Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ
合作研究:CICI:安全和弹性架构:S3D:用于科学 DMZ 的新的基于 SDN 的安全框架
基本信息
- 批准号:1642150
- 负责人:
- 金额:$ 34.98万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2016
- 资助国家:美国
- 起止时间:2016-11-01 至 2020-10-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The Science DMZ (SDMZ) is a key foundational element in building state-of-the-art scientific research infrastructure. The SDMZ is a portion of the network, built at the campus or laboratory's edge, that is designed such that the equipment, configuration, and security policies are optimized for high-performance scientific applications rather than for general-purpose business systems or enterprise computing. SDMZs are increasingly being implemented by research agencies, campuses and national labs. In order to improve the throughput of scientific research data, NSF has funded many Science DMZ implementations on campuses by upgrading research network connectivity and encouraging installation of a SDMZ. However, the SDMZ has characteristics that separate it as a unique ecosystem which cannot simply adopt existing enterprise and cloud based network security technologies and policies. This project designs and prototypes an integrated Software Defined Network (SDN) security framework for managing data-intensive science applications utilizing the Science DMZ (SDMZ) model. It offers one of the first demonstrations of how fine-grained security controls can co-exist within a high performance data-intensive network. This project produces significant advancements in the trustworthiness and reliability of large-scale data-intensive scientific research infrastructures.This project evaluates the current state of the SDMZ security architecture, then identifies the current shortcomings in its existing security services. The new proposed framework: 1) defines fine-grained network flow controls using dynamically deployable security services that are migratable and science-application aware; 2) defines a new class of network privilege management policies that can revoke or divert flows that violate SDMZ policies or that differ from user-defined, application-specific usage expectations; 3) establishes high-performance virtual circuits that enable data intensive applications to register and fast-path their authenticated flows across the SDMZ. Furthermore, this project introduces a unified security policy engine to dramatically simplify the control of the above three services. The policy engine offers a valuable and user-friendly abstraction to meet the domain-specific needs of the SDMZ.
科学非军事区(SDMZ)是建设最先进的科学研究基础设施的关键基础要素。SDMZ是网络的一部分,建立在校园或实验室的边缘,其设计使得设备、配置和安全策略针对高性能科学应用而不是通用业务系统或企业计算进行优化。SDMZ越来越多地由研究机构、校园和国家实验室实施。为了提高科学研究数据的吞吐量,NSF通过升级研究网络连接和鼓励安装SDMZ,资助了许多校园科学DMZ的实施。然而,SDMZ具有独特的生态系统特征,不能简单地采用现有的基于企业和云的网络安全技术和策略。该项目设计和原型集成的软件定义网络(SDN)的安全框架,用于管理数据密集型科学应用程序利用科学DMZ(SDMZ)模型。它首次演示了细粒度安全控制如何在高性能数据密集型网络中共存。该项目在大规模数据密集型科研基础设施的可信性和可靠性方面取得了重大进展。该项目评估了SDMZ安全架构的现状,然后确定了其现有安全服务的当前缺陷。新的拟议框架:1)使用可迁移和科学应用感知的可动态部署的安全服务来定义细粒度的网络流控制; 2)定义一类新的网络权限管理策略,其可以撤销或转移违反SDMZ策略或不同于用户定义的特定于应用的使用期望的流; 3)建立高性能虚拟电路,使数据密集型应用程序能够在SDMZ上注册和快速通过其认证流。此外,该项目还引入了一个统一的安全策略引擎,大大简化了对上述三个服务的控制。策略引擎提供了一个有价值的、用户友好的抽象,以满足SDMZ的特定于域的需求。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Phillip Porras其他文献
LANTERN: Layered Adaptive Network Telemetry Collection for Programmable Dataplanes
LANTERN:可编程数据平面的分层自适应网络遥测收集
- DOI:
10.1145/3630047.3630194 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Kaiyu Hou;Dhiraj Saharia;V. Yegneswaran;Phillip Porras - 通讯作者:
Phillip Porras
Coordinated dataflow protection for ultra-high bandwidth science networks
超高带宽科学网络的协调数据流保护
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Vasudevan Nagendra;V. Yegneswaran;Phillip Porras;Samir Ranjan Das - 通讯作者:
Samir Ranjan Das
Phillip Porras的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Phillip Porras', 18)}}的其他基金
