A Layered Approach to Securing Network File Systems
A Layered Approach to Securing Network File Systems
批准号:
0310493
负责人:
Erez Zadok
金额:
$40.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-08-15 至 2007-07-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
CCR-0310493A Layered Approach to Securing Network File SystemsErez ZadokFile systems protect important data, but existing file systems are not secure enough for today's needs. Moreover, file system development is difficult. This project investigates and develops an infrastructure for easy development of highly-secure and efficient file systems, using an incremental, layered approach, with a focus on network-based file systems. The main technique used is called "stacking": a method for one file system to pass through the operations and data to one or more other file systems. With stacking it is possible to intercept file system operations and then control them as needed. Examples of file systems that are being developed include strong transparent encryption, transparent checksumming for integrity, versioning, transparent virus detection, load-balancing, replication, sand-boxing, hooks for Intrusion Detection Systems (IDSs), and more.Stackable file systems placement is investigated for three different locations along the data path. (1) on clients, offering end-to-end assurances; (2) on servers, enabling powerful IDS capabilities; and (3) on intermediate proxies, transparently controlling file servers with minimal site impact.The significance of this work is that it creates OS infrastructure that will allow future developers to build highly-secure and efficient file systems easily; several working file system examples are developed; and enhancements are investigated for general OS support for secure file systems. This research and teaching will usher a new era of secure file system development.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CyberTraining: Implementation: Medium: FOUNT: Scaffolded, Hands-On Learning for a Data-Centric Future
-
批准号:2230078
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2022
-
负责人:Erez Zadok
-
依托单位:
Collaborative Research: CNS Core: Medium: Secure, Reliable, and Efficient Long-Term Storage
-
批准号:2106263
-
项目类别:Continuing Grant
-
资助金额:$71.73万
-
财政年份:2021
-
负责人:Erez Zadok
-
依托单位:
Collaborative Research: CNS Core: Medium: Optimizing Storage Caches via Adaptive and Reconfigurable Tiering
-
批准号:2106434
-
项目类别:Continuing Grant
-
资助金额:$53.33万
-
财政年份:2021
-
负责人:Erez Zadok
-
依托单位:
CNS Core: III: Medium: Collaborative Research: Optimizing and Understanding Large Parameter Spaces in Storage Systems
-
批准号:1900706
-
项目类别:Continuing Grant
-
资助金额:$82.31万
-
财政年份:2019
-
负责人:Erez Zadok
-
依托单位:
FMitF: Track I: NLP-Assisted Formal Verification of the NFS Distributed File System Protocol
-
批准号:1918225
-
项目类别:Standard Grant
-
资助金额:$74.83万
-
财政年份:2019
-
负责人:Erez Zadok
-
依托单位:
Collaborative Research: CI-SUSTAIN: National File System Trace Repository
-
批准号:1729939
-
项目类别:Standard Grant
-
资助金额:$12.99万
-
财政年份:2017
-
负责人:Erez Zadok
-
依托单位:
Student Travel Support for the 13th USENIX File and Storage Technologies conference (FASTI 2015)
-
批准号:1522834
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2015
-
负责人:Erez Zadok
-
依托单位:
CSR: Medium: Collaborative Research: Workload-Aware Storage Architectures for Optimal Performance and Energy Efficiency
-
批准号:1302246
-
项目类别:Standard Grant
-
资助金额:$51.39万
-
财政年份:2013
-
负责人:Erez Zadok
-
依托单位:
BIGDATA: Small: DCM: Collaborative Research: An efficient, versatile, scalable, and portable storage system for scientific data containers
-
批准号:1251137
-
项目类别:Standard Grant
-
资助金额:$44.43万
-
财政年份:2013
-
负责人:Erez Zadok
-
依托单位:
TTP: Small: NFS4Sec: An Extensible Security Layer for Network Storage
-
批准号:1223239
-
项目类别:Standard Grant
-
资助金额:$48.68万
-
财政年份:2012
-
负责人:Erez Zadok
-
依托单位:
Student Travel Support for the First USENIX Workshop on Sustainable Information Technology (SustainIT 2010)
-
批准号:0968748
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2010
-
负责人:Erez Zadok
-
依托单位:
Performance- and Energy-Aware HEC Storage Stacks
-
批准号:0937854
-
项目类别:Standard Grant
-
资助金额:$65.2万
-
财政年份:2009
-
负责人:Erez Zadok
-
依托单位:
CSR---PDOS: Support for Atomic Sequences of File System Operations
-
批准号:0614784
-
项目类别:Standard Grant
-
资助金额:$56.17万
-
财政年份:2006
-
负责人:Erez Zadok
-
依托单位:
HEC: File System Tracing, Replaying, Profiling, and Analysis on HEC Systems
-
批准号:0621463
-
项目类别:Standard Grant
-
资助金额:$76.03万
-
财政年份:2006
-
负责人:Erez Zadok
-
依托单位:
CSR---AES: Runtime Monitoring and Model Checking for High-Confidence System Software
-
批准号:0509230
-
项目类别:Continuing Grant
-
资助金额:$83.0万
-
财政年份:2005
-
负责人:Erez Zadok
-
依托单位:
CAREER: An In-Kernel Runtime Execution Environment for User-Level Programs
-
批准号:0133589
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2002
-
负责人:Erez Zadok
-
依托单位:
国内基金
海外基金
EnSite array指导下对Stepwise approach无效的慢性房颤机制及消融径线设计的实验研究
-
批准号:81070152
-
项目类别:面上项目
-
资助金额:10.0万元
-
批准年份:2010
-
负责人:唐恺
-
依托单位: