CAREER: A Timing Approach to Network Forensics
CAREER: A Timing Approach to Network Forensics
批准号:
1054937
负责人:
Negar Kiyavash
金额:
$45.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-02-01 至 2018-01-31
中文摘要
翻译后摘要:提供网络安全的攻击者渗透到网络,内部攻击者,非恶意的用户错误或设备故障是一个艰巨的挑战,科学界。调查员解决了网络取证领域的问题,这些问题出现在基于数据包的信息通信中。研究方法的一个关键特征是使用时间作为未充分利用的自由度,提供了丰富的统计结构的信息动态。使用定时模态来执行网络取证具有以下优点:它将不会过度干扰分组网络中的正常操作,其中信息交换是经由分组内容实现的。这项研究的一个新奇是包括因果推理。人类对事件的可能性和变量之间的依赖关系的判断受到因果关系的强烈影响。为了扩展同样的决策能力,人造系统必须获得处理因果关系的能力,而不仅仅是评估统计依赖性的问题。PI的目标是了解网络流量之间的因果关系的影响,使用定时模态。PI将开展一项雄心勃勃的多学科研究计划,目标是安全领域的理论和实践基本问题。PI的主要研究工作包括:(1)分析和缓解共享资源下出现的排队定时侧信道;(2)开发复杂网络的因果推理度量和算法;(3)使用点过程的良好压缩码设计网络流的有效压缩和存储方法;(4)设计基于网络流的数据流压缩算法。(4)网络流水印的设计,该网络流水印将被插入到分组定时中,并且服务于提供数据完整性以及用于网络推断的手段的双重目的。
英文摘要
Abstract:Providing cyber security against attackers who penetrate the network, insider attackers, and non-malicious user errors or equipment failures is a formidable challenge for the scientific community. The investigator addresses problems in the area of network forensics that arise in packet-based communication of information. A key feature of the research approach is the use of timing as an under-utilized degree of freedom that provides rich statistical structure about the information dynamics. Using timing modality for performing network forensics has the advantage that it will not excessively perturb normal operation in packet networks where the information exchange is achieved via packet contents. A novelty of this research is the inclusion of causal inference. Human judgments about the likelihood of events and dependencies among variables is strongly influenced by the perception of cause-effect relationships. To extend the same decision making power, a man-made system must acquire the ability to process cause-effect relationships, rather than only assessing questions of statistical dependence. PI's objective is to understand causal influences between network flows using the timing modality. The PI will embark on an ambitious multidisciplinary research program that targets both theoretical and practical fundamental problems in security. The main research endeavors undertaken by the PI are: (1) analysis and mitigation of queuing timing side channels that arise in presence of shared resources; (2) develop of causal inference metrics and algorithms for complex networks; (3) design of efficient compression and storage approaches for network flows using good compression codes for point processes; (4) design of network flow watermarks that will be inserted in packet timings and serve the dual purpose of providing data integrity as well as a means for network inference.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CIF: Small: Collaborative Research: Analytics on Edge-labeled Hypergraphs: Limits to De-anonymization
-
批准号:1619216
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2016
-
负责人:Negar Kiyavash
-
依托单位:
CIF: Medium: Collaborative Research: Toward a General Theory of Information Transfer via Timing
-
批准号:1065022
-
项目类别:Continuing Grant
-
资助金额:$61.5万
-
财政年份:2011
-
负责人:Negar Kiyavash
-
依托单位:
海外基金