NSF Convergence Accelerator Track: G: The Security-Enhanced Radio Access Network (SE-RAN)
NSF 融合加速器轨道:G:安全增强型无线接入网络 (SE-RAN)
- 批准号:
2326882 - 财政年份:2023
- 资助金额:
$ 34.98万 - 项目类别:
Cooperative Agreement
NSF Convergence Accelerator Track: G: Security Services for the 5G Software-Defined Edge
NSF 融合加速器轨道:G:5G 软件定义边缘的安全服务
- 批准号:
2226443 - 财政年份:2022
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
EAGER: Visualizing Cyber Defense Networks
EAGER:可视化网络防御网络
- 批准号:
1824258 - 财政年份:2018
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
Exploring the Transition of Research-Derived Cyber-Threat Data
探索研究衍生的网络威胁数据的转变
- 批准号:
1640386 - 财政年份:2016
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
EAGER: ACI: A Software-Defined Network (SDN) WAN Security Testbed
EAGER:ACI:软件定义网络 (SDN) WAN 安全测试平台
- 批准号:
1547206 - 财政年份:2015
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
EAGER: ACI: Secure and Effective Policy Enforcement in Software-Defined WANs
EAGER:ACI:软件定义的 WAN 中安全有效的策略执行
- 批准号:
1446426 - 财政年份:2014
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Multi-Perspective Bayesian Learning for Automated Diagnosis of Advanced Malware
TC:媒介:协作研究:用于高级恶意软件自动诊断的多视角贝叶斯学习
- 批准号:
0905518 - 财政年份:2009
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
Collaborative Research: CT-L: CLEANSE: Cross-Layer Large-Scale Efficient Analysis of Network Activities to Secure the Internet
合作研究:CT-L:CLEANSE:跨层大规模有效分析网络活动以保护互联网安全
- 批准号:
0831170 - 财政年份:2008
- 资助金额:
$ 34.98万 - 项目类别:
Continuing Grant
Collaborative Research: CT-T: Logic and Data Flow Extraction for Live and Informed Malware Execution
协作研究:CT-T:实时且知情的恶意软件执行的逻辑和数据流提取
- 批准号:
0716612 - 财政年份:2007
- 资助金额:
$ 34.98万 - 项目类别:
Continuing Grant
相似国自然基金
Research on Quantum Field Theory without a Lagrangian Description
- 批准号:24ZR1403900
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Cell Research
- 批准号:31224802
- 批准年份:2012
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research
- 批准号:31024804
- 批准年份:2010
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research (细胞研究)
- 批准号:30824808
- 批准年份:2008
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
- 批准号:10774081
- 批准年份:2007
- 资助金额:45.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
- 批准号:
2128607 - 财政年份:2021
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
- 批准号:
1642031 - 财政年份:2017
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Regional: SouthEast SciEntific Cybersecurity for University Research (SouthEast SECURE)
合作研究:CICI:区域:东南大学研究科学网络安全 (SouthEast SECURE)
- 批准号:
1812404 - 财政年份:2017
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
- 批准号:
1642143 - 财政年份:2017
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
CICI: Data Provenance: Collaborative Research: Provenance Assurance Using Currency Primitives
CICI:数据来源:协作研究:使用货币基元的来源保证
- 批准号:
1821926 - 财政年份:2017
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Regional: SouthEast SciEntific Cybersecurity for University REsearch (SouthEast SECURE)
合作研究:CICI:区域:东南大学研究科学网络安全 (SouthEast SECURE)
- 批准号:
1642038 - 财政年份:2016
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: Scientific Workflow Integrity with Pegasus
合作研究:CICI:安全和弹性架构:与 Pegasus 的科学工作流程完整性
- 批准号:
1642070 - 财政年份:2016
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: Creating Dynamic Superfacilities the SAFE Way
合作研究:CICI:安全和弹性架构:以安全方式创建动态超级设施
- 批准号:
1642142 - 财政年份:2016
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: NetSecOps -- Policy-Driven, Knowledge-Centric, Holistic Network Security Operations Architecture
合作研究:CICI:安全和弹性架构:NetSecOps——策略驱动、以知识为中心、整体网络安全运营架构
- 批准号:
1642134 - 财政年份:2016
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant
CICI: Data Provenance: Collaborative Research: Provenance Assurance Using Currency Primitives
CICI:数据来源:协作研究:使用货币基元的来源保证
- 批准号:
1547164 - 财政年份:2016
- 资助金额:
$ 34.98万 - 项目类别:
Standard Grant