Secure Networking by Design (SNbD)
Secure Networking by Design (SNbD)
批准号:
10028034
负责人:
金额:
$152.93万
依托单位:
依托单位国家:
英国
项目类别:
Collaborative R&D
财政年份:
2022
资助国家:
英国
项目状态:
未结题
起止时间:
2022 至 --
中文摘要
根据最近的一份行业报告,路由器占受感染设备的75%以上,受感染的路由器比受感染的物联网设备、电话或PC更危险。路由器既是几乎所有网络流量的中介,也是抵御外部攻击(防火墙)的防线;因此,受损的路由器可能会打开新攻击的闸门,并充当二次攻击的跳跃点。因为路由器实际上控制着网络,所以它具有对整个设备组合进行中间人攻击的潜伏能力。回顾已披露的漏洞显示,与路由组件中的当前和历史内存相关的漏洞列表是巨大的。不可避免地,最危险的漏洞是一个尚未公开的漏洞。安全网络设计(SNBD)项目直接解决了这一威胁。在路由器安全(多安全)最新进展的基础上,SNbD项目将加强对路由器和网络的保护。在Cheri/Morello SNbD的基础上,SNbD将使用内存保护和安全分区功能来提高路由器提供的安全性。通过采用模块化方法,SNBD将确保在这一努力中升级的单个模块可用于其他操作系统和应用程序,以确保最大限度地影响生态系统。SNBD将以开放的方式运行,并公开接受第三方贡献。从一开始,SNBD将被设计为一个自我维持的、协作的计划,具有长期的遗产。SNBD直接应对最重要和高度扩展的安全威胁;感染和交叉感染互联网连接设备的能力。Cheri/Morello架构提供的安全保护与该领域的相关性最强。SNbD是NquiringMinds、牛津大学和TechWorks的合作成果,这些组织无论是个人还是集体都在大规模提供积极的安全影响方面有着堪称典范的记录。
英文摘要
According to a recent industry report routers account for over 75% of infected devices An infected router is more dangerous than infected IOT devices, phones or PCs. A router is both an intermediary for almost all networking traffic and a line of defence from external attack (firewall); a compromised router therefore has the potential to both open the floodgates to new attacks and act as a jump off point for secondary attacks. Because the router essentially controls the network, it has insidious ability to mount man in the middle attacks on entire portfolios of devices.A review of disclosed vulnerabilities show that the list of current and historical memory related vulnerabilities in routing components is enormous. And inevitably the most dangerous vulnerability is the one not yet publicly disclosed.The Secure Networking by Design (SNbD) project directly addresses this threat. Building on recent advances in router security (ManySecured), the SNbD project will to harden router and networking protections. Building on CHERI/Morello SNbD will use the memory protection and secure compartmentalisation features to improve the security offered by routers. By taking a modular approach SNbD, will ensure that the individual modules that are upgraded in this endeavour are available to other operating systems and applications, guaranteeing maximum ecosystem impact.SNbD will operate in a "working in open" fashion, and openly accept third party contributions. From the outset, SNbD will be designed to be a self sustaining, collaborative initiative, with a long lasting legacy.SNbD directly addresses, the most significant, and hyper scaling security threat; the ability to infect and cross infect internet connected devices. The security protections the CHERI/Morello architecture offers, are more relevant to this domain than any other.SNbD is a collaboration between NquiringMinds, University of Oxford and the Techworks; organisations which both individually and collectively have an exemplary track record of delivering positive security impact at scale.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金