CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
批准号:
1846291
负责人:
Hongxin Hu
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2021-06-30
中文摘要
传统的网络安全功能一般是在厂商专有的设备或中间盒上实现的,通常缺乏通用的编程接口,通用性和灵活性也很差。这些传统的网络安全设备通常需要放置在固定的网络入口点,并且在它们可以处理的最大流量方面具有恒定的容量。这种僵化的性质使它们在保护当今流行的可编程和可虚拟化环境方面效率低下。网络功能虚拟化(NFV)和软件定义网络(SDN)是两种新兴的网络模式,它们提供了解决这些限制的潜力,并能够通过设计一种称为虚拟网络安全功能(VNSF)的新型网络安全功能来促进弹性安全。这个项目的主要目标是扩展对虚拟网络安全功能的理解和科学。它将开发虚拟网络安全功能的新技术,其中安全微服务可以根据情况的需要按需灵活、安全和高效地部署。它解决了虚拟网络安全功能的管理、设计、部署和执行中固有的主要挑战,这些功能目前阻碍了其优势的充分利用。该项目还将把一项全面的教育计划与拟议的研究结合起来,以培训计算科学领域的下一代劳动力。该项目将通过积极招募女性和其他代表性不足的群体参与研究,培养学生的多样性。该项目将首先提出一个新的防火墙架构,以应对虚拟防火墙扩展方面的挑战。然后,该项目将探索解决方案,以促进传统和基于人工神经网络(ANN)的入侵检测系统的安全和高效虚拟化。最后,该项目将开发一个通用框架OpenNSFV,以支持安全高效的网络安全功能虚拟化。该项目建议的解决方案将是灵活、可扩展、值得信赖和最佳的,并将显著增强可编程和可虚拟化网络基础设施的安全性。为了证明建议的解决方案的实用性和可行性,该项目将在实际生产环境中实施、部署和评估建议的安全机制。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Traditional network security functions are generally implemented on vendor proprietary appliances or middleboxes, which usually lack a general programming interface, and their versatility and flexibility are also very poor. These traditional network security appliances often need to be placed at fixed network entry points and have a constant capacity with respect to the maximum amount of traffic they can process. Such rigid nature makes them inefficient in protecting today's prevailing programmable and virtualizable environments. Network Function Virtualization (NFV) and Software-Defined Networking (SDN) are two emerging networking paradigms that offer the potential to address those limitations and are able to facilitate elastic security with the design of a new breed of network security functions called virtual Network Security Functions (vNSFs). The major goal of this project is to extend the understanding and science of virtual Network Security Functions. It will develop new technology for virtual Network Security Functions where security microservices can be deployed elastically, safely and efficiently, on demand, tailored to the needs of the situation. It addresses major challenges inherent in the management, design, deployment, and execution of virtual Network Security Functions that currently prevent the full use of their benefits. This project will also integrate a comprehensive education plan with the proposed research to train the next generation workforce in computational sciences. The project will foster the diversity of students by active recruitment of women and other under-represented groups for participation in the research.This project will first propose a new firewall architecture to address challenges in virtual firewall scaling. This project will then explore solutions to facilitate safe and efficient virtualization of both traditional and Artificial Neural Network (ANN)-based Intrusion Detection Systems. Finally, this project will develop a general framework, OpenNSFV, for supporting safe and efficient virtualization of network security functions. The proposed solutions of this project will be flexible, scalable, trustworthy, and optimal, and will substantially enhance the security of programmable and virtualizable network infrastructure. To demonstrate the practicality and feasibility of the proposed solutions, the project will implement, deploy, and evaluate the proposed security mechanisms in real production environments.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/icc40277.2020.9149136
发表时间:
2020-06
期刊:
ICC 2020 - 2020 IEEE International Conference on Communications (ICC)
影响因子:
--
作者:
[Shuhe Wang;Zili Meng;Chen Sun;Minhu Wang;Mingwei Xu;J. Bi;Tong Yang;Qun Huang;Hongxin Hu]
通讯作者:
Shuhe Wang;Zili Meng;Chen Sun;Minhu Wang;Mingwei Xu;J. Bi;Tong Yang;Qun Huang;Hongxin Hu
Poseidon: Mitigating Volumetric DDoS Attacks with Programmable Switches
Poseidon:利用可编程开关缓解容量 DDoS 攻击
DOI:
10.14722/ndss.2020.24007
发表时间:
2020
期刊:
the 27th Network and Distributed System Security Symposium (NDSS 2020
影响因子:
--
作者:
[Zhang, M., Li, G., Wang, S., Liu, C., Chen, A., Hu, H., Gu, G., Li, Q., Xu, M., Wu, J.]
通讯作者:
Wu, J.
DOI:
10.1109/icnp.2019.8888133
发表时间:
2019-10
期刊:
2019 IEEE 27th International Conference on Network Protocols (ICNP)
影响因子:
--
作者:
[Menghao Zhang;Jia-Ju Bai;Guanyu Li;Zili Meng;Hongda Li;Hongxin Hu;Mingwei Xu]
通讯作者:
Menghao Zhang;Jia-Ju Bai;Guanyu Li;Zili Meng;Hongda Li;Hongxin Hu;Mingwei Xu
DOI:
10.1145/3387514.3405859
发表时间:
2019-10
期刊:
Proceedings of the Annual conference of the ACM Special Interest Group on Data Communication on the applications, technologies, architectures, and protocols for computer communication
影响因子:
--
作者:
[Zili Meng;Minhu Wang;Jia-Ju Bai;Mingwei Xu;Hongzi Mao;Hongxin Hu]
通讯作者:
Zili Meng;Minhu Wang;Jia-Ju Bai;Mingwei Xu;Hongzi Mao;Hongxin Hu
DOI:
10.1109/tcc.2020.2985045
发表时间:
2022-04
期刊:
IEEE Transactions on Cloud Computing
影响因子:
6.5
作者:
[Juan Wang;Shirong Hao;Hongxin Hu;Bo Zhao;Hongda Li;Wenhui Zhang;Jun Xu;Peng Liu;Jing Ma]
通讯作者:
Juan Wang;Shirong Hao;Hongxin Hu;Bo Zhao;Hongda Li;Wenhui Zhang;Jun Xu;Peng Liu;Jing Ma
共 8 条
Collaborative Research: SAI-R: Integrative Cyberinfrastructure for Enhancing and Accelerating Online Abuse Research
-
批准号:2228617
-
项目类别:Standard Grant
-
资助金额:$37.5万
-
财政年份:2022
-
负责人:Hongxin Hu
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:2128107
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
-
批准号:2129164
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
-
批准号:2128607
-
项目类别:Standard Grant
-
资助金额:$49.98万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
Collaborative Research: EAGER: SaTC-EDU: Learning Platform and Education Curriculum for Artificial Intelligence-Driven Socially-Relevant Cybersecurity
-
批准号:2114982
-
项目类别:Standard Grant
-
资助金额:$7.0万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
NSF Student Travel Grant for 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization (SDN-NFV Security)
-
批准号:1807103
-
项目类别:Standard Grant
-
资助金额:$0.56万
-
财政年份:2018
-
负责人:Hongxin Hu
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
-
批准号:1642143
-
项目类别:Standard Grant
-
资助金额:$49.98万
-
财政年份:2017
-
负责人:Hongxin Hu
-
依托单位:
SaTC: EDU: Collaborative: Enhancing Security Education through Transiting Research on Security in Emerging Network Technologies
-
批准号:1723663
-
项目类别:Standard Grant
-
资助金额:$8.0万
-
财政年份:2017
-
负责人:Hongxin Hu
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:1700499
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2017
-
负责人:Hongxin Hu
-
依托单位:
EAGER: Defending Against Visual Cyberbullying Attacks in Emerging Mobile Social Networks
-
批准号:1537924
-
项目类别:Standard Grant
-
资助金额:$23.97万
-
财政年份:2015
-
负责人:Hongxin Hu
-
依托单位:
III: Small: Collaborative Research: Privacy-Aware Collaborative Data Sharing in Human-Centered Social Networks
-
批准号:1527421
-
项目类别:Standard Grant
-
资助金额:$29.98万
-
财政年份:2015
-
负责人:Hongxin Hu
-
依托单位:
海外基金