CICI: SSC: Real-Time Operating System and Network Security for Scientific Middleware
CICI:SSC:科学中间件的实时操作系统和网络安全
基本信息
- 批准号:1839321
- 负责人:
- 金额:$ 99.99万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-10-01 至 2019-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Remote monitoring and control of industrial control systems are protected using firewalls and user passwords. Cyberattacks that get past firewalls have unfettered access to command industrial control systems with potential to harm digital assets, environmental resources, and humans in proximity to the compromised system. To prevent and mitigate such harms in scientific industrial control systems, this project enhances the security of open-source cyberinfrastructure used for high energy physics, astronomy, and space sciences. The results of this project enhance the security of scientific instruments used in particle accelerators, large-scale telescopes, satellites, and space probes. The benefits to science and the public include greater confidence in the fidelity of experimental data collected from these scientific instruments, and increased reliability of scientific cyberinfrastructure that reduces the costs associated with accidental misconfigurations or malicious cyberattacks.The objective of this project is to enhance the security of the open-source Real-Time Executive for Multiprocessor Systems (RTEMS) real-time operating system and the Experimental Physics and Industrial Control System (EPICS) software and networks; RTEMS and EPICS are widely used cyberinfrastructure for controlling scientific instruments. The security enhancements span eight related project activities: (1) static analysis and security fuzzing as part of continuous integration; (2) cryptographic security for the open-source software development life cycle; (3) secure boot and update for remotely-managed scientific instruments; (4) open-source cryptographic libraries for secure communication; (5) real-time memory protection; (6) formal modeling and analysis of network protocols; (7) enhanced security event logging; and (8) network-based intrusion detection for scientific industrial control systems. The project outcomes provide a roadmap for enculturating cybersecurity best practices in open-source, open-science communities while advancing the state-of-the-art research in cyberinfrastructure software engineering and industrial control system security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
使用防火墙和用户密码保护工业控制系统的远程监视和控制。越过防火墙的网络攻击不受限制地访问命令工业控制系统,该系统可能会损害数字资产,环境资源和人类与受损系统的距离。 为了预防和减轻科学工业控制系统中的这种危害,该项目增强了用于高能物理,天文学和太空科学的开源网络基础设施的安全性。该项目的结果增强了粒子加速器,大规模望远镜,卫星和空间探针中使用的科学仪器的安全性。 The benefits to science and the public include greater confidence in the fidelity of experimental data collected from these scientific instruments, and increased reliability of scientific cyberinfrastructure that reduces the costs associated with accidental misconfigurations or malicious cyberattacks.The objective of this project is to enhance the security of the open-source Real-Time Executive for Multiprocessor Systems (RTEMS) real-time operating system and the Experimental Physics and Industrial Control System (EPICS)软件和网络; RTEM和EPICS广泛用于控制科学仪器的网络基础设施。安全性增强范围涵盖了八项相关项目活动:(1)作为连续集成的一部分,静态分析和安全性构成; (2)开源软件开发生命周期的加密安全; (3)安全启动并更新以远程管理的科学仪器; (4)用于安全通信的开源加密库; (5)实时内存保护; (6)网络协议的正式建模和分析; (7)增强的安全事件记录; (8)基于网络的科学工业控制系统的入侵检测。该项目成果为在开源,开放科学社区中提供网络安全的最佳实践提供了路线图,同时推进了网络基础设施软件工程和工业控制系统安全的最先进研究。这奖反映了NSF的法定任务,并通过评估基础的智力效果和广阔的范围来评估,并被视为值得通过评估来进行评估。
项目成果
期刊论文数量(2)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Controller Area Network Intrusion Prevention System Leveraging Fault Recovery
利用故障恢复的控制器局域网入侵防御系统
- DOI:10.1145/3338499.3357360
