SaTC: CORE: Small: Hybrid Capability-Enforcement for Endpoint-Driven Traffic Control
SaTC:核心:小型:端点驱动流量控制的混合能力实施
基本信息
- 批准号:1717313
- 负责人:
- 金额:$ 50万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2017
- 资助国家:美国
- 起止时间:2017-09-01 至 2021-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The Internet has become a societally transformative technology. Because the design of the Internet allows any Internet-connected device to send any amount of traffic to any other Internet-connected device, attackers can send large volumes of traffic to a victim, overwhelming the ability of the network to carry legitimate traffic to the victim. When many different devices send such attack traffic in a coordinated manner, the attack is called a Distributed Denial-of-Service (DDoS) attack, and is difficult to filter in the current Internet architecture. This research investigates a new architecture for filtering DDoS attacks that is efficient, economical, and readily deployable. The proposed architecture aims to alleviate the burden of maintaining an Internet service in the presence of DDoS attacks, and to improve the availability of Internet services.The proposed architecture combines a filtering functionality deployed in the cloud with a network state estimation algorithm performed with the cooperation of the cloud and the victim server. Traffic is redirected to the cloud server using DNS; the cloud server then polices each sender's traffic according to a receiver-selected fair sharing policy. The fair sharing algorithm uses the bandwidth estimate derived from the network state estimator. The network state estimator uses capability feedback from the receiver to estimate the available bandwidth for fair-sharing. This research expands the proposed architecture to make it more secure, more effective at catching obvious Denial-of-Service attacks, and more robust against powerful adversaries. The research will also provide a more through evaluation of the proposed architecture. The work will advance the understanding of how incrementally-deployable approaches, deployed based on economic incentives rather than relying on altruistic deployments, can also provide strong properties. Specifically, it aims to develop and evaluate a collection of methods that when fully deployed would provide the same strengths as an approach like SIBRA, yet be incrementally deployable, providing benefits as each Internet entity deploys each individual mechanism.
互联网已成为一种具有社会变革性的技术。由于Internet的设计允许任何与Internet连接的设备向任何其他与Internet连接的设备一起发送任何流量,因此攻击者可以向受害者发送大量流量,从而压倒网络将合法流量运送到受害者的能力。当许多不同的设备以协调的方式发送此类攻击流量时,该攻击称为分布式拒绝服务(DDOS)攻击,并且在当前的Internet体系结构中很难过滤。这项研究调查了一种用于过滤DDOS攻击的新体系结构,该攻击效率高,经济且易于部署。拟议的架构旨在减轻在存在DDOS攻击的情况下维持互联网服务的负担,并提高互联网服务的可用性。拟议的体系结构将在云中部署的过滤功能与网络状态估计算法与云的合作和受害者服务器和受害者服务器一起执行。使用DNS将流量重定向到云服务器;然后,云服务器根据接收方选择的公平共享策略进行警察每个发件人的流量。博览会共享算法使用从网络状态估计器得出的带宽估计值。网络状态估计器使用接收器的功能反馈来估算可用的带宽以进行公平共享。这项研究扩大了拟议的体系结构,使其更加安全,更有效地捕捉明显的拒绝服务攻击,并对强大的对手更强大。这项研究还将通过评估所提出的体系结构提供更多。这项工作将促进对基于经济激励而不是依靠无私部署的逐步部署方法的逐步发展方法的理解,这也可以提供强大的财产。具体而言,它旨在开发和评估一系列方法,当完全部署时,这些方法将提供与Sibra这样的方法相同的优势,但可以逐步部署,并在每个Internet实体部署每个单个机制时提供好处。
项目成果
期刊论文数量(6)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
SmartCrowd: Decentralized and Automated Incentives for Distributed IoT System Detection
