Collaborative Research: CICI: Secure and Resilient Architecture: NetSecOps -- Policy-Driven, Knowledge-Centric, Holistic Network Security Operations Architecture

合作研究:CICI:安全和弹性架构:NetSecOps——策略驱动、以知识为中心、整体网络安全运营架构

基本信息

项目摘要

Network infrastructure at University campuses is complex and sophisticated, often supporting a mix of enterprise, academic, student, research, and healthcare data, each having its own distinct security, privacy, and priority policies. Securing this complex and highly dynamic environment is extremely challenging, particularly since campus infrastructures are increasingly under attack from malicious actors on the Internet and (often unknowingly) internal campus devices. Different parts of the campus have very different policies and regulations that govern its treatment of sensitive data (e.g., private student/employee information, health care data, financial transactions, etc.). Furthermore, data-intensive scientific research traffic often requires exceptions to normal security policies, resulting in ad-hoc solutions that bypass standard operational procedures and leave both the scientific workflow and the campus as a whole vulnerable to attack. In short, state-of-the-art campus security operations still heavily rely on human domain experts to interpret high level policy documents, implement those policies through low-level mechanisms, create exceptions to accommodate scientific workflows, interpret reports and alerts, and be able to react to security events in near real time on a 24-by-7 basis.This project addresses these challenges through a collaborative research effort, called NetSecOps (Network Security Operations), that assists information technology (IT) security teams by automating many of the operational tasks that are tedious, error-prone, and otherwise problematic in current campus networks. NetSecOps is policy-driven in that the framework encodes high-level human-readable policies into systematic policy specifications that drive the actual configuration and operation of the infrastructure. NetSecOps is knowledge-centric in that the framework captures data, information, and knowledge about the infrastructure in a central knowledge store that informs and guides IT operational tasks. The proposed NetSecOps architecture has the following unique capabilities: (1) the ability to capture campus network security policies systematically; (2) the ability to create new fine-grained network control abstractions that leverage existing security capabilities and emerging software defined networks (SDN) to implement security policies, including policies related to both scientific workflows and IT domains; (3) the ability to implement policy traceability tools that verify whether these network abstractions maintain the integrity of the high-level policies; (4) the ability to implement knowledge-discovery tools that enable reasoning across data from existing security point-solutions, including security monitoring tools and authentication and authorization frameworks; and (5) the ability to automatically adjust the network's security posture based on detected security events. Research results and tools from the project will be released into the public domain allowing academic institutions to utilize the resources as part of their best-practice IT security operations.
大学校园中的网络基础设施复杂而复杂,通常支持企业、学术、学生、研究和医疗保健数据的混合,每个数据都有自己独特的安全、隐私和优先级策略。保护这种复杂且高度动态的环境极具挑战性,特别是因为校园基础设施越来越多地受到互联网上恶意行为者和(通常是在不知不觉中)校园内部设备的攻击。校园的不同部分有非常不同的政策和法规来管理敏感数据的处理(例如,私人学生/员工信息、医疗保健数据、金融交易等)。此外,数据密集型的科研流量通常需要例外的正常安全策略,导致临时解决方案绕过标准操作流程,使科研工作流程和校园作为一个整体容易受到攻击。简而言之,最先进的校园安全操作仍然严重依赖于人类领域专家来解释高级政策文件,通过低级机制实施这些政策,创建例外以适应科学工作流程,解释报告和警报,并能够在24 × 7的基础上近乎实时地对安全事件做出反应。该项目通过一项名为NetSecOps(网络安全运营)的合作研究工作来解决这些挑战,该项目帮助信息技术(IT)安全团队将当前校园网中繁琐、容易出错和其他问题的许多操作任务自动化。NetSecOps是策略驱动的,因为该框架将高级的人类可读策略编码为驱动基础设施的实际配置和操作的系统策略规范。NetSecOps是以知识为中心的,因为该框架在通知和指导IT操作任务的中央知识存储中捕获有关基础设施的数据、信息和知识。提出的NetSecOps架构具有以下独特的功能:(1)能够系统地捕获校园网安全策略;(2)创建新的细粒度网络控制抽象的能力,利用现有的安全功能和新兴的软件定义网络(SDN)来实施安全策略,包括与科学工作流和IT领域相关的策略;(3)实施策略可追溯性工具的能力,这些工具可以验证这些网络抽象是否保持高层策略的完整性;(4)实现知识发现工具的能力,这些工具能够从现有的安全点解决方案(包括安全监控工具和身份验证和授权框架)中进行数据推理;(5)根据检测到的安全事件自动调整网络安全态势的能力。该项目的研究成果和工具将发布到公共领域,允许学术机构利用这些资源作为其最佳实践IT安全操作的一部分。

项目成果

期刊论文数量(16)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
POLANCO: Enforcing Natural Language Network Policies
POLANCO:执行自然语言网络政策
Towards Improved Network Security Requirements and Policy: Domain-Specific Completeness Analysis via Topic Modeling
提高网络安全要求和策略:通过主题建模进行特定领域的完整性分析
Dynamically Creating Custom SDN High-Speed Network Paths for Big Data Science Flows
为大数据科学流程动态创建自定义 SDN 高速网络路径
Multi-user Input in Determining Answer Sets (MIDAS)
确定答案集中的多用户输入 (MIDAS)
Automating Requirements Traceability: Two Decades of Learning from KDD
自动化需求可追溯性:从 KDD 中学习的两个十年
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

James Griffioen其他文献

Building layered active services
  • DOI:
    10.1016/j.comnet.2006.04.020
  • 发表时间:
    2006-10-05
  • 期刊:
  • 影响因子:
  • 作者:
    Chetan Singh Dhillon;Mary Bond;James Griffioen;Kenneth L. Calvert
  • 通讯作者:
    Kenneth L. Calvert
The Reappearances of St. Basil the Great in British Library MS Cotton Otho B. x
  • DOI:
    10.1023/a:1013111213156
  • 发表时间:
    2002-02-01
  • 期刊:
  • 影响因子:
    1.800
  • 作者:
    Kevin Kiernan;Brent Seales;James Griffioen
  • 通讯作者:
    James Griffioen
Measuring experiments in GENI
  • DOI:
    10.1016/j.bjp.2013.10.016
  • 发表时间:
    2014-04-22
  • 期刊:
  • 影响因子:
  • 作者:
    James Griffioen;Zongming Fei;Hussamuddin Nasir;Xiongqi Wu;Jeremy Reed;Charles Carpenter
  • 通讯作者:
    Charles Carpenter

James Griffioen的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('James Griffioen', 18)}}的其他基金

Collaborative Research: IRNC Testbed: FAB: FABRIC Across Borders
合作研究:IRNC 测试平台:FAB:FABRIC 跨境
  • 批准号:
    2029235
  • 财政年份:
    2020
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Continuing Grant
Collaborative Research: ENTeR: Enabling NeTwork Research and the Evolution of a Next Generation Midscale Research Infrastructure
协作研究:ENTeR:支持网络研究和下一代中型研究基础设施的发展
  • 批准号:
    1836742
  • 财政年份:
    2018
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
MRI: Acquisition of the Kentucky Research Informatics Cloud (KyRIC)
MRI:收购肯塔基州研究信息学云 (KyRIC)
  • 批准号:
    1626364
  • 财政年份:
    2016
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
EAGER: Collaborative Research: Enabling Economic Policies in Software-Defined Internet Exchange Points
EAGER:协作研究:在软件定义的互联网交换点中实现经济政策
  • 批准号:
    1551453
  • 财政年份:
    2015
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CC*DNI Integration: Enhancing Science Through Custom Paths For Trusted Users
CC*DNI 集成:通过受信任用户的自定义路径增强科学
  • 批准号:
    1541426
  • 财政年份:
    2015
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
NeTS: Large: Collaborative Research: Network Innovation through Choice
NeTS:大型:协作研究:通过选择进行网络创新
  • 批准号:
    1111040
  • 财政年份:
    2011
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
Collaborative Research: Emulation Infrastructure and Material for OS/Network Classes
协作研究:操作系统/网络类的仿真基础设施和材料
  • 批准号:
    0511534
  • 财政年份:
    2005
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CISE Research Infrastructure: The Metaverse: A Laboratory for Digital Media Networks
CISE 研究基础设施:Metaverse:数字媒体网络实验室
  • 批准号:
    0101242
  • 财政年份:
    2001
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
RIA: A Memory-Based Architecture for High-Performance Distributed File Systems
RIA:基于内存的高性能分布式文件系统架构
  • 批准号:
    9309176
  • 财政年份:
    1993
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant

相似国自然基金

Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 批准年份:
    2024
  • 资助金额:
    0.0 万元
  • 项目类别:
    省市级项目
Cell Research
  • 批准号:
    31224802
  • 批准年份:
    2012
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research
  • 批准号:
    31024804
  • 批准年份:
    2010
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research (细胞研究)
  • 批准号:
    30824808
  • 批准年份:
    2008
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
  • 批准号:
    10774081
  • 批准年份:
    2007
  • 资助金额:
    45.0 万元
  • 项目类别:
    面上项目

相似海外基金

Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    2128607
  • 财政年份:
    2021
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    1642031
  • 财政年份:
    2017
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Regional: SouthEast SciEntific Cybersecurity for University Research (SouthEast SECURE)
合作研究:CICI:区域:东南大学研究科学网络安全 (SouthEast SECURE)
  • 批准号:
    1812404
  • 财政年份:
    2017
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    1642143
  • 财政年份:
    2017
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CICI: Data Provenance: Collaborative Research: Provenance Assurance Using Currency Primitives
CICI:数据来源:协作研究:使用货币基元的来源保证
  • 批准号:
    1821926
  • 财政年份:
    2017
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Regional: SouthEast SciEntific Cybersecurity for University REsearch (SouthEast SECURE)
合作研究:CICI:区域:东南大学研究科学网络安全 (SouthEast SECURE)
  • 批准号:
    1642038
  • 财政年份:
    2016
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: Scientific Workflow Integrity with Pegasus
合作研究:CICI:安全和弹性架构:与 Pegasus 的科学工作流程完整性
  • 批准号:
    1642070
  • 财政年份:
    2016
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: Creating Dynamic Superfacilities the SAFE Way
合作研究:CICI:安全和弹性架构:以安全方式创建动态超级设施
  • 批准号:
    1642142
  • 财政年份:
    2016
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CICI: Data Provenance: Collaborative Research: Provenance Assurance Using Currency Primitives
CICI:数据来源:协作研究:使用货币基元的来源保证
  • 批准号:
    1547164
  • 财政年份:
    2016
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CICI: Secure Data Architecture: Collaborative Research: Assured Mission Delivery Network Framework for Secure Scientific Collaboration
CICI:安全数据架构:协作研究:确保安全科学协作的任务交付网络框架
  • 批准号:
    1547390
  • 财政年份:
    2016
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了