SaTC: CORE: Small: Collaborative: A New Approach to Federated Network Security
SaTC: CORE: Small: Collaborative: A New Approach to Federated Network Security
批准号:
1717581
负责人:
John Foster
金额:
$13.17万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-09-01 至 2020-08-31
中文摘要
现代网络通常在本质上是联合的——即,它们是跨多个管理域的独立网络之间的互操作。例如,在许多企业中,不同的业务单元控制着网络的各种逻辑段,但共享公共资源,如路由器、防火墙和负载平衡器。在这样的联邦系统中,网络安全策略的正确实施依赖于跨多个管理域的交互。该项目正在开发使用一种专门用于网络领域的新形式的携带证明代码(PCC)在联邦网络中执行安全策略的技术。这种强制机制将确保只有经过授权的参与者才能重新配置联邦网络中的设备,并将保证组态软件保留“行为”策略,如访问控制、片隔离等。本研究的技术贡献将包括(i)为NetKAT开发PCC技术,NetKAT是一种用于SDN编程的语言,配备了健全完整的方程推理系统;以及(ii)将NetKAT PCC集成到Nexus授权语言(NAL)中,该框架提供了指定和执行分布式授权策略的方法。关键的挑战将包括如何生成、表示和转换NetKAT证明,以及如何处理动态行为,如网络配置变化和不断发展的信任模型。该项目的广泛影响包括:(1)开发开源软件,该软件将在由BTV Ignite项目主办的GENI平台上进行测试,并在佛蒙特州伯灵顿当地社区产生更广泛的影响;(2)通过与纽约州4-H和科学领导学院合作开发的高中生外展项目,为代表性不足的群体提供教育机会。
英文摘要
Modern networks are often federated in nature---i.e., they are an interoperation between independent networks spanning multiple administrative domains. For example, in many enterprises, different business units control various logical segments of the network, but share common resources, such as routers, firewalls, and load-balancers. In such federated systems, the correct enforcement of network security policies relies on interactions that span multiple administrative domains. This project is developing techniques for enforcing security policies in federated networks using a new form of Proof Carrying Code (PCC), specialized to the networking domain. This enforcement mechanism will ensure that only authorized actors can reconfigure devices in federated networks, and will guarantee that configuration software preserves "behavioral" policies such as access control, slice isolation, etc.The technical contributions of this research will include (i) developing PCC techniques for NetKAT, a language for SDN programming that comes equipped with a sound and complete equational reasoning system, and (ii) integrating NetKAT PCC into the Nexus Authorization Language (NAL), a framework that provides methods for specifying and enforcing distributed authorization policies. Key challenges will include how to generate, represent, and transform NetKAT proofs, and how to deal with dynamic behaviors such as network configuration changes and evolving trust models. The broader impacts of this project include (i) developing open-source software that will be tested on a GENI rack hosted by the BTV Ignite program with broader impacts in the local Burlington, VT community, and (ii) presenting education opportunities for underrepresented groups via an outreach program for high school students developed in partnership with the New York State 4-H and Science Leadership Academy.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3319535.3363214
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[C. Skalka;J. Ring;David Darais;Minseok Kwon;Sahil Gupta;Kyle I. Diller;S. Smolka;Nate Foster]
通讯作者:
C. Skalka;J. Ring;David Darais;Minseok Kwon;Sahil Gupta;Kyle I. Diller;S. Smolka;Nate Foster
ECLIPSE: CAS-Climate: Understanding the Role of Thermally-Driven Processes in Pattern Formation and Droplet Emission in DC Glows with Applications to Water Treatment
-
批准号:2206039
-
项目类别:Standard Grant
-
资助金额:$51.12万
-
财政年份:2022
-
负责人:John Foster
-
依托单位:
FMitF: Track 2: Formal Reasoning for Legal Conveyances
-
批准号:2019313
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2020
-
负责人:John Foster
-
依托单位:
FMitF: Track I: Petr4: Formal Foundations for Programmable Networks
-
批准号:1918396
-
项目类别:Standard Grant
-
资助金额:$75.0万
-
财政年份:2019
-
负责人:John Foster
-
依托单位:
Travel Support: 15th US National Congress on Computational Mechanics (USNCCM XV); Austin, Texas; July 28-August 1, 2019
-
批准号:1935320
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2019
-
负责人:John Foster
-
依托单位:
IUCRC Phase I: The University of Michigan Center for High Pressure Plasma Energy, Agriculture, and Biomedical Technologies (PEAB)
-
批准号:1747739
-
项目类别:Continuing Grant
-
资助金额:$75.0万
-
财政年份:2018
-
负责人:John Foster
-
依托单位:
Planning I/UCRC University of Michigan Ann Arbor: Center for High Pressure Plasma Energy, Agriculture, and Biomedical Technologies (PEAB)
-
批准号:1650488
-
项目类别:Standard Grant
-
资助金额:$1.5万
-
财政年份:2017
-
负责人:John Foster
-
依托单位:
CICI: Secure and Resilient Architecture: Campus Infrastructure for Microscale, Privacy-Conscious, Data-Driven Planning
-
批准号:1642120
-
项目类别:Standard Grant
-
资助金额:$99.94万
-
财政年份:2017
-
负责人:John Foster
-
依托单位:
PFI:AIR - TT: High Throughput Plasma Water Purifier
-
批准号:1700848
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2017
-
负责人:John Foster
-
依托单位:
AitF: Theory and Practice of Probabilistic Network Programming
-
批准号:1637532
-
项目类别:Standard Grant
-
资助金额:$79.9万
-
财政年份:2016
-
负责人:John Foster
-
依托单位:
CC*IIE: Integration: COSciN: Cornell Open Science Network
-
批准号:1440744
-
项目类别:Standard Grant
-
资助金额:$98.63万
-
财政年份:2015
-
负责人:John Foster
-
依托单位:
Micro-Plasmas Through Porous Media
-
批准号:1519117
-
项目类别:Continuing Grant
-
资助金额:$40.5万
-
财政年份:2015
-
负责人:John Foster
-
依托单位:
I-Corps: Plasma-Based High Throughput Water Purification
-
批准号:1550469
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2015
-
负责人:John Foster
-
依托单位:
AitF: Full: Algorithms and Probabilistic Semantics for Next-Generation Networks
-
批准号:1535952
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2015
-
负责人:John Foster
-
依托单位:
SHF:Small:Collaborative Research:Practical Synthesis of Network Updates
-
批准号:1422046
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2014
-
负责人:John Foster
-
依托单位:
NeTS: Large: Collaborative Research:Programmable Inter-Domain Observation and Control
-
批准号:1413972
-
项目类别:Continuing Grant
-
资助金额:$65.72万
-
财政年份:2014
-
负责人:John Foster
-
依托单位:
An investigation of plasma formation in electromechanically driven free bubbles at resonance in water with applications for the treatment of water
-
批准号:1336375
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2013
-
负责人:John Foster
-
依托单位:
CAREER: Principles and Practice of Distributed Updates
-
批准号:1253165
-
项目类别:Continuing Grant
-
资助金额:$53.2万
-
财政年份:2013
-
负责人:John Foster
-
依托单位:
Programming Languages Mentoring Workshop
-
批准号:1251376
-
项目类别:Standard Grant
-
资助金额:$3.0万
-
财政年份:2012
-
负责人:John Foster
-
依托单位:
EAGER: Plasma-Soft Matter interactions: Towards understanding the effect of nonequilibrium, cold plasma on liquid phase chemical reactions in cells using novel chemical sensors
-
批准号:1249787
-
项目类别:Standard Grant
-
资助金额:$6.95万
-
财政年份:2012
-
负责人:John Foster
-
依托单位:
TC: Large: Collaborative Research: High-Level Language Support for Trustworthy Networks
-
批准号:1111698
-
项目类别:Standard Grant
-
资助金额:$160.0万
-
财政年份:2011
-
负责人:John Foster
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: