课题基金 / 基金详情

A Layered Approach to Securing Network File Systems

A Layered Approach to Securing Network File Systems
保护网络文件系统的分层方法
批准号:
0310493
负责人:
Erez Zadok
金额:
$40.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-08-15 至 2007-07-31

项目摘要

项目成果

Erez Zadok的其他基金

相似基金

相关文献

中文摘要
翻译
保护网络文件系统的分层方法文件系统保护重要数据,但是现有的文件系统不够安全,无法满足当今的需求。此外,文件系统的开发也很困难。该项目研究并开发了一种基础设施,用于轻松开发高度安全和高效的文件系统,使用增量的分层方法,重点关注基于网络的文件系统。使用的主要技术称为“堆叠”:一个文件系统将操作和数据传递到一个或多个其他文件系统的方法。通过堆叠,可以拦截文件系统操作,然后根据需要对其进行控制。正在开发的文件系统示例包括强透明加密、透明完整性校验和、版本控制、透明病毒检测、负载平衡、复制、沙箱、入侵检测系统(ids)钩子等等。研究可堆叠文件系统在数据路径上的三个不同位置的放置。(1)对客户,提供端到端的保证;(2)在服务器上,实现强大的IDS功能;(3)在中间代理上,以最小的站点影响透明地控制文件服务器。这项工作的意义在于,它创建了操作系统基础设施,使未来的开发人员能够轻松构建高度安全和高效的文件系统;开发了几个工作文件系统示例;并研究了对安全文件系统的通用操作系统支持的增强。这一研究和教学将开创一个安全文件系统开发的新时代。
英文摘要
CCR-0310493A Layered Approach to Securing Network File SystemsErez ZadokFile systems protect important data, but existing file systems are not secure enough for today's needs. Moreover, file system development is difficult. This project investigates and develops an infrastructure for easy development of highly-secure and efficient file systems, using an incremental, layered approach, with a focus on network-based file systems. The main technique used is called "stacking": a method for one file system to pass through the operations and data to one or more other file systems. With stacking it is possible to intercept file system operations and then control them as needed. Examples of file systems that are being developed include strong transparent encryption, transparent checksumming for integrity, versioning, transparent virus detection, load-balancing, replication, sand-boxing, hooks for Intrusion Detection Systems (IDSs), and more.Stackable file systems placement is investigated for three different locations along the data path. (1) on clients, offering end-to-end assurances; (2) on servers, enabling powerful IDS capabilities; and (3) on intermediate proxies, transparently controlling file servers with minimal site impact.The significance of this work is that it creates OS infrastructure that will allow future developers to build highly-secure and efficient file systems easily; several working file system examples are developed; and enhancements are investigated for general OS support for secure file systems. This research and teaching will usher a new era of secure file system development.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CyberTraining: Implementation: Medium: FOUNT: Scaffolded, Hands-On Learning for a Data-Centric Future
  • 批准号:
    2230078
  • 项目类别:
    Standard Grant
  • 资助金额:
    $17.49万
  • 财政年份:
    2022
  • 负责人:
    Erez Zadok
  • 依托单位:
Collaborative Research: CNS Core: Medium: Secure, Reliable, and Efficient Long-Term Storage
  • 批准号:
    2106263
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $71.73万
  • 财政年份:
    2021
  • 负责人:
    Erez Zadok
  • 依托单位:
Collaborative Research: CNS Core: Medium: Optimizing Storage Caches via Adaptive and Reconfigurable Tiering
  • 批准号:
    2106434
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $53.33万
  • 财政年份:
    2021
  • 负责人:
    Erez Zadok
  • 依托单位:
CNS Core: III: Medium: Collaborative Research: Optimizing and Understanding Large Parameter Spaces in Storage Systems
  • 批准号:
    1900706
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $82.31万
  • 财政年份:
    2019
  • 负责人:
    Erez Zadok
  • 依托单位:
国内基金
海外基金
EnSite array指导下对Stepwise approach无效的慢性房颤机制及消融径线设计的实验研究
  • 批准号:
    81070152
  • 项目类别:
    面上项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2010
  • 负责人:
    唐恺
  • 依托单位: