课题基金 / 基金详情

CRII: OAC: Inferring, Attributing, Mitigating and Analyzing the Malicious Orchestration of Internet-scale Exploited IoT Devices: A Network Telescope Approach

CRII: OAC: Inferring, Attributing, Mitigating and Analyzing the Malicious Orchestration of Internet-scale Exploited IoT Devices: A Network Telescope Approach
CRII:OAC:推断、归因、减轻和分析互联网规模被利用物联网设备的恶意编排:网络望远镜方法
批准号:
1755179
负责人:
Elias Bou-Harb
金额:
$17.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-03-01 至 2019-11-30

项目摘要

项目成果

Elias Bou-Harb的其他基金

相似基金

相关文献

中文摘要
翻译
尽管在消费市场和关键基础设施-所谓的物联网(IoT)设备-广泛采用和部署各种支持互联网的设备(如手机和智能家居组件)带来了好处,但安全担忧正在上升,因为此类设备也引入了新的漏洞,攻击者可能会利用这些漏洞发动破坏性的网络攻击。该项目的目标是通过探索应用于原始网络安全数据的创新数据分析,来探索物联网范式的内在不安全性。所获得的洞察力将允许近乎实时地检测、表征和归因于互联网规模的受危害的物联网设备及其恶意活动。有几个技术挑战阻碍了整个物联网安全的解决,包括物联网设备的过度多样化以及互联网范围内的部署,缺乏与物联网相关的数据,以及缺乏针对物联网的可操作攻击签名。在这种背景下,该项目服务于NSF的使命,即通过旨在产生一种首创的、大规模的对受危害的物联网设备的规模的分析来促进科学进步。该项目还促进了对少数族裔的网络安全研究和培训,因为它将在指定的拉美裔服务机构的边界内执行。此外,该项目将通过开发存储和共享物联网相关威胁信息的实时能力,为运营网络安全做出贡献。该项目将利用从网络望远镜实时收集的宏观、大规模被动测量数据,以突显物联网范式不安全的严重性。网络望远镜,通常被称为飞镖,构成了一组可路由的、已分配但未使用的IP地址。该项目将设计和开发实时算法,能够通过探索暗网数据来推断互联网规模的被利用的物联网设备。此外,该项目将调查与物联网相关的被动测量和恶意软件样本之间植根于随机数据结构的正式关联方法,以帮助确定属性,从而实现补救目标。该项目将进一步探索看似独立的物联网活动的协调行为,这些活动在协调良好的物联网僵尸网络中运行。为此,该项目将创新基于三角内插技术、递归最优随机估计器和位图匹配算法的时间序列分析,通过使用被动测量来推断此类物联网僵尸网络。此外,该项目还将(1)通过自动化所提出的算法、技术和方法,为物联网网络威胁索引开发独特的网络基础设施,(2)通过采用分段散列技术来生成物联网特有的签名,以及(3)基于API机制和Elasticearch提供的前端服务来创建访问方法,以允许共享以物联网为中心的经验数据。威胁情报和签名。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Despite the benefits provided by the widespread adoption and deployment of diverse Internet-enabled devices such as phones and smart home components in consumer markets and critical infrastructure - the so called Internet of Things (IoT) devices, security concerns are rising as such devices also introduce new vulnerabilities that could be leveraged by attackers to launch disrupting cyber-attacks. The objective of this project is to enable exploration of the inherent insecurity of the IoT paradigm by exploring innovative data analytics as applied to raw cyber security data. Insights gained will allow detection, characterization and attribution of Internet-scale compromised IoT devices, coupled with their malicious activities, in near real-time. Several technical challenges impede addressing IoT security at large, including, the excessive diversity of IoT devices in addition to their Internet-wide deployment, the lack of IoT-relevant data and the shortage of IoT-specific actionable attack signatures. In this context, this project serves NSF's mission to promote the progress of science by aiming to generate a first-of-a-kind, large-scale analysis of the magnitude of compromised IoT devices. The project also promotes cyber security research and training for minorities, given that it will be executed within the boundaries of a designated Hispanic-serving institution. Moreover, the project will contribute to operational cyber security by developing a real-time capability for storing and sharing IoT-relevant threat information.The project will draw-upon macroscopic, large-scale passive measurement data collected in real-time from a network telescope to highlight the severity of the insecurity of the IoT paradigm. Network telescopes, most commonly known as darknets, constitute a set of routable, allocated yet unused IP addresses. The project will design and develop real-time algorithms that are capable of inferring Internet-scale exploited IoT devices by exploring darknet data. Furthermore, the project will investigate formal correlation approaches rooted in stochastic data structures between IoT-relevant passive measurements and malware samples to aid in the attribution and thus the remediation objective. The project will further explore the orchestration behavior of seemingly independent IoT activities, which operate within well-coordinated IoT botnets. To this end, the project will innovate time series analytics based upon trigonometric interpolation techniques, recursive optimal stochastic estimators, and bitmap matching algorithms to infer such IoT botnets by employing passive measurements.  