课题基金 / 基金详情

NSF Convergence Accelerator Track G: 5G Hidden Operations through Securing Traffic (GHOST)

NSF Convergence Accelerator Track G: 5G Hidden Operations through Securing Traffic (GHOST)
NSF 融合加速器轨道 G:通过保护流量实现 5G 隐藏操作 (GHOST)
批准号:
2226426
负责人:
Keith Gremban
金额:
$74.92万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
已结题
起止时间:
2022-08-15 至 2024-07-31

项目摘要

项目成果

Keith Gremban的其他基金

相似基金

相关文献

中文摘要
翻译
:5G网络在世界各地的激增为美国政府组织、非政府人道主义援助组织和私营部门企业提供了一个有吸引力的机会,可以利用本土5G网络来消除安装和维护替代通信基础设施的成本。然而,在世界许多地区,5G网络的部署和运营是由不受信任的组织部署和运营的,这些组织可能对美国怀有敌意。在这些环境中,需要新的安全技术来确保运营安全。5G安全流量隐藏运营(Ghost)项目提供了四层安全保障。首先,Ghost保护终端用户和网络设备免受恶意网络的危害。其次,Ghost将个人身份匿名化,并模糊用户位置。第三,Ghost通过匿名通信连接并将“幽灵”流量引入网络以保持恒定的活跃度,从而防止可能揭示运营计划和活动的流量分析。最后,Ghost项目将通过注入模拟真实操作的“假标志”流量来进一步混淆流量分析,从而混淆和误导分析。Ghost技术将使从美国军方到私人实体的组织能够安全地在本地5G网络上运行,而不考虑网络运营商的政治。Ghost项目解决了核心的智力挑战,即在不可信的网络上提供安全的通信抵抗渗透和流量分析。幽灵计划将网络视为假定由敌对特工操作的黑匣子。应对这一挑战将给研究和运营社区带来四个智力上的好处。·首先,Ghost项目将提供保护终端用户设备和非本地网络设备免受渗透和危害的技术。该技术通过使用可信执行环境(TEE)在硬件级别保护设备。T恤背后的理念是,来自芯片边界之外的任何东西都是不可信的。TES通过实施数据和代码的完整性验证并在它们越过可信边界时对其进行加密来实施此可信边界。·第二,Ghost项目将提供匿名或伪装最终用户身份、位置和通信终端的技术。最终用户身份将使用软件定义的凭据进行保护。使用地理空间身份管理保护位置。通信连接受到点对点匿名化的保护。·第三,Ghost项目将提供技术,将正常流量与“幽灵”流量--本质上是网络白噪声--覆盖,以混淆流量分析。·第四,幽灵项目将提供技术来对流量进行建模并生成“虚假标记”流量。通过监控和模拟,将生成与特定操作相关联的交通模式模型。注入到网络中的“假标志”流量将反映与特定操作相关的流量,并对任何观察者具有说服力。GHOST技术将使任何网络的最终用户受益,而不仅仅是不可信的网络。Ghost项目成功的主要标准将是:·设备保护免受网络运营商的攻击;·用户身份、位置和通信连接的混淆;·流量模式的混淆;·注入“虚假旗帜”流量。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
: The proliferation of 5G networks around the world presents an attractive opportunity for U.S. government organizations, nongovernmental humanitarian aid organizations, and private sector enterprises to take advantage of indigenous 5G networks to eliminate the costs of installing and maintaining an alternate communications infrastructure. However, in many areas of the world, 5G networks are deployed and operated by organizations that are untrusted and potentially hostile to the U.S. In these environments, new security technologies are needed to secure operations. The 5G Hidden Operations through Securing Traffic (GHOST) project provides four layers of security. First, GHOST protects against end-user and networking devices from being compromised by a hostile network. Second, GHOST anonymizes individual identities and obscures user locations. Third, GHOST prevents traffic analysis that could reveal operational plans and activities by anonymizing communication connections and introducing “GHOST” traffic into the network to maintain a constant level of activity. Finally, the GHOST project will further obfuscate traffic analysis by injecting “false flag” traffic that models real operations to confuse and mislead analysis. The GHOST technology will enable organizations ranging from the U.S. military to private entities to securely operate over indigenous 5G networks, regardless of the politics of the network operators.The GHOST project addresses the core intellectual challenge of providing secure communications resistant to penetration and traffic analysis over untrusted networks. The GHOST project considers the network as a black box that is assumed to be operated by a hostile agent. Addressing the challenge will yield four intellectual benefits to the research and operational communities. • First, the GHOST project will deliver technology that will protect end-user devices and non-indigenous networking equipment from penetration and compromise. The technology secures devices at the hardware level through the use of Trusted Execution Environments (TEEs). The idea behind a TEE is that anything coming from outside the chip boundary is untrusted. TEEs enforce this trusted boundary by implementing integrity verification of data and code and encrypting them once they cross the trusted boundary. • Second, the GHOST project will deliver technology to anonymize or disguise end-user identities, locations, and communications endpoints. End-user identities will be protected using software defined credentials. Locations are protected using geo-spatial identity management. Communications connections are protected by peer-to-peer anonymization.• Third, the GHOST project will deliver technology to overlay normal traffic with “GHOST” traffic — essentially network white noise — to obfuscate traffic analysis. • Fourth, the GHOST project will deliver technology to model and generate “false flag” traffic. Through monitoring and simulation, models of traffic patterns associated with specific operations will be generated. “False flag” traffic injected into the network will reflect the traffic associated with a particular operation and be convincing to any observers.GHOST technology will benefit end-users of any network, not just untrusted networks. The primary criteria for success of the GHOST project will be:• Device protection from network operator attacks;• The obfuscation of user identities, locations, and communications connections;• The obfuscation of traffic patterns;• The injection of “false flag” traffic.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF Converence Accelerator Track G: 5G Hidden Operations through Securing Traffic (GHOST) Phase 2
  • 批准号:
    2326835
  • 项目类别:
    Cooperative Agreement
  • 资助金额:
    $498.32万
  • 财政年份:
    2023
  • 负责人:
    Keith Gremban
  • 依托单位:
海外基金