SmartCrowd:分布式物联网系统检测的去中心化和自动化激励
- DOI:10.1109/icdcs.2019.00112
- 发表时间:2019
- 期刊:
- 影响因子:0
- 作者:Wu, Bo;Xu, Ke;Li, Qi;Liu, Zhuotao;Hu, Yih-Chun;Zhang, Zhichao;Du, Xinle;Liu, Bingyang;Ren, Shoushou
- 通讯作者:Ren, Shoushou
Enabling Work-Conserving Bandwidth Guarantees for Multi-Tenant Datacenters via Dynamic Tenant-Queue Binding
- DOI:10.1109/infocom.2018.8486219
- 发表时间:2018-01-01
- 期刊:
- 影响因子:0
- 作者:Liu, Zhuotao;Chen, Kai;Zhang, Gong
- 通讯作者:Zhang, Gong
Enabling Efficient Source and Path Verification via Probabilistic Packet Marking
- DOI:10.1109/iwqos.2018.8624169
- 发表时间:2018-06
- 期刊:
- 影响因子:0
- 作者:Bo Wu;Ke Xu;Qi Li;Zhuotao Liu;Yih-Chun Hu;M. Reed;Meng Shen;F. Yang
- 通讯作者:Bo Wu;Ke Xu;Qi Li;Zhuotao Liu;Yih-Chun Hu;M. Reed;Meng Shen;F. Yang
DefRec: Establishing Physical Function Virtualization to Disrupt Reconnaissance of Power Grids' Cyber-Physical Infrastructures
DefRec:建立物理功能虚拟化以中断电网网络物理基础设施的侦察
- DOI:10.14722/ndss.2020.24365
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Lin, Hui;Zhuang, Jianing;Hu, Yih-Chun;Zhou, Huayu
- 通讯作者:Zhou, Huayu
Double-Edge Embedding Based Provenance Recovery for Low-Latency Applications in Wireless Networks
- DOI:10.1109/tdsc.2020.3001185
- 发表时间:2022-03
- 期刊:
- 影响因子:7.3
- 作者:Harshan Jagadeesh;Amogh Vithalkar;Naman Jhunjhunwala;Manthan Kabra;Prafull Manav;Yih-Chun Hu
- 通讯作者:Harshan Jagadeesh;Amogh Vithalkar;Naman Jhunjhunwala;Manthan Kabra;Prafull Manav;Yih-Chun Hu
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Yih-Chun Hu其他文献
Packet Leashes : A Defense against Wormhole Attacks in Wireless Ad Hoc Networks
- DOI:
- 发表时间:
2001 - 期刊:
- 影响因子:0
- 作者:
Yih-Chun Hu - 通讯作者:
Yih-Chun Hu
Efficient Security Mechanisms for Routing Protocols
- DOI:
- 发表时间:
2003 - 期刊:
- 影响因子:0
- 作者:
Yih-Chun Hu - 通讯作者:
Yih-Chun Hu
Yih-Chun Hu的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Yih-Chun Hu', 18)}}的其他基金
I-Corps: In-cloud Destination-driven Distributed Denial of Service Filtering
I-Corps:云中目标驱动的分布式拒绝服务过滤
- 批准号:
1758179 - 财政年份:2017
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CAREER: Protecting against Layer-Violating Attacks in Wireless Networks
职业:防止无线网络中的层违规攻击
- 批准号:
0953600 - 财政年份:2010
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
相似国自然基金
基于NRF2调控KPNB1促进PD-L1核转位介导非小细胞肺癌免疫治疗耐药的机制研究
- 批准号:82303969
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
小胶质细胞调控外侧隔核-腹侧被盖区神经环路介导社交奖赏障碍的机制研究
- 批准号:82304474
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
肾去交感神经术促进下丘脑室旁核小胶质细胞M2型极化减轻心衰损伤的机制研究
- 批准号:82370387
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
空间邻近标记技术研究莱茵衣藻蛋白核小管与碳浓缩机制的潜在关系
- 批准号:32300220
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
polyG蛋白聚集体诱导小胶质细胞活化在神经元核内包涵体病中的作用及机制研究
- 批准号:82301603
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
- 批准号:
2327427 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
SaTC: CORE: Small: NSF-DST: Understanding Network Structure and Communication for Supporting Information Authenticity
SaTC:核心:小型:NSF-DST:了解支持信息真实性的网络结构和通信
- 批准号:
2343387 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
NSF-NSERC: SaTC: CORE: Small: Managing Risks of AI-generated Code in the Software Supply Chain
NSF-NSERC:SaTC:核心:小型:管理软件供应链中人工智能生成代码的风险
- 批准号:
2341206 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant