课题基金 / 基金详情

TWC: TTP Option: Small: Differential Introspective Side Channels --- Discovery, Analysis, and Defense

TWC: TTP Option: Small: Differential Introspective Side Channels --- Discovery, Analysis, and Defense
TWC:TTP 选项:小:差异内省侧通道 --- 发现、分析和防御
批准号:
1526455
负责人:
Zhuoqing Mao
金额:
$60.53万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-10-01 至 2021-09-30

项目摘要

项目成果

Zhuoqing Mao的其他基金

相似基金

相关文献

中文摘要
翻译
安全领域中的边信道被认为是系统地发现和消除的挑战。然而,它们可能导致各种隐形攻击,严重危及网络安全。这项工作的重点是一类重要的侧通道,网络系统的操作是根本的。这项工作不是因为使用ad-hoc补丁的安全漏洞而不断地对新发现的侧信道做出反应,而是能够自动发现由于暴露信息以实现调试和管理计算系统的固有目标而存在的一类重要的侧信道。预计该项目将为侧通道调查的安全领域带来范式转变,从而为防止各种网络攻击带来重大经济效益。该项目还具有重要的教育和劳动力培训的本科生和研究生的好处,除了通过适用的标准流程,以确保操作adoption.This研究调查了一个全新的类侧信道攻击网络系统,如网络堆栈,可能会导致严重损害用户隐私,网络安全和应用程序的完整性的研究结果更广泛的传播。这类攻击的一个示例特征是需要主动注入精心制作的和可能不正确的事件,以触发程序中的错误条件,从而揭示其内部敏感状态,这可能间接暴露关键信息。有趣的是,这些攻击是网络和操作系统设计和实现的固有副产品,从根本上说很难修改。 与可以通过被动监测直接观察到的其他众所周知的侧信道相反,功率和时间,这类侧信道更难发现,也更难防御。 所提出的安全工作有助于引入更严格的方法来发现一类新的侧信道,其对诸如移动的设备的小型系统以及诸如企业网络的大型网络系统的安全保证具有直接影响。这项研究开发了系统和严格地检测和消除这些侧通道的方法,利用程序分析和网络测量科学。 通过研究网络系统的安全保障和可维护性之间的权衡关系,可以得到更实用、更有用的安全解决方案,并可在实践中部署。
英文摘要
Side channels in the security domain are known to be challenging to discover and eliminate systematically. Nevertheless, they can lead to a variety of stealthy attacks seriously compromising cybersecurity. This work focuses on an important class of side channels that are fundamental to the operations of networked systems. Rather than constantly reacting to newly discovered side channels because of security breaches with ad-hoc patches, this work enables the automated discovery of an important class of side channels that exist due to the inherent goal of exposing information to enable debugging and management of computing systems. This project is expected to bring a paradigm shift to the security area of side channel investigation that can bring significant economic benefits of preventing a diverse set of cyberattacks. This project also has important educational and workforce training benefits for both undergraduate and graduate students, in addition to the broader dissemination of the findings through applicable standards processes to ensure operational adoption.This research investigates an entirely new class of side channel attacks against networked systems such as network stacks that can lead to significant damage to user privacy, network security, and application integrity. An example feature about this class of attacks is the requirement of actively injecting carefully crafted and potentially incorrect events to trigger error conditions in a program so as to reveal their internal sensitive states, which can indirectly expose critical information. Interestingly, the attacks are inherent byproducts of network and operating system design and implementation, which are fundamentally hard to modify. In contrast to other well-known side channels that can be directly observed through passive monitoring, e.g., power and timing, this class of side channels is much more subtle to discover and also more challenging to defend against. The proposed security work helps introduce a more rigorous approach to discovering a new class of side channels, that have direct impact on the security assurance of both small systems such as mobile devices as well as large network systems such as enterprise networks. This research develops methods to systematically and rigorously detect and eliminate such side channels by leveraging both program analysis and network measurement science. The investigation to understand the tradeoffs between security guarantee and manageability of network systems leads to more practical and usable security solutions that can be deployed in practice.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CISE: Large: Integrated Networking, Edge System and AI Support for Resilient and Safety-Critical Tele-Operations of Autonomous Vehicles
IMR: MT: xGTracker -- Mobile xG Performance Monitoring and Data Collection Platform to Enable Large-Scale Crowd-Sourced Measurement
CPS: Medium: Collaborative Research: Transforming Connected and Automated Transportation with Smart Networking, Cooperative Sensing, and Edge Computing
SBIR Phase I: Automated Safety/Security Compliance Verification and Enforcement for Autonomous Vehicle Software
  • 批准号:
    2015019
  • 项目类别:
    Standard Grant
  • 资助金额:
    $22.5万
  • 财政年份:
    2020
  • 负责人:
    Zhuoqing Mao
  • 依托单位:
国内基金
海外基金
RNA结合蛋白TTP在阿尔茨海默病中的作用机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2023
  • 负责人:
  • 依托单位:
TTP和XPO4蛋白介导lncRNA转运在子宫颈鳞状细胞癌中功能及机制的研究
  • 批准号:
    --
  • 项目类别:
    面上项目
  • 资助金额:
    54万元
  • 批准年份:
    2022
  • 负责人:
    陈亮
  • 依托单位:
平滑肌中TTP在血压调控中的作用及机制研究
  • 批准号:
    --
  • 项目类别:
    面上项目
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    张文程
  • 依托单位:
TTP-KDM3A/CYP19A1调控滋养层细胞分化和侵袭的机制研究
  • 批准号:
    82171669
  • 项目类别:
    面上项目
  • 资助金额:
    54万元
  • 批准年份:
    2021
  • 负责人:
    林羿
  • 依托单位: