IMR: MT: Tools for Measuring Route Origin Validation in Resource Public Key Infrastructure (RPKI) at Scale
IMR:MT:用于大规模测量资源公钥基础设施 (RPKI) 中的路由源验证的工具
基本信息
- 批准号:2323137
- 负责人:
- 金额:$ 60万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-12-15 至 2025-11-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
The initial design of the Internet's global routing lacked security mechanisms, leaving it vulnerable to various attacks, including BGP (Border Gateway Protocol) hijacking. To address this issue, a security protocol called RPKI (Resource Public Key Infrastructure) was introduced. At its core, RPKI aims to enhance security by enabling routers to verify the legitimacy of the route and its authorized owner through a process known as Route Origin Validation (ROV). By implementing ROV, routers can ensure that the routes they receive originate from legitimate sources, thereby mitigating the risks associated with unauthorized route hijacking.This proposal aims to develop and enhance a dedicated tool, designed to measure and evaluate the Route Origin Validation (ROV) status of network operators. The project will involve implementing automated processes to collect measurable hosts within Autonomous Systems (ASes) and assess the ROV status of ASes on a large scale by leveraging the in-the-wild RPKI-invalid prefixes and applying IP-ID side-channel technique. A significant challenge lies in obtaining accurate ground truth datasets from network operators. To overcome this challenge, we will utilize periodic surveys and manual efforts to gather ground truth information from network operators, ensuring reliable and comprehensive data for analysis.This project's significance lies in its ability to facilitate valuable research. By providing reliable sources of information regarding network operators, it will enable a deeper understanding of the overall security level of Internet routing. Additionally, the project's findings can be utilized to estimate the adoption and deployment of potential new standards like ASPA (Autonomous System Provider Authorization). Through these insights, the project will contribute to advancing the understanding and development of secure Internet routing practices.The tools, datasets, and source codes will be thoroughly documented and accessible for download as well. Furthermore, there are plans to maintain the tools for the foreseeable future, ensuring continued availability and support for users interested in leveraging its capabilities.This award is jointly supported by the Networking Technology and Systems (NeTS) Program and the Secure and Trustworthy Cyberspace (SaTC) Program in the Computer and Network Systems Division, and by the Office of Advanced Cyberinfrastructure.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
互联网全球路由的最初设计缺乏安全机制,容易受到各种攻击,包括BGP(边界网关协议)劫持。为了解决这个问题,引入了称为 RPKI(资源公钥基础设施)的安全协议。 RPKI 的核心目标是让路由器能够通过称为路由源验证 (ROV) 的过程来验证路由及其授权所有者的合法性,从而增强安全性。通过实施ROV,路由器可以确保它们接收的路由来自合法来源,从而减轻与未经授权的路由劫持相关的风险。该提案旨在开发和增强专用工具,旨在测量和评估路由来源验证(ROV)网络运营商的状况。该项目将涉及实施自动化流程来收集自治系统(ASes)内的可测量主机,并通过利用野外 RPKI 无效前缀和应用 IP-ID 侧信道技术大规模评估 ASes 的 ROV 状态。一个重大挑战在于从网络运营商那里获取准确的地面实况数据集。为了克服这一挑战,我们将利用定期调查和人工从网络运营商收集地面真实信息,确保可靠和全面的数据进行分析。该项目的意义在于它能够促进有价值的研究。通过提供有关网络运营商的可靠信息来源,它将能够更深入地了解互联网路由的整体安全级别。此外,该项目的研究结果还可用于估计 ASPA(自治系统提供商授权)等潜在新标准的采用和部署。通过这些见解,该项目将有助于促进对安全互联网路由实践的理解和开发。工具、数据集和源代码将被完整记录并可供下载。此外,计划在可预见的未来维护这些工具,确保对有兴趣利用其功能的用户持续可用和支持。该奖项由网络技术和系统 (NeTS) 计划和安全可信网络空间 (SaTC) 联合支持)计算机和网络系统部门的计划,并由高级网络基础设施办公室颁发。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力优点和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Taejoong Chung其他文献
Rolling With Confidence: Managing the Complexity of DNSSEC Operations
充满信心地滚动:管理 DNSSEC 操作的复杂性
- DOI:
10.1109/tnsm.2019.2916176 - 发表时间:
2019-05-10 - 期刊:
- 影响因子:5.3
- 作者:
M. Müller;Taejoong Chung;A. Mislove;Rol;van Rijswijk - 通讯作者:
van Rijswijk
maTLS: How to Make TLS middlebox-aware?
maTLS:如何使 TLS 中间件感知?
