TWC: TTP Option: Small: Differential Introspective Side Channels --- Discovery, Analysis, and Defense
TWC:TTP 选项:小:差异内省侧通道 --- 发现、分析和防御
基本信息
- 批准号:1526455
- 负责人:
- 金额:$ 60.53万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2015
- 资助国家:美国
- 起止时间:2015-10-01 至 2021-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Side channels in the security domain are known to be challenging to discover and eliminate systematically. Nevertheless, they can lead to a variety of stealthy attacks seriously compromising cybersecurity. This work focuses on an important class of side channels that are fundamental to the operations of networked systems. Rather than constantly reacting to newly discovered side channels because of security breaches with ad-hoc patches, this work enables the automated discovery of an important class of side channels that exist due to the inherent goal of exposing information to enable debugging and management of computing systems. This project is expected to bring a paradigm shift to the security area of side channel investigation that can bring significant economic benefits of preventing a diverse set of cyberattacks. This project also has important educational and workforce training benefits for both undergraduate and graduate students, in addition to the broader dissemination of the findings through applicable standards processes to ensure operational adoption.This research investigates an entirely new class of side channel attacks against networked systems such as network stacks that can lead to significant damage to user privacy, network security, and application integrity. An example feature about this class of attacks is the requirement of actively injecting carefully crafted and potentially incorrect events to trigger error conditions in a program so as to reveal their internal sensitive states, which can indirectly expose critical information. Interestingly, the attacks are inherent byproducts of network and operating system design and implementation, which are fundamentally hard to modify. In contrast to other well-known side channels that can be directly observed through passive monitoring, e.g., power and timing, this class of side channels is much more subtle to discover and also more challenging to defend against. The proposed security work helps introduce a more rigorous approach to discovering a new class of side channels, that have direct impact on the security assurance of both small systems such as mobile devices as well as large network systems such as enterprise networks. This research develops methods to systematically and rigorously detect and eliminate such side channels by leveraging both program analysis and network measurement science. The investigation to understand the tradeoffs between security guarantee and manageability of network systems leads to more practical and usable security solutions that can be deployed in practice.
众所周知,安全域中的侧通道很难系统地发现和消除。然而,它们可能导致各种秘密攻击,严重损害网络安全。这项工作重点关注一类重要的侧通道,它们对于网络系统的操作至关重要。这项工作不是因为临时补丁的安全漏洞而不断地对新发现的侧通道做出反应,而是能够自动发现一类重要的侧通道,这些侧通道的存在是由于公开信息以实现计算系统的调试和管理的固有目标。 。该项目预计将为侧通道调查的安全领域带来范式转变,从而在防止各种网络攻击方面带来显着的经济效益。除了通过适用的标准流程更广泛地传播研究结果以确保操作采用之外,该项目还为本科生和研究生带来了重要的教育和劳动力培训好处。这项研究调查了针对网络系统的全新一类侧信道攻击,例如作为网络堆栈,可能会对用户隐私、网络安全和应用程序完整性造成重大损害。此类攻击的一个示例特征是需要主动注入精心设计的可能不正确的事件来触发程序中的错误条件,从而揭示其内部敏感状态,从而间接暴露关键信息。有趣的是,这些攻击是网络和操作系统设计和实现的固有副产品,从根本上来说很难修改。 与其他众所周知的可以通过被动监控直接观察到的侧信道(例如功率和时序)相比,此类侧信道更难以发现,也更难以防御。 所提出的安全工作有助于引入更严格的方法来发现新型侧通道,这对移动设备等小型系统以及企业网络等大型网络系统的安全保证有直接影响。这项研究开发了利用程序分析和网络测量科学系统地、严格地检测和消除此类侧信道的方法。 通过研究了解网络系统的安全保障和可管理性之间的权衡,可以得出更实用、更可用的安全解决方案,可以在实践中部署。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Zhuoqing Mao其他文献
Turning a Curse into a Blessing: Enabling In-Distribution-Data-Free Backdoor Removal via Stabilized Model Inversion
化咒为福:通过稳定模型反演实现分布内无数据后门删除
- DOI:
- 发表时间:
