CICI: Secure Data Architecture: CapNet: Secure Scientific Workloads with Capability Enabled Networks
CICI: Secure Data Architecture: CapNet: Secure Scientific Workloads with Capability Enabled Networks
批准号:
1547457
负责人:
Jacobus VAN DER MERWE
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-10-01 至 2019-03-31
中文摘要
现代科学实验已经超出了一个实验室的能力。 它们需要数据中心的存储和处理能力,涉及对敏感数据的跨机构访问,并跨越多个管理信任域。在这种情况下,安全是脆弱的。面对不断增长的复杂网络攻击工具,现代服务器和台式机从根本上说是不安全的。每年在Linux内核中发现超过100个允许不受限制地访问整个系统的关键漏洞。由于缺乏表达细粒度访问控制策略的灵活性,现代网络通常为易受攻击的主机提供与网络其余部分的过度甚至不受限制的连接。 利用任何主机都可以使攻击者探索,利用和控制整个网络设施。没有网络的支持,科学设施将仍然脆弱。CapNet是一种网络架构,可在现代研究机构的跨机构环境中实现安全、最低权限的协作。基于能力访问控制的原则,本研究开发了确保现代科学基础设施网络安全所需的关键要素:1)“默认关闭”行为,根据需要授予连接性; 2)分散的,应用程序驱动的动态连接管理机制; 3)正式基础,实现细粒度,动态,多机构负责人的安全协作。CapNet设计的基础是通过软件定义网络(SDN)机制对网络活动进行强隔离,并通过能力访问控制模型对网络主机之间的所有通信进行调解。CapNet将网络表示为访问控制图。节点是网络主机,边(或“能力”)是指向其他主机的指针,允许通信和进一步的权利交换。 通过控制能力及其流的初始分布,CapNet通过细粒度的应用驱动策略来管理网络交互,从而实现多个机构和第三方服务之间的安全协作。最后,在采用整体方法进行网络访问控制的同时,CapNet仍然实用:它保留了与未修改的网络堆栈的兼容性,与现有的数据中心和云管理堆栈集成,支持增量采用,并且快速且可扩展。
英文摘要
Modern scientific experiments have outgrown the capacity of a single lab. They require the storage and processing power of a datacenter, involve cross-institutional access to sensitive data, and span multiple domains of administrative trust. In such a setting, security is fragile. In the face of steady growth of sophisticated cyber-attack tools, modern server and desktop machines are fundamentally insecure. Over a hundred critical vulnerabilities that allow unrestricted access to the entire system are discovered in the Linux kernel each year. Lacking flexibility to express fine-grained access control policies, modern networks often give vulnerable hosts excessive or even unrestricted connectivity to the rest of the network. An exploit of any host enables attackers to explore, exploit and take control over an entire cyber facility. Without support from the network, scientific facilities will remain vulnerable. CapNet is a network architecture that enables secure, least privilege collaboration in the cross-institutional environment of a modern research facility. Building on the principles of capability access control, this research develops key elements needed to secure a network of a modern scientific infrastructure: 1) "off by default" behavior, with connectivity granted on as-needed basis; 2) mechanisms for decentralized, application-driven dynamic management of connectivity; and 3) a formal foundation enabling secure collaboration of fine-grained, dynamic, multi-institutional principals. The basis for CapNet's design is strong isolation of network activities with the mechanisms of software defined networks (SDN) and mediation of all communication between network hosts by a capability access control model. CapNet represents the network as an access control graph. Nodes are network hosts, edges (or "capabilities") are pointers to other hosts allowing communication and further exchange of rights. By controlling the initial distribution of capabilities and their flow, CapNet governs network interactions through fine-grained, application-driven policies that enable safe collaboration among multiple institutions and third-party services. Finally, while taking a holistic approach to network access control, CapNet remains practical: it retains compatibility with unmodified network network stacks, integrates with existing datacenter and cloud management stacks, enables incremental adoption, and is fast and scalable.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SII-NRDZ: POWDER-RDZ - Spectrum sharing in the POWDER platform
-
批准号:2232463
-
项目类别:Continuing Grant
-
资助金额:$112.4万
-
财政年份:2022
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
NSF Convergence Accelerator Track G: SONIC: Securely Operate through 5G Networks with Informed Control
-
批准号:2226437
-
项目类别:Standard Grant
-
资助金额:$75.0万
-
财政年份:2022
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: NetSecOps - Policy-Driven, Knowledge-Centric, Holistic Network Security Operations Architecture
-
批准号:1642158
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2016
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
US Ignite: Focus Area 1: SafeEdge - Dynamic Public Safety Response through a Municipal Software Defined Infrastructure
-
批准号:1647264
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2016
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
PhantomNet Users' Workshop
-
批准号:1455803
-
项目类别:Standard Grant
-
资助金额:$4.96万
-
财政年份:2014
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
Student Travel Support for the Tenth Symposium on Networked Systems Design and Implementation (NSDI)
-
批准号:1333988
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2013
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
EAGER: SeaCat: An SDN End-to-End Application Containment ArchitecTure to Enable Secure Role Based Network Access in Healthcare
-
批准号:1343713
-
项目类别:Standard Grant
-
资助金额:$29.87万
-
财政年份:2013
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
TWC: Medium: TCloud: A Self-Defending, Self-Evolving and Self-Accounting Trustworthy Cloud Platform
-
批准号:1314945
-
项目类别:Standard Grant
-
资助金额:$100.0万
-
财政年份:2013
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
NeTS: Medium: KnowOps-Making Network Management and Operations Software Defined
-
批准号:1302688
-
项目类别:Continuing Grant
-
资助金额:$114.07万
-
财政年份:2013
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
CI-ADDO-NEW: PhantomNet: An End-to-End Mobile Network Testbed
-
批准号:1305384
-
项目类别:Standard Grant
-
资助金额:$199.85万
-
财政年份:2013
-
负责人:Jacobus VAN DER MERWE
-
依托单位:
海外基金