CAREER: Resilient Execution with Bounded-Time Recovery (REBOUND)
CAREER: Resilient Execution with Bounded-Time Recovery (REBOUND)
批准号:
1750158
负责人:
Linh Thi Xuan Phan
金额:
$47.54万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-09-01 至 2024-08-31
中文摘要
该项目开发了保护关键基础设施系统(如工厂控制网络、医疗设备或发电厂)免受攻击的新方法。这些系统直接与物理世界交互,因此成功的攻击可能会产生严重的后果:例如,受损的化工厂可能会造成严重的环境后果,受损的医疗设备可能会导致受伤或死亡。然而,由于两个原因,当代的安全机制可能不够充分。首先,目前的防御措施往往相当重量级,这使得它们很难应用于资源受限的基础设施系统。其次,时机很关键:当前的防御措施往往侧重于防止系统“做错事”或“没能做正确的事”,而不是防止系统“在错误的时间做正确的事”,后者往往同样具有破坏性。为了解决这个问题,该项目创建了专门为基础设施系统量身定做的更强大的防御机制。新机制明确考虑了时机,预计成本较低,并将首先与一家主要汽车制造商合作应用于汽车系统。首席调查员将为实践者组织教程,并将加强宾夕法尼亚大学嵌入式系统硕士课程的课程,更多地涵盖物联网安全。她还正在开展一系列外联活动,以提高妇女和少数群体在实时系统社区中的代表性。与法学院和宾夕法尼亚大学医学院的合作将调查如何使用新技术来改善基础设施系统的法律框架,例如,通过对产品缺陷提供更好的责任,以及如何应用这些技术来提高医疗系统的安全性。该项目采用了一种称为有限时间恢复的方法。与许多现有技术不同,有限时间恢复并不试图掩盖攻击的所有症状,而现有的防御系统会付出巨大的成本;相反,它利用了这样一个事实,即许多系统由于惯性或热容量等属性无法任意快速更改其状态,因此已经可以容忍短暂的中断,前提是系统迅速恢复到正确状态。该方法寻求保证:1)在没有攻击的情况下,系统将满足其定时要求,以及2)当受到攻击时,系统将在有限的时间量内返回到正确的状态,可能在重新配置自身以排除受危害的节点之后。目标是在拜占庭模型中提供这些保证,即在不知道攻击将是什么样子或哪些节点将被攻击的情况下提供这些保证。为了实现这一目标,该项目将构建实用的算法,以篡改明显的日志和密码证据等技术为基础,在有限的时间内检测攻击;使用来自多模式系统的想法,创建在有限的时间内从检测到的攻击中恢复的方法;并产生新技术的可重复使用的实现,这些新技术将在开放源码许可下广泛传播和提供。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project develops new ways to defend critical infrastructure systems, such as factory control networks, medical devices, or power plants, against attacks. These systems directly interact with the physical world, so a successful attack can have serious consequences: for instance, a compromised chemical plant could have severe environmental consequences, and a compromised medical device could result in injury or death. Contemporary security mechanisms, however, can be inadequate for at two reasons. First, current defenses tend to be quite heavyweight, which makes them difficult to apply to resource-constrained infrastructure systems. And second, timing is critical: current defenses tend to focus on preventing systems from 'doing the wrong thing' or 'failing to do the right thing', as opposed to preventing systems from 'doing the right thing at the wrong time', which is often just as damaging. To address this problem, this project creates stronger defense mechanisms tailored specifically for infrastructure systems. The new mechanisms explicitly take timing into account, are expected to have lower cost, and will initially be applied to automotive systems in collaboration with a major car manufacturer. The principal investigator will organize tutorials for practitioners, and will enhance the curriculum of the Master's in Embedded Systems program at the University of Pennsylvania with more coverage of Internet-of-Things security. She is also developing a series of outreach activities to improve the representation of women and minorities in the real-time systems community. Collaborations with the law school and the medical school at the University of Pennsylvania will investigate how to use the new techniques to improve the legal framework for infrastructure systems, by offering better accountability for product defects, for example, and how to apply them to improve the security of medical systems. This project pursues an approach called bounded-time recovery. Unlike many existing techniques, bounded time recovery does not attempt to mask all symptoms of an attack, which existing defenses do at great cost; rather, it leverages the fact that many systems cannot change their state arbitrarily quickly, due to properties such as inertia or thermal capacity, and can thus already tolerate brief disruptions, provided the system quickly returns to a correct state. This approach seeks guarantees that 1) the system will meet its timing requirements in the absence of an attack, and that 2) when under attack, the system will return to a correct state within a bounded amount of time, potentially after reconfiguring itself to exclude compromised nodes. The goal is to provide these guarantees in the Byzantine model, that is, without a priori knowledge of what the attacks will look like, or which nodes will be attacked. To achieve this goal, the project will construct practical algorithms for (provably) detecting attacks within bounded time, based on techniques such as tamper-evident logs and cryptographic evidence; create methods for recovering from detected attacks within bounded time, using ideas from multi-mode systems; and produce reusable implementations of the new techniques that will be widely disseminated and made available under an open-source license.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(18)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3447786.3456257
发表时间:
2021-04
期刊:
Proceedings of the Sixteenth European Conference on Computer Systems
影响因子:
--
作者:
[N. Gandhi;Edo Roth;Brian Sandler;Andreas Haeberlen;L. T. Phan]
通讯作者:
N. Gandhi;Edo Roth;Brian Sandler;Andreas Haeberlen;L. T. Phan
DNA: Dynamic Resource Allocation for Soft Real-Time Multicore Systems
DNA:软实时多核系统的动态资源分配
DOI:
10.1109/rtas52030.2021.00024
发表时间:
2021
期刊:
Proceedings of the 27th IEEE Real-Time and Embedded Technology and Applications Symposium (RTAS '21
影响因子:
--
作者:
[Gifford, Robert, Gandhi, Neeraj, Phan, Linh Thi, Haeberlen, Andreas]
通讯作者:
Haeberlen, Andreas
Real-Time Packet-Based Intrusion Detection on Edge Devices
边缘设备上基于数据包的实时入侵检测
DOI:
10.1145/3576914.3587551
发表时间:
2023
期刊:
2nd International Workshop on Real-Time and IntelliGent Edge Computing (RAGE
影响因子:
--
作者:
[Borgioli, Niccolò, Thi Xuan Phan, Linh, Aromolo, Federico, Biondi, Alessandro, Buttazzo, Giorgio]
通讯作者:
Buttazzo, Giorgio
Mitigating Computational Constraints via Adaptive Control and Resource Allocation Co-design.
通过自适应控制和资源分配协同设计减轻计算约束。
DOI:
--
发表时间:
2022
期刊:
Workshop on Computation-Aware Algorithmic Design for Cyber-Physical Systems
影响因子:
--
作者:
[Linh Thi Xuan Phan, Ricardo G. Sanfelice]
通讯作者:
Ricardo G. Sanfelice
IGOR: Accelerating Byzantine Fault Tolerance for Real-Time Systems with Eager Execution
IGOR:通过 Eager Execution 加速实时系统的拜占庭容错
DOI:
--
发表时间:
2021
期刊:
IEEE Real-Time and Embedded Technology and Applications Symposium (RTAS
影响因子:
--
作者:
[A. Loveless, R. Dreslinski]
通讯作者:
A. Loveless, R. Dreslinski
共 17 条
NeTS: Medium: Collaborative Research: Diagnosing Datacenter Networks with Quantitative Provenance
-
批准号:1703936
-
项目类别:Continuing Grant
-
资助金额:$85.65万
-
财政年份:2017
-
负责人:Linh Thi Xuan Phan
-
依托单位:
NeTS: CSR: Medium: Network Functions Virtualization With Timing Guarantees
-
批准号:1563873
-
项目类别:Continuing Grant
-
资助金额:$110.0万
-
财政年份:2016
-
负责人:Linh Thi Xuan Phan
-
依托单位:
CSR: Small: Resource Management for Real-time Cloud Computing
-
批准号:1117185
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2011
-
负责人:Linh Thi Xuan Phan
-
依托单位:
海外基金