CAREER: Enabling New Networking Applications and Distributed Systems with Mobile, Lightweight Protection Domains
CAREER: Enabling New Networking Applications and Distributed Systems with Mobile, Lightweight Protection Domains
批准号:
0132817
负责人:
Steven Gribble
金额:
$49.93万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-03-15 至 2008-02-29
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Advances in network and computing technologies have accelerated the proliferation of infrastructuresuch as content distribution, caching, middleware services, and network measurement testbeds. Recently,however, a number of new application domains are beginning to emerge that are not well-supported byexisting technologies, such as the ability to distribute dynamically generated or active content, to rapidlydeploy new and untrusted Internet services into existing infrastructure, and the ability to dynamically injectnetwork measurement code into an existing network experimentation infrastructure. These new application domains all share several security and resource management requirements: safelyexecuting untrusted code, scaling to a large number (100s or 1000s) of protection domains per physical host, and supporting a large degree of multiplexing of physical host resources across many concurrently active protection domains. Although there have been many sandboxing technologies proposed in the past, none of them have the combination of water-tight isolation and the ability to scale to a large number of protectiondomains required by these new applications. The goal of this CAREER proposal is to enable this wide array of new networking and distributedmiddleware applications by designing and implementing lightweight protection domains, technically focusingon the notion of using virtual machine monitors (VMMs). A virtual machine monitor is a software layerthat runs immediately on top of the hardware/software boundary, virtualizing all names exposed by thatboundary to give higher-level virtual machines the illusion of their own dedicated physical machine. Virtualmachines are known to have strong isolation, and they are known to support code migration. However,existing virtual machines and guest operating systems are typically heavyweight, permitting only a smallnumber (3-10) to concurrently execute on a single physical machine. The first research challenge posed inthis proposal is designing and implementing mechanisms for building lightweight VMMs, virtual machines,and guest operating systems, so that 100s or 1000s can concurrently execute. An ancillary challenge impliedby this is resource management across virtual machines: to fully isolate one VM from another, each VM'sresource usage (e.g., CPU consumption, I/O rates, memory footprint) must be bounded by the VMM. Once the researchers have successfully implemented lightweight virtual machines, they intend to heavily leverage this new mechanism to explore several new research topics, as well as revisiting a few existing ones. For example,they will use virtual machines as a sandboxing mechanism enabling web servers to dynamically inject new content-generation code into content delivery networks or web caching systems. As another example, they will use VMs to enable untrusted code authors to upload new Internet services into a virtual hosting platform. As a third example, the researchers plan on exploring the role of virtual machines as a resource container in cluster-of-workstations, in particular exploring the ability to dynamically alter relative resource consumption rates of virtual machines to create the effect of isolated \virtual clusters" within a single physical cluster. For the educational component of the CAREER proposal, the researchs plan on exploring the use of their virtual machine monitor as a substrate for supporting novel projects in undergraduate and graduate advancedoperating systems courses, such as CSE451 and CSE551 at the University of Washington. A virtual machinemonitor is a natural place for supporting intricate debugging mechanisms, and hardware device emulation.Having students augment the virtual machine monitor and use it to develop simple components of anoperating system will radically improve the students' understanding of OS issues, as they will be forced tounderstand the interface between the OS and the hardware, as well as the structure of the OS itself. Finally,this will also provide us with an opportunity to revise the OS course curriculum to include modern topics assecurity, isolation, mobility, and OS support for embedded devices (which share characteristics of the virtual machines that we will emulate with our VMM).
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Student Travel Support for the Ninth Symposium on Networked Systems Design and Implementation (NSDI 2012)
-
批准号:1232584
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2012
-
负责人:Steven Gribble
-
依托单位:
Student Travel Support for the 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 2012)
-
批准号:1249332
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2012
-
负责人:Steven Gribble
-
依托单位:
CSR: Small: Bringing Predictable Low Latency and Strong Consistency to Data Center Services
-
批准号:1217597
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2012
-
负责人:Steven Gribble
-
依托单位:
CSR: Small: Driverless Operating Systems
-
批准号:1016477
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2010
-
负责人:Steven Gribble
-
依托单位:
CT-T: The Detection and Prevention of Spyware
-
批准号:0627367
-
项目类别:Continuing Grant
-
资助金额:$95.0万
-
财政年份:2006
-
负责人:Steven Gribble
-
依托单位:
OS Support for Application Installation, Execution, and Management in an Untrustworthy World
-
批准号:0430477
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2004
-
负责人:Steven Gribble
-
依托单位:
海外基金