The project will also (1) develop a unique cyberinfrastructure for IoT cyber threat indexing by automating the proposed algorithms, techniques and methods, (2) generate IoT-specific signatures by employing piecewise hashing techniques, and (3) create access methods based on an API mechanism and a front-end service facilitated by Elasticsearch to allow the sharing of IoT-centric empirical data, threat intelligence and signatures.  This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
Inferring, Characterizing, and Investigating Internet-Scale Malicious IoT Device Activities: A Network Telescope Perspective
推断、表征和调查互联网规模的恶意物联网设备活动:网络望远镜视角
DOI: 10.1109/dsn.2018.00064
发表时间: 2018
期刊: 2018 48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN
影响因子: --
作者: [Torabi, Sadegh, Bou-Harb, Elias, Assi, Chadi, Galluscio, Mario, Boukhtouta, Amine, Debbabi, Mourad]
通讯作者: Debbabi, Mourad
DOI: 10.1109/icc.2018.8422720
发表时间: 2018
期刊: IEEE International Conference on Communications (ICC
影响因子: --
作者: [Pour, Morteza Safaei, Bou-Harb, Elias]
通讯作者: Bou-Harb, Elias
A first empirical look on internet-scale exploitations of IoT devices
对物联网设备的互联网规模利用的首次实证研究
DOI: 10.1109/pimrc.2017.8292628
发表时间: 2017
期刊: and Mobile Radio Communications (PIMRC
影响因子: --
作者: [Galluscio, Mario, Neshenko, Nataliia, Bou-Harb, Elias, Huang, Yongliang, Ghani, Nasir, Crichigno, Jorge, Kaddoum, Georges]
通讯作者: Kaddoum, Georges
Theoretic derivations of scan detection operating on darknet traffic
对暗网流量进行扫描检测的理论推导
DOI: --
发表时间: 2019
期刊: Computer communications
影响因子: 6
作者: [Safaei Pour, Morteza, Bou-Harb, Elias]
通讯作者: Bou-Harb, Elias
共 6 条
    Collaborative Research: CyberTraining: Implementation: Medium: Cross-Disciplinary Training for Joint Cyber-Physical Systems and IoT Security
    • 批准号:
      2230086
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $59.95万
    • 财政年份:
      2023
    • 负责人:
      Elias Bou-Harb
    • 依托单位:
    Collaborative Research: CyberTraining: Implementation: Medium: Cross-Disciplinary Training for Joint Cyber-Physical Systems and IoT Security
    • 批准号:
      2404946
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $59.95万
    • 财政年份:
      2023
    • 负责人:
      Elias Bou-Harb
    • 依托单位:
    OAC Core: Data-driven Methods and Techniques For Protecting Research and Critical Cyberinfrastructure By Characterizing and Defending Against Ransomware
    • 批准号:
      2348719
    • 项目类别:
      Standard Grant
    • 资助金额:
      $50.0万
    • 财政年份:
      2023
    • 负责人:
      Elias Bou-Harb
    • 依托单位:
    OAC Core: Data-driven Methods and Techniques For Protecting Research and Critical Cyberinfrastructure By Characterizing and Defending Against Ransomware
    • 批准号:
      2104273
    • 项目类别:
      Standard Grant
    • 资助金额:
      $50.0万
    • 财政年份:
      2021
    • 负责人:
      Elias Bou-Harb
    • 依托单位:
    国内基金
    海外基金
    Z8-12:OH和Z8-14:OAc分别维持梨小食心虫和李小食心虫性诱剂特异性的分子基础
    • 批准号:
      --
    • 项目类别:
      地区科学基金项目
    • 资助金额:
      35万元
    • 批准年份:
      2021
    • 负责人:
      陈秀琳
    • 依托单位:
    亚硝酰钌配合物[Ru(OAc)(2mqn)2NO]的光异构反应机理研究
    • 批准号:
      21603131
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      19.0万元
    • 批准年份:
      2016
    • 负责人:
      王建茹
    • 依托单位:
    机械化学条件下Mn(OAc)3促进的自由基串联反应研究
    • 批准号:
      21242013
    • 项目类别:
      专项基金项目
    • 资助金额:
      10.0万元
    • 批准年份:
      2012
    • 负责人:
      张泽
    • 依托单位: