Towards Scalable Computer Defenses
Towards Scalable Computer Defenses
批准号:
RGPIN-2014-03782
负责人:
Somayaji, Anil
金额:
$2.33万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2015
资助国家:
加拿大
项目状态:
已结题
起止时间:
2015-01-01 至 2016-12-31
中文摘要
我们似乎正在输掉这场计算机安全之战。尽管各方在软件安全方面的投资都在增加,但攻击者仍然能够似乎随意地绕过防御。情况如此糟糕,以至于大型网络管理员必须假设他们的网络已经被渗透,无论他们为防御付出多少努力。
我们断言,这种看似无望的情况的关键原因是,攻击是可扩展的,而计算机防御是不可扩展的。攻击者可以在攻击开发中进行固定成本的投资(例如,找到零日漏洞攻击、开发漏洞攻击部署机制),从而使他们能够危害数百万台主机。然而,防御者可以花费无限的资源部署防火墙、安装反恶意软件、运行入侵防御系统,并手动审计他们的软件和配置,结果却发现他们的系统仍然受到攻击-假设他们足够幸运地注意到。
我们建议研究制造可伸缩防御背后的理论和实践。构建可扩展防御的关键见解是,攻击者的工作应该随着防御者的人口规模而扩展:应该要求攻击者付出与要被攻破的主机数量成比例的努力。这项研究的关键问题是,首先,我们如何从软件体系结构和经济角度定义防御可伸缩性,以及当前防御的可伸缩性在多大程度上是可扩展的。如果这项研究成功,它应该会为建造和评估新一代可扩展的计算机防御系统提供基础。
英文摘要
We seem to be losing the battle of computer security. Despite increasing investments in software security on all sides, attackers are still able to bypass defenses seemingly at will. The situation is so bad that large network administrators must assume that their networks have already been infiltrated no matter how much effort they put in to their defenses.
We assert that the key reason for this seemingly hopeless situation is that attacks are scalable while computer defenses are not. Attackers can make fixed-cost investments in attack development (e.g., finding a zero-day exploit, deveolping an exploit deployment mechanism) that can allow them to compromise millions of hosts. Defenders, however, can expend an unbounded amount of resources deploying firewalls, installing anti-malware software, running intrusion prevention systems, and manually auditing their software and configuration, only to find that their systems have still been compromised - assuming they are fortunate enough to even notice.
We propose to study the theory and practice behind making scalable defenses. The key insight for building scalable defenses is that attacker work should scale with the population size of the defenders: attackers should be required to expend effort proportional to the number of hosts that are to be compromised. The key questions addressed in this research are first, how can we define defense scalability in terms of software architecture and economics, and to what extent are current defenses scalable. If this research is successful it should provide a foundation for building and evaluating a new generation of scalable computer defenses.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Towards Scalable Computer Defenses
-
批准号:RGPIN-2014-03782
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.33万
-
财政年份:2018
-
负责人:Somayaji, Anil
-
依托单位:
Towards Scalable Computer Defenses
-
批准号:RGPIN-2014-03782
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.33万
-
财政年份:2017
-
负责人:Somayaji, Anil
-
依托单位:
Towards Scalable Computer Defenses
-
批准号:RGPIN-2014-03782
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.33万
-
财政年份:2016
-
负责人:Somayaji, Anil
-
依托单位:
Towards Scalable Computer Defenses
-
批准号:RGPIN-2014-03782
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.33万
-
财政年份:2014
-
负责人:Somayaji, Anil
-
依托单位:
Securing software with automated functional diversity
-
批准号:298545-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2013
-
负责人:Somayaji, Anil
-
依托单位:
Mobile Authentication & Fraud Detection
-
批准号:451552-2013
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$7.29万
-
财政年份:2013
-
负责人:Somayaji, Anil
-
依托单位:
Swipe-based implicit authentication for smartphones
-
批准号:442654-2012
-
项目类别:Engage Grants Program
-
资助金额:$1.82万
-
财政年份:2012
-
负责人:Somayaji, Anil
-
依托单位:
Securing software with automated functional diversity
-
批准号:298545-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2012
-
负责人:Somayaji, Anil
-
依托单位:
Securing software with automated functional diversity
-
批准号:298545-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2011
-
负责人:Somayaji, Anil
-
依托单位:
Securing software with automated functional diversity
-
批准号:298545-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2010
-
负责人:Somayaji, Anil
-
依托单位:
Securing software with automated functional diversity
-
批准号:298545-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2009
-
负责人:Somayaji, Anil
-
依托单位:
Improving security through lightweight learned models
-
批准号:298545-2007
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2008
-
负责人:Somayaji, Anil
-
依托单位:
Improving security through lightweight learned models
-
批准号:298545-2007
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2007
-
负责人:Somayaji, Anil
-
依托单位:
Improving security and availability through computer homeostasis
-
批准号:298545-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2006
-
负责人:Somayaji, Anil
-
依托单位:
Improving security and availability through computer homeostasis
-
批准号:298545-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2005
-
负责人:Somayaji, Anil
-
依托单位:
Improving security and availability through computer homeostasis
-
批准号:298545-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2004
-
负责人:Somayaji, Anil
-
依托单位:
国内基金
海外基金
Scalable Learning and Optimization: High-dimensional Models and Online Decision-Making Strategies for Big Data Analysis
-
批准号:--
-
项目类别:合作创新研究团队
-
资助金额:--
-
批准年份:2024
-
负责人:姚韬
-
依托单位: