CICI: Secure and Resilient Architecture: Effective and Economical Protection for High-Performance Research and Education Networks

CICI:安全和弹性架构:为高性能研究和教育网络提供有效且经济的保护

基本信息

  • 批准号:
    1642161
  • 负责人:
  • 金额:
    $ 99.95万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2016
  • 资助国家:
    美国
  • 起止时间:
    2016-10-01 至 2022-09-30
  • 项目状态:
    已结题

项目摘要

Scientific research requires the free exchange of information and ideas among collaborators worldwide. For this, scientists depend critically on full and open access to the Internet. Yet in today's world, such open access also exposes sites to incessant network attacks like theft of information, parasitic resource consumption, or suffering from (or inadvertently participating in) denial-of-service (DOS) attacks. Some of the most powerful networks today remain particularly hard to defend: the 100G environments and backbones that facilitate modern data-intensive sciences - physics, astronomy, medicine, climate research - prove extremely sensitive to the slightest disturbances. For these networks, traditional enterprise solutions such as firewalls and intrusion detection systems (IDS), remain infeasible as they cannot operate reliably at such high speeds. This project develops a novel, comprehensive framework that integrates software and hardware for the economical protection of critical high-performance science infrastructure.The project increases the performance of network monitoring by offloading low-level operations from software into hardware, such as switches and computer network interface cards. The project enables network monitoring systems to tie into the hardware offloading being developed. Furthermore, the project expands the capabilities of network monitoring systems to create visibility into science networks, for example, by adding support for the protocols used for high-speed scientific data transfers. It also extends support for responding actively to malicious activity like denial-of-service attacks. This project implements these capabilities in the open-source Bro network security monitor utilized by many NSF-supported organizations nationwide to protect their scientific cyberinfrastructure.
科学研究需要全世界合作者之间的信息和思想的自由交流。为此,科学家们关键地依赖于对互联网的全面和开放的访问。然而,在当今世界,这种开放访问也使站点暴露在不断的网络攻击之下,例如信息盗窃、寄生资源消耗或遭受(或无意中参与)拒绝服务(DOS)攻击。如今,一些最强大的网络仍然特别难以防御:100G环境和骨干网络促进了现代数据密集型科学——物理学、天文学、医学、气候研究——被证明对最轻微的干扰极其敏感。对于这些网络,传统的企业解决方案(如防火墙和入侵检测系统(IDS))仍然不可行,因为它们无法在如此高的速度下可靠地运行。该项目开发了一种新颖、全面的框架,将软件和硬件集成在一起,为关键的高性能科学基础设施提供经济保护。该项目通过将低级操作从软件卸载到硬件(如交换机和计算机网络接口卡)来提高网络监控的性能。该项目使网络监控系统能够与正在开发的硬件卸载相结合。此外,该项目扩展了网络监测系统的能力,例如通过增加对用于高速科学数据传输的协议的支持,从而创建科学网络的可见性。它还扩展了对主动响应恶意活动(如拒绝服务攻击)的支持。该项目在开放源代码的Bro网络安全监视器中实现了这些功能,该监视器被全国许多nsf支持的组织用于保护其科学网络基础设施。

项目成果

期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Viable Protection of High-Performance Networks through Hardware/Software Co-Design
通过硬件/软件协同设计对高性能网络提供可行的保护
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Johanna Amann其他文献

Johanna Amann的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Johanna Amann', 18)}}的其他基金

TWC: TTP Option: Small: Understanding the State of TLS Using Large-scale Passive Measurements
TWC:TTP 选项:小:使用大规模被动测量了解 TLS 的状态
  • 批准号:
    1528156
  • 财政年份:
    2015
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
A Bro Center of Expertise for the NSF Community
NSF 社区的兄弟专业知识中心
  • 批准号:
    1348077
  • 财政年份:
    2013
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant

相似海外基金

Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    2128607
  • 财政年份:
    2021
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    1642031
  • 财政年份:
    2017
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    1642143
  • 财政年份:
    2017
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
CICI: Secure and Resilient Architecture: Campus Infrastructure for Microscale, Privacy-Conscious, Data-Driven Planning
CICI:安全和弹性架构:用于微型、隐私意识、数据驱动规划的园区基础设施
  • 批准号:
    1642120
  • 财政年份:
    2017
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: Scientific Workflow Integrity with Pegasus
合作研究:CICI:安全和弹性架构:与 Pegasus 的科学工作流程完整性
  • 批准号:
    1642070
  • 财政年份:
    2016
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: Creating Dynamic Superfacilities the SAFE Way
合作研究:CICI:安全和弹性架构:以安全方式创建动态超级设施
  • 批准号:
    1642142
  • 财政年份:
    2016
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: NetSecOps -- Policy-Driven, Knowledge-Centric, Holistic Network Security Operations Architecture
合作研究:CICI:安全和弹性架构:NetSecOps——策略驱动、以知识为中心、整体网络安全运营架构
  • 批准号:
    1642134
  • 财政年份:
    2016
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: Scientific Workflow Integrity with Pegasus.
合作研究:CICI:安全和弹性架构:与 Pegasus 的科学工作流程完整性。
  • 批准号:
    1642090
  • 财政年份:
    2016
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: Scientific Workflow Integrity with Pegasus
合作研究:CICI:安全和弹性架构:与 Pegasus 的科学工作流程完整性
  • 批准号:
    1642053
  • 财政年份:
    2016
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ
合作研究:CICI:安全和弹性架构:S3D:用于科学 DMZ 的新的基于 SDN 的安全框架
  • 批准号:
    1642129
  • 财政年份:
    2016
  • 资助金额:
    $ 99.95万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了