CC*DNI Integration: Enhancing Science Through Custom Paths For Trusted Users
CC*DNI Integration: Enhancing Science Through Custom Paths For Trusted Users
批准号:
1541426
负责人:
James Griffioen
金额:
$99.93万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2019-08-31
中文摘要
医学、科学和工程的进步——就像人类努力的所有领域一样——越来越依赖于网络对非常大的数据集(数十亿到数万亿字节)的访问,这些数据集包含诸如科学测量、监控信息、图像、视频、模拟结果等信息。处理、传输和共享大型数据集的研究人员数量正以惊人的速度增长。尽管网络传输速度正在迅速提高,但出于安全和管理目的而部署在网络中间的设备——例如防火墙、入侵探测器等——造成了主要的瓶颈,使研究人员无法在实验室、高性能计算站点和存储设施之间快速移动这些大文件。从历史上看,网络设计者通过创建和维护一个特殊的“科学DMZ”网络来解决这个问题,该网络提供了一条“快车道”,绕过了性能限制的安全设备,这要归功于连接到科学DMZ的用户和应用程序的可信任性质。然而,今天,需要高性能数据传输的用户数量和种类不断增加,使得维护这样一个独立的基础设施变得越来越困难。该项目正在开发一种方法,通过对正常(校园)网络上的可信用户进行动态认证,确定其数据传输的性质,以及是否应该允许,从而为他们提供对这种快速通道的动态访问。该项目利用新兴的软件定义网络(SDN)功能,在网络中挑选出单独的数据流进行专门处理。利用已经部署在校园的SDN基础设施,该项目正在开发新的控制软件和协议,使受信任的用户能够对网络进行身份验证,并建立不受中间盒干扰的网络连接,同时仍然为正常的校园流量执行中间盒安全功能。与(仅)网络管理员相反,受信任的用户能够创建这样的快速通道,这将使未来的网络能够处理快速增长的大数据用户数量。
英文摘要
Progress in medicine, science, and engineering -- as in essentially all areas of human endeavor -- increasingly depends on network access to very large data sets (billions to trillions of bytes) containing information such as scientific measurements, monitoring information, images, videos, simulation results, etc. The number of researchers working with, transferring, and sharing very large data sets is growing at an alarming rate. Although network transmission speeds are rapidly increasing, devices deployed in the middle of the network for security and management purposes -- e.g., firewalls, intrusion detectors, and the like -- create major bottlenecks that prevent researchers from being able to quickly move these large files between laboratories, high-performance computing sites, and storage facilities.Historically, network designers have addressed this problem by creating and maintaining a special "Science DMZ" network that provided a "fast lane", bypassing performance-limiting security devices thanks to the trusted nature of the users and applications connected to the Science DMZ. Today, however, the growing number and variety of users who need high-performance data transfer makes it increasingly difficult to maintain such a separate infrastructure. This project is developing ways to provide trusted users on the normal (campus) network with dynamic access to such fast lanes by authenticating them on-the-fly, determining the nature of their data transfer, and whether it should be allowed or not.This project leverages emerging Software-Defined Networking (SDN) capabilities to single out individual data flows for specialized treatment in the network. Using the SDN infrastructure already deployed on campus, the project is developing new control software and protocols that enable trusted users to authenticate themselves to the network and set up network connections free from middlebox interference while still enforcing middlebox security functionality for normal campus traffic. The ability of trusted users to create such fast lanes -- as opposed to (only) network administrators -- will enable future networks to handle the rapidly growing number of big data users.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3219104.3229277
发表时间:
2018-07
期刊:
Proceedings of the Practice and Experience on Advanced Research Computing
影响因子:
--
作者:
[M. Hayashida;Sergio Rivera;James N. Griffioen;Zongming Fei;Yongwook Song]
通讯作者:
M. Hayashida;Sergio Rivera;James N. Griffioen;Zongming Fei;Yongwook Song
Dynamically Creating Custom SDN High-Speed Network Paths for Big Data Science Flows
为大数据科学流程动态创建自定义 SDN 高速网络路径
DOI:
10.1145/3093338.3104155
发表时间:
2017
期刊:
Practice & Experience in Advanced Research Computing Conference (PEARC 2017
影响因子:
--
作者:
[Rivera, Sergio, Hayashida, Mami, Griffioen, James, Fei, Zongming]
通讯作者:
Fei, Zongming
Navigating the Unexpected Realities of Big Data Transfers in a Cloud-based World
在基于云的世界中应对大数据传输的意外现实
DOI:
10.1145/3219104.3229276
发表时间:
2018
期刊:
PEARC '18 Proceedings of the Practice and Experience on Advanced Research Computing
影响因子:
--
作者:
[Rivera, Sergio, Griffioen, James, Fei, Zongming, Hayashida, Mami, Shi, Pinyi, Chitre, Bhushan, Chappell, Jacob, Song, Yongwook, Pike, Lowell, Carpenter, Charles]
通讯作者:
Carpenter, Charles
Collaborative Research: IRNC Testbed: FAB: FABRIC Across Borders
-
批准号:2029235
-
项目类别:Continuing Grant
-
资助金额:$35.0万
-
财政年份:2020
-
负责人:James Griffioen
-
依托单位:
Collaborative Research: ENTeR: Enabling NeTwork Research and the Evolution of a Next Generation Midscale Research Infrastructure
-
批准号:1836742
-
项目类别:Standard Grant
-
资助金额:$87.76万
-
财政年份:2018
-
负责人:James Griffioen
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: NetSecOps -- Policy-Driven, Knowledge-Centric, Holistic Network Security Operations Architecture
-
批准号:1642134
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2016
-
负责人:James Griffioen
-
依托单位:
MRI: Acquisition of the Kentucky Research Informatics Cloud (KyRIC)
-
批准号:1626364
-
项目类别:Standard Grant
-
资助金额:$224.0万
-
财政年份:2016
-
负责人:James Griffioen
-
依托单位:
EAGER: Collaborative Research: Enabling Economic Policies in Software-Defined Internet Exchange Points
-
批准号:1551453
-
项目类别:Standard Grant
-
资助金额:$14.99万
-
财政年份:2015
-
负责人:James Griffioen
-
依托单位:
NeTS: Large: Collaborative Research: Network Innovation through Choice
-
批准号:1111040
-
项目类别:Standard Grant
-
资助金额:$69.75万
-
财政年份:2011
-
负责人:James Griffioen
-
依托单位:
Collaborative Research: Emulation Infrastructure and Material for OS/Network Classes
-
批准号:0511534
-
项目类别:Standard Grant
-
资助金额:$5.71万
-
财政年份:2005
-
负责人:James Griffioen
-
依托单位:
CISE Research Infrastructure: The Metaverse: A Laboratory for Digital Media Networks
-
批准号:0101242
-
项目类别:Standard Grant
-
资助金额:$82.46万
-
财政年份:2001
-
负责人:James Griffioen
-
依托单位:
RIA: A Memory-Based Architecture for High-Performance Distributed File Systems
-
批准号:9309176
-
项目类别:Standard Grant
-
资助金额:$10.5万
-
财政年份:1993
-
负责人:James Griffioen
-
依托单位:
海外基金