- 发表时间:2019
- 期刊:
- 影响因子:0
- 作者:Olufowobi, Habeeb;Hounsinou, Sena;Bloom, Gedare
- 通讯作者:Bloom, Gedare
On the Pitfalls and Vulnerabilities of Schedule Randomization Against Schedule-Based Attacks
- DOI:10.1109/rtas.2019.00017
- 发表时间:2019-04
- 期刊:
- 影响因子:0
- 作者:M. Nasri;Thidapat Chantem;Gedare Bloom;Ryan M. Gerdes
- 通讯作者:M. Nasri;Thidapat Chantem;Gedare Bloom;Ryan M. Gerdes
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Gedare Bloom其他文献
Precise Cache Profiling for Studying Radiation Effects
用于研究辐射效应的精确缓存分析
- DOI:
10.1145/3442339 - 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
James Marshall;Robert Gifford;Gedare Bloom;Gabriel Parmer;R. Simha - 通讯作者:
R. Simha
Scheduling and thread management with RTEMS
使用 RTEMS 进行调度和线程管理
- DOI:
10.1145/2597457.2597459 - 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Gedare Bloom;J. Sherrill - 通讯作者:
J. Sherrill
L-IDS: A Multi-Layered Approach to Ransomware Detection in IoT
L-IDS:物联网勒索软件检测的多层方法
- DOI:
10.1109/ccwc60891.2024.10427870 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Farhad Mofidi;Sena Hounsinou;Gedare Bloom - 通讯作者:
Gedare Bloom
OS support for detecting Trojan circuit attacks
操作系统支持检测木马电路攻击
- DOI:
10.1109/hst.2009.5224959 - 发表时间:
2009 - 期刊:
- 影响因子:0
- 作者:
Gedare Bloom;B. Narahari;R. Simha - 通讯作者:
R. Simha
Vulnerabilities and Solutions
漏洞及解决方案
- DOI:
- 发表时间:
2012 - 期刊:
- 影响因子:0
- 作者:
Gedare Bloom;Eugen Leontie;B. Narahari;R. Simha - 通讯作者:
R. Simha
Gedare Bloom的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Gedare Bloom', 18)}}的其他基金
CAREER: Foundations for Real-Time System Security
职业:实时系统安全的基础
- 批准号:
2046705 - 财政年份:2021
- 资助金额:
$ 99.99万 - 项目类别:
Continuing Grant
CICI: SSC: Real-Time Operating System and Network Security for Scientific Middleware
CICI:SSC:科学中间件的实时操作系统和网络安全
- 批准号:
2001789 - 财政年份:2019
- 资助金额:
$ 99.99万 - 项目类别:
Standard Grant
CPS: Breakthrough: Collaborative Research: Track and Fallback: Intrusion Detection to Counteract Carjack Hacks with Fail-Operational Feedback
CPS:突破:协作研究:跟踪和回退:入侵检测通过失败操作反馈来对抗劫车黑客
- 批准号:
2011620 - 财政年份:2019
- 资助金额:
$ 99.99万 - 项目类别:
Standard Grant
CPS: Breakthrough: Collaborative Research: Track and Fallback: Intrusion Detection to Counteract Carjack Hacks with Fail-Operational Feedback
CPS:突破:协作研究:跟踪和回退:入侵检测通过失败操作反馈来对抗劫车黑客
- 批准号:
1646317 - 财政年份:2016
- 资助金额:
$ 99.99万 - 项目类别:
Standard Grant
相似国自然基金
CD84+单核巨噬细胞招募至肺组织形成niche促进SSc-ILD进展
- 批准号:82370073
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
湿热海洋环境下3D打印FRP筋SSC梁长期抗剪性能及计算方法研究
- 批准号:52308288
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
新型125ksi级低合金油井管钢的抗SSC性能及机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
VMP1棕榈酰化调控Sertoli细胞外泌体在SSC微环境中的作用和机制研究
- 批准号:
- 批准年份:2022
- 资助金额:54 万元
- 项目类别:面上项目
Fstl1调控血管内皮细胞活化和炎症参与系统性硬化症相关间质性肺疾病(SSc-ILD)的作用机制研究
- 批准号:
- 批准年份:2022
- 资助金额:52 万元
- 项目类别:面上项目
相似海外基金
The SSS project: a historical study of scientific collaborations between Japan and U.S.
SSS项目:日本和美国之间科学合作的历史研究
- 批准号:
23K00266 - 财政年份:2023
- 资助金额:
$ 99.99万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
A platelet-fibroblast axis connecting bioenergetics and metabolism in SSc-pulmonary arterial hypertension
连接 SSc 肺动脉高压生物能学和代谢的血小板-成纤维细胞轴
- 批准号:
10404145 - 财政年份:2022
- 资助金额:
$ 99.99万 - 项目类别:
SSCを用いた運動制御について:前腕屈筋における腱動態特性の解明
关于使用 SSC 进行运动控制:阐明前臂屈肌肌腱动态特性
- 批准号:
22K17683 - 财政年份:2022
- 资助金额:
$ 99.99万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
CICI: SSC: Horizon: Secure Large-Scale Scientific Cloud Computing
CICI:SSC:地平线:安全大规模科学云计算
- 批准号:
2341138 - 财政年份:2022
- 资助金额:
$ 99.99万 - 项目类别:
Standard Grant
A platelet-fibroblast axis connecting bioenergetics and metabolism in SSc-pulmonary arterial hypertension
连接 SSc 肺动脉高压生物能学和代谢的血小板-成纤维细胞轴
- 批准号:
10705673 - 财政年份:2022
- 资助金额:
$ 99.99万 - 项目类别: