CICI: Secure Data Architecture: CapNet: Secure Scientific Workloads with Capability Enabled Networks
CICI:安全数据架构:CapNet:通过能力支持的网络保护科学工作负载
基本信息
- 批准号:1547457
- 负责人:
- 金额:$ 50万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2015
- 资助国家:美国
- 起止时间:2015-10-01 至 2019-03-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Modern scientific experiments have outgrown the capacity of a single lab. They require the storage and processing power of a datacenter, involve cross-institutional access to sensitive data, and span multiple domains of administrative trust. In such a setting, security is fragile. In the face of steady growth of sophisticated cyber-attack tools, modern server and desktop machines are fundamentally insecure. Over a hundred critical vulnerabilities that allow unrestricted access to the entire system are discovered in the Linux kernel each year. Lacking flexibility to express fine-grained access control policies, modern networks often give vulnerable hosts excessive or even unrestricted connectivity to the rest of the network. An exploit of any host enables attackers to explore, exploit and take control over an entire cyber facility. Without support from the network, scientific facilities will remain vulnerable. CapNet is a network architecture that enables secure, least privilege collaboration in the cross-institutional environment of a modern research facility. Building on the principles of capability access control, this research develops key elements needed to secure a network of a modern scientific infrastructure: 1) "off by default" behavior, with connectivity granted on as-needed basis; 2) mechanisms for decentralized, application-driven dynamic management of connectivity; and 3) a formal foundation enabling secure collaboration of fine-grained, dynamic, multi-institutional principals. The basis for CapNet's design is strong isolation of network activities with the mechanisms of software defined networks (SDN) and mediation of all communication between network hosts by a capability access control model. CapNet represents the network as an access control graph. Nodes are network hosts, edges (or "capabilities") are pointers to other hosts allowing communication and further exchange of rights. By controlling the initial distribution of capabilities and their flow, CapNet governs network interactions through fine-grained, application-driven policies that enable safe collaboration among multiple institutions and third-party services. Finally, while taking a holistic approach to network access control, CapNet remains practical: it retains compatibility with unmodified network network stacks, integrates with existing datacenter and cloud management stacks, enables incremental adoption, and is fast and scalable.
现代科学实验已经超过了一个实验室的能力。它们需要数据中心的存储和处理能力,涉及对敏感数据的跨机构访问,并跨越多个管理信任域。在这样的环境下,安全是脆弱的。面对复杂的网络攻击工具的稳步增长,现代服务器和台式机从根本上是不安全的。每年在Linux内核中都会发现一百多个允许不受限制地访问整个系统的关键漏洞。由于缺乏表达细粒度访问控制策略的灵活性,现代网络经常为易受攻击的主机提供过多甚至不受限制的到网络其余部分的连接。利用任何主机的漏洞,攻击者都可以探索、利用并控制整个网络设施。如果没有网络的支持,科学设施仍将脆弱不堪。CapNet是一种网络架构,可在现代研究机构的跨机构环境中实现安全、最低权限的协作。在能力访问控制原则的基础上,这项研究开发了确保现代科学基础设施网络安全所需的关键要素:1)“默认关闭”行为,根据需要授予连接;2)分散的、应用程序驱动的动态连接管理机制;以及3)支持细粒度、动态、多机构主体安全协作的正式基础。CapNet设计的基础是使用软件定义网络(SDN)机制对网络活动进行强隔离,并通过能力访问控制模型协调网络主机之间的所有通信。CapNet将网络表示为访问控制图。节点是网络主机,边(或“能力”)是指向允许通信和进一步交换权利的其他主机的指针。通过控制功能及其流量的初始分布,CapNet通过细粒度、应用驱动的策略管理网络交互,这些策略支持多个机构和第三方服务之间的安全协作。最后,虽然CapNet采用了全面的网络访问控制方法,但它仍然实用:它保留了与未经修改的网络网络堆栈的兼容性,与现有的数据中心和云管理堆栈集成,支持增量采用,并且快速且可扩展。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Jacobus VAN DER MERWE其他文献
Jacobus VAN DER MERWE的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Jacobus VAN DER MERWE', 18)}}的其他基金
Collaborative Research: SII-NRDZ: POWDER-RDZ - Spectrum sharing in the POWDER platform
合作研究:SII-NRDZ:POWDER-RDZ - POWDER 平台中的频谱共享
- 批准号:
2232463 - 财政年份:2022
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
NSF Convergence Accelerator Track G: SONIC: Securely Operate through 5G Networks with Informed Control
NSF 融合加速器轨道 G:SONIC:通过 5G 网络通过知情控制安全运行
- 批准号:
2226437 - 财政年份:2022
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: NetSecOps - Policy-Driven, Knowledge-Centric, Holistic Network Security Operations Architecture
协作研究:CICI:安全和弹性架构:NetSecOps - 策略驱动、以知识为中心的整体网络安全运营架构
- 批准号:
1642158 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
US Ignite: Focus Area 1: SafeEdge - Dynamic Public Safety Response through a Municipal Software Defined Infrastructure
US Ignite:重点领域 1:SafeEdge - 通过市政软件定义基础设施实现动态公共安全响应
- 批准号:
1647264 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Student Travel Support for the Tenth Symposium on Networked Systems Design and Implementation (NSDI)
第十届网络系统设计与实现(NSDI)研讨会的学生旅行支持
- 批准号:
1333988 - 财政年份:2013
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
EAGER: SeaCat: An SDN End-to-End Application Containment ArchitecTure to Enable Secure Role Based Network Access in Healthcare
EAGER:SeaCat:SDN 端到端应用遏制架构,可在医疗保健领域实现基于角色的安全网络访问
- 批准号:
1343713 - 财政年份:2013
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TWC: Medium: TCloud: A Self-Defending, Self-Evolving and Self-Accounting Trustworthy Cloud Platform
TWC:媒介:TCloud:一个自我防御、自我进化、自我记账的可信云平台
- 批准号:
1314945 - 财政年份:2013
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
NeTS: Medium: KnowOps-Making Network Management and Operations Software Defined
NeTS:媒介:KnowOps - 定义网络管理和运营软件
- 批准号:
1302688 - 财政年份:2013
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
CI-ADDO-NEW: PhantomNet: An End-to-End Mobile Network Testbed
CI-ADDO-NEW:PhantomNet:端到端移动网络测试平台
- 批准号:
1305384 - 财政年份:2013
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
相似海外基金
CICI: UCSS: Maximizing Data Utility and Participant Privacy through Usable, Secure Data Workflows for Human-Centered AI Research
CICI:UCSS:通过可用、安全的数据工作流程实现以人为本的人工智能研究,最大限度地提高数据效用和参与者隐私
- 批准号:
2232690 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: UCSS: Enhancing Integrity and Confidentiality for Secure Distributed Data Sharing
CICI:UCSS:增强安全分布式数据共享的完整性和保密性
- 批准号:
2114202 - 财政年份:2021
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: RDP: Open Badge Researcher Credentials for Secure Access to Restricted and Sensitive Data
CICI:RDP:用于安全访问受限和敏感数据的开放徽章研究人员证书
- 批准号:
1839868 - 财政年份:2018
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: SSC: Development of a Secure and Privacy-Preserving Workflow Architecture for Dynamic Data Sharing in Scientific Infrastructures
CICI:SSC:开发安全且保护隐私的工作流程架构,用于科学基础设施中的动态数据共享
- 批准号:
1839746 - 财政年份:2018
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: Secure and Resilient Architecture: Campus Infrastructure for Microscale, Privacy-Conscious, Data-Driven Planning
CICI:安全和弹性架构:用于微型、隐私意识、数据驱动规划的园区基础设施
- 批准号:
1642120 - 财政年份:2017
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: CE: SciTokens: Capability-Based Secure Access to Remote Scientific Data
CICI:CE:SciTokens:基于能力的远程科学数据安全访问
- 批准号:
1738962 - 财政年份:2017
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: Ensuring Data Integrity at the Beginning of the Scientific Workflow; A Mini-ScienceDMZ for Instruments
CICI:安全数据架构:在科学工作流程开始时确保数据完整性;
- 批准号:
1547099 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: Collaborative Research: Assured Mission Delivery Network Framework for Secure Scientific Collaboration
CICI:安全数据架构:协作研究:确保安全科学协作的任务交付网络框架
- 批准号:
1547390 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: Collaborative Research: Assured Mission Delivery Network Framework for Secure Scientific Collaboration
CICI:安全数据架构:协作研究:确保安全科学协作的任务交付网络框架
- 批准号:
1547411 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: CILogon 2.0 - An Integrated Identity and Access Management Platform for Science
CICI:安全数据架构:CILogon 2.0 - 科学的集成身份和访问管理平台
- 批准号:
1547268 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant