课题基金 / 基金详情

Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ

Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ
合作研究:CICI:安全和弹性架构:S3D:用于科学 DMZ 的新的基于 SDN 的安全框架
批准号:
1642101
负责人:
Douglas Swany
金额:
$30.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-11-01 至 2019-10-31

项目摘要

项目成果

Douglas Swany的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The Science DMZ (SDMZ) is a key foundational element in building state-of-the-art scientific research infrastructure. The SDMZ is a portion of the network, built at the campus or laboratory's edge, that is designed such that the equipment, configuration, and security policies are optimized for high-performance scientific applications rather than for general-purpose business systems or enterprise computing. SDMZs are increasingly being implemented by research agencies, campuses and national labs. In order to improve the throughput of scientific research data, NSF has funded many Science DMZ implementations on campuses by upgrading research network connectivity and encouraging installation of a SDMZ. However, the SDMZ has characteristics that separate it as a unique ecosystem which cannot simply adopt existing enterprise and cloud based network security technologies and policies. This project designs and prototypes an integrated Software Defined Network (SDN) security framework for managing data-intensive science applications utilizing the Science DMZ (SDMZ) model. It offers one of the first demonstrations of how fine-grained security controls can co-exist within a high performance data-intensive network. This project produces significant advancements in the trustworthiness and reliability of large-scale data-intensive scientific research infrastructures.This project evaluates the current state of the SDMZ security architecture, then identifies the current shortcomings in its existing security services. The new proposed framework: 1) defines fine-grained network flow controls using dynamically deployable security services that are migratable and science-application aware; 2) defines a new class of network privilege management policies that can revoke or divert flows that violate SDMZ policies or that differ from user-defined, application-specific usage expectations; 3) establishes high-performance virtual circuits that enable data intensive applications to register and fast-path their authenticated flows across the SDMZ. Furthermore, this project introduces a unified security policy engine to dramatically simplify the control of the above three services. The policy engine offers a valuable and user-friendly abstraction to meet the domain-specific needs of the SDMZ.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CC* Integration-Large: In-Network Distributed Infrastructure for Advanced Network Applications
  • 批准号:
    2126266
  • 项目类别:
    Standard Grant
  • 资助金额:
    $93.85万
  • 财政年份:
    2021
  • 负责人:
    Douglas Swany
  • 依托单位:
EAGER: Reconfigurable Network Hardware for Message-Driven Systems
  • 批准号:
    1446950
  • 项目类别:
    Standard Grant
  • 资助金额:
    $7.56万
  • 财政年份:
    2014
  • 负责人:
    Douglas Swany
  • 依托单位:
CC*IIE Integration: Development and Integration of perfSONAR for End-to End Network Cyberinfrastructure
  • 批准号:
    1440667
  • 项目类别:
    Standard Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2014
  • 负责人:
    Douglas Swany
  • 依托单位:
Collaborative Research: Workshop on perfSONAR based Multi-domain Network Performance Measurement and Monitoring
  • 批准号:
    1346852
  • 项目类别:
    Standard Grant
  • 资助金额:
    $7.68万
  • 财政年份:
    2013
  • 负责人:
    Douglas Swany
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)