SaTC: CORE: Small: Adversarial Network Reconnaissance in Software Defined Networking
SaTC: CORE: Small: Adversarial Network Reconnaissance in Software Defined Networking
批准号:
1946022
负责人:
Ting He
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
未结题
起止时间:
2020-03-15 至 2025-02-28
中文摘要
软件定义网络(SDN)从根本上改变了网络和构建在其上的系统的创建和维护方式。快速部署和重新配置SDN及其支持的服务的能力使组织能够灵活地应对不断变化的需求和威胁。此外,当与网络功能虚拟化(NFV)一起部署时,SDN使防火墙,网络入侵检测系统(NIDS)和负载均衡器等网络服务能够从其部署的物理基础设施中抽象出来,从而大大简化服务组合和扩展。然而,随着SDN被广泛采用,安全问题也随之出现。一方面,SDN的逻辑集中视图简化了对传统IP网络攻击(如端口扫描和防火墙探测)的防御。另一方面,SDN引入了对抗性侦察的新机会,这是一系列技术,允许内部和外部攻击者使用网络行为和控制平面消息来推断目标SDN的结构,配置和漏洞。为了保护未来的网络免受此类攻击者的攻击,该项目建议系统地了解SDN中对抗性侦察的技术,能力,基本限制和对策。该项目计划开发侦察技术的系统建模和分析,并在SDN中启用攻击。这种侦察的目的包括秘密提取策略(例如,规则替换策略)和各州(例如,网络拥塞状态、链路负载)。该项目计划通过开发和评估显式推理算法来实现这些目标,这些算法可以从容易获得的测量中学习目标SDN的内部参数,具体工作集中在基于主机的交换机内部参数侦察,以及基于交换机的内部逻辑侦察和重要控制应用的状态。为了了解对抗性侦察的后果,该项目还计划开发和评估利用侦察期间学习的网络参数的智能攻击。这种攻击的一般目标是在造成可测量的损害的同时最小化检测的风险,具体努力集中在设计攻击流以实现攻击性能和成本之间的最佳权衡的基于主机的智能攻击,以及利用目标控制应用的学习逻辑和状态的基于交换机的智能攻击(例如,负载平衡器)来操纵其决策。 这项工作将开发新的理论,算法,方法,评估工具和在线工具,将网络科学与安全分析结合起来,并与模拟和真实世界的实验相结合。其成果将推动SDN安全和漏洞分析的科学和实践,并通过激励攻击弹性设计来增强未来SDN的安全性。这项工作还将支持参与机构的教育,培养SDN和安全分析方面的专业人才,并促进PI在扩大参与计算方面的积极努力。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Software-defined networks (SDNs) have fundamentally altered the way in which networks and the systems built upon them are created and maintained. The ability to rapidly deploy and reconfigure SDNs and their supported services allow organizations to be agile in addressing changing needs and threats. Moreover, when deployed together with Network Function Virtualization (NFV), SDN enables network services such as firewalls, network intrusion detection systems (NIDS), and load balancers to be abstracted from the physical infrastructure that they are deployed on, thereby greatly simplifying service composition and scaling. However, as SDNs become widely adopted, the issue of security emerges. On the one hand, the logically centralized view of SDN eases defenses against traditional IP-network attacks such as port scanning and firewall probing. On the other hand, SDN introduces new opportunities for adversarial reconnaissance, which is a family of techniques that allow insider and outsider attackers to use the network behavior and control-plane messaging to infer the structure, configuration, and vulnerabilities of the target SDN. To secure future networks against such attackers, this project proposes to develop a systematic understanding of the techniques, capabilities, fundamental limits, and countermeasures of adversarial reconnaissance in SDNs. The project plans to develop systematic modeling and analysis of reconnaissance techniques and enabled attacks in SDNs. The objectives of such reconnaissance include the covert extraction of the policies (e.g., rule replacement policy) and the states (e.g., network congestion state, link loads) at both the network level and the service level. The project plans to achieve these objectives by developing and evaluating explicit inference algorithms that can learn the internal parameters of the target SDN from easily obtainable measurements, with concrete efforts focused on host-based reconnaissance of the internal parameters of switches, as well as switch-based reconnaissance of the internal logic and state of important control applications. To understand the consequence of adversarial reconnaissance, the project also plans to develop and evaluate intelligent attacks that make use of the network parameters learned during reconnaissance. The general objective of such attacks is to minimize the risk of detection while causing measurable damage, with concrete efforts focused on intelligent host-based attacks that design attack flows to achieve the optimal tradeoff between attack performance and cost, as well as intelligent switch-based attacks that exploit the learned logic and state of the target control application (e.g., load balancer) to manipulate its decisions. This work will develop new theories, algorithms, methodologies, evaluation harnesses, and online tools by combining network science with security analysis in concert with simulated and real-world experiments. Its outcome will advance the science and practice of SDN security and vulnerability analysis and enhance the security of future SDNs by motivating attack-resilient designs. The work will also support education at the participating institution and develop workforce expertise in SDN and security analysis, as well as fostering the PIs’ already active efforts in Broadening Participation in Computing.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(14)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Queuing Network Topology Inference Using Passive Measurements
使用被动测量进行排队网络拓扑推断
DOI:
--
发表时间:
2021
期刊:
IFIP Networking Conference
影响因子:
--
作者:
[Lin, Yilei, He, Ting, Pang, Guodong]
通讯作者:
Pang, Guodong
DOI:
10.1109/tnet.2021.3099717
发表时间:
2021-12
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
作者:
[Mingli Yu;Tian Xie;T. He;P. Mcdaniel;Quinn K. Burke]
通讯作者:
Mingli Yu;Tian Xie;T. He;P. Mcdaniel;Quinn K. Burke
DOI:
10.1109/infocom42981.2021.9488697
发表时间:
2021-05
期刊:
IEEE INFOCOM 2021 - IEEE Conference on Computer Communications
影响因子:
--
作者:
[Tian Xie;Ting-nian He;P. Mcdaniel;Namitha Nambiar]
通讯作者:
Tian Xie;Ting-nian He;P. Mcdaniel;Namitha Nambiar
DOI:
10.1145/3626789
发表时间:
2023-12
期刊:
Proceedings of the ACM on Measurement and Analysis of Computing Systems
影响因子:
--
作者:
[Yudi Huang;Yilei Lin;Ting He]
通讯作者:
Yudi Huang;Yilei Lin;Ting He
DOI:
10.1109/tnet.2022.3171720
发表时间:
2022-12
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
作者:
[Tian Xie;Namitha Nambiar;Ting He;P. Mcdaniel]
通讯作者:
Tian Xie;Namitha Nambiar;Ting He;P. Mcdaniel
共 12 条
Collaborative Research: CNS Core: Medium: Inference and Control in Overlay Networks
-
批准号:2106294
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2021
-
负责人:Ting He
-
依托单位:
CIF: Small: Adversarial Network Tomography: Inferring Network State from Manipulated End-to-End Measurements
-
批准号:1813219
-
项目类别:Standard Grant
-
资助金额:$17.0万
-
财政年份:2018
-
负责人:Ting He
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: