课题基金 / 基金详情

Collaborative Research: CNS Core: Small: Retrofitting IoT Ecosystems with a Software-defined Overlay to Enforce Safety, Security, and Privacy Policies

Collaborative Research: CNS Core: Small: Retrofitting IoT Ecosystems with a Software-defined Overlay to Enforce Safety, Security, and Privacy Policies
合作研究:CNS 核心:小型:使用软件定义的覆盖层改造物联网生态系统,以执行安全、安保和隐私政策
批准号:
2006556
负责人:
Kasturi Varadarajan
金额:
$24.99万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2023-09-30

项目摘要

项目成果

Kasturi Varadarajan的其他基金

相似基金

相关文献

中文摘要
翻译
物联网(IoT)领域的最新进展已经实质性地改变了许多重要领域(例如,制造业、医疗保健、智能家居),通过引入可编程物联网平台来满足其不同的业务需求。这种可编程平台便于用户将一系列低功耗物联网设备汇集在一起,通过安装各种本地和第三方自动化应用程序来自动执行手头的定制任务。不幸的是,这些现有的可编程物联网平台中的许多都没有提供足够的内置安全措施(例如,细粒度访问控制),以阻止行为不当(流氓/故障)应用程序的风险。因此,行为不端的应用程序可以对设备进行不受限制的访问,从而将IoT系统转换到不期望和/或不安全的状态。这可能导致经济损失、致命后果或环境灾难。该项目的重点是通过防止本机和第三方应用程序管理物联网设备上的意外操作来保护物联网系统免受此类威胁。该项目开发了一个与平台无关的解决方案,有可能大幅提高现有可编程物联网系统的整体安全性、隐私性和安全性。本项目中开发的基础技术也适用于各种网络系统(例如,使命/安全关键系统)。为了开发一个有效的解决方案,这个合作研究项目依赖于物联网系统的不期望的状态转换可以被视为违反系统所需的有状态不变量或策略的洞察力。该系统应遵守这些政策,以确保其安全性,保密性和隐私保障。这项研究的核心目标是创建一个策略引导的防御机制,通过在运行时动态执行用户定义的策略,即使存在行为不端的应用程序,也可以防止物联网系统进入不期望的状态。本项目通过三个研究方向实现项目目标。第一个目标是设计一种统一的、表达性强的策略语言,以捕获用户定义的丰富的有状态策略,这将决定系统的预期行为。第二个重点是开发一个软件定义的覆盖,它不仅可以概括通过多种网络技术连接的异构物联网设备,还可以实现与平台无关的策略执行方法。第三个重点是设计必要的技术,以实现现实世界物联网生态系统的高级基础发展(例如,智能家居、工业控制系统)。为了培养一支有竞争力的网络安全人才队伍,该项目中开发的理论和原型用于教育本科生和研究生在构建实用、安全和弹性系统时的固有设计权衡。该奖项反映了NSF的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The recent advancement in the Internet-of-Things (IoT) domain has substantially transformed many important sectors (e.g., manufacturing, healthcare, smart-home) by introducing programmable IoT platforms to fulfill their varying business needs. Such programmable platforms facilitate a user to bring together a collection of low-powered IoT devices to automatically carry out customized tasks at hand by installing various native and third-party automation apps. Unfortunately, many of these existing programmable IoT platforms do not provide adequate in-built security measures (e.g., fine-grained access control) to thwart risks from misbehaving (rogue/faulty) apps. As a result, a misbehaving app can exercise unrestricted access to the devices and thus, transition the IoT system to an undesirable and/or unsafe state. This can lead to financial loss, fatal consequences, or environmental disasters. This project focuses on defending IoT systems against such threats by preventing native and third-party apps from administering unexpected operations on IoT devices. The project develops a platform-agnostic solution, which has the potential to substantially improve the overall security, privacy and safety of existing programmable IoT systems. The foundational techniques developed in this project are also applicable to a variety of networked systems (e.g., mission-/safety-critical systems). To develop an effective solution, this collaborative research project relies on the insight that undesirable state transitions of the IoT system can be viewed as violations of the system's desired stateful invariants or policies. The system is expected to comply with these policies to ensure its safety, security, and privacy guarantees. The core objective of this research is to create a policy-guided defense mechanism which prevents an IoT system from entering into an undesired state, even at the presence of misbehaving apps, by dynamically enforcing user-defined policies at runtime. This project realizes the project's objective through three research thrusts. The first thrust designs a unified, expressive policy language to capture user-defined rich stateful policies, which would dictate the expected behavior of a system. The second thrust develops a software-defined overlay which not only generalizes heterogeneous IoT devices connected through several network technologies but also enables a platform-agnostic policy enforcement approach. The third thrust devises the necessary techniques to realize the high-level foundational developments from the preceding thrusts for real-world IoT ecosystems (e.g., smart-home, industrial control systems). With the goal of developing a competitive cybersecurity workforce, the theories and prototypes developed in this project are used to educate undergraduate and graduate students on the inherent design trade-offs in building practical, secure and resilient systems.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3460120.3484569
发表时间: 2021-11
期刊: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Man Hong Hue;Joyanta Debnath;Kin Man Leung;Li Li-Li;Mohsen Minaei;M. Mazhar;Kailiang Xian;Md. Endadul Hoque;Omar Chowdhury;Sze Yiu Chau]
通讯作者: Man Hong Hue;Joyanta Debnath;Kin Man Leung;Li Li-Li;Mohsen Minaei;M. Mazhar;Kailiang Xian;Md. Endadul Hoque;Omar Chowdhury;Sze Yiu Chau
DOI: 10.1145/3460120.3485382
发表时间: 2021-11
期刊: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Moosa Yahyazadeh;Sze Yiu Chau;Li Li-Li;Man Hong Hue;Joyanta Debnath;Sheung Chiu Ip;Chun Ngai Li;Md. Endadul Hoque;Omar Chowdhury]
通讯作者: Moosa Yahyazadeh;Sze Yiu Chau;Li Li-Li;Man Hong Hue;Joyanta Debnath;Sheung Chiu Ip;Chun Ngai Li;Md. Endadul Hoque;Omar Chowdhury
DOI: 10.1145/3460120.3484793
发表时间: 2021-11
期刊: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Joyanta Debnath;Sze Yiu Chau;Omar Chowdhury]
通讯作者: Joyanta Debnath;Sze Yiu Chau;Omar Chowdhury
AF: Small: Geometric Clustering and Covering: New Directions
  • 批准号:
    1615845
  • 项目类别:
    Standard Grant
  • 资助金额:
    $39.97万
  • 财政年份:
    2016
  • 负责人:
    Kasturi Varadarajan
  • 依托单位:
AF: Small: Some New and Old Frontiers in Geometric Optimization
  • 批准号:
    1318996
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.99万
  • 财政年份:
    2013
  • 负责人:
    Kasturi Varadarajan
  • 依托单位:
CAREER: Algorithms for fitting, matching, and simplifying shapes
  • 批准号:
    0237431
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $40.07万
  • 财政年份:
    2003
  • 负责人:
    Kasturi Varadarajan
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)