Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
批准号:
1642143
负责人:
Hongxin Hu
金额:
$49.98万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-01-01 至 2021-04-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
As data-intensive science becomes the norm in many fields of science, high-performance data transfer is rapidly becoming a standard cyberinfrastructure requirement. To meet this requirement, an increasingly large number of university campuses have deployed Science DMZs. A Science DMZ is a portion of the network, built at or near the edge of the campus or laboratory's network, that is designed such that the equipment, configuration, and security policies are optimized for high-performance scientific applications rather than for general-purpose computing. This project develops a secure and resilient architecture called SciGuard that addresses the security challenges and the inherent weaknesses in Science DMZs. SciGuard is based on two emerging networking paradigms, Software-Defined Networking (SDN) and Network Function Virtualization (NFV), both of which enable the granularity, flexibility and elasticity needed to secure Science DMZs. Two core security functions, an SDN firewall application and a virtual Intrusion Detection System (IDS), coexist in SciGuard for protecting Science DMZs. The SDN firewall application is a software-based, in-line security function running atop the SDN controller. It can scale well without bypassing the firewall using per-flow/per-connection network traffic processing. It is also separated from the institutional hardware-based firewalls to enforce tailored security policies for the science-only traffic sent to Science DMZs. The virtual IDS is an NFV-based, passive security function, which can be quickly instantiated and elastically scaled to deal with attack traffic variations in Science DMZs, while significantly reducing both equipment and operational costs. In addition to these functions, the researchers also design a cloud-based federation mechanism for SciGuard to support security policy automatic testing and security intelligence sharing. The new mechanisms developed in this project are robust, scalable, low cost, easily managed, and optimally provisioned, therefore substantially enhancing the security of Science DMZs. This research encourages the diversity of students involved in the project by active recruitment of women and other underrepresented groups for participation in the project. The project has substantial involvement of graduate students in research, and trains promising undergraduate students in the implementation and experiments of the proposed approach. Moreover, the project enhances academic curricula by integrating the research findings into new and existing courses.
期刊论文(24)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/icc40277.2020.9149136
发表时间:
2020-06
期刊:
ICC 2020 - 2020 IEEE International Conference on Communications (ICC)
影响因子:
--
作者:
[Shuhe Wang;Zili Meng;Chen Sun;Minhu Wang;Mingwei Xu;J. Bi;Tong Yang;Qun Huang;Hongxin Hu]
通讯作者:
Shuhe Wang;Zili Meng;Chen Sun;Minhu Wang;Mingwei Xu;J. Bi;Tong Yang;Qun Huang;Hongxin Hu
DOI:
10.1109/jsac.2018.2869953
发表时间:
2018-09
期刊:
IEEE Journal on Selected Areas in Communications
影响因子:
16.4
作者:
[Chen Sun;J. Bi;Zili Meng;Tong Yang;Xiao Zhang;Hongxin Hu]
通讯作者:
Chen Sun;J. Bi;Zili Meng;Tong Yang;Xiao Zhang;Hongxin Hu
FastFE: Accelerating ML-based Traffic Analysis with Programmable Switches
FastFE:利用可编程交换机加速基于 ML 的流量分析
DOI:
10.1145/3405669.3405818
发表时间:
2020
期刊:
SPIN '20: Proceedings of the Workshop on Secure Programmable Network Infrastructure
影响因子:
--
作者:
[Bai, Jiasong, Zhang, Menghao, Li, Guanyu, Liu, Chang, Xu, Mingwei, Hu, Hongxin]
通讯作者:
Hu, Hongxin
Teaching SDN Security Using Hands-on Labs in CloudLab
使用 CloudLab 中的动手实验室教授 SDN 安全性
DOI:
--
发表时间:
2020
期刊:
Journal of the Colloquium for Information System Security Education
影响因子:
--
作者:
[Yuan, Xiaohong, Liu, Zhipeng, Park, Younghee, Hu, Hongxin, Li, Hongda]
通讯作者:
Li, Hongda
DOI:
10.1145/3040992.3041005
发表时间:
2017-03
期刊:
Proceedings of the ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization
影响因子:
--
作者:
[Younghee Park;P. Chandaliya;Akshaya Muralidharan;Nikash Kumar;Hongxin Hu]
通讯作者:
Younghee Park;P. Chandaliya;Akshaya Muralidharan;Nikash Kumar;Hongxin Hu
共 23 条
Collaborative Research: SAI-R: Integrative Cyberinfrastructure for Enhancing and Accelerating Online Abuse Research
-
批准号:2228617
-
项目类别:Standard Grant
-
资助金额:$37.5万
-
财政年份:2022
-
负责人:Hongxin Hu
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:2128107
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
-
批准号:2129164
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
-
批准号:2128607
-
项目类别:Standard Grant
-
资助金额:$49.98万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
Collaborative Research: EAGER: SaTC-EDU: Learning Platform and Education Curriculum for Artificial Intelligence-Driven Socially-Relevant Cybersecurity
-
批准号:2114982
-
项目类别:Standard Grant
-
资助金额:$7.0万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
-
批准号:1846291
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2019
-
负责人:Hongxin Hu
-
依托单位:
NSF Student Travel Grant for 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization (SDN-NFV Security)
-
批准号:1807103
-
项目类别:Standard Grant
-
资助金额:$0.56万
-
财政年份:2018
-
负责人:Hongxin Hu
-
依托单位:
SaTC: EDU: Collaborative: Enhancing Security Education through Transiting Research on Security in Emerging Network Technologies
-
批准号:1723663
-
项目类别:Standard Grant
-
资助金额:$8.0万
-
财政年份:2017
-
负责人:Hongxin Hu
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:1700499
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2017
-
负责人:Hongxin Hu
-
依托单位:
EAGER: Defending Against Visual Cyberbullying Attacks in Emerging Mobile Social Networks
-
批准号:1537924
-
项目类别:Standard Grant
-
资助金额:$23.97万
-
财政年份:2015
-
负责人:Hongxin Hu
-
依托单位:
III: Small: Collaborative Research: Privacy-Aware Collaborative Data Sharing in Human-Centered Social Networks
-
批准号:1527421
-
项目类别:Standard Grant
-
资助金额:$29.98万
-
财政年份:2015
-
负责人:Hongxin Hu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: