TWC: TTP Option: Small: Differential Introspective Side Channels --- Discovery, Analysis, and Defense

TWC:TTP 选项:小:差异内省侧通道 --- 发现、分析和防御

基本信息

项目摘要

Side channels in the security domain are known to be challenging to discover and eliminate systematically. Nevertheless, they can lead to a variety of stealthy attacks seriously compromising cybersecurity. This work focuses on an important class of side channels that are fundamental to the operations of networked systems. Rather than constantly reacting to newly discovered side channels because of security breaches with ad-hoc patches, this work enables the automated discovery of an important class of side channels that exist due to the inherent goal of exposing information to enable debugging and management of computing systems. This project is expected to bring a paradigm shift to the security area of side channel investigation that can bring significant economic benefits of preventing a diverse set of cyberattacks. This project also has important educational and workforce training benefits for both undergraduate and graduate students, in addition to the broader dissemination of the findings through applicable standards processes to ensure operational adoption.This research investigates an entirely new class of side channel attacks against networked systems such as network stacks that can lead to significant damage to user privacy, network security, and application integrity. An example feature about this class of attacks is the requirement of actively injecting carefully crafted and potentially incorrect events to trigger error conditions in a program so as to reveal their internal sensitive states, which can indirectly expose critical information. Interestingly, the attacks are inherent byproducts of network and operating system design and implementation, which are fundamentally hard to modify. In contrast to other well-known side channels that can be directly observed through passive monitoring, e.g., power and timing, this class of side channels is much more subtle to discover and also more challenging to defend against. The proposed security work helps introduce a more rigorous approach to discovering a new class of side channels, that have direct impact on the security assurance of both small systems such as mobile devices as well as large network systems such as enterprise networks. This research develops methods to systematically and rigorously detect and eliminate such side channels by leveraging both program analysis and network measurement science. The investigation to understand the tradeoffs between security guarantee and manageability of network systems leads to more practical and usable security solutions that can be deployed in practice.
众所周知,安全域中的侧渠道是具有挑战性的,要系统地发现和消除。然而,它们可能导致各种隐秘攻击严重损害了网络安全。这项工作着重于一系列重要的侧渠道,这些渠道是网络系统运营基础的重要渠道。这项工作并没有因为对临时补丁的安全漏洞而不断对新发现的侧渠道做出反应,而是可以自动发现一类重要的侧渠道,而这些侧面渠道的存在是由于固有的目标是公开信息以实现计算系统的调试和管理。预计该项目将带来范式调查的安全区域的范式,这可以带来巨大的经济利益,以防止各种各样的网络攻击。该项目还通过适用的标准流程更广泛地传播发现结果,以确保运营采用,还对本科生和研究生都具有重要的教育和劳动力培训优势。本研究还研究了一类全新的侧渠道攻击,这是针对网络堆栈(例如网络堆栈)的全新类别的侧面渠道攻击,这些系统可以对用户隐私,网络安全性,网络安全性和应用程序进行重大损害。有关此类攻击的一个示例功能是主动注入精心设计的事件,并可能触发程序中的错误条件,以揭示其内部敏感状态,以揭示其内部敏感状态,这可以间接暴露出关键信息。有趣的是,这些攻击是网络和操作系统设计和实施的固有副产品,从根本上讲,它们很难修改。 与其他众所周知的侧渠道相反,可以通过被动监控(例如功率和时间安排)直接观察到,这类侧渠道更加微妙,并且更具挑战性地防御。 拟议的安全工作有助于引入更严格的方法,以发现新的侧渠道,这些渠道直接影响了两个小型系统(例如移动设备)以及大型网络系统(例如企业网络)的安全保证。这项研究开发了通过利用程序分析和网络测量科学来系统,严格地检测和消除此类侧渠道的方法。 了解安全保证与网络系统可管理性之间的权衡的调查导致可以在实践中部署的更实际和可用的安全解决方案。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Zhuoqing Mao其他文献

Zhuoqing Mao的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Zhuoqing Mao', 18)}}的其他基金

