Collaborative research: Testing and Benchmarking Methodologies for Future Networking Security Mechanisms
合作研究:未来网络安全机制的测试和基准测试方法
基本信息
- 批准号:0335247
- 负责人:
- 金额:--
- 依托单位:
- 依托单位国家:美国
- 项目类别:Cooperative Agreement
- 财政年份:2003
- 资助国家:美国
- 起止时间:2003-09-01 至 2007-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Networks and computer systems are becoming increasingly attractive targets to large-scale programmedattacks such as worms and Distributed Denial of Service attacks (DDoS), which can compromise a vastnumber of vulnerable targets in a few minutes. Critical end-user applications vulnerable to such attacksinclude e-commerce, e-medicine, command-and-control applications, video surveillance and tracking, andmany other applications. While there is a growing body of research techniques, prototypes, and commercialproducts that purport to protect these applications and the network infrastructure on which they rely, thereis little existing scientific methodology by which to objectively evaluate the merits of such claims. Moreover,thorough testing of a defense system for worms or for attacks on the infrastructure cannot be evaluatedsafely on a live network without affecting its operation.To make rapid advancements in defending against these and future attacks, the state of the art in theevaluation of network security mechanisms must be improved. This will require the emergence of large-scalesecurity testbeds coupled with new standards for testing and benchmarking that can make these testbedstruly useful. Current shortcomings and impediments to evaluating network security mechanisms include lackof scientific rigor;lack of relevant and representative network data;inadequate models of defense mechanisms;and inadequate models of both the network and the transmitted data (benign and attack traffic). The latteris challenging because of the complexity of interactions among traffic, topology and protocols.The researchers propose to develop thorough, realistic,and scientifically rigorous testing frameworks and methodologies for particular classes of network attacks and defense mechanisms. These testing frameworks will be adapted for different kinds of testbeds, including simulators such as NS, emulation facilities such as Emulab, and both small and large hardware testbeds. They will include attack scenarios; attack simulators;generators for topology and background traffic; data sets derived from live traffic; and tools to monitor andsummarize test results. These frameworks will allow researchers to experiment with a variety of parameters representing the network environment, attack behaviors, and the configuration of the mechanisms under test.In addition to developing testing frameworks, the researchers propose to validate them by conducting tests on representative network defense mechanisms. Defense mechanisms of interest include network-based Intrusion Detection Systems (IDS); automated attack traceback mechanisms;t raffic rate-limiting to control DDoS attacks; and mechanisms to detect large-scale worm attacks. Conducting these tests will require incorporating real defense mechanisms into a testbed, and applying and evaluating frameworks and methodologies. Conducting these tests will also help us to ensure that the testbed framework allows other researchers to easily integrate and test network defense echanisms of their own.The research team includes experts in security, networking, data analysis, software engineering, and operating systems who are committed to developing these challenging integrated testing frameworks.Intellectual Merit: The development of testing methodologies for network defense mechanisms requiressignificant advances in our understanding of network attacks and the interactions between attacks and theirenvironment including:deployed defense technology, traffic, topology, protocols, and applications. It willalso require advances in our understanding of metrics for evaluating defenses.Education: The research into testing methodologies for network defense mechanisms will involve graduate students and provide new curriculum material for universities.Broader Impact: By providing new testing frameworks, the work will accelerate improvements innetwork defense mechanisms and facilitate their evaluation and deployment. The researchers will hold yearly workshops to disseminate results and obtain community feedback.
网络和计算机系统正越来越有吸引力的目标对大规模编程的目标(例如蠕虫和分布式拒绝服务攻击(DDOS)),这可能会在几分钟内损害大量的弱势目标。关键的最终用户应用程序很容易受到此类攻击的攻击,包括电子商务,电子商务,指挥和控制应用程序,视频监视和跟踪,其他应用程序。尽管越来越多的研究技术,原型和商业生产旨在保护这些应用程序以及它们所依赖的网络基础架构,但几乎没有现有的科学方法来客观地评估此类主张的优点。此外,对防御系统的蠕虫或对基础设施的攻击的彻底测试不能在不影响其运营的情况下在实时网络上进行评估。要在防御这些和未来的攻击方面取得快速的进步,必须改善网络安全机制的最新技术。这将需要大规模测试床的出现,再加上用于测试和基准测试标准的新标准,这些标准可以使这些测试床位有用。当前评估网络安全机制的缺点和障碍包括缺乏科学严谨性;缺乏相关和代表性的网络数据;防御机制模型不足;网络模型和传输数据(良性和攻击流量)的模型不足。由于流量,拓扑和协议之间相互作用的复杂性,后来的挑战。研究人员建议为特定类别的网络攻击和防御机制开发彻底,现实和科学严格的测试框架和方法。这些测试框架将适用于不同类型的测试台,包括NS,仿真设施(例如Emulab)以及小型和大型硬件测试台。它们将包括攻击方案;攻击模拟器;用于拓扑和背景流量的发电机;来自实时流量的数据集;以及监视测试结果的工具。这些框架将使研究人员可以尝试各种代表网络环境,攻击行为以及正在测试的机制的配置的参数。在开发测试框架的外,研究人员建议通过对代表性网络防御机制进行测试来验证它们。 感兴趣的防御机制包括基于网络的入侵检测系统(IDS);自动攻击追溯机制;限制限制DDOS攻击;以及检测大规模蠕虫攻击的机制。进行这些测试将需要将实际的防御机制纳入测试床,并应用和评估框架和方法论。 Conducting these tests will also help us to ensure that the testbed framework allows other researchers to easily integrate and test network defense echanisms of their own.The research team includes experts in security, networking, data analysis, software engineering, and operating systems who are committed to developing these challenging integrated testing frameworks.Intellectual Merit: The development of testing methodologies for network defense mechanisms requiressignificant advances in our understanding of network attacks and the interactions between attacks and他们的环境包括:部署国防技术,交通,拓扑,协议和应用程序。 WillaLSO需要我们对评估防御的指标的理解的进步。研究人员将举办年度研讨会,以传播结果并获得社区反馈。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

暂无数据
数据更新时间:2024-06-01
Sonia Fahmy其他文献
ATM Forum Document Number: ATM_Forum/96-1294 ************************************************************************ Title: Performance of TCP over ABR on ATM backbone and with various VBR traffic patterns
ATM 论坛文档编号:ATM_Forum/96-1294 ********************************************
- DOI:
- 发表时间:20162016
- 期刊:
- 影响因子:0
- 作者:Sonia FahmySonia Fahmy
- 通讯作者:Sonia FahmySonia Fahmy
Understanding the Impact of Wi-Fi Configuration on Volumetric Video Streaming Applications
了解 Wi-Fi 配置对体积视频流应用的影响
- DOI:10.1145/3609395.361059910.1145/3609395.3610599
- 发表时间:20232023
- 期刊:
- 影响因子:0
- 作者:U. Kulkarni;Khaled Diab;S. Aggarwal;Lianjie Cao;Faraz Ahmed;P. Sharma;Sonia FahmyU. Kulkarni;Khaled Diab;S. Aggarwal;Lianjie Cao;Faraz Ahmed;P. Sharma;Sonia Fahmy
- 通讯作者:Sonia FahmySonia Fahmy
Downscaling Network Scenarios with Denial of Service (DoS) Attacks
通过拒绝服务 (DoS) 攻击缩小网络场景
- DOI:10.1109/sarnof.2008.452009910.1109/sarnof.2008.4520099
- 发表时间:20082008
- 期刊:
- 影响因子:0
- 作者:Wei;Sonia FahmyWei;Sonia Fahmy
- 通讯作者:Sonia FahmySonia Fahmy
Title : Performance of TCP over ABR on ATM backbone and with various VBR traffic patterns
标题:ATM 主干上 TCP over ABR 的性能以及各种 VBR 流量模式
- DOI:
- 发表时间:19961996
- 期刊:
- 影响因子:0
- 作者:Sonia FahmySonia Fahmy
- 通讯作者:Sonia FahmySonia Fahmy
共 4 条
- 1
Sonia Fahmy的其他基金
Collaborative Research: CNS Core: Medium: Rethinking Multi-User VR - Jointly Optimized Representation, Caching and Transport
合作研究:CNS 核心:媒介:重新思考多用户 VR - 联合优化表示、缓存和传输
- 批准号:22122002212200
- 财政年份:2022
- 资助金额:----
- 项目类别:Continuing GrantContinuing Grant
CICI: CE: Enhancing Cybersecurity for Broadening Data-Driven Research and Partnerships
CICI:CE:加强网络安全,扩大数据驱动的研究和合作伙伴关系
- 批准号:17389811738981
- 财政年份:2017
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
NeTS: Small: Meta-Networking Research: Analysis, Partitioning, and Mapping Tools for Large Experiments
NeTS:小型:元网络研究:大型实验的分析、分区和映射工具
- 批准号:13199241319924
- 财政年份:2013
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
NeTS: Medium: Collaborative Research: Building an Intelligent, Uncertainty-Resilient Detection and Tracking Sensor Network
NeTS:媒介:协作研究:构建智能、抗不确定性的检测和跟踪传感器网络
- 批准号:09640860964086
- 财政年份:2010
- 资助金额:----
- 项目类别:Continuing GrantContinuing Grant
NeTS: Medium: Collaborative Research: A Comprehensive Approach for Data Quality and Provenance in Sensor Networks
NeTS:媒介:协作研究:传感器网络中数据质量和来源的综合方法
- 批准号:09642940964294
- 财政年份:2010
- 资助金额:----
- 项目类别:Continuing GrantContinuing Grant
Student Travel Support for the 18th IEEE International Conference on Nework Protocols (ICNP), Kyoto, Japan - October 5-8, 2010
第 18 届 IEEE 国际网络协议会议 (ICNP) 学生旅行支持,日本京都 - 2010 年 10 月 5 日至 8 日
- 批准号:10368561036856
- 财政年份:2010
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
CT-ISG: Collaborative Research: Router Models and Downscaling Tools for Scalable Security Experiments
CT-ISG:协作研究:用于可扩展安全实验的路由器模型和缩减工具
- 批准号:08313530831353
- 财政年份:2008
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
Colloborative Research: CRI: A Testbed for Research and Development of Secure IP Multimedia Communication Services
合作研究:CRI:安全 IP 多媒体通信服务研究和开发的测试平台
- 批准号:05514100551410
- 财政年份:2006
- 资助金额:----
- 项目类别:Continuing GrantContinuing Grant
CT-T: Collaborative Research: Protecting TCP Congestion Control: Tools for Design, Analysis, and Emulation
CT-T:协作研究:保护 TCP 拥塞控制:设计、分析和仿真工具
- 批准号:05232490523249
- 财政年份:2005
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
CAREER: Exploiting Tomography in Network-Aware Protocols: Theory and Practice
职业:在网络感知协议中利用断层扫描:理论与实践
- 批准号:02382940238294
- 财政年份:2003
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
相似国自然基金
无人船自主航行系统软硬件耦合失效机理及可靠性测试模型研究
- 批准号:52301401
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于CPTU原位测试的污染场地土-膨润土隔离墙工程特性评价及防渗性能辨识研究
- 批准号:42302320
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
面向编译优化的故障测试与定位技术研究
- 批准号:62302212
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
面向操作系统内核漏洞检测的语义感知模糊测试技术研究
- 批准号:62302388
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
数据驱动的持续集成测试加速技术研究
- 批准号:62372005
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: BoCP-Implementation: Testing Evolutionary Models of Biotic Survival and Recovery from the Permo-Triassic Mass Extinction and Climate Crisis
合作研究:BoCP-实施:测试二叠纪-三叠纪大规模灭绝和气候危机中生物生存和恢复的进化模型
- 批准号:23253802325380
- 财政年份:2024
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
Collaborative Research: Superinvaders: testing a general hypothesis of forest invasions by woody species across the Americas
合作研究:超级入侵者:测试美洲木本物种入侵森林的一般假设
- 批准号:23312782331278
- 财政年份:2024
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
Collaborative Research: Superinvaders: testing a general hypothesis of forest invasions by woody species across the Americas
合作研究:超级入侵者:测试美洲木本物种入侵森林的一般假设
- 批准号:23312772331277
- 财政年份:2024
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
Collaborative Research: AF: Small: New Connections between Optimization and Property Testing
合作研究:AF:小型:优化和性能测试之间的新联系
- 批准号:24025722402572
- 财政年份:2024
- 资助金额:----
- 项目类别:Standard GrantStandard Grant
Collaborative Research: Superinvaders: testing a general hypothesis of forest invasions by woody species across the Americas
合作研究:超级入侵者:测试美洲木本物种入侵森林的一般假设
- 批准号:23312762331276
- 财政年份:2024
- 资助金额:----
- 项目类别:Standard GrantStandard Grant