SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
SaTC:核心:媒介:协作:REVELARE:用于物联网安全和取证的硬件支持的动态信息流跟踪框架
基本信息
- 批准号:1801599
- 负责人:
- 金额:$ 59.97万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-08-15 至 2023-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Smart and connected devices, also known as Internet of Things (IoT) devices, are now an integral part of our daily lives. These devices are found in cars, phones, watches, appliances, home security systems, and in critical applications, such as utilities and in the biomedical industry. The convenience provided by IoT devices comes with unique security and privacy concerns. Because of the shortened time-to-market and the fierce competition among companies, security has not been treated as a priority in these devices. Very importantly, IoT security challenges are different from those present in conventional devices because IoT devices (i) are heterogeneous, (ii) have limited computational resources, and (iii) can be prevalent in very large numbers. Thus, there is an urgent need to develop standardized, efficient, and embedded security modules to protect such devices from cyber attacks. The goal of this project is to design, implement, and fabricate REVELARE, a security solution for IoT devices, which protects IoT devices in two ways. The first is through a hardware module embedded in the device, which can analyze and filter low-level events based on predefined security policies. The second component resides on a cloud environment and performs forensic analyses on a large set of events continuously recorded from the IoT device. This project has the potential to immensely improve IoT security. Manufacturers will be able to ship IoT devices with built-in protection against cyber attacks. The principal investigators, with complementary expertises in the Computer Science and Engineering fields, have a strong record of advancement of female and minority students, as well as involvement of undergraduate students in research projects. Further, this project opens up new avenues for future work in hardware-for-software security, an area which, while still in its infancy, has the potential for breakthroughs in cyber security.REVELARE is a hardware-supported dynamic information flow tracking (DIFT) framework to enhance IoT security and forensics. It consists of the following components: (i) a DIFT-enabling core for the ARM and the RISC-V architectures, which complements the main processor with DIFT capabilities, (ii) two DIFT-based security policies (prevention of memory corruption and in-memory-only attacks) enforced by hardware, whose accuracy is enhanced by the capture of DIFT indirect flows, and (iii) a mechanism for IoT virtualization-based security analysis and forensics, with the implementation of two types of security/forensics analyses: causality graphs and personalized (per-device) anomaly detection. REVELARE realizes the potential of DIFT capabilities for the needs of IoT security and forensics, transforming the state-of-the-art for how researchers in academia and industry have been addressing IoT security. Our efficient (architecture-supported) and effective (addressing indirect flows) DIFT framework can also inform future research on architecture-supported DIFT for other architectures (e.g., Intel x86) leveraged in traditional devices. Our combination of in-device built-in protection with cloud heavy-weight analysis and forensics has the potential to ignite the new field of IoT virtualization, in which IoT device management and security are outsourced to the cloud via virtualized devices.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
智能和连接的设备,也称为物联网(IoT)设备,现在已成为我们日常生活中不可或缺的一部分。这些设备位于汽车,电话,手表,电器,家庭安全系统以及关键应用程序(例如公用事业和生物医学行业)中。物联网设备提供的便利性带有独特的安全性和隐私问题。由于上市时间缩短和公司之间激烈的竞争,因此在这些设备中,安全尚未被视为优先事项。非常重要的是,物联网安全挑战与传统设备中存在的挑战不同,因为物联网设备(i)是异质的,(ii)的计算资源有限,并且(iii)可以很大程度上普遍存在。 因此,迫切需要开发标准化,高效和嵌入式安全模块,以保护此类设备免受网络攻击。该项目的目的是设计,实施和制造Revelare,这是针对IoT设备的安全解决方案,该解决方案以两种方式保护IoT设备。首先是通过嵌入设备中的硬件模块,该模块可以根据预定义的安全策略分析和过滤低级事件。第二个组件位于云环境上,并对从物联网设备连续记录的大型事件进行法医分析。 该项目有可能大大提高物联网安全性。制造商将能够通过内置防护网络攻击运送IoT设备。在计算机科学和工程领域具有互补专业的主要研究人员,在女性和少数族裔学生的进步以及本科生参与研究项目方面有很强的记录。此外,该项目为硬件软件安全性的未来工作开辟了新的途径,该领域仍处于起步阶段,但仍具有在网络安全方面取得突破的潜力。Revelare是一个硬件支持的动态信息流跟踪(DIFT)框架,以增强IoT安全性和forensics。它由以下组件组成:(i)手臂和RISC-V体系结构的差异核心,它具有Dift功能,(ii)两种基于Dift的安全策略(预防记忆损坏和唯一的记忆中唯一的内存攻击)由硬件强大的机制增强了III的机制,并且III(III)是III(III)(III IID)(II II IID)(II II IID)(II II IID),并且它是III(II III)(II II flow ford a)分析和取证,实施了两种类型的安全/取证分析:因果关系图和个性化(人均)异常检测。 Revelare意识到了对物联网安全和法医需求的Dift功能的潜力,从而改变了学术界和行业研究人员如何解决IoT安全的最新技术。我们的高效(由建筑支持)和有效(解决间接流)DIFT框架还可以为未来在传统设备中利用其他体系结构(例如Intel X86)建筑支持的差异的研究提供信息。 Our combination of in-device built-in protection with cloud heavy-weight analysis and forensics has the potential to ignite the new field of IoT virtualization, in which IoT device management and security are outsourced to the cloud via virtualized devices.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
项目成果
期刊论文数量(9)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Challenges and Opportunities for Practical and Effective Dynamic Information Flow Tracking
实用有效的动态信息流跟踪的挑战和机遇
- DOI:10.1145/3483790
- 发表时间:2023
- 期刊:
- 影响因子:16.6
- 作者:Brant, Christopher;Shrestha, Prakash;Mixon-Baca, Benjamin;Chen, Kejun;Varlioglu, Said;Elsayed, Nelly;Jin, Yier;Crandall, Jedidiah;Oliveira, Daniela
- 通讯作者:Oliveira, Daniela
Towards Hardware-Assisted Security for IoT Systems
迈向物联网系统的硬件辅助安全
- DOI:10.1109/isvlsi.2019.00118
- 发表时间:2019
- 期刊:
- 影响因子:0
- 作者:Jin, Yier
- 通讯作者:Jin, Yier
RTSEC: Automated RTL Code Augmentation for Hardware Security Enhancement
RTSEC:用于增强硬件安全性的自动 RTL 代码增强
- DOI:10.23919/date54114.2022.9774745
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Arias, Orlando;Liu, Zhaoxiang;Guo, Xiaolong;Jin, Yier;Wang, Shuo
- 通讯作者:Wang, Shuo
FineDIFT: Fine-Grained Dynamic Information Flow Tracking for Data-Flow Integrity Using Coprocessor
FineDIFT:使用协处理器实现数据流完整性的细粒度动态信息流跟踪
- DOI:10.1109/tifs.2022.3144868
- 发表时间:2022
- 期刊:
- 影响因子:6.8
- 作者:Chen, Kejun;Arias, Orlando;Deng, Qingxu;Oliveira, Daniela;Guo, Xiaolong;Jin, Yier
- 通讯作者:Jin, Yier
Dual-Leak: Deep Unsupervised Active Learning for Cross-Device Profiled Side-Channel Leakage Analysis
- DOI:10.1109/host55118.2023.10133491
- 发表时间:2023-05
- 期刊:
- 影响因子:0
- 作者:H. Yu;Shuo Wang;Haoqi Shan;Max Panoff;Michael Lee;Kaichen Yang;Yier Jin
- 通讯作者:H. Yu;Shuo Wang;Haoqi Shan;Max Panoff;Michael Lee;Kaichen Yang;Yier Jin
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Renato Figueiredo其他文献
On the Performance and Cost of Cloud-Assisted Multi-Path Bulk Data Transfer
云辅助多路径批量数据传输的性能和成本
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Kyuho Jeong;Renato Figueiredo;Kohei Ichikawa - 通讯作者:
Kohei Ichikawa
A Pipeline for Deep Learning with Specimen Images in iDigBio - Applying and Generalizing an Examination of Mercury Use in Preparing Herbarium Specimens
iDigBio 中标本图像深度学习的流程 - 应用和推广汞在制备植物标本室标本中的使用检查
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Matthew Collins;G. Yeole;P. Frandsen;Rebecca B. Dikow;Sylvia S. Orli;Renato Figueiredo - 通讯作者:
Renato Figueiredo
Extending PRAGMA-ENT for End Users using IPOP Overlay Networks
使用 IPOP 覆盖网络为最终用户扩展 PRAGMA-ENT
- DOI:
- 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Kyuho Jeong;Renato Figueiredo;Kohei Ichikawa - 通讯作者:
Kohei Ichikawa
Investigating the Performance and Scalability of Kubernetes on Distributed Cluster of Resource-Constrained Edge Devices
研究 Kubernetes 在资源受限边缘设备分布式集群上的性能和可扩展性
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Vahid Daneshmand;Renato Figueiredo;Kohei Ichikawa;Keichi Takahashi;Kundjanasith Thonglek and Kensworth Subratie - 通讯作者:
Kundjanasith Thonglek and Kensworth Subratie
保育者は保育カンファレンスを行うことで何を学ぶのか?ー質的研究のメタ統合の試みからー
托儿工作者通过举办托儿会议学到了什么?
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Kyuho Jeong;Renato Figueiredo;Kohei Ichikawa;上田敏丈 - 通讯作者:
上田敏丈
Renato Figueiredo的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Renato Figueiredo', 18)}}的其他基金
Collaborative Research: URoL:ASC: Applying rules of life to forecast emergent behavior of phytoplankton and advance water quality management
合作研究:URoL:ASC:应用生命规则预测浮游植物的紧急行为并推进水质管理
- 批准号:
2318862 - 财政年份:2023
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
Collaborative Research: Elements: FaaSr: Enabling Cloud-native Event-driven Function-as-a-Service Computing Workflows in R
协作研究:要素:FaaSr:在 R 中启用云原生事件驱动的函数即服务计算工作流程
- 批准号:
2311123 - 财政年份:2023
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
I-Corps: Software-Defined Overlay Virtual Private Network for Edge Computing
I-Corps:用于边缘计算的软件定义的覆盖虚拟专用网络
- 批准号:
2134548 - 财政年份:2021
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
SaTC: CORE: Small: GOALI: Predicting and Labeling Email Phishing from Social Influence Cues and User Characteristics.
SaTC:核心:小:GOALI:根据社会影响线索和用户特征预测和标记电子邮件网络钓鱼。
- 批准号:
2028734 - 财政年份:2020
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
Collaborative Research: Elements: EdgeVPN: Seamless Secure Virtual Networking for Edge and Fog Computing
协作研究:要素:EdgeVPN:用于边缘和雾计算的无缝安全虚拟网络
- 批准号:
2004441 - 财政年份:2020
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
Collaborative Research: CIBR: Cyberinfrastructure Enabling End-to-End Workflows for Aquatic Ecosystem Forecasting
合作研究:CIBR:网络基础设施支持水生生态系统预测的端到端工作流程
- 批准号:
1933102 - 财政年份:2020
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
SaTC: CORE: Small: FIRMA: Personalized Cross-Layer Continuous Authentication
SaTC:核心:小型:FIRMA:个性化跨层连续身份验证
- 批准号:
1814557 - 财政年份:2018
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
NeTS: Small: PerSoNet: Overlay Virtual Private Networks Spanning Personal Clouds and Social Peers
NetS:小型:PerSoNet:跨越个人云和社交对等的覆盖虚拟专用网络
- 批准号:
1527415 - 财政年份:2015
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
SHF: Small: Collaborative Research: Exploring Energy-Efficient GPGPUs Through Emerging Technology Integration
SHF:小型:协作研究:通过新兴技术集成探索节能 GPGPU
- 批准号:
1320100 - 财政年份:2013
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
SI2-SSE: Peer-to-Peer Overlay Virtual Network for Cloud Computing Research
SI2-SSE:用于云计算研究的点对点覆盖虚拟网络
- 批准号:
1339737 - 财政年份:2013
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant
相似国自然基金
中等质量丰中子核区的新核结构模型方法
- 批准号:
- 批准年份:2020
- 资助金额:18 万元
- 项目类别:专项基金项目
伏隔核D1/D2共表达中等多棘神经元在孤独症小鼠社交奖赏障碍中的作用及机制研究
- 批准号:81901381
- 批准年份:2019
- 资助金额:20.5 万元
- 项目类别:青年科学基金项目
星系中心的中等质量黑洞研究
- 批准号:11473062
- 批准年份:2014
- 资助金额:90.0 万元
- 项目类别:面上项目
过渡区中等质量原子核结构的配对壳模型研究
- 批准号:11305101
- 批准年份:2013
- 资助金额:22.0 万元
- 项目类别:青年科学基金项目
中等和大质量黑洞的潮汐瓦解及其吸积与辐射
- 批准号:10873015
- 批准年份:2008
- 资助金额:42.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 59.97万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 59.97万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 59.97万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Increasing user autonomy and advertiser and platform responsibility in online advertising
SaTC:核心:中:增加在线广告中的用户自主权以及广告商和平台责任
- 批准号:
2318290 - 财政年份:2024
- 资助金额:
$ 59.97万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Testing the causal influence of social media on well-being and animosity
SaTC:核心:中:测试社交媒体对幸福感和敌意的因果影响
- 批准号:
2334148 - 财政年份:2024
- 资助金额:
$ 59.97万 - 项目类别:
Standard Grant