CAREER: Empowering Attacker-Centric Security Analysis of Network Protocols
职业:支持以攻击者为中心的网络协议安全分析
基本信息
- 批准号:1652954
- 负责人:
- 金额:$ 50万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2017
- 资助国家:美国
- 起止时间:2017-03-15 至 2024-02-29
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The objective of this project is to improve the security of a wide range of network protocols that the Internet relies on. Unfortunately, the Internet has been evolving at a rapid rate but its initial design did not take security into consideration. In practice, this leads to a never-ending stream of network attacks that are continuously being discovered. The defenders are forced into a reactive position to these new and creative attacks, without having the necessary tools to understand and anticipate them. The proposed project aims to identify and analyze protocol flaws proactively and stay ahead of attackers. In particular, the project will develop a set of innovative and timely techniques, tools, and insights that will empower developers and researchers to analyze network protocols, identify their weaknesses, and correct them early on. The results will benefit all Internet users by providing a more secure network environment overall. Specifically, the research is motivated by the following observations. First, emerging threats such as side channels have been largely overlooked in network protocols. Second, network attacks are getting more sophisticated, with new threat models such as cooperating local and remote attackers. Third, the network protocols and their interactions with the environment are getting more complex, especially when considering the prevalence of network middleboxes, host-based firewalls, and censorship firewalls, etc. The research will develop a combination of program analysis and network measurement techniques to systematically uncover vulnerabilities in a variety of network protocols. The insights gained from the project will enable better and more secure design and implementation of protocols.
该项目的目的是提高互联网所依赖的广泛网络协议的安全性。不幸的是,互联网一直在快速发展,但其最初的设计并未考虑到安全性。在实践中,这导致了不断发现的无休止的网络攻击流。捍卫者被迫对这些新的创造性攻击的反应性立场,而没有必要的工具来理解和预测它们。拟议的项目旨在积极识别和分析协议缺陷,并保持攻击者的领先地位。特别是,该项目将开发一系列创新和及时的技术,工具和见解,这些技术,工具和见解将使开发人员和研究人员能够分析网络协议,确定其弱点并尽早纠正它们。结果将通过整体提供更安全的网络环境来使所有互联网用户受益。具体而言,该研究是由以下观察结果激励的。首先,在网络协议中,新兴威胁(例如侧渠道)在很大程度上被忽略了。其次,网络攻击变得越来越复杂,新的威胁模型,例如合作本地和远程攻击者。第三,网络协议及其与环境的互动变得越来越复杂,尤其是在考虑网络中间箱,基于主机的防火墙和审查防火墙等的盛行时。该研究将开发程序分析和网络测量技术以系统地在各种网络协议中系统地发现脆弱性的结合。从项目中获得的见解将使协议的更好,更安全的设计和实施。
项目成果
期刊论文数量(21)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
DNS Cache Poisoning Attack Reloaded: Revolutions with Side Channels
- DOI:10.1145/3372297.3417280
- 发表时间:2020-10
- 期刊:
- 影响因子:0
- 作者:Keyu Man;Zhiyun Qian;Zhongjie Wang;Xiaofeng Zheng;Youjun Huang;Haixin Duan
- 通讯作者:Keyu Man;Zhiyun Qian;Zhongjie Wang;Xiaofeng Zheng;Youjun Huang;Haixin Duan
Principled Unearthing of TCP Side Channel Vulnerabilities
- DOI:10.1145/3319535.3354250
- 发表时间:2019-11
- 期刊:
- 影响因子:0
- 作者:Yue Cao;Zhongjie Wang;Zhiyun Qian;Chengyu Song;S. Krishnamurthy;Paul L. Yu
- 通讯作者:Yue Cao;Zhongjie Wang;Zhiyun Qian;Chengyu Song;S. Krishnamurthy;Paul L. Yu
DNS Cache Poisoning Attack: Resurrections with Side Channels
- DOI:10.1145/3460120.3486219
- 发表时间:2021-11
- 期刊:
- 影响因子:0
- 作者:Keyu Man;Xin'an Zhou;Zhiyun Qian
- 通讯作者:Keyu Man;Xin'an Zhou;Zhiyun Qian
K-LEAK: Towards Automating the Generation of Multi-Step Infoleak Exploits against the Linux Kernel
- DOI:10.14722/ndss.2024.24935
- 发表时间:2024
- 期刊:
- 影响因子:0
- 作者:Zhengchuan Liang;Xiaochen Zou;Chengyu Song;Zhiyun Qian
- 通讯作者:Zhengchuan Liang;Xiaochen Zou;Chengyu Song;Zhiyun Qian
SyzGen: Automated Generation of Syscall Specification of Closed-Source macOS Drivers
- DOI:10.1145/3460120.3484564
- 发表时间:2021-11
- 期刊:
- 影响因子:0
- 作者:Weiteng Chen;Yu Wang;Zheng Zhang;Zhiyun Qian
- 通讯作者:Weiteng Chen;Yu Wang;Zheng Zhang;Zhiyun Qian
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Zhiyun Qian其他文献
Where Is the Weakest Link? A Study on Security Discrepancies Between Android Apps and Their Website Counterparts
最薄弱的环节在哪里?
- DOI:
10.1007/978-3-319-54328-4_8 - 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Arash Alavi;Alan Quach;Hang Zhang;Bryan Marsh;Farhan ul Haq;Zhiyun Qian;Long Lu;Rajiv Gupta - 通讯作者:
Rajiv Gupta
Packet Header Obfuscation Using MIMO
使用 MIMO 进行数据包标头混淆
- DOI:
10.1109/tnet.2020.2998398 - 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
Yue Cao;A. Atya;Shailendra Singh;Zhiyun Qian;S. Krishnamurthy;T. L. Porta;P. Krishnamurthy;L. Marvel - 通讯作者:
L. Marvel
Used by device administration to set the maximum screen off timeout . *
由设备管理用来设置最大屏幕关闭超时。
- DOI:
- 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Yuru Shao;Jason Ott;Qi Alfred Chen;Zhiyun Qian;Z. Morley Mao - 通讯作者:
Z. Morley Mao
Who Moves My App Promotion Investment A Systematic Study about App Distribution Fraud
谁动了我的应用推广投资 关于应用分发欺诈的系统研究
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:7.3
- 作者:
Shaoyong Du;Minrui Zhao;Jingyu Hua;Hang Zhang;Xiaoyu Chen;Zhiyun Qian;Sheng Zhong - 通讯作者:
Sheng Zhong
Investigation of the 2016 Linux TCP Stack Vulnerability at Scale
对 2016 年 Linux TCP 堆栈漏洞的大规模调查
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Alan Quach;Zhongjie Wang;Zhiyun Qian - 通讯作者:
Zhiyun Qian
Zhiyun Qian的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Zhiyun Qian', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Small: Self-Driving Continuous Fuzzing
协作研究:SaTC:核心:小型:自驱动连续模糊测试
- 批准号:
2247881 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Improving Decentralized Kernel Patch Ecosystems
协作研究:SaTC:CORE:小型:改善去中心化内核补丁生态系统
- 批准号:
2155213 - 财政年份:2022
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Collaborative: Deep and Efficient Dynamic Analysis of Operating System Kernels
SaTC:核心:小型:协作:操作系统内核的深入有效的动态分析
- 批准号:
1953933 - 财政年份:2020
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Collaborative: The Web Ad Technology Arms Race: Measurement, Analysis, and Countermeasures
SaTC:核心:小型:协作:网络广告技术军备竞赛:测量、分析和对策
- 批准号:
1719147 - 财政年份:2017
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
NeTS: Small: Collaborative Research: Practical HTTPS Traffic Manipulation At Middleboxes
NetS:小型:协作研究:中间盒的实用 HTTPS 流量操纵
- 批准号:
1619391 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TWC: Small: Cache-based Side Channel Attacks on Smartphone Graphics Buffers: New Vulnerabilities and Defenses
TWC:小型:针对智能手机图形缓冲区的基于缓存的侧通道攻击:新漏洞和防御
- 批准号:
1619450 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CSR: Small: Collaborative Research: Taming Mobile Hardware & OS Diversity for Comprehensive Software Analysis
CSR:小型:协作研究:驯服移动硬件
- 批准号:
1617573 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CRII: SaTC: Analyzing and verifying the security of TCP stacks under multi-entity interactions
CRII:SaTC:多实体交互下TCP协议栈的安全性分析与验证
- 批准号:
1464410 - 财政年份:2015
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TWC: Small: Collaborative: Multipath TCP Side Channel Vulnerabilities and Defenses
TWC:小:协作:多路径 TCP 侧信道漏洞和防御
- 批准号:
1528114 - 财政年份:2015
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
相似国自然基金
云边端融合新型网络架构下的授权可搜索加密研究
- 批准号:62372068
- 批准年份:2023
- 资助金额:50.00 万元
- 项目类别:面上项目
考虑成本分担和市场培育的授权再制造闭环供应链耦合驱动机制研究
- 批准号:72303058
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于授权控制的深度神经网络模型主动式版权保护方法研究
- 批准号:62372231
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
基于优化和学习的大规模免授权接入理论与技术
- 批准号:62371412
- 批准年份:2023
- 资助金额:49.00 万元
- 项目类别:面上项目
基于免授权频谱资源的接入及回传链路一体化传输理论与技术研究
- 批准号:
- 批准年份:2022
- 资助金额:54 万元
- 项目类别:面上项目
相似海外基金
I-Corps: Translation Potential of a Secure Data Platform Empowering Artificial Intelligence Assisted Digital Pathology
I-Corps:安全数据平台的翻译潜力,赋能人工智能辅助数字病理学
- 批准号:
2409130 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CAREER: Eradicate the Gate: Empowering Learners and Equalizing Assessment in K12 Engineering Education
职业:消除大门:K12 工程教育中的学习者赋权和均衡评估
- 批准号:
2339619 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Reel Voices: Empowering Language Learners Through Filmmaking
Reel Voices:通过电影制作赋予语言学习者权力
- 批准号:
24K04057 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
Conference: Quantum Horizons: Empowering Faculty for the Future of Quantum Information
会议:量子视野:为量子信息的未来赋予教师权力
- 批准号:
2345607 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Cens-able - Improving and empowering census data research opportunities in Scotland
Cens-able - 改善和增强苏格兰的人口普查数据研究机会
- 批准号:
ES/Z502881/1 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Research Grant