课题基金 / 基金详情

Towards Provable Security of Real-world Servers: Where Online Learning Meets Server Retrofitting

Towards Provable Security of Real-world Servers: Where Online Learning Meets Server Retrofitting
实现现实服务器的可证明安全性:在线学习与服务器改造的结合
批准号:
2140175
负责人:
Minghui Zhu
金额:
$42.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-09-01 至 2025-08-31

项目摘要

项目成果

Minghui Zhu的其他基金

相似基金

相关文献

中文摘要
翻译
位于企业(例如私有数据中心和公共云数据中心)中的服务器在人类社会中扮演着至关重要的角色。然而,现实世界中的服务器受到各种安全漏洞的困扰。内存覆盖和过度读取漏洞是已知漏洞中最危险的漏洞。它们是各种严重的真实服务器攻击的根本原因。网络防御被广泛部署,以保护现实世界的服务器免受这些网络攻击。然而,网络安全界普遍认为,没有灵丹妙药。此外,现有的网络防御(例如打补丁)在处理所谓的零日漏洞方面仍然非常有限。此外,一个根本的限制是,广泛部署的现实世界防御措施通常不提供可证明的保证。该项目旨在开发基于在线学习的自适应网络防御,有望为现实世界的服务器提供可证明的保证。开发的防御将为对手提供经过优化的动态变化的攻击面,从而显著增加对手为取得成功而需要克服的不确定性和复杂性。该项目将开发一个新的联合设计框架,以保护数据中心免受(I)通过动态运行时环境的随机攻击;(Ii)通过动态平台的智能战略攻击;(Iii)通过动态网络的多阶段攻击。合作设计框架将涉及三个相互交织的组件:新合成的数学模型、基于在线学习的防御算法和服务器改造。特别是,数学模型将是高保真的,而且在分析上也很容易处理,从而允许在线学习提供可证明的保证。另一方面,数学模型与现实世界服务器的偏差将通过服务器改造来弥合。在每个提出的数学模型中,效用函数可以通过部署的初步防御来轻松地评估,并将提供执行在线学习所需的反馈,另一方面,它适当地反映了防御的成本效益。开发在线学习算法是为了应对计算机安全的独特挑战(例如,检测延迟、检测不准确、战略攻击、未知系统状态和未知利用可能性)。将定制最合适的服务器改装,以满足数学模型的假设。此外,这三个相互交织的组成部分将被整合到真正的防御中。拟议的研究是跨学科的,整合了机器学习、博弈论、控制论和网络安全的技术工具。将举办黑客松活动,鼓励学生参与机器学习和网络安全的研究。所有研究成果将提供给行业利益相关者、联邦政府机构和研究社区。这一奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Servers located in enterprises (e.g. private data centers and public cloud data centers) play a critical role in human society. However, real-world servers are plagued by various security vulnerabilities. Memory overwrite and over-read vulnerabilities are among the most dangerous of the known vulnerabilities. They are the root causes for a variety of serious real-world server attacks. Cyber-defenses are broadly deployed to protect real-world servers from these cyberattacks. However, it is widely recognized in the cybersecurity community that there is no silver bullet. Moreover, the existing cyber-defenses (e.g. patching) are still very limited in handling the so-called zero-day vulnerabilities. Furthermore, a fundamental limitation is that the widely deployed real-world defenses usually do not provide provable guarantees. This project aims to develop online learning-based adaptive cyber defenses, which are expected to be able to provide provable guarantees for real-world servers. The developed defenses will present adversaries with optimized dynamically changing attack surfaces, thereby significantly increasing uncertainty and complexity that adversaries would need to overcome in order to succeed. These measures are expected to substantially improve adaptive and autonomous defense capabilities of real-world servers against zero-day attacks.This project will develop a new co-design framework to protect data centers against (i) stochastic attacks through dynamic runtime environments; (ii) intelligent strategic attacks through dynamic platforms; and (iii) multi-stage attacks through dynamic networks. The co-design framework will involve three intertwined components: newly synthesized mathematical models, online learning-based defense algorithms and server retrofitting. In particular, the mathematical models will be of high-fidelity and also analytically tractable to allow online learning to provide provable guarantees. On the other hand, the deviations of the mathematical models from real-world servers will be bridged by server retrofitting. In each proposed mathematical model, a utility function can be easily evaluated by deployed preliminary defenses and will provide necessary feedback to perform online learning, and on the other hand, it properly reflects the cost-effectiveness of defenses. Online learning algorithms are developed to tackle the unique challenges of computer security (e.g., detection delays, detection inaccuracies, strategic attacks, unknown system states and unknown exploit likelihoods). The most suitable server retrofitting will be customized to meet the assumptions of the mathematical models. Further, the three intertwined components will be integrated into real defenses. The proposed research is interdisciplinary and integrates technical tools from machine learning, game theory, control theory and cybersecurity. Hackathon events will be held to inspire students’ engagement in research on machine learning and cybersecurity. All the research results will be made available to industrial stakeholders, federal government agencies and the research community.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2022
期刊:
影响因子: --
作者: [Xu Zhang;Zhenyuan Yuan;Minghui Zhu]
通讯作者: Xu Zhang;Zhenyuan Yuan;Minghui Zhu
DOI: 10.1609/aaai.v37i10.26473
发表时间: 2023-02
期刊:
影响因子: --
作者: [Siyuan Xu;Minghui Zhu]
通讯作者: Siyuan Xu;Minghui Zhu
DOI: 10.1145/3597926.3598062
发表时间: 2023-07
期刊: Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis
影响因子: --
作者: [Kai Cheng;Yaowen Zheng;Tao Liu;Le Guan;Peng Liu;Hong Li;Hongsong Zhu;Kejiang Ye;Limin Sun]
通讯作者: Kai Cheng;Yaowen Zheng;Tao Liu;Le Guan;Peng Liu;Hong Li;Hongsong Zhu;Kejiang Ye;Limin Sun
CAREER: New control-theoretic approaches for cyber-physical privacy
Data-driven distributed control of mobile robotic networks: Where machine learning meets game theory
Breakthrough: CPS-Security: Towards Provably Correct Distributed Attack-Resilient Control of Unmanned-Vehicle-Operator Networks
海外基金