CPS: Medium: S2Guard: Building Security and Safety in Autonomous Vehicles via Multi-Layer Protection
CPS: Medium: S2Guard: Building Security and Safety in Autonomous Vehicles via Multi-Layer Protection
批准号:
1837519
负责人:
Wenjing Lou
金额:
$100.0万
依托单位国家:
美国
项目类别:
Cooperative Agreement
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2024-09-30
中文摘要
自动驾驶汽车(AV)正在给交通生态系统带来革命性的变化,并有望成为我们社会的重要组成部分。AVS配备了许多电子设备,包括各种传感器、电子控制单元(ECU)、内部控制网络以及人工智能、计算、存储和通信能力。尽管汽车行业和公众都乐观地认为,自动驾驶汽车可以像人类司机一样执行许多基本功能,但很少有人对自动驾驶汽车的安全性和安全性有信心,特别是当自动驾驶汽车非常容易受到来自网络空间的潜在攻击时,就像最近发生的一系列汽车黑客事件所表明的那样。在这个项目中,来自弗吉尼亚理工大学的一组研究人员致力于解决AVS的一些基本安全挑战。研究小组采用了一种新颖的深度防御方法,该方法结合了针对针对反病毒中的软件系统、车载网络和安全关键ECU的攻击的三层防御。每一层都可以独立于其他层进行设计和部署,当它们共同工作时,它们不仅可以有效地挫败大多数系统和网络攻击,而且还可以针对已知和潜在的不可预见的网络攻击提供故障操作保护。反病毒与网络空间的紧密结合带来了新的安全和安全风险,继续挑战着汽车行业和计算机安全社区。该项目将开发一个多层保护框架S2Guard,该框架采用深入防御的方法来解决由于网络攻击而产生的广泛的安全和安全问题。第一层旨在通过采用硬件辅助安全保护机制来增强具有外部接口的ECU的软件系统安全性。这方面的研究将集中在设计有效的软件系统设计,以隔离和保护安全关键软件组件,而不显著增加可信计算基础,同时仍然能够满足系统的实时要求。第二层旨在防御能够通过在车辆内物理绕过第一层防御或利用不可预见的漏洞来突破第一层防御的攻击者。重点是建立创新的车载网络安全机制,并实现对能够在车载网络内发送原始控制数据包的对手的网络级防御。最后一层防御旨在为AVS提供最坏情况下的安全保证,即使攻击者能够绕过前两层防御。该团队将开发新的方法来了解自动驾驶汽车的安全规则,并在运行时提供安全保证。这些安全机制将被部署在安全关键ECU中,以自动检测和纠正不安全的ECU行为。该奖项反映了NSF的法定使命,并已通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Autonomous vehicles (AVs) are revolutionizing the transportation ecosystem and are expected to become a critical part of our society. AVs are equipped with many electronic devices, including various sensors, electronic control units (ECUs), internal control networks, as well as capabilities in artificial intelligence, computing, storage, and communication. Although the automotive industry, as well as the public, are optimistic that an AV can perform many basic functions on par with human drivers, few are confident about the security and safety of AVs, especially when AVs are highly vulnerable to potential attacks from cyberspace, as demonstrated in recent series of car hacking incidents. In this project, a team of researchers from Virginia Tech aims to address some of the fundamental security and safety challenges for AVs. The research team follows a novel defense-in-depth approach that combines three layers of defense against attacks on software systems, in-vehicle networks, and safety-critical ECUs in an AV. Each layer can be designed and deployed independently from the other layers and when working jointly, they can not only effectively thwart most system and network attacks but also provide fail-operational protection against both known and potentially unforeseen cyberattacks. The close coupling of AV with cyberspace introduces new security and safety risks that continue to challenge the automobile industry and the computer security community. This project will develop a multi-layer protection framework, S2Guard, that takes a defense-in-depth approach to address a broad range of security and safety issues due to cyberattacks. The first layer aims to enhance the software system security of ECUs with external interfaces by employing hardware-assisted security protection mechanisms. Research in this thrust will focus on devising effective software system design to isolate and protect safety-critical software components, without significantly increasing the trusted computing base while still being able to meet real-time requirements of the system. The second layer aims to defend against attackers that are able to breach the first layer of defense by either physically bypassing it inside the vehicle or exploiting an unforeseen vulnerability. The focus is to build innovative in-vehicle network security mechanisms and enable network-level defenses against adversaries who are capable of sending raw control packets within the in-vehicle network. The last layer of defense aims to offer worst-case safety guarantee to AVs even if an attacker is able to circumvent the first two layers of defenses. The team will develop novel methods to understand the safety rules of autonomous vehicles and provide safety guarantees at runtime. These safety mechanisms are to be deployed in the safety-critical ECUs to automatically detect and correct unsafe ECU behaviors.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Real-time DoA Estimation for Automotive Radar
汽车雷达实时 DoA 估计
DOI:
10.23919/eurad50154.2022.9784501
发表时间:
2022
期刊:
2021 18th European Radar Conference (EuRAD
影响因子:
--
作者:
[Wu, Yubo, Li, Chengzhang, Hou, Y. Thomas, Lou, Wenjing]
通讯作者:
Lou, Wenjing
MS-PTP: Protecting Network Timing from Byzantine Attacks
MS-PTP:保护网络时序免受拜占庭攻击
DOI:
10.1145/3558482.3590184
发表时间:
2023
期刊:
WiSec '23: Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks
影响因子:
--
作者:
[Shi, Shanghao, Xiao, Yang, Du, Changlai, Shahriar, Md Hasan, Li, Ao, Zhang, Ning, Hou, Y. Thomas, Lou, Wenjing]
通讯作者:
Lou, Wenjing
RT-TEE: Real-time System Availability for Cyber-physical Systems using ARM TrustZone
RT-TEE:使用 ARM TrustZone 的网络物理系统的实时系统可用性
DOI:
10.1109/sp46214.2022.9833604
发表时间:
2022
期刊:
2022 IEEE Symposium on Security and Privacy (SP
影响因子:
--
作者:
[Wang, Jinwen, Li, Ao, Li, Haoran, Lu, Chenyang, Zhang, Ning]
通讯作者:
Zhang, Ning
DOI:
10.1109/tdsc.2022.3148990
发表时间:
2023-03
期刊:
IEEE Transactions on Dependable and Secure Computing
影响因子:
7.3
作者:
[Ning Wang;Yimin Chen;Yang Xiao-;Yang Hu;W. Lou;Y. T. Hou]
通讯作者:
Ning Wang;Yimin Chen;Yang Xiao-;Yang Hu;W. Lou;Y. T. Hou
DOI:
10.1109/infocom48880.2022.9796926
发表时间:
2022-05
期刊:
IEEE INFOCOM 2022 - IEEE Conference on Computer Communications
影响因子:
--
作者:
[Ning Wang;Yimin Chen;Yang Hu;W. Lou;Y. T. Hou]
通讯作者:
Ning Wang;Yimin Chen;Yang Hu;W. Lou;Y. T. Hou
共 8 条
Collaborative Research: SaTC: CORE: Medium: An Anti-tracking and Robocall-free Architecture for Next-G Mobile Networks
-
批准号:2247560
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2023
-
负责人:Wenjing Lou
-
依托单位:
CPS: Medium: Collaborative Research: Robust Sensing and Learning for Autonomous Driving Against Perceptual Illusion
-
批准号:2235232
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2023
-
负责人:Wenjing Lou
-
依托单位:
Conference: CISE CAREER Proposal Writing Workshop
-
批准号:2318476
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2023
-
负责人:Wenjing Lou
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: A Networking Perspective of Blockchain Security: Modeling, Analysis, and Defense
-
批准号:2154929
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2022
-
负责人:Wenjing Lou
-
依托单位:
SaTC: CORE: Medium: Collaborative: Toward Enforceable Data Usage Control in Cloud-based IoT Systems
-
批准号:1916902
-
项目类别:Standard Grant
-
资助金额:$75.0万
-
财政年份:2019
-
负责人:Wenjing Lou
-
依托单位:
EAGER: A Novel Approach to Achieve Real-time Wireless Network Optimization
-
批准号:1800650
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2018
-
负责人:Wenjing Lou
-
依托单位:
Collaborative Research: A Multi-Layer Approach Towards Reliable Cognitive Radio Networks
-
批准号:1443889
-
项目类别:Standard Grant
-
资助金额:$42.75万
-
财政年份:2014
-
负责人:Wenjing Lou
-
依托单位:
IEEE Communications Society Conference on Sensor, Mesh, and Ad Hoc Communications and Networks (SECON) 2011: Student Travel Awards
-
批准号:1138789
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2011
-
负责人:Wenjing Lou
-
依托单位:
NeTS: Small: Collaborative Research: Mobile Content Distribution in Vehicular Ad Hoc Networks
-
批准号:1117084
-
项目类别:Standard Grant
-
资助金额:$27.21万
-
财政年份:2011
-
负责人:Wenjing Lou
-
依托单位:
CSR: Small: Collaborative Research: Engineering Secure Data Computation Outsourcing in Cloud Computing
-
批准号:1117111
-
项目类别:Standard Grant
-
资助金额:$8.0万
-
财政年份:2011
-
负责人:Wenjing Lou
-
依托单位:
CSR: Small: Collaborative Research: Engineering Secure Data Computation Outsourcing in Cloud Computing
-
批准号:1155988
-
项目类别:Standard Grant
-
资助金额:$8.0万
-
财政年份:2011
-
负责人:Wenjing Lou
-
依托单位:
CAREER: Opportunistic Routing in Multihop and Multirate Wireless Networks
-
批准号:1156311
-
项目类别:Continuing Grant
-
资助金额:$27.2万
-
财政年份:2011
-
负责人:Wenjing Lou
-
依托单位:
CAREER: Opportunistic Routing in Multihop and Multirate Wireless Networks
-
批准号:0746977
-
项目类别:Continuing Grant
-
资助金额:$45.0万
-
财政年份:2008
-
负责人:Wenjing Lou
-
依托单位:
NeTS-NECO: Collaborative Research: New Approaches for Secure and Dependable Distributed Data Storage and Access Control in Mission-critical Wireless Sensor Networks
-
批准号:0831628
-
项目类别:Standard Grant
-
资助金额:$17.18万
-
财政年份:2008
-
负责人:Wenjing Lou
-
依托单位:
CT-ISG: Broadcast/Multicast Security in Multi-User Wireless Sensor Networks
-
批准号:0716306
-
项目类别:Continuing Grant
-
资助金额:$33.72万
-
财政年份:2007
-
负责人:Wenjing Lou
-
依托单位:
NeTS-NBD: COLLABORATIVE RESEARCH: UPASS-An Attack Resilient Security Architecture for Wireless Mesh Networks
-
批准号:0626601
-
项目类别:Continuing Grant
-
资助金额:$25.0万
-
财政年份:2006
-
负责人:Wenjing Lou
-
依托单位:
海外基金