课题基金 / 基金详情

CAREER: Programmable In-network Security

CAREER: Programmable In-network Security
职业:可编程网络安全
批准号:
1942219
负责人:
Ang Chen
金额:
$55.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-01-15 至 2024-03-31

项目摘要

项目成果

Ang Chen的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Attacks on the Internet cost the economy billions of dollars. While today’s Internet was developed to provide widespread connectivity to individuals and businesses across the world, the networks that support the Internet do not have built-in security mechanisms. This project is focused on solving that problem by investigating future network designs based on new network technology that would support security and provide defense across a wide variety of attacks. The project vision is to develop Programmable In-network Security, or ‘Poise’. Poise aims to design and integrate a wide range of defenses directly inside the network, leveraging the technology trend of network programmability. If successful, a Poise network would support security as naturally as today’s networks support connectivity. This project will develop new scientific foundations for network security, investigate practical use cases, release open-source tools, and produce educational materials. The potential impact of Poise is to make future networks fundamentally more secure than they are today. This project presents a vision of Programmable In-network Security, or ‘Poise’, informed by the recent trend that network devices are becoming increasingly programmable, and with a goal of supporting security as a first-class network attribute. The project plans to take a three-pronged approach to realizing this goal. First, Poise aims to transform a programmable switch into a defense platform by designing a wide range of security applications that reside in the switch. Second, Poise aims to transform a network of programmable switches into a defense fleet, by architecting defense applications into the network paths and synchronizing them for whole-network defense. Third, Poise seeks to ensure that the defense applications, individually and collectively, are themselves secure against attacks. In its ultimate embodiment, a Poise network would toggle a wide array of defenses rapidly on and off as traffic flows through, mitigating attacks in real time. This project will advance the state of the art in network security in the above three dimensions and will produce scientific foundations and reusable system prototypes.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
Probabilistic Profiling of Stateful Data Planes for Adversarial Testing
用于对抗性测试的状态数据平面的概率分析
DOI: --
发表时间: 2021
期刊: ASPLOS
影响因子: --
作者: [Qiao, K, Xing, J, Qiu, Y, Chen, A]
通讯作者: Chen, A
DOI: 10.1145/3560826.3563382
发表时间: 2022-11
期刊: Proceedings of the 4th Workshop on CPS & IoT Security and Privacy
影响因子: --
作者: [Patrick Tser Jern Kon;Diogo Barradas;Ang Chen]
通讯作者: Patrick Tser Jern Kon;Diogo Barradas;Ang Chen
DOI: --
发表时间: 2023
期刊:
影响因子: --
作者: [Hongyi Liu;Jiarong Xing;Yibo Huang;Danyang Zhuo;S. Devadas;Ang Chen]
通讯作者: Hongyi Liu;Jiarong Xing;Yibo Huang;Danyang Zhuo;S. Devadas;Ang Chen
DOI: 10.1145/3405669.3405821
发表时间: 2020-08
期刊: Proceedings of the Workshop on Secure Programmable Network Infrastructure
影响因子: --
作者: [Yiming Qiu;Kuo-Feng Hsu;Jiarong Xing;Ang Chen]
通讯作者: Yiming Qiu;Kuo-Feng Hsu;Jiarong Xing;Ang Chen
7
    Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
    Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
    I-Corps: A Learned Cloud Infrastructure-as-Code (IaC) Linter
    CAREER: Programmable In-network Security
    海外基金