课题基金 / 基金详情

CNS Core: Small: BehavIoT: Modeling and Controlling Internet of Things Behavior Using Netowork-Inferred State Machines

CNS Core: Small: BehavIoT: Modeling and Controlling Internet of Things Behavior Using Netowork-Inferred State Machines
CNS 核心:小型:BehavIoT:使用网络推断状态机建模和控制物联网行为
批准号:
1909020
负责人:
David Choffnes
金额:
$49.86万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2022-09-30

项目摘要

项目成果

David Choffnes的其他基金

相似基金

相关文献

中文摘要
翻译
越来越多的智能互联对象,即物联网(IoT),正在变得负担得起、受欢迎和功能丰富。虽然这些设备带来了广泛的社会效益,包括健康、安全、可获得性和可持续性,但由于它们提供的大量不同服务,它们也带来了重要的安全、隐私和管理挑战。为此类行为打开大门的根本问题是,物联网系统传统上是封闭的系统,为消费者和调查人员提供关于一台设备(或一组设备)的行为方式是否可能违反隐私、安全性和正确性等预期的信息很少或根本没有。为了解决这一问题,该项目将研究如何自动确定物联网系统何时危及隐私、安全和正确性,以及如何缓解这些问题。关键思想是将重点放在从此类设备产生的网络流量收集的信息上,因为网络流量是所有此类物联网系统最终依赖的公共平台。具体地说,该项目将开发技术,根据物联网系统的网络流量对物联网系统的行为进行建模,然后使用这些模型来识别意外行为。为了减少意外行为,该项目将确定网络内策略,例如隔离、更改和/或阻止此类流量。通过了解设备行为并对其进行建模,并解决来自物联网设备的意外行为,该项目有可能提高用户的安全性。此外,通过提高对新威胁和现有威胁的认识,我们建议的工作可以鼓励设备制造商提高其部署的隐私、安全性和正确性。该项目的目标是探索物联网部署的网络推断行为分析,以及对其生成的网络流量的控制,在多大程度上可以识别和减少物联网系统中的不当行为。我们的主要见解是,物联网设备特别容易接受状态机分析,因为它们往往具有有限的功能集(即,状态,如“摄像机记录”、“麦克风监听”等)。这是由一系列有限的事件触发的。为了解决人们不能依靠源代码通过静态分析来构建此类模型的事实,该项目将把物联网设备视为黑匣子,并推断使用所有物联网设备生成的外部可观察信号来描述其行为的状态机模型:网络流量。在构建了这样的推断状态机(以及它们的转移概率)之后,该项目将分析它们随时间的演变,以识别错误行为--当设备以意外或不想要的方式在状态之间转移时(例如,由于危害、数据外泄或错误配置)。为了覆盖广泛的不当行为,该项目将(I)检测以前依靠非监督分类技术从未遇到过的行为;(Ii)通过在我们的模型中结合单个物联网设备的行为来考虑整个系统的行为,从而捕获任何紧急全局系统行为的原因;(Iii)产生一个易于理解和分析的系统范围行为模型,例如状态机,其中状态表示单个物联网设备的行为变化,转换显示以概率表示的时间依赖关系。最后,该项目将使用中间盒来实际使用状态机模型,作为保护整个物联网系统免受个人和全局不当行为影响的一种方式。这种方法的一个优势是,它依靠物联网系统中的共同点,即互联网流量,自然是独立于平台的;此外,网络内解决方案可以立即部署(例如,在家庭或企业网关中)以实现广泛影响。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
An increasing number of smart interconnected objects, known as the Internet of Things (IoT), are becoming affordable, popular, and rich in functionality. While these devices enabled a wide range of societal benefits including health, safety, accessibility and sustainability, they also present important security, privacy, and management challenges due to the large set of diverse services they offer. The fundamental problem that opens the door to such behavior is that IoT systems are traditionally closed systems that provide consumers and investigators with little-to-no information about whether a device (or set of devices) is behaving in ways that might violate expectations such as privacy, security, and correctness. To address this problem, this project will investigate how to automatically determine when IoT systems compromise privacy, security and correctness, and how to mitigate such problems. The key idea is to focus on information gleaned from the network traffic that such devices generate, since network traffic is the common platform that all such IoT systems ultimately rely upon. Specifically, the project will develop technology that models the behavior of an IoT system from its network traffic, then use these models to identify unexpected behavior. To mitigate unexpected behavior, the project will identify in-network strategies such as isolating, changing, and/or blocking such traffic. By understanding and modeling device behavior and addressing unexpected behavior from IoT devices, this project has the potential to improve safety and security for users. Further, by raising awareness of new and existing threats, our proposed work can encourage device manufacturers to improve the privacy, security, and correctness of their deployments.The goal of this project is to explore the extent to which network-inferred behavioral analysis of IoT deployments, combined with control over the network traffic they generate, can identify and mitigate misbehavior in IoT systems. Our key insight is that IoT devices are particularly amenable to state-machine analysis, as they tend to have a limited set of functionality (i.e., states such as "camera recording", "microphone listening", etc.) that is triggered by a limited set of events. To address the fact that one cannot rely on source code to build such models via static analysis, this project will instead treat IoT devices as black boxes and inferring state-machine models that describe their behavior using the one externally observable signal all IoT devices generate: net- work traffic. After building such inferred state machines (and their transition probabilities), the project will analyze their evolution over time to identify misbehaviors -- when a device transitions between states in unexpected or unwanted ways (e.g., due to compromise, data exfiltration, or misconfiguration). To provide coverage of a wide range of misbehaviors, the project will (i) detect behaviors that never before encountered by relying on unsupervised classification techniques; (ii) consider the behavior of the system as a whole by combining in our model the behavior of individual IoT devices, thus capturing the cause of any emergent global system behavior; (iii) produce a system-wide behavior model that is easy to understand and analyze in practice, such as a state machine in which states represents changes in the behavior of individual IoT devices, and transitions show temporal dependencies expressed as probabilities. Finally, the project will employ middleboxes to actually use state machine models as a way to protect a whole IoT system from both individual and global misbehavior. An advantage to this approach is that it is naturally platform-independent by relying on the common denominator in IoT systems, i.e., Internet traffic; further, an in-network solution can be immediately deployed (e.g., in a home or enterprise gateway) for broad impact.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
Blocking Without Breaking: Identification and Mitigation of Non-Essential IoT Traffic
阻塞而不中断:非必要物联网流量的识别和缓解
DOI: 10.2478/popets-2021-0075
发表时间: 2021
期刊: Proceedings on Privacy Enhancing Technologies
影响因子: --
作者: [Mandalari, Anna Maria, Dubois, Daniel J., Kolcun, Roman, Paracha, Muhammad Talha, Haddadi, Hamed, Choffnes, David]
通讯作者: Choffnes, David
Detecting consumer IoT devices through the lens of an ISP
通过 ISP 的视角检测消费者物联网设备
DOI: 10.1145/3472305.3472885
发表时间: 2021
期刊: ANRW '21: Proceedings of the Applied Networking Research Workshop
影响因子: --
作者: [Saidi, Said Jawad, Mandalari, Anna Maria, Haddadi, Hamed, Dubois, Daniel J., Choffnes, David, Smaragdakis, Georgios, Feldmann, Anja]
通讯作者: Feldmann, Anja
When Speakers Are All Ears: Characterizing Misactivations of IoT Smart Speakers
当扬声器全神贯注时:物联网智能扬声器误激活的特征
DOI: 10.2478/popets-2020-0072
发表时间: 2020
期刊: Proceedings on Privacy Enhancing Technologies
影响因子: --
作者: [Dubois, Daniel J., Kolcun, Roman, Mandalari, Anna Maria, Paracha, Muhammad Talha, Choffnes, David, Haddadi, Hamed]
通讯作者: Haddadi, Hamed
DOI: 10.1145/3487552.3487830
发表时间: 2021-11
期刊: Proceedings of the 21st ACM Internet Measurement Conference
影响因子: --
作者: [Muhammad Talha Paracha;Daniel J. Dubois;Narseo Vallina-Rodriguez;D. Choffnes]
通讯作者: Muhammad Talha Paracha;Daniel J. Dubois;Narseo Vallina-Rodriguez;D. Choffnes
NeTS: Small: Continuous Monitoring and Localization of Network Neutrality Violations
  • 批准号:
    2332541
  • 项目类别:
    Standard Grant
  • 资助金额:
    $10.0万
  • 财政年份:
    2023
  • 负责人:
    David Choffnes
  • 依托单位:
RAPID: Collaborative Research: The Internet under Widespread Shelter-in-Place: Resilience, Response, and Lessons for the Future
  • 批准号:
    2028536
  • 项目类别:
    Standard Grant
  • 资助金额:
    $7.5万
  • 财政年份:
    2020
  • 负责人:
    David Choffnes
  • 依托单位:
SaTC: Frontiers: Collaborative: Protecting Personal Data Flow on the Internet
  • 批准号:
    1955227
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $169.73万
  • 财政年份:
    2020
  • 负责人:
    David Choffnes
  • 依托单位:
CAREER: Personal Virtual Networks
  • 批准号:
    1750253
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $51.34万
  • 财政年份:
    2018
  • 负责人:
    David Choffnes
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: