CRII: SaTC: Measuring and Improving the Management of Resource Public Key Infrastructure (RPKI)
CRII:SaTC:衡量和改进资源公钥基础设施 (RPKI) 的管理
基本信息
- 批准号:2051166
- 负责人:
- 金额:$ 14.94万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2020
- 资助国家:美国
- 起止时间:2020-08-01 至 2022-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The Border Gateway Protocol (BGP) is responsible for managing how packets are routed across the Internet by exchanging routing related messages (path announcements) between routers. While the Border Gateway Protocol plays a critical role in the Internet communications, it remains highly vulnerable to many attacks. This is because the protocol was originally designed for each BGP router to trust all protocol related messages, especially path announcements, sent by its neighboring routers. As a result, incorrect and malicious path information would be accepted by routers at face value, potentially leading to destination unreachable problems in the Internet. To address this issue, Resource Public Key Infrastructure (RPKI) was introduced in 2012 to allow routers to verify path announcements in the Border Gateway Protocol. However, today there is a dearth of information available about the vulnerability of the RPKI, and how routers in the Internet have actually deployed and managed it. This project will develop techniques to better understand and improve the management of RPKI, helping to better secure the Internet. Given the early stage of the RPKI protocol, the findings in this project stand a good chance of being integrated to improve the state of the system. The project would train students in related research. The findings of the project would identify what the current security problems of RPKI are and help spur a greater adoption of RPKI by releasing the codes, datasets and analysis tools developed in the project and presenting the research outcomes to other researchers, administrators, and Internet operations related working groups.This project has two research foci, each examining the management and improving security challenges of the Resource Public Key Infrastructure. First, the project will analyze existing RPKI repositories from multiple vantage points in an effort to understand how much of actual Border Gateway Protocol feeds in the Internet are verifiable. It will also determine what fraction of routers are actually using RPKI to validate paths. For this focus, the investigators will collaborate with one of the biggest network operators that have the most-peered global networks in existence. Second, the project will develop new techniques to detect misconfigurations of routers and potential security vulnerabilities. For this purpose, the project will host a custom RPKI repository that have multiple invalid routes, which will be used to test RPKI validators or routers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
边界网关协议(BGP)负责通过路由器之间的路由器之间交换相关消息(路径公告)来管理如何在互联网上进行路由。尽管边境网关协议在Internet通信中起着至关重要的作用,但它仍然很容易受到许多攻击的影响。这是因为该协议最初是为每个BGP路由器设计的,以信任其相邻路由器发送的所有相关消息,尤其是路径公告。结果,路由器以表面价值接受了不正确和恶意的路径信息,这可能导致互联网中目的地无法达到的问题。为了解决此问题,资源公共密钥基础架构(RPKI)于2012年引入,以允许路由器在边界网关协议中验证路径公告。但是,今天,缺乏有关RPKI脆弱性的信息,以及互联网中的路由器实际上是如何部署和管理的。该项目将开发技术,以更好地理解和改善RPKI的管理,从而更好地保护互联网。鉴于RPKI协议的早期阶段,该项目的发现很有可能被整合起来改善系统状态。该项目将培训学生进行相关研究。 The findings of the project would identify what the current security problems of RPKI are and help spur a greater adoption of RPKI by releasing the codes, datasets and analysis tools developed in the project and presenting the research outcomes to other researchers, administrators, and Internet operations related working groups.This project has two research foci, each examining the management and improving security challenges of the Resource Public Key Infrastructure.首先,该项目将从多个有利位置分析现有的RPKI存储库,以了解Internet中有多少实际边境网关协议提要是可以验证的。它还将确定哪些路由器实际使用RPKI来验证路径。为了重点,调查人员将与拥有最多的全球网络的最大网络运营商之一合作。其次,该项目将开发新技术,以检测路由器和潜在安全漏洞的构造错误。为此,该项目将托管一个具有多个无效路线的自定义RPKI存储库,该存储库将用于测试RPKI验证器或路由器。该奖项反映了NSF的法定任务,并被认为是通过基金会的知识分子优点和更广泛影响的审查标准通过评估来获得支持的。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Taejoong Chung其他文献
Privacy Guarantees of Bluetooth Low Energy Contact Tracing: A Case Study on COVIDWISE
低功耗蓝牙接触者追踪的隐私保证:COVIDWISE 案例研究
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:2.2
- 作者:
Salman Ahmed;Ya Xiao;Taejoong Chung;Carol J. Fung;M. Yung;D. Yao - 通讯作者:
D. Yao
Strategic bundling for content availability and fast distribution in BitTorrent
- DOI:
10.1016/j.comcom.2014.01.013 - 发表时间:
2014-05-01 - 期刊:
- 影响因子:
- 作者:
Jinyoung Han;Taejoong Chung;Seungbae Kim;Hyun-chul Kim;Jussi Kangasharju;Ted “Taekyoung” Kwon;Yanghee Choi - 通讯作者:
Yanghee Choi
RoVista: Measuring and Analyzing the Route Origin Validation (ROV) in RPKI
RoVista:测量和分析 RPKI 中的路线起点验证 (ROV)
- DOI:
10.1145/3618257.3624806 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Weitong Li;Zhexiao Lin;Md. Ishtiaq Ashiq;E. Aben;Romain Fontugne;Amreesh Phokeer;Taejoong Chung - 通讯作者:
Taejoong Chung
The Reality of Algorithm Agility: Studying the DNSSEC Algorithm Life-Cycle
算法敏捷性的现实:研究 DNSSEC 算法生命周期
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
M. Müller;W. Toorop;Taejoong Chung;J. Jansen;R. V. Rijswijk - 通讯作者:
R. V. Rijswijk
Delegation of TLS Authentication to CDNs using Revocable Delegated Credentials
使用可撤销委派凭证将 TLS 身份验证委派给 CDN
- DOI:
- 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Daegeun Yoon;Taejoong Chung;Yongdae Kim - 通讯作者:
Yongdae Kim
Taejoong Chung的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Taejoong Chung', 18)}}的其他基金
CAREER: Securing and Evolving Internet Security Protocols for Naming and Routing
职业:保护和发展用于命名和路由的互联网安全协议
- 批准号:
2339378 - 财政年份:2024
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
IMR: MT: Tools for Measuring Route Origin Validation in Resource Public Key Infrastructure (RPKI) at Scale
IMR:MT:用于大规模测量资源公钥基础设施 (RPKI) 中的路由源验证的工具
- 批准号:
2323137 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Cryptographic accumulators and revocation of credentials
协作研究:SaTC:核心:中:加密累加器和凭证撤销
- 批准号:
2247306 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
Travel: NSF Student Travel Grant for 2022 Internet Measurement Conference (IMC)
旅行:2022 年互联网测量会议 (IMC) 的 NSF 学生旅行补助金
- 批准号:
2234443 - 财政年份:2022
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
CNS Core: Large: Collaborative Research: Towards an Evolvable Public Key Infrastructure
CNS 核心:大型:协作研究:迈向可进化的公钥基础设施
- 批准号:
2053363 - 财政年份:2020
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
CRII: SaTC: Measuring and Improving the Management of Resource Public Key Infrastructure (RPKI)
CRII:SaTC:衡量和改进资源公钥基础设施 (RPKI) 的管理
- 批准号:
1850465 - 财政年份:2019
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
CNS Core: Large: Collaborative Research: Towards an Evolvable Public Key Infrastructure
CNS 核心:大型:协作研究:迈向可进化的公钥基础设施
- 批准号:
1901090 - 财政年份:2019
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
相似海外基金
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
合作研究:SaTC:核心:小型:测量、验证和改进基于应用程序的隐私营养标签
- 批准号:
2247952 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: TTP: Medium: iDRAMA.cloud: A Platform for Measuring and Understanding Information Manipulation
协作研究:SaTC:TTP:中:iDRAMA.cloud:测量和理解信息操纵的平台
- 批准号:
2247867 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
合作研究:SaTC:核心:小型:测量、验证和改进基于应用程序的隐私营养标签
- 批准号:
2247953 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: TTP: Medium: iDRAMA.cloud: A Platform for Measuring and Understanding Information Manipulation
协作研究:SaTC:TTP:中:iDRAMA.cloud:测量和理解信息操纵的平台
- 批准号:
2247868 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
合作研究:SaTC:核心:小型:测量、验证和改进基于应用程序的隐私营养标签
- 批准号:
2247951 - 财政年份:2023
- 资助金额:
$ 14.94万 - 项目类别:
Standard Grant