- DOI:
10.14722/ndss.2019.23547 - 发表时间:
2024-09-14 - 期刊:
- 影响因子:0
- 作者:
Hyunwoo Lee;Zach Smith;Junghwan Lim;Gyeongjae Choi;Selin Chun;Taejoong Chung;T. Kwon - 通讯作者:
T. Kwon
Tunneling for Transparency: A Large-Scale Analysis of End-to-End Violations in the Internet
透明隧道:对互联网中端到端违规行为的大规模分析
- DOI:
10.1145/2987443.2987455 - 发表时间:
2016-11-14 - 期刊:
- 影响因子:0
- 作者:
Taejoong Chung;D. Choffnes;A. Mislove - 通讯作者:
A. Mislove
The Reality of Algorithm Agility: Studying the DNSSEC Algorithm Life-Cycle
算法敏捷性的现实:研究 DNSSEC 算法生命周期
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
M. Müller;W. Toorop;Taejoong Chung;J. Jansen;R. V. Rijswijk - 通讯作者:
R. V. Rijswijk
A Longitudinal, End-to-End View of the DNSSEC Ecosystem
DNSSEC 生态系统的纵向、端到端视图
- DOI:
10.1109/cns.2013.6682711 - 发表时间:
2017-08-16 - 期刊:
- 影响因子:0
- 作者:
Taejoong Chung;R. V. Rijswijk;B. Ch;rasekaran;rasekaran;D. Choffnes;Dave Levin;B. Maggs;A. Mislove;Christo Wilson - 通讯作者:
Christo Wilson
Taejoong Chung的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Taejoong Chung', 18)}}的其他基金
CAREER: Securing and Evolving Internet Security Protocols for Naming and Routing
职业:保护和发展用于命名和路由的互联网安全协议
- 批准号:
2339378 - 财政年份:2024
- 资助金额:
$ 60万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Cryptographic accumulators and revocation of credentials
协作研究:SaTC:核心:中:加密累加器和凭证撤销
- 批准号:
2247306 - 财政年份:2023
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
Travel: NSF Student Travel Grant for 2022 Internet Measurement Conference (IMC)
旅行:2022 年互联网测量会议 (IMC) 的 NSF 学生旅行补助金
- 批准号:
2234443 - 财政年份:2022
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
CNS Core: Large: Collaborative Research: Towards an Evolvable Public Key Infrastructure
CNS 核心:大型:协作研究:迈向可进化的公钥基础设施
- 批准号:
2053363 - 财政年份:2020
- 资助金额:
$ 60万 - 项目类别:
Continuing Grant
CRII: SaTC: Measuring and Improving the Management of Resource Public Key Infrastructure (RPKI)
CRII:SaTC:衡量和改进资源公钥基础设施 (RPKI) 的管理
- 批准号:
2051166 - 财政年份:2020
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
CNS Core: Large: Collaborative Research: Towards an Evolvable Public Key Infrastructure
CNS 核心:大型:协作研究:迈向可进化的公钥基础设施
- 批准号:
1901090 - 财政年份:2019
- 资助金额:
$ 60万 - 项目类别:
Continuing Grant
CRII: SaTC: Measuring and Improving the Management of Resource Public Key Infrastructure (RPKI)
CRII:SaTC:衡量和改进资源公钥基础设施 (RPKI) 的管理
- 批准号:
1850465 - 财政年份:2019
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
相似国自然基金
转录因子c-Myb通过增强MT-ND1/4/5转录介导急性髓系白血病代谢异质性的分子机制研究
- 批准号:82360030
- 批准年份:2023
- 资助金额:32 万元
- 项目类别:地区科学基金项目
基于巨噬细胞线粒体二级靶向递送mt-cricRNA ND5促进糖尿病创面修复的作用及机制研究
- 批准号:82372523
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
SNORA14A/MT2A抗氧化轴失调介导Activin-A表达增加促进肝母细胞瘤进展的机制及临床价值研究
- 批准号:82302615
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
MT1高表达巨噬细胞调控血管平滑肌表型转化在腹主动脉瘤形成中的作用与机制研究
- 批准号:82370479
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
MT2A调控的髓核细胞铁死亡途径在椎间盘退变中的作用及机制研究
- 批准号:82302741
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
IMR: MT: Tools for Programming Distributed Data-plane Measurements
IMR:MT:分布式数据平面测量编程工具
- 批准号:
2223515 - 财政年份:2022
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
IMR: MT: Tools for Safe, Easy, and Reliable Active Global Internet Measurement
IMR:MT:用于安全、简单和可靠的主动全球互联网测量的工具
- 批准号:
2223360 - 财政年份:2022
- 资助金额:
$ 60万 - 项目类别:
Continuing Grant
A novel, short isoform of the +TIP microtubule (MT) binding protein CLIP170 confers taxane resistance by obstructing the MT pore.
TIP 微管 (MT) 结合蛋白 CLIP170 的一种新型短亚型通过阻塞 MT 孔而赋予紫杉烷抗性。
- 批准号:
10437609 - 财政年份:2018
- 资助金额:
$ 60万 - 项目类别:
A novel, short isoform of the +TIP microtubule (MT) binding protein CLIP170 confers taxane resistance by obstructing the MT pore.
TIP 微管 (MT) 结合蛋白 CLIP170 的一种新型短亚型通过阻塞 MT 孔而赋予紫杉烷抗性。
- 批准号:
9918278 - 财政年份:2018
- 资助金额:
$ 60万 - 项目类别:
International Conference: Mathematical tools for multi-scale biological processes, June 2008. Bozeman, MT
国际会议:多尺度生物过程的数学工具,2008 年 6 月。博兹曼,MT
- 批准号:
0803127 - 财政年份:2008
- 资助金额:
$ 60万 - 项目类别:
Standard Grant