids作为架构的一部分。IDS将充当怀疑检测器,允许BFT定义相互信任的站点集,从而可以在它们之间使用较低延迟的协议。入侵防御系统将使用BFT来商定检测状态,以进行更有用的检测。BFT收集的信息将被IDS用于检测恶意行为。并且,在可能的情况下,BFT和IDS将相互检查,以增加系统的检测能力。将实现该系统的原型,并构建一个简单的综合应用程序,以测量对一系列模拟攻击的性能和灵敏度。
英文摘要
Two principal components for providing protection in large-scale distributed systems are Byzantine fault-tolerance (BFT) and intrusion detection systems (IDS). BFT is used to implement strictly consistent replication of state in the face of arbitrary failures, including those introduced by malware and Internet pathogens. Intrusion detection relates to a broad set of services that detect events that could indicate the presence of an ongoing attack. IDSs are far from perfect -- they can both miss attacks or misinterpret events as being malicious. In addition, IDSs themselves are vulnerable to attack. These two components approach different parts of system security. Each, however, has the potential to improve the other, which is the theme of this project. The integration of these two efforts, at both the fundamental and system levels, has proven elusive. Fault-tolerant distributed algorithms have been designed to use failure detectors for some time, but only as an abstraction. Intrusion detection has been, for the most part, a service that gives some general improvement in system security. Attempting to marry these two approaches could be a large step towards making BFT a truly practical approach in multisite systems, and gives a novel way to integrate multiple IDSs to improve the security in a multisite system with nonuniform and varying trust. Some examples of such benefit are (1) Any evidence gathered by BFT about suspicious behavior can be useful for an IDS, since it could indicate that the system has been compromised. (2) Information from an IDS can be used by BFT to influence its behavior towards the servers of the replicated service. This could, for example, allow BFT to stop using a site even though the service has not (yet) been affected, or to assume a more benign set of failures for a site that appears to be well managed. (3) The way that BFT reacts to suspicious behavior is a complex policy that could, at least in part, be moved to IDS. Doing so would allow the policy to be tuned. (4) A further detection method is to compare the internal suspicions of BFT with the external suspicions of the IDS. (5) BFT can be used to detect and cope with attacks on an IDS. (6) IDS can confirm that parties in a BFT set are behaving according to the BFT protocol which if so can improve the performance of a BFT system. This research explores this potential of a merged system by developing a version of BFT for wide-area networks that is designed with several IDSs as part of the architecture. The IDS will serve as a suspicion detector that allows BFT to define sets of sites that trust each other, and can thus use a lower latency protocol among them. The IDSs will use BFT to agree upon detection states to make more useful detections. Information collected by BFT will be used by the IDS to detect malicious behavior. And, BFT and IDS will, where possible, check each other to increase the detection power of the system. A prototype of the system will be implement and a simple synthetic application to measure performance and sensitivity to a set of simulated attacks will be built.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: Medium: Collaborative: Towards Securing Coupled Financial and Power Systems in the Next Generation Smart Grid
  • 批准号:
    1229008
  • 项目类别:
    Standard Grant
  • 资助金额:
    $84.0万
  • 财政年份:
    2012
  • 负责人:
    Karl Levitt
  • 依托单位:
TC: Small: Collaborative Research: An Argumentation-based Framework for Security Management
  • 批准号:
    1118077
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.9万
  • 财政年份:
    2011
  • 负责人:
    Karl Levitt
  • 依托单位:
GENI: EAGER: GENI Experiments to Explore Adoption of New Security Services
  • 批准号:
    1152664
  • 项目类别:
    Standard Grant
  • 资助金额:
    $19.9万
  • 财政年份:
    2011
  • 负责人:
    Karl Levitt
  • 依托单位:
The Verification of Hierarchically Structured Programs
  • 批准号:
    7418661
  • 项目类别:
    Standard Grant
  • 资助金额:
    $15.0万
  • 财政年份:
    1975
  • 负责人:
    Karl Levitt
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: