SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
批准号:
1801613
负责人:
Jedidiah Crandall
金额:
$29.97万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-08-15 至 2020-10-31
中文摘要
智能和互联设备,也称为物联网(IoT)设备,现在是我们日常生活中不可或缺的一部分。这些设备广泛应用于汽车、电话、手表、家用电器、家庭安全系统以及关键应用中,如公用事业和生物医学行业。物联网设备提供的便利带来了独特的安全和隐私问题。由于上市时间缩短和公司之间的激烈竞争,安全性并没有被视为这些设备的优先事项。非常重要的是,物联网安全挑战与传统设备中存在的挑战不同,因为物联网设备(i)是异构的,(ii)具有有限的计算资源,并且(iii)可以大量流行。 因此,迫切需要开发标准化,高效和嵌入式的安全模块来保护这些设备免受网络攻击。该项目的目标是设计,实施和制造REVELARE,这是一种物联网设备的安全解决方案,可以通过两种方式保护物联网设备。第一种是通过嵌入在设备中的硬件模块,该模块可以根据预定义的安全策略分析和过滤低级别事件。第二个组件驻留在云环境中,并对从IoT设备连续记录的大量事件执行取证分析。 该项目有可能极大地提高物联网安全性。制造商将能够提供内置网络攻击保护的物联网设备。主要研究人员在计算机科学和工程领域具有互补的专业知识,在女性和少数民族学生的进步以及本科生参与研究项目方面有着良好的记录。此外,该项目还为未来在硬件换软件安全领域的工作开辟了新的途径,这一领域虽然仍处于起步阶段,但在网络安全方面有可能取得突破。REVELARE是一个硬件支持的动态信息流跟踪(DIFT)框架,旨在增强物联网安全和取证。它由以下部分组成:(i)用于ARM和RISC-V架构的DIFT使能核心,其补充具有DIFT能力的主处理器,(ii)两个基于DIFT的安全策略(防止内存损坏和仅内存攻击),其准确性通过捕获DIFT间接流来增强,以及(iii)基于物联网虚拟化的安全分析和取证机制,实现两种类型的安全/取证分析:因果关系图和个性化(每设备)异常检测。REVELARE实现了DIFT功能在满足物联网安全和取证需求方面的潜力,改变了学术界和工业界研究人员解决物联网安全问题的最新技术。我们高效(架构支持)和有效(解决间接流)的DIFT框架也可以为其他架构(例如,英特尔x86)在传统设备中得到利用。我们将设备内置保护与云重量级分析和取证相结合,有可能点燃物联网虚拟化的新领域,在物联网虚拟化中,物联网设备管理和安全性通过虚拟化设备外包到云。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Smart and connected devices, also known as Internet of Things (IoT) devices, are now an integral part of our daily lives. These devices are found in cars, phones, watches, appliances, home security systems, and in critical applications, such as utilities and in the biomedical industry. The convenience provided by IoT devices comes with unique security and privacy concerns. Because of the shortened time-to-market and the fierce competition among companies, security has not been treated as a priority in these devices. Very importantly, IoT security challenges are different from those present in conventional devices because IoT devices (i) are heterogeneous, (ii) have limited computational resources, and (iii) can be prevalent in very large numbers. Thus, there is an urgent need to develop standardized, efficient, and embedded security modules to protect such devices from cyber attacks. The goal of this project is to design, implement, and fabricate REVELARE, a security solution for IoT devices, which protects IoT devices in two ways. The first is through a hardware module embedded in the device, which can analyze and filter low-level events based on predefined security policies. The second component resides on a cloud environment and performs forensic analyses on a large set of events continuously recorded from the IoT device. This project has the potential to immensely improve IoT security. Manufacturers will be able to ship IoT devices with built-in protection against cyber attacks. The principal investigators, with complementary expertises in the Computer Science and Engineering fields, have a strong record of advancement of female and minority students, as well as involvement of undergraduate students in research projects. Further, this project opens up new avenues for future work in hardware-for-software security, an area which, while still in its infancy, has the potential for breakthroughs in cyber security.REVELARE is a hardware-supported dynamic information flow tracking (DIFT) framework to enhance IoT security and forensics. It consists of the following components: (i) a DIFT-enabling core for the ARM and the RISC-V architectures, which complements the main processor with DIFT capabilities, (ii) two DIFT-based security policies (prevention of memory corruption and in-memory-only attacks) enforced by hardware, whose accuracy is enhanced by the capture of DIFT indirect flows, and (iii) a mechanism for IoT virtualization-based security analysis and forensics, with the implementation of two types of security/forensics analyses: causality graphs and personalized (per-device) anomaly detection. REVELARE realizes the potential of DIFT capabilities for the needs of IoT security and forensics, transforming the state-of-the-art for how researchers in academia and industry have been addressing IoT security. Our efficient (architecture-supported) and effective (addressing indirect flows) DIFT framework can also inform future research on architecture-supported DIFT for other architectures (e.g., Intel x86) leveraged in traditional devices. Our combination of in-device built-in protection with cloud heavy-weight analysis and forensics has the potential to ignite the new field of IoT virtualization, in which IoT device management and security are outsourced to the cloud via virtualized devices.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI:
10.2478/popets-2019-0071
发表时间:
2019-07
期刊:
Proceedings on Privacy Enhancing Technologies
影响因子:
--
作者:
[Geoffrey Alexander;Antonio M. Espinoza;Jedidiah R. Crandall]
通讯作者:
Geoffrey Alexander;Antonio M. Espinoza;Jedidiah R. Crandall
Collaborative Research: SaTC: CORE: Medium: Rethinking the Fundamentals of Tunneling Technologies for Security, Privacy, and Usability
-
批准号:2141547
-
项目类别:Continuing Grant
-
资助金额:$46.66万
-
财政年份:2022
-
负责人:Jedidiah Crandall
-
依托单位:
Collaborative Research: CNS Core: Small: Internet-Scale Measurement of TCP/IP Implementation Weaknesses
-
批准号:2007741
-
项目类别:Standard Grant
-
资助金额:$22.5万
-
财政年份:2020
-
负责人:Jedidiah Crandall
-
依托单位:
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
-
批准号:2042795
-
项目类别:Standard Grant
-
资助金额:$6.64万
-
财政年份:2020
-
负责人:Jedidiah Crandall
-
依托单位:
NeTS: Large: Measuring and Modeling Internet Choke Points as Threats to Online Freedom
-
批准号:1518878
-
项目类别:Standard Grant
-
资助金额:$140.0万
-
财政年份:2015
-
负责人:Jedidiah Crandall
-
依托单位:
TWC: TTP Option: Large: Collaborative: Towards a Science of Censorship Resistance
-
批准号:1518523
-
项目类别:Continuing Grant
-
资助金额:$37.78万
-
财政年份:2015
-
负责人:Jedidiah Crandall
-
依托单位:
TWC: Small: Developing Advanced Digital Forensic Tools Based on Network Stack Side Channels
-
批准号:1420716
-
项目类别:Standard Grant
-
资助金额:$45.8万
-
财政年份:2014
-
负责人:Jedidiah Crandall
-
依托单位:
TWC: Medium: Collaborative: Measurement and Analysis Techniques for Internet Freedom on IP and Social Networks
-
批准号:1314297
-
项目类别:Standard Grant
-
资助金额:$59.7万
-
财政年份:2013
-
负责人:Jedidiah Crandall
-
依托单位:
Realizing Full-System Dynamic Information Flow Tracking via Relaxed Static Stability
-
批准号:1017602
-
项目类别:Standard Grant
-
资助金额:$45.54万
-
财政年份:2010
-
负责人:Jedidiah Crandall
-
依托单位:
TC: Medium: Collaborative Research: Securing Concurrency in Modern Systems
-
批准号:0905177
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Jedidiah Crandall
-
依托单位:
CAREER: Internet Measurement in the Cat's Cradle of Global Internet Censorship
-
批准号:0844880
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Jedidiah Crandall
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: