CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization

职业:通过安全高效的网络安全功能虚拟化迈向弹性安全

基本信息

  • 批准号:
    2129164
  • 负责人:
  • 金额:
    $ 50万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2021
  • 资助国家:
    美国
  • 起止时间:
    2021-02-01 至 2025-10-31
  • 项目状态:
    未结题

项目摘要

Traditional network security functions are generally implemented on vendor proprietary appliances or middleboxes, which usually lack a general programming interface, and their versatility and flexibility are also very poor. These traditional network security appliances often need to be placed at fixed network entry points and have a constant capacity with respect to the maximum amount of traffic they can process. Such rigid nature makes them inefficient in protecting today's prevailing programmable and virtualizable environments. Network Function Virtualization (NFV) and Software-Defined Networking (SDN) are two emerging networking paradigms that offer the potential to address those limitations and are able to facilitate elastic security with the design of a new breed of network security functions called virtual Network Security Functions (vNSFs). The major goal of this project is to extend the understanding and science of virtual Network Security Functions. It will develop new technology for virtual Network Security Functions where security microservices can be deployed elastically, safely and efficiently, on demand, tailored to the needs of the situation. It addresses major challenges inherent in the management, design, deployment, and execution of virtual Network Security Functions that currently prevent the full use of their benefits. This project will also integrate a comprehensive education plan with the proposed research to train the next generation workforce in computational sciences. The project will foster the diversity of students by active recruitment of women and other under-represented groups for participation in the research.This project will first propose a new firewall architecture to address challenges in virtual firewall scaling. This project will then explore solutions to facilitate safe and efficient virtualization of both traditional and Artificial Neural Network (ANN)-based Intrusion Detection Systems. Finally, this project will develop a general framework, OpenNSFV, for supporting safe and efficient virtualization of network security functions. The proposed solutions of this project will be flexible, scalable, trustworthy, and optimal, and will substantially enhance the security of programmable and virtualizable network infrastructure. To demonstrate the practicality and feasibility of the proposed solutions, the project will implement, deploy, and evaluate the proposed security mechanisms in real production environments.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
传统的网络安全功能一般都是在厂商专有设备或中间盒上实现的,通常缺乏通用的编程接口,通用性和灵活性也很差。这些传统的网络安全设备通常需要放置在固定的网络入口点,并且具有相对于它们可以处理的最大流量的恒定容量。这种僵化的性质使得它们在保护当今流行的可编程和虚拟化环境方面效率低下。网络功能虚拟化(NFV)和软件定义网络(SDN)是两种新兴的网络范例,它们提供了解决这些限制的潜力,并且能够通过设计称为虚拟网络安全功能(vNSF)的新型网络安全功能来促进弹性安全。该项目的主要目标是扩展虚拟网络安全功能的理解和科学。 它将为虚拟网络安全功能开发新技术,其中安全微服务可以根据需要灵活,安全和高效地部署,并根据情况的需要进行定制。它解决了虚拟网络安全功能的管理、设计、部署和执行中固有的主要挑战,这些挑战目前阻碍了充分利用其优势。该项目还将整合一个全面的教育计划与拟议的研究,以培养计算科学的下一代劳动力。该项目将通过积极招募女性和其他代表性不足的群体参与研究来促进学生的多样性。该项目将首先提出一个新的防火墙架构,以解决虚拟防火墙扩展方面的挑战。该项目将探索解决方案,以促进传统和基于人工神经网络(ANN)的入侵检测系统的安全和有效的虚拟化。最后,本项目将开发一个通用框架OpenNSFV,用于支持安全和高效的网络安全功能虚拟化。该项目提出的解决方案将是灵活的,可扩展的,值得信赖的和最佳的,并将大大提高可编程和虚拟化网络基础设施的安全性。为了证明所提出的解决方案的实用性和可行性,该项目将在真实的生产环境中实施、部署和评估所提出的安全机制。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(22)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Understanding and Measuring Robustness of Vision and Language Multimodal Models
理解和测量视觉和语言多模态模型的鲁棒性
BYOZ: Protecting BYOD Through Zero Trust Network Security
BYOZ:通过零信任网络安全保护 BYOD
  • DOI:
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Anderson, John;Huang, Qiqing;Cheng, Long;Hu, Hongxin
  • 通讯作者:
    Hu, Hongxin
xNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses
Teaching SDN Security Using Hands-on Labs in CloudLab
使用 CloudLab 中的动手实验室教授 SDN 安全性
HierTopo: Towards High-Performance and Efficient Topology Optimization for Dynamic Networks
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Hongxin Hu其他文献

