课题基金 / 基金详情

CICI: Secure Data Architecture: CapNet: Secure Scientific Workloads with Capability Enabled Networks

CICI: Secure Data Architecture: CapNet: Secure Scientific Workloads with Capability Enabled Networks
CICI:安全数据架构:CapNet:通过能力支持的网络保护科学工作负载
批准号:
1547457
负责人:
Jacobus VAN DER MERWE
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-10-01 至 2019-03-31

项目摘要

项目成果

Jacobus VAN DER MERWE的其他基金

相似基金

相关文献

中文摘要
翻译
现代科学实验的发展已经超出了单个实验室的能力。它们需要数据中心的存储和处理能力,涉及对敏感数据的跨机构访问,并且跨越多个管理信任域。在这样的环境下,安全是脆弱的。面对复杂的网络攻击工具的稳步增长,现代服务器和台式机从根本上来说是不安全的。每年都会在Linux内核中发现一百多个允许不受限制地访问整个系统的关键漏洞。由于缺乏表达细粒度访问控制策略的灵活性,现代网络经常向易受攻击的主机提供与网络其他部分的过度甚至无限制的连接。对任何主机的攻击都使攻击者能够探索、利用和控制整个网络设施。没有网络的支持,科学设施将仍然脆弱。CapNet是一种网络架构,可以在现代研究设施的跨机构环境中实现安全、最少特权的协作。基于能力访问控制原则,本研究开发了确保现代科学基础设施网络安全所需的关键要素:1)“默认关闭”行为,根据需要授予连接;2)分散的、应用驱动的连接动态管理机制;3)一个正式的基础,支持细粒度的、动态的、多机构主体的安全协作。CapNet设计的基础是使用软件定义网络(SDN)机制对网络活动进行强隔离,并通过功能访问控制模型对网络主机之间的所有通信进行中介。CapNet将网络表示为访问控制图。节点是网络主机,边缘(或“能力”)是指向其他主机的指针,允许通信和进一步交换权利。通过控制功能及其流的初始分布,CapNet通过细粒度的、应用程序驱动的策略来管理网络交互,这些策略支持多个机构和第三方服务之间的安全协作。最后,在采用整体方法进行网络访问控制的同时,CapNet仍然是实用的:它保留了与未修改的网络网络堆栈的兼容性,与现有的数据中心和云管理堆栈集成,支持增量采用,并且快速且可扩展。
英文摘要
Modern scientific experiments have outgrown the capacity of a single lab. They require the storage and processing power of a datacenter, involve cross-institutional access to sensitive data, and span multiple domains of administrative trust. In such a setting, security is fragile. In the face of steady growth of sophisticated cyber-attack tools, modern server and desktop machines are fundamentally insecure. Over a hundred critical vulnerabilities that allow unrestricted access to the entire system are discovered in the Linux kernel each year. Lacking flexibility to express fine-grained access control policies, modern networks often give vulnerable hosts excessive or even unrestricted connectivity to the rest of the network. An exploit of any host enables attackers to explore, exploit and take control over an entire cyber facility. Without support from the network, scientific facilities will remain vulnerable. CapNet is a network architecture that enables secure, least privilege collaboration in the cross-institutional environment of a modern research facility. Building on the principles of capability access control, this research develops key elements needed to secure a network of a modern scientific infrastructure: 1) "off by default" behavior, with connectivity granted on as-needed basis; 2) mechanisms for decentralized, application-driven dynamic management of connectivity; and 3) a formal foundation enabling secure collaboration of fine-grained, dynamic, multi-institutional principals. The basis for CapNet's design is strong isolation of network activities with the mechanisms of software defined networks (SDN) and mediation of all communication between network hosts by a capability access control model. CapNet represents the network as an access control graph. Nodes are network hosts, edges (or "capabilities") are pointers to other hosts allowing communication and further exchange of rights. By controlling the initial distribution of capabilities and their flow, CapNet governs network interactions through fine-grained, application-driven policies that enable safe collaboration among multiple institutions and third-party services. Finally, while taking a holistic approach to network access control, CapNet remains practical: it retains compatibility with unmodified network network stacks, integrates with existing datacenter and cloud management stacks, enables incremental adoption, and is fast and scalable.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SII-NRDZ: POWDER-RDZ - Spectrum sharing in the POWDER platform
  • 批准号:
    2232463
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $112.4万
  • 财政年份:
    2022
  • 负责人:
    Jacobus VAN DER MERWE
  • 依托单位:
NSF Convergence Accelerator Track G: SONIC: Securely Operate through 5G Networks with Informed Control
  • 批准号:
    2226437
  • 项目类别:
    Standard Grant
  • 资助金额:
    $75.0万
  • 财政年份:
    2022
  • 负责人:
    Jacobus VAN DER MERWE
  • 依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: NetSecOps - Policy-Driven, Knowledge-Centric, Holistic Network Security Operations Architecture
  • 批准号:
    1642158
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.99万
  • 财政年份:
    2016
  • 负责人:
    Jacobus VAN DER MERWE
  • 依托单位:
US Ignite: Focus Area 1: SafeEdge - Dynamic Public Safety Response through a Municipal Software Defined Infrastructure
  • 批准号:
    1647264
  • 项目类别:
    Standard Grant
  • 资助金额:
    $60.0万
  • 财政年份:
    2016
  • 负责人:
    Jacobus VAN DER MERWE
  • 依托单位:
海外基金