EAGER: Collaborative: Secure and Efficient Data Provenance
EAGER: Collaborative: Secure and Efficient Data Provenance
批准号:
1445983
负责人:
Kevin Butler
金额:
$11.01万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-10-01 至 2015-06-30
中文摘要
数据来源涉及确定最初生成信息的条件,以及对该信息的所有后续修改以及执行这些修改的条件。随着系统变得越来越分散,组织越来越依赖云计算来处理数据,安全管理和验证数据来源的需求变得至关重要。该项目开发了新的框架,用于评估主机中安全的细粒度来源收集和管理。研究活动检查了使可信来源的收集和管理在规模上可行所需的架构和算法。我们提供了一个用于在内核级别收集来源的通用架构,并考虑了在保持高保真来源记录的同时减少生成和管理来源数量的方法。该项目引入了许多优化,以支持可扩展和高性能的来源收集,包括基于策略的日志减少和来源重复数据删除。该项目的主要科学贡献包括(1)开发Linux出处模块,在Linux内核中提供完整的出处中介;(2)通过使用强制访问控制策略来设计策略减少的溯源,以减少系统中产生溯源事件的主体和操作的数量;(3)来源重复数据删除技术,这样可以存储通常发生的事件的最小记录,并在以后完全重建。我们将演示我们的方法使来源收集在规模上变得实用,从而实现更安全、更可信的计算环境。
英文摘要
Data provenance involves determining the conditions under which information was originally generated, as well as all subsequent modifications to that information and the conditions under which those modifications were performed. As systems become increasingly distributed and organizations become reliant on cloud computing for processing their data, the need to securely manage and validate the provenance of that data becomes critical.This project develops new frameworks for evaluating secure fine-grained provenance collection and management in hosts. The research activities examine the architectures and algorithms required to make the collection and management of trustworthy provenance feasible at scale. We provide a general architecture for collecting provenance at the kernel level and consider methods of reducing the amount of provenance generated and managed while maintaining high-fidelity provenance records. The project introduces a number of optimizations to enable scalable and performant provenance collection, including policy-based log reduction and provenance deduplication. The project's main scientific contributions include (1) the development of Linux Provenance Modules that provide complete provenance mediation within the Linux kernel; (2) the design of policy-reduced provenance through the use of mandatory access control policies to reduce the number of subjects and actions that are provenance-generating events to those of interest in a system; and (3) techniques for deduplication of provenance such that minimal records for commonly occurring events can be stored and later fully reconstructed. We will demonstrate that our approach makes provenance collection practical at scale, enabling more secure and trustworthy computing environments.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Enabling Practically Secure Cellular Infrastructure
-
批准号:2055014
-
项目类别:Standard Grant
-
资助金额:$59.8万
-
财政年份:2022
-
负责人:Kevin Butler
-
依托单位:
Collaborative Proposal: SaTC: Frontiers: Securing the Future of Computing for Marginalized and Vulnerable Populations
-
批准号:2206950
-
项目类别:Continuing Grant
-
资助金额:$403.58万
-
财政年份:2022
-
负责人:Kevin Butler
-
依托单位:
Travel Grant Support for Association for Computing Machinery (AC) WiSec 2018
-
批准号:1823067
-
项目类别:Standard Grant
-
资助金额:$0.9万
-
财政年份:2018
-
负责人:Kevin Butler
-
依托单位:
SaTC: STARSS: Small: Domain Informed Techniques for Detecting and Defending Against Malicious Firmware
-
批准号:1815883
-
项目类别:Standard Grant
-
资助金额:$33.33万
-
财政年份:2018
-
负责人:Kevin Butler
-
依托单位:
EAGER: Collaborative: Secure and Efficient Data Provenance
-
批准号:1540216
-
项目类别:Standard Grant
-
资助金额:$11.01万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
TC: Small: Protection Mechanisms for Portable Storage
-
批准号:1540218
-
项目类别:Continuing Grant
-
资助金额:$20.78万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
CAREER: Securing Critical Infrastructure with Autonomously Secure Storage
-
批准号:1540217
-
项目类别:Continuing Grant
-
资助金额:$32.2万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
CAREER: Securing Critical Infrastructure with Autonomously Secure Storage
-
批准号:1254198
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2013
-
负责人:Kevin Butler
-
依托单位:
TC: Small: Protection Mechanisms for Portable Storage
-
批准号:1118046
-
项目类别:Continuing Grant
-
资助金额:$49.95万
-
财政年份:2011
-
负责人:Kevin Butler
-
依托单位:
海外基金