Tripod: Towards a Scalable, Efficient and Resilient Cloud Gateway
Tripod:迈向可扩展、高效且有弹性的云网关
Dynamic Audit Services for Outsourced Storages in Clouds
云中外包存储的动态审计服务
  • DOI:
    10.1109/tsc.2011.51
  • 发表时间:
    2013-04
  • 期刊:
  • 影响因子:
    8.1
  • 作者:
    Hongxin Hu;Stephen S. Yau;Ho G. An;Chang-Jun Hu
  • 通讯作者:
    Chang-Jun Hu
Infection control rate in two-stage exchange for chronic periprosthetic joint infection: a retrospective cohort study focusing on antibiotic-free period
  • DOI:
    10.1186/s12879-025-10919-1
  • 发表时间:
    2025-04-14
  • 期刊:
  • 影响因子:
    3.000
  • 作者:
    Haiqi Ding;Xuhui Yuan;Yang Chen;Changyu Huang;Hongxin Hu;Yufeng Guo;Chengguo Huang;Xinyu Fang;Wenming Zhang
  • 通讯作者:
    Wenming Zhang
Involvement of annexin A2 in anti-beta2GPI/beta2GPI-induced tissue factor expression on monocytes.
膜联蛋白 A2 参与抗 β2GPI/β2GPI 诱导的单核细胞组织因子表达。
  • DOI:
  • 发表时间:
    2007
  • 期刊:
  • 影响因子:
    44.1
  • 作者:
    Hong Zhou;S. Ling;Yinjing Yu;Ting Wang;Hongxin Hu
  • 通讯作者:
    Hongxin Hu
Effectiveness and Users’ Experience of Face Blurring as a Privacy Protection for Sharing Photos via Online Social Networks
面部模糊作为在线社交网络共享照片隐私保护的有效性和用户体验

Hongxin Hu的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Hongxin Hu', 18)}}的其他基金

Collaborative Research: SAI-R: Integrative Cyberinfrastructure for Enhancing and Accelerating Online Abuse Research
合作研究:SAI-R:用于加强和加速在线滥用研究的综合网络基础设施
  • 批准号:
    2228617
  • 财政年份:
    2022
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
  • 批准号:
    2128107
  • 财政年份:
    2021
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    2128607
  • 财政年份:
    2021
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
Collaborative Research: EAGER: SaTC-EDU: Learning Platform and Education Curriculum for Artificial Intelligence-Driven Socially-Relevant Cybersecurity
合作研究:EAGER:SaTC-EDU:人工智能驱动的社会相关网络安全的学习平台和教育课程
  • 批准号:
    2114982
  • 财政年份:
    2021
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
职业:通过安全高效的网络安全功能虚拟化迈向弹性安全
  • 批准号:
    1846291
  • 财政年份:
    2019
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
NSF Student Travel Grant for 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization (SDN-NFV Security)
NSF 学生旅费补助金用于 2018 年 ACM 软件定义网络和网络功能虚拟化安全(SDN-NFV 安全)国际研讨会
  • 批准号:
    1807103
  • 财政年份:
    2018
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    1642143
  • 财政年份:
    2017
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
SaTC: EDU: Collaborative: Enhancing Security Education through Transiting Research on Security in Emerging Network Technologies
SaTC:EDU:协作:通过新兴网络技术安全的过渡研究加强安全教育
  • 批准号:
    1723663
  • 财政年份:
    2017
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
  • 批准号:
    1700499
  • 财政年份:
    2017
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
III: Small: Collaborative Research: Privacy-Aware Collaborative Data Sharing in Human-Centered Social Networks
III:小:协作研究:以人为本的社交网络中的隐私意识协作数据共享
  • 批准号:
    1527421
  • 财政年份:
    2015
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant

相似海外基金

CAREER: Adaptive Deep Learning Systems Towards Edge Intelligence
职业:迈向边缘智能的自适应深度学习系统
  • 批准号:
    2338512
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
CAREER: Towards highly efficient UV emitters with lattice engineered substrates
事业:采用晶格工程基板实现高效紫外线发射器
  • 批准号:
    2338683
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
Postdoctoral Fellowship: STEMEdIPRF: Towards a Diverse Professoriate: Experiences that Inform Underrepresented Scholars' Perceptions of Value Alignment and Career Decisions
博士后奖学金:STEMEdIPRF:走向多元化的教授职称:为代表性不足的学者对价值调整和职业决策的看法提供信息的经验
  • 批准号:
    2327411
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
Collaborative Research: Maritime to Inland Transitions Towards ENvironments for Convection Initiation (MITTEN CI)
合作研究:海洋到内陆向对流引发环境的转变(MITTEN CI)
  • 批准号:
    2349935
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
Collaborative Research: Maritime to Inland Transitions Towards ENvironments for Convection Initiation (MITTEN CI)
合作研究:海洋到内陆向对流引发环境的转变(MITTEN CI)
  • 批准号:
    2349934
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
NSF-BSF: Towards a Molecular Understanding of Dynamic Active Sites in Advanced Alkaline Water Oxidation Catalysts
NSF-BSF:高级碱性水氧化催化剂动态活性位点的分子理解
  • 批准号:
    2400195
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
ASCENT: Heterogeneously Integrated and AI-Empowered Millimeter-Wave Wide-Bandgap Transmitter Array towards Energy- and Spectrum-Efficient Next-G Communications
ASCENT:异构集成和人工智能支持的毫米波宽带隙发射机阵列,实现节能和频谱高效的下一代通信
  • 批准号:
    2328281
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CAREER: Towards a comprehensive model of seismicity throughout the seismic cycle
职业:建立整个地震周期地震活动的综合模型
  • 批准号:
    2339556
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
CAREER: Towards Safety-Critical Real-Time Systems with Learning Components
职业:迈向具有学习组件的安全关键实时系统
  • 批准号:
    2340171
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
Sexual offence interviewing: Towards victim-survivor well-being and justice
性犯罪面谈:为了受害者-幸存者的福祉和正义
  • 批准号:
    DE240100109
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Discovery Early Career Researcher Award
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了