Collaborative Research: CISE: Large: Integrated Networking, Edge System and AI Support for Resilient and Safety-Critical Tele-Operations of Autonomous Vehicles
合作研究:CISE:大型:集成网络、边缘系统和人工智能支持自动驾驶汽车的弹性和安全关键远程操作
  • 批准号:
    2321532
  • 财政年份:
    2023
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Continuing Grant
IMR: MT: xGTracker -- Mobile xG Performance Monitoring and Data Collection Platform to Enable Large-Scale Crowd-Sourced Measurement
IMR:MT:xGTracker——移动 xG 性能监控和数据收集平台,支持大规模众包测量
  • 批准号:
    2323174
  • 财政年份:
    2023
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Continuing Grant
CPS: Medium: Collaborative Research: Transforming Connected and Automated Transportation with Smart Networking, Cooperative Sensing, and Edge Computing
CPS:中:协作研究:通过智能网络、协作传感和边缘计算改变互联和自动化交通
  • 批准号:
    2038215
  • 财政年份:
    2021
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
SBIR Phase I: Automated Safety/Security Compliance Verification and Enforcement for Autonomous Vehicle Software
SBIR 第一阶段:自动驾驶汽车软件的安全/安保合规性验证和执行
  • 批准号:
    2015019
  • 财政年份:
    2020
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
SaTC: TTP: Medium: Collaborative: Exposing and Mitigating Security/Safety Concerns of CAVs: A Holistic and Realistic Security Testing Platform for Emerging CAVs
SaTC:TTP:媒介:协作:暴露和减轻 CAV 的安全/安全问题:针对新兴 CAV 的全面且现实的安全测试平台
  • 批准号:
    1930041
  • 财政年份:
    2019
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
CI-SUSTAIN: Collaborative Research: Sustaining Successful Smartphone Testbeds to Enable Diverse Mobile Experiments
CI-SUSTAIN:协作研究:维持成功的智能手机测试平台以实现多样化的移动实验
  • 批准号:
    1629763
  • 财政年份:
    2016
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
XPS: FULL: Collaborative Research: Enabling Scalable Cloud And Edge-device Integration Using Cross-layer Parallelism
XPS:完整:协作研究:使用跨层并行性实现可扩展的云和边缘设备集成
  • 批准号:
    1628991
  • 财政年份:
    2016
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
EAGER: Cybermanufacturing: Enabling Production as a Service (PaaS)
EAGER:网络制造:实现生产即服务 (PaaS)
  • 批准号:
    1546036
  • 财政年份:
    2015
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
NSF Workshop on Mobile Community Infrastructure
NSF 移动社区基础设施研讨会
  • 批准号:
    1455719
  • 财政年份:
    2014
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
FIA-NP: Collaborative Research: The Next-Phase MobilityFirst Project - From Architecture and Protocol Design to Advanced Services and Trial Deployments
FIA-NP:协作研究:下一阶段 MobilityFirst 项目 - 从架构和协议设计到高级服务和试验部署
  • 批准号:
    1345226
  • 财政年份:
    2014
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Cooperative Agreement

相似国自然基金

TTP和XPO4蛋白介导lncRNA转运在子宫颈鳞状细胞癌中功能及机制的研究
  • 批准号:
  • 批准年份:
    2022
  • 资助金额:
    54 万元
  • 项目类别:
    面上项目
TTP和XPO4蛋白介导lncRNA转运在子宫颈鳞状细胞癌中功能及机制的研究
  • 批准号:
    32270590
  • 批准年份:
    2022
  • 资助金额:
    54.00 万元
  • 项目类别:
    面上项目
平滑肌中TTP在血压调控中的作用及机制研究
  • 批准号:
    82270457
  • 批准年份:
    2022
  • 资助金额:
    52.00 万元
  • 项目类别:
    面上项目
平滑肌中TTP在血压调控中的作用及机制研究
  • 批准号:
  • 批准年份:
    2022
  • 资助金额:
    52 万元
  • 项目类别:
    面上项目
TTP-KDM3A/CYP19A1调控滋养层细胞分化和侵袭的机制研究
  • 批准号:
    82171669
  • 批准年份:
    2021
  • 资助金额:
    54 万元
  • 项目类别:
    面上项目

相似海外基金

TWC: TTP Option: Large: Collaborative: Towards a Science of Censorship Resistance
TWC:TTP 选项:大:协作:走向审查制度抵抗的科学
  • 批准号:
    1953513
  • 财政年份:
    2019
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Continuing Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
  • 批准号:
    1748127
  • 财政年份:
    2017
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
TWC SBE: TTP Option: Medium: Collaborative: EPICA: Empowering People to Overcome Information Controls and Attacks
TWC SBE:TTP 选项:中:协作:EPICA:赋予人们克服信息控制和攻击的能力
  • 批准号:
    1664786
  • 财政年份:
    2016
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Large: Collaborative: Towards a Science of Censorship Resistance
TWC:TTP 选项:大:协作:走向审查制度抵抗的科学
  • 批准号:
    1700657
  • 财政年份:
    2016
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Continuing Grant
TWC: TTP Option: Small: Understanding the State of TLS Using Large-scale Passive Measurements
TWC:TTP 选项:小:使用大规模被动测量了解 TLS 的状态
  • 批准号:
    1528156
  • 财政年份:
    2015
  • 资助金额:
    $ 60.53万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了