2022-06-14 - 期刊:
- 影响因子:0
- 作者:
Si Chen;Yi Zeng;J. T.Wang;Won Park;Xun Chen;L. Lyu;Zhuoqing Mao;R. Jia - 通讯作者:
R. Jia
Zhuoqing Mao的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Zhuoqing Mao', 18)}}的其他基金
Collaborative Research: CISE: Large: Integrated Networking, Edge System and AI Support for Resilient and Safety-Critical Tele-Operations of Autonomous Vehicles
合作研究:CISE:大型:集成网络、边缘系统和人工智能支持自动驾驶汽车的弹性和安全关键远程操作
- 批准号:
2321532 - 财政年份:2023
- 资助金额:
$ 60.53万 - 项目类别:
Continuing Grant
IMR: MT: xGTracker -- Mobile xG Performance Monitoring and Data Collection Platform to Enable Large-Scale Crowd-Sourced Measurement
IMR:MT:xGTracker——移动 xG 性能监控和数据收集平台,支持大规模众包测量
- 批准号:
2323174 - 财政年份:2023
- 资助金额:
$ 60.53万 - 项目类别:
Continuing Grant
CPS: Medium: Collaborative Research: Transforming Connected and Automated Transportation with Smart Networking, Cooperative Sensing, and Edge Computing
CPS:中:协作研究:通过智能网络、协作传感和边缘计算改变互联和自动化交通
- 批准号:
2038215 - 财政年份:2021
- 资助金额:
$ 60.53万 - 项目类别:
Standard Grant
SBIR Phase I: Automated Safety/Security Compliance Verification and Enforcement for Autonomous Vehicle Software
SBIR 第一阶段:自动驾驶汽车软件的安全/安保合规性验证和执行
- 批准号:
2015019 - 财政年份:2020
- 资助金额:
$ 60.53万 - 项目类别:
Standard Grant
SaTC: TTP: Medium: Collaborative: Exposing and Mitigating Security/Safety Concerns of CAVs: A Holistic and Realistic Security Testing Platform for Emerging CAVs
SaTC:TTP:媒介:协作:暴露和减轻 CAV 的安全/安全问题:针对新兴 CAV 的全面且现实的安全测试平台
- 批准号:
1930041 - 财政年份:2019
- 资助金额:
$ 60.53万 - 项目类别:
Standard Grant
CI-SUSTAIN: Collaborative Research: Sustaining Successful Smartphone Testbeds to Enable Diverse Mobile Experiments
CI-SUSTAIN:协作研究:维持成功的智能手机测试平台以实现多样化的移动实验
- 批准号:
1629763 - 财政年份:2016
- 资助金额:
$ 60.53万 - 项目类别:
Standard Grant
XPS: FULL: Collaborative Research: Enabling Scalable Cloud And Edge-device Integration Using Cross-layer Parallelism
XPS:完整:协作研究:使用跨层并行性实现可扩展的云和边缘设备集成
- 批准号:
1628991 - 财政年份:2016
- 资助金额:
$ 60.53万 - 项目类别:
Standard Grant
EAGER: Cybermanufacturing: Enabling Production as a Service (PaaS)
EAGER:网络制造:实现生产即服务 (PaaS)
- 批准号:
1546036 - 财政年份:2015
- 资助金额:
$ 60.53万 - 项目类别:
Standard Grant
FIA-NP: Collaborative Research: The Next-Phase MobilityFirst Project - From Architecture and Protocol Design to Advanced Services and Trial Deployments
FIA-NP:协作研究:下一阶段 MobilityFirst 项目 - 从架构和协议设计到高级服务和试验部署
- 批准号:
1345226 - 财政年份:2014
- 资助金额:
$ 60.53万 - 项目类别:
Cooperative Agreement
NSF Workshop on Mobile Community Infrastructure
NSF 移动社区基础设施研讨会
- 批准号:
1455719 - 财政年份:2014
- 资助金额:
$ 60.53万 - 项目类别:
Standard Grant
相似国自然基金
TTP和XPO4蛋白介导lncRNA转运在子宫颈鳞状细胞癌中功能及机制的研究
- 批准号:
- 批准年份:2022
- 资助金额:54 万元
- 项目类别:面上项目
平滑肌中TTP在血压调控中的作用及机制研究
- 批准号:
- 批准年份:2022
- 资助金额:52 万元
- 项目类别:面上项目
TTP-KDM3A/CYP19A1调控滋养层细胞分化和侵袭的机制研究
- 批准号:82171669
- 批准年份:2021
- 资助金额:54 万元
- 项目类别:面上项目
心外膜脂肪组织TTP在病理性心肌肥厚发生发展中的作用及机制研究
- 批准号:
- 批准年份:2021
- 资助金额:30 万元
- 项目类别:青年科学基金项目
锌指蛋白TTP调控m6A抑制血吸虫病肝纤维化的机制研究
- 批准号:
- 批准年份:2021
- 资助金额:55 万元
- 项目类别:面上项目
相似海外基金
TWC: TTP Option: Large: Collaborative: Towards a Science of Censorship Resistance
TWC:TTP 选项:大:协作:走向审查制度抵抗的科学
- 批准号:
1953513 - 财政年份:2019
- 资助金额:
$ 60.53万 - 项目类别:
Continuing Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1748127 - 财政年份:2017
- 资助金额:
$ 60.53万 - 项目类别:
Standard Grant
TWC SBE: TTP Option: Medium: Collaborative: EPICA: Empowering People to Overcome Information Controls and Attacks
TWC SBE:TTP 选项:中:协作:EPICA:赋予人们克服信息控制和攻击的能力
- 批准号:
1664786 - 财政年份:2016
- 资助金额:
$ 60.53万 - 项目类别:
Standard Grant
TWC: TTP Option: Large: Collaborative: Towards a Science of Censorship Resistance
TWC:TTP 选项:大:协作:走向审查制度抵抗的科学
- 批准号:
1700657 - 财政年份:2016
- 资助金额:
$ 60.53万 - 项目类别:
Continuing Grant
TWC: TTP Option: Large: Collaborative: Internet-Wide Vulnerability Measurement, Assessment, and Notification
TWC:TTP 选项:大型:协作:互联网范围内的漏洞测量、评估和通知
- 批准号:
1518921 - 财政年份:2015
- 资助金额:
$ 60.53万 - 项目类别:
Continuing Grant