CC*DNI Integration: Enhancing Science Through Custom Paths For Trusted Users
CC*DNI Integration: Enhancing Science Through Custom Paths For Trusted Users
批准号:
1541426
负责人:
James Griffioen
金额:
$99.93万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2019-08-31
中文摘要
医学、科学和工程的进步--就像基本上所有人类努力的领域一样--越来越依赖于通过网络访问包含科学测量、监测信息、图像、视频、模拟结果等信息的超大数据集(数十亿到数万亿字节)。研究人员使用、传输和共享超大数据集的数量正在以惊人的速度增长。尽管网络传输速度在迅速提高,但出于安全和管理目的部署在网络中间的设备--例如防火墙、入侵检测器等--造成了主要的瓶颈,使研究人员无法在实验室、高性能计算站点和存储设施之间快速移动这些大文件。从历史上看,网络设计人员通过创建和维护特殊的“科学非军事区”网络来解决这个问题,该网络提供了一条“快速通道”,由于连接到科学非军事区的用户和应用程序的可信性质,绕过了性能受限的安全设备。然而,如今,需要高性能数据传输的用户数量和种类不断增加,维护这样一个独立的基础设施变得越来越困难。该项目正在开发各种方法,通过对正常(园区)网络上的受信任用户进行实时身份验证、确定其数据传输的性质以及是否应允许该数据传输,为他们提供对此类快速通道的动态访问。该项目利用新兴的软件定义网络(SDN)功能来挑选出个别数据流,以便在网络中进行专门处理。利用已部署在园区的SDN基础设施,该项目正在开发新的控制软件和协议,使受信任的用户能够向网络进行身份验证,并建立不受中间盒干扰的网络连接,同时仍对正常校园流量实施中间盒安全功能。受信任的用户能够创建这样的快速通道--而不是(仅)网络管理员--将使未来的网络能够处理快速增长的大数据用户数量。
英文摘要
Progress in medicine, science, and engineering -- as in essentially all areas of human endeavor -- increasingly depends on network access to very large data sets (billions to trillions of bytes) containing information such as scientific measurements, monitoring information, images, videos, simulation results, etc. The number of researchers working with, transferring, and sharing very large data sets is growing at an alarming rate. Although network transmission speeds are rapidly increasing, devices deployed in the middle of the network for security and management purposes -- e.g., firewalls, intrusion detectors, and the like -- create major bottlenecks that prevent researchers from being able to quickly move these large files between laboratories, high-performance computing sites, and storage facilities.Historically, network designers have addressed this problem by creating and maintaining a special "Science DMZ" network that provided a "fast lane", bypassing performance-limiting security devices thanks to the trusted nature of the users and applications connected to the Science DMZ. Today, however, the growing number and variety of users who need high-performance data transfer makes it increasingly difficult to maintain such a separate infrastructure. This project is developing ways to provide trusted users on the normal (campus) network with dynamic access to such fast lanes by authenticating them on-the-fly, determining the nature of their data transfer, and whether it should be allowed or not.This project leverages emerging Software-Defined Networking (SDN) capabilities to single out individual data flows for specialized treatment in the network. Using the SDN infrastructure already deployed on campus, the project is developing new control software and protocols that enable trusted users to authenticate themselves to the network and set up network connections free from middlebox interference while still enforcing middlebox security functionality for normal campus traffic. The ability of trusted users to create such fast lanes -- as opposed to (only) network administrators -- will enable future networks to handle the rapidly growing number of big data users.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3219104.3229277
发表时间:
2018-07
期刊:
Proceedings of the Practice and Experience on Advanced Research Computing
影响因子:
--
作者:
[M. Hayashida;Sergio Rivera;James N. Griffioen;Zongming Fei;Yongwook Song]
通讯作者:
M. Hayashida;Sergio Rivera;James N. Griffioen;Zongming Fei;Yongwook Song
Dynamically Creating Custom SDN High-Speed Network Paths for Big Data Science Flows
为大数据科学流程动态创建自定义 SDN 高速网络路径
DOI:
10.1145/3093338.3104155
发表时间:
2017
期刊:
Practice & Experience in Advanced Research Computing Conference (PEARC 2017
影响因子:
--
作者:
[Rivera, Sergio, Hayashida, Mami, Griffioen, James, Fei, Zongming]
通讯作者:
Fei, Zongming
Navigating the Unexpected Realities of Big Data Transfers in a Cloud-based World
在基于云的世界中应对大数据传输的意外现实
DOI:
10.1145/3219104.3229276
发表时间:
2018
期刊:
PEARC '18 Proceedings of the Practice and Experience on Advanced Research Computing
影响因子:
--
作者:
[Rivera, Sergio, Griffioen, James, Fei, Zongming, Hayashida, Mami, Shi, Pinyi, Chitre, Bhushan, Chappell, Jacob, Song, Yongwook, Pike, Lowell, Carpenter, Charles]
通讯作者:
Carpenter, Charles
Collaborative Research: IRNC Testbed: FAB: FABRIC Across Borders
-
批准号:2029235
-
项目类别:Continuing Grant
-
资助金额:$35.0万
-
财政年份:2020
-
负责人:James Griffioen
-
依托单位:
Collaborative Research: ENTeR: Enabling NeTwork Research and the Evolution of a Next Generation Midscale Research Infrastructure
-
批准号:1836742
-
项目类别:Standard Grant
-
资助金额:$87.76万
-
财政年份:2018
-
负责人:James Griffioen
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: NetSecOps -- Policy-Driven, Knowledge-Centric, Holistic Network Security Operations Architecture
-
批准号:1642134
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2016
-
负责人:James Griffioen
-
依托单位:
MRI: Acquisition of the Kentucky Research Informatics Cloud (KyRIC)
-
批准号:1626364
-
项目类别:Standard Grant
-
资助金额:$224.0万
-
财政年份:2016
-
负责人:James Griffioen
-
依托单位:
EAGER: Collaborative Research: Enabling Economic Policies in Software-Defined Internet Exchange Points
-
批准号:1551453
-
项目类别:Standard Grant
-
资助金额:$14.99万
-
财政年份:2015
-
负责人:James Griffioen
-
依托单位:
NeTS: Large: Collaborative Research: Network Innovation through Choice
-
批准号:1111040
-
项目类别:Standard Grant
-
资助金额:$69.75万
-
财政年份:2011
-
负责人:James Griffioen
-
依托单位:
Collaborative Research: Emulation Infrastructure and Material for OS/Network Classes
-
批准号:0511534
-
项目类别:Standard Grant
-
资助金额:$5.71万
-
财政年份:2005
-
负责人:James Griffioen
-
依托单位:
CISE Research Infrastructure: The Metaverse: A Laboratory for Digital Media Networks
-
批准号:0101242
-
项目类别:Standard Grant
-
资助金额:$82.46万
-
财政年份:2001
-
负责人:James Griffioen
-
依托单位:
RIA: A Memory-Based Architecture for High-Performance Distributed File Systems
-
批准号:9309176
-
项目类别:Standard Grant
-
资助金额:$10.5万
-
财政年份:1993
-
负责人:James Griffioen
-
依托单位:
海外基金