CT-T:Exploiting Multi-Core CPUs for Parallelizing Network Intrusion Prevention
CT-T:Exploiting Multi-Core CPUs for Parallelizing Network Intrusion Prevention
批准号:
0716636
负责人:
Vern Paxson
金额:
$49.94万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2007
资助国家:
美国
项目状态:
已结题
起止时间:
2007-09-01 至 2010-08-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
The performance pressures on implementing effective network security monitoring are growing fiercely in multiple dimensions, outpacing improvements in CPU performance. The situation has now become dire with the end of Moore's Law for single CPUs. In general, hardware vendors now turn to parallel execution---many cores and many threads---to sustain performance growth. But adapting network security monitoring to such parallelism raises a host of challenging issues.This project seeks to develop methodologies for effectively parallelizing in-depth security analysis of network activity. Doing so requires structuring the processing into separate, low-level threads suitable for concurrent execution, for which several key issues must be addressed: forwarding packets only when all relevant threads have finished their vetting; minimizing inter-thread communication in the presence of global analysis algorithms; optimizing memory access patterns for locality; and providing effective performance debugging tools.The work centers around an event-oriented underlying architecture, which allows for exposing many opportunities for concurrent execution due to the decoupled asynchrony that events introduce into the flow of analysis. In addition, by associating events with the packets that ultimately stimulated them, the system can make sound decisions for resolving whether and when it becomes safe to forward pending packets.Ultimately, the effort aims to enable network intrusion prevention to reap both the benefits of executing on general purpose commodity hardware, as well as the exponential scaling that Moore's Law promises for future parallel processors.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
II-New: Enabling Security Analysis at Scale
-
批准号:1406041
-
项目类别:Standard Grant
-
资助金额:$59.38万
-
财政年份:2014
-
负责人:Vern Paxson
-
依托单位:
TWC: Phase: Small: Censorship Counterstrike via Measurement, Filtering, Evasion, and Protocol Enhancement
-
批准号:1223717
-
项目类别:Standard Grant
-
资助金额:$66.66万
-
财政年份:2012
-
负责人:Vern Paxson
-
依托单位:
NeTS: Large: Collaborative Research: Measuring and Modeling the Dynamics of IPv4 Address Exhaustion
-
批准号:1111672
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2011
-
负责人:Vern Paxson
-
依托单位:
CT-L: Collaborative Research: Comprehensive Application Analysis and Control
-
批准号:0831535
-
项目类别:Continuing Grant
-
资助金额:$127.75万
-
财政年份:2008
-
负责人:Vern Paxson
-
依托单位:
CT-T: Establishing a Cross-Institutional Platform for Cooperative Security Monitoring and Forensics
-
批准号:0716640
-
项目类别:Standard Grant
-
资助金额:$69.98万
-
财政年份:2007
-
负责人:Vern Paxson
-
依托单位:
CT-T: Approaches to Network Defense Proven in Open Scientific Environments
-
批准号:0627320
-
项目类别:Standard Grant
-
资助金额:$23.61万
-
财政年份:2006
-
负责人:Vern Paxson
-
依托单位:
NeTS-FIND: Collaborative Research: Network Fabric for Personal, Social, and Urban Sensing Applications
-
批准号:0626539
-
项目类别:Continuing Grant
-
资助金额:$22.01万
-
财政年份:2006
-
负责人:Vern Paxson
-
依托单位:
Collaborative Proposal Cybertrust: Center for Internet Epidemiology and Defenses
-
批准号:0433702
-
项目类别:Continuing Grant
-
资助金额:$309.75万
-
财政年份:2004
-
负责人:Vern Paxson
-
依托单位:
STI: Viable Network Defense for Scientific Research Institutions
-
批准号:0334088
-
项目类别:Continuing Grant
-
资助金额:$90.0万
-
财政年份:2003
-
负责人:Vern Paxson
-
依托单位:
NRT: Collaborative Research: Testing and Benchmarking Methodologies for Future Network Security Mechanisms
-
批准号:0335290
-
项目类别:Cooperative Agreement
-
资助金额:$0.0万
-
财政年份:2003
-
负责人:Vern Paxson
-
依托单位:
海外基金