EAGER: USBRCCR: Collaborative: Securing Networks in the Programmable Data Plane Era
EAGER: USBRCCR: Collaborative: Securing Networks in the Programmable Data Plane Era
批准号:
1740791
负责人:
Guofei Gu
金额:
$10.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-09-01 至 2020-08-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Recent advances in software-defined networking (SDN) and programmable data planes allow datacenter and enterprise network operators to quickly deploy new protocols, customize network behavior, and develop innovative services. These advances promise to improve and streamline network operations, improving the quality of service provided to end users. However programmable data planes also introduce new complexities to network management, notably, ensuring that the network satisfies critical security properties. Current network verification and analysis tools cannot handle these complex new networks. This work aims to address three important problems at the intersection of networking and computer security: First, the work proposes to develop new techniques that allow operators to verify that their network satisfies security properties like tenant isolation in a cloud hosting environment. Second, this work proposes to use the data plane to implement a security mechanism to enforce security properties, an approach that complements verification as a way to ensure correct network behavior. Finally, the work proposes to develop new security services that leverage the capabilities of a programmable data plane. Results of the proposed work will promote the adoption of more secure and flexible next-generation networks by providing operators the tools necessary to verify and enforce critical network security properties. As programmable data planes are poised to transform modern the architecture of modern networks, the proposed work will advance the current state of the art in networking by extending verification and enforcement techniques to programmable data plane networks, for which neither network verification nor security policy mechanisms currently exist. To do so, investigators will transform data plane programs, expressed in P4, into assertions suitable for analysis using existing network verification tools based on SMT solvers. Investigators will also develop a security kernel implemented as a P4 data plane program to enforce network-wide security properties at run time. Finally, this work will also develop new data plane services that will enable a new class of security functions to be deployed in the network in order to improve the overall security of computer networks.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1007/978-3-030-00470-5_8
发表时间:
2018-09
期刊:
影响因子:
--
作者:
[Menghao Zhang;Guanyu Li;Lei Xu;J. Bi;G. Gu;Jia-Ju Bai]
通讯作者:
Menghao Zhang;Guanyu Li;Lei Xu;J. Bi;G. Gu;Jia-Ju Bai
DOI:
10.1109/dsn.2018.00047
发表时间:
2018-06
期刊:
2018 48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
作者:
[R. Skowyra;Lei Xu;G. Gu;V. Dedhia;Thomas Hobson;Hamed Okhravi;James Landry]
通讯作者:
R. Skowyra;Lei Xu;G. Gu;V. Dedhia;Thomas Hobson;Hamed Okhravi;James Landry
DOI:
10.1109/icnp.2019.8888057
发表时间:
2019-10
期刊:
2019 IEEE 27th International Conference on Network Protocols (ICNP)
影响因子:
--
作者:
[G. Li;Menghao Zhang;Chang Liu;Xiao Kong;Ang Chen;G. Gu;Haixin Duan]
通讯作者:
G. Li;Menghao Zhang;Chang Liu;Xiao Kong;Ang Chen;G. Gu;Haixin Duan
DOI:
10.1109/sp40000.2020.00017
发表时间:
2020-05
期刊:
2020 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Feng Xiao;Jinquan Zhang;Jianwei Huang;G. Gu;Dinghao Wu;Peng Liu]
通讯作者:
Feng Xiao;Jinquan Zhang;Jianwei Huang;G. Gu;Dinghao Wu;Peng Liu
DOI:
10.1145/3243734.3243749
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Haopei Wang;Guangliang Yang;Phakpoom Chinprutthiwong;Lei Xu;Yangyong Zhang;G. Gu]
通讯作者:
Haopei Wang;Guangliang Yang;Phakpoom Chinprutthiwong;Lei Xu;Yangyong Zhang;G. Gu
共 10 条
NSF Convergence Accelerator Track G: PETS: Programmable Zero-Trust Security for Operating Through 5G Infrastructure
-
批准号:2226339
-
项目类别:Standard Grant
-
资助金额:$75.0万
-
财政年份:2022
-
负责人:Guofei Gu
-
依托单位:
RINGS: NextSec: Zero-Trust, Programmable and Verifiable Security Transformation for NextG
-
批准号:2148374
-
项目类别:Continuing Grant
-
资助金额:$100.0万
-
财政年份:2022
-
负责人:Guofei Gu
-
依托单位:
Community-Building Workshop on Programmable System Security in a Software-Defined World
-
批准号:1841099
-
项目类别:Standard Grant
-
资助金额:$0.15万
-
财政年份:2018
-
负责人:Guofei Gu
-
依托单位:
SaTC: CORE: Small: Adversarial Learning via Modeling Interpretation
-
批准号:1816497
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Guofei Gu
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:1700544
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2017
-
负责人:Guofei Gu
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ
-
批准号:1642129
-
项目类别:Standard Grant
-
资助金额:$35.0万
-
财政年份:2016
-
负责人:Guofei Gu
-
依托单位:
NeTS: Small: Detecting Races in SDN Control Plane
-
批准号:1617985
-
项目类别:Standard Grant
-
资助金额:$35.0万
-
财政年份:2016
-
负责人:Guofei Gu
-
依托单位:
TWC: Medium: Collaborative: HIMALAYAS: Hierarchical Machine Learning Stack for Fine-Grained Analysis of Malware Domain Groups
-
批准号:1314823
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2013
-
负责人:Guofei Gu
-
依托单位:
CAREER: Coordination- and Correlation-based Botnet Defense
-
批准号:0954096
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2010
-
负责人:Guofei Gu
-
依托单位:
海外基金