课题基金 / 基金详情

SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI

SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
批准号:
1700512
负责人:
Donald Porter
金额:
$40.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-09-01 至 2021-08-31

项目摘要

项目成果

Donald Porter的其他基金

相似基金

相关文献

中文摘要
翻译
传统上,我们的许多关键系统都是将安全性作为响应式附加组件开发的,而不是默认设计。因此,现有的安全机制往往是碎片化的,难以配置或验证,这使得很难抵御各种网络攻击。该项目将通过软件定义基础设施(SDI)为企业/云/数据中心安全管理构建“圣杯”:一个统一的框架,用于不同资源的安全和管理,从流程到存储再到网络。云计算现在是我们国家网络基础设施的重要组成部分;拟议的工作将降低云的总拥有成本-进一步释放经济和环境效益-以及提高当今云的安全性。该项目提出了S2 OS(SDI定义的安全操作系统),它在主机操作系统(OS)和网络级别上抽象了安全功能和原语,并提供了一个易于使用可编程的安全模型,用于监控和动态保护应用程序。该项目将探索新技术,将软件透明地组合成一个统一的企业,即使各个部分从未明确设计为互操作,类似于传统操作系统管理上层用户应用程序的各种硬件资源。此外,这一项目还将为利用全球信息作出有效的地方安保管理决定提供新的途径。最后,该项目将在动态、主机-网络协调和智能安全应用程序编程方面实现新的创新,以保护整个基础设施。该项目将为企业、数据中心和云计算的安全构建和管理做出重大贡献。该项目的PI将参与教育和推广活动,以培训下一代人才。特别是,PI计划将跨学科的研究思想整合到网络,系统和安全课程中。该项目还将积极鼓励代表性不足的群体参与,并向行业合作伙伴转让技术。
英文摘要
Traditionally, many of our critical systems have been developed with security as a reactive add-on, rather than a by default design. As a result, existing security mechanisms are often fragmented, hard to configure or verify, which makes it difficult to defend against various cyber attacks. This project will build the "holy grail" for enterprise/cloud/data-center security management with software-defined infrastructure (SDI): a unified framework for security and management of disparate resources, ranging from processes to storage to networking. Cloud computing is now an essential part of our national cyberinfrastructure; the proposed work will lower the total cost of ownership for clouds - further unlocking economic and environmental benefits - as well as improving the security of today's clouds.This project proposes S2OS (SDI-defined Security Operating System), which abstracts security capabilities and primitives at both the host Operating System (OS) and network levels and offers an easy-to-use and programmable security model for monitoring and dynamically securing applications. This project will explore new techniques to transparently compose software into a unified enterprise, even if the individual pieces were never explicitly designed to inter-operate, similar in a way a traditional operating system managing various hardware resources for upper-layer user applications. Further, this project will contribute new ways to leverage global information for making effective local security management decisions. Finally, this project enables new innovations in programming dynamic, host-network coordinated, and intelligent security applications to protect the entire infrastructure.This project will make significant contributions to how enterprise, data centers and cloud computing are securely built and managed. The project's PIs will engage in educational and outreach activities to train the next generation talent. In particular, the PIs plan to integrate the interdisciplinary research ideas into courses spanning networking, systems and security. The project will also actively encourage participation from underrepresented groups and transfer technology to industry partners.
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3373376.3378466
发表时间: 2020-03
期刊: Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子: --
作者: [Hangchen Yu;A. Peters;Amogh Akshintala;C. Rossbach]
通讯作者: Hangchen Yu;A. Peters;Amogh Akshintala;C. Rossbach
Challenges For Scaling Applications Across Enclaves
跨飞地扩展应用程序的挑战
DOI: 10.1145/3152701.3152710
发表时间: 2017
期刊: Proceedings of the 2nd Workshop on System Software for Trusted Execution
影响因子: --
作者: [Beekman, Jethro G., Porter, Donald E.]
通讯作者: Porter, Donald E.
On the Effectiveness of Behavior-Based Ransomware Detection
基于行为的勒索软件检测的有效性
DOI: 10.1007/978-3-030-63095-9_7
发表时间: 2020
期刊: International Conference on Security and Privacy in Communication Systems
影响因子: --
作者: [Han, Jaehyun, Lin, Zhiqiang, Porter, Donald E]
通讯作者: Porter, Donald E
DOI: 10.1145/3319647.3325833
发表时间: 2019-05
期刊: Proceedings of the 12th ACM International Conference on Systems and Storage
影响因子: --
作者: [Amogh Akshintala;Bhushan Jain;Chia-che Tsai;M. Ferdman;Donald E. Porter]
通讯作者: Amogh Akshintala;Bhushan Jain;Chia-che Tsai;M. Ferdman;Donald E. Porter
8
    Collaborative Research: SaTC: TTP: Medium: Toward Complete, User-Friendly, and Trustworthy Confidential Computing with Gramine
    NSF-BSF: SaTC: CORE: Small: Rowhammering Peripherals
    Collaborative Research: PPoSS: Planning: Efficient Address Translation with Formal Guarantees for Data-Center-Scale Applications
    SaTC: NSF-BSF: CORE: Small: Attacking and Defending the Lifespan of Mobile and Embedded Flash Storage
    国内基金
    海外基金
    ARL-1通过Wnt/β-catenin信号通路调控CSCs干性促进结直肠癌远处转移的机制研究
    • 批准号:
    • 项目类别:
      省市级项目
    • 资助金额:
      --
    • 批准年份:
      2025
    • 负责人:
      李秋锦
    • 依托单位:
    基于CSCs-内皮细胞间LY6E/FGFR1/VEGFA正反馈环路重塑血管微环境探讨片仔癀抑制大肠癌生长的分子机制
    CSCs 外泌体靶向递送 SOX11蛋白调节胎盘血管内皮 细胞衰老参与子痫前期发病的研究
    • 批准号:
      2024JJ5550
    • 项目类别:
      省市级项目
    • 资助金额:
      --
    • 批准年份:
      2024
    • 负责人:
      李平
    • 依托单位:
    线粒体来源非编码RNAASncmtRNA-2通过线粒体途径调控人卵巢CSCs化疗抵抗的分子机制
    • 批准号:
      2023JJ60077
    • 项目类别:
      省市级项目
    • 资助金额:
      --
    • 批准年份:
      2023
    • 负责人:
      陈蒲香
    • 依托单位: