课题基金 / 基金详情

Robustness-as-evolvability: building a dynamic control plane with Software-Defined Networking

Robustness-as-evolvability: building a dynamic control plane with Software-Defined Networking
鲁棒性即进化性:使用软件定义网络构建动态控制平面
批准号:
EP/L022796/2
负责人:
Shishir Nagaraja
金额:
$15.25万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --

项目摘要

项目成果

Shishir Nagaraja的其他基金

相似基金

相关文献

中文摘要
翻译
高度可用的信息网络是现代社会日益重要的组成部分。有针对性的攻击是这些网络可用性的主要威胁。这些攻击利用网络基础设施中的薄弱组件并攻击它们,引发伤害最终受害者的副作用。有针对性的攻击是使用高度分布式的攻击者网络进行的,称为僵尸网络,由数千到数十万台受损计算机组成。一个关键特征是僵尸网络是可编程的,允许攻击者适应发展和适应基础设施提供商开发的防御。然而,当前的网络基础设施在很大程度上是静态的,因此无法适应快速发展的攻击者。为了设计有效的响应,一个可编程的网络基础设施是必要的,可以实现大规模的合作。我们的研究将创造一种新的安全网络基础设施,它可以检测对自身的目标攻击。然后,它会自动重组基础设施,以最大限度地提高攻击抵御能力。最后,它自我验证是否可以确保安全性和正确性的全局属性,即使基础设施的每个部分只有局部视图。我们的研究将检查收集和合并网络内分布优势点推断的技术,同时使用新颖的隐私技术将数据聚合对用户隐私的风险降至最低。我们开始解决可编程性本身带来的风险,通过开发智能保证技术,可以在基础设施重新编程之前验证良好意图的证据。我们为我们的设计设定了三个基本设计目标:(1)自动无缝地重组网络基础设施,以抵御针对基础设施战略目标的攻击。(2)测量系统,可以动态分配资源,并对基础设施上每个监测点收集数据的方式、位置、频率和强度进行精细控制。(3)在基础设施重新规划时,确保安全并遵守良好的结构弹性原则。我们的目标是开发基于智能和不断发展的网络基础设施的未来网络防御。
英文摘要
Highly available information networks are an increasingly essential component of the modern society. Targeted attacks are a key threat to the availability of these networks. These attacks exploit weak components in network infrastructure and attack them, triggering side-effects that harm the ultimate victim. Targeted attacks are carried out using highly distributed attacker networks called botnets comprising between thousands and hundreds of thousands of compromised computers. A key feature is that botnets are programmable allowing the attacker to adapt to evolve and adapt to defences developed by infrastructure providers. However current network infrastructure is largely static and hence cannot adapt to a fast evolving attacker.To design effective responses, a programmable network infrastructure enabling large-scale cooperation is necessary. Our research will create a new form of secure network infrastructure which detects targeted attacks on itself. It then automatically restructures the infrastructure to maximise attack resilience. Finally, it self-verifies whether global properties of safety and correctness can be assured even though each part of the infrastructure only has a local view of the world.Our research will examine techniques to collect and merge inferences across distributed vantage points within a network whilst minimising risks to user privacy from data-aggregation using novel privacy techniques. We make a start on addressing the risks introduced by programmability itself, by developing smart assurance techniques that can verify evidence of good intention before the infrastructure is reprogrammed.We set three fundamental design objectives for our design: (1) Automated and seamless restructuring of network infrastructure to withstand attacks aimed at strategic targets on the infrastructure.(2) A measurement system that allows dynamic allocation of resources and fine control over the manner, location, frequency, and intensity of data collected at each monitoring location on the infrastructure.(3) Assurance of safety and compliance to sound principles of structural resilience when infrastructure is reprogrammed.Our aim is to develop future network defences based on a smart and evolving network infrastructure.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
Poster
海报
DOI: --
发表时间: 2010
期刊:
影响因子: --
作者: [Bennett N G]
通讯作者: Bennett N G
Do we have the time for IRM?
我们有时间进行 IRM 吗?
DOI: 10.1145/3288599.3295582
发表时间: 2019
期刊:
影响因子: --
作者: [Shah R]
通讯作者: Shah R
Robustness-as-evolvability: building a dynamic control plane with Software-Defined Networking
  • 批准号:
    EP/L022796/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $44.08万
  • 财政年份:
    2015
  • 负责人:
    Shishir Nagaraja
  • 依托单位:
海外基金