CSR: Medium: Security and Isolation in the Era of Microservices
CSR:中:微服务时代的安全与隔离
基本信息
- 批准号:2203152
- 负责人:
- 金额:$ 120万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-10-01 至 2024-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Years ago, applications such as news, e-commerce, or banking websites ran on computers deployed at organizations owning them. Today, with the advent of "cloud computing", such applications instead run in a far-away server farm operated by third-parties. Because the computers are shared by many applications, it is crucial to ensure that one application in the cloud, such as a news website, does not compromise the confidentiality or integrity of another application (e.g., a banking website) running on the same set of computers. The goal of this project is to develop systems that ensure cloud applications are suitably protected without sacrificing their performance and ability to grow/shrink. This goal will be realized by developing two core building blocks to achieve optimal trade-offs between isolation and performance/agility. The first is variable isolation, where we automatically determine the least privilege and best isolation techniques needed for components of an application, and deploy the highest (weakest) isolation where needed most (least). The second is isolation-aware replication, where tenants selectively replicate their compute and storage within higher-isolation sandboxes. Finally, the project will develop new programming models for correct distributed execution of microservices-based applications.The research, if successful, will improve both the performance and the security posture of cloud-based applications. Research outcomes of the project, including the experimental harnesses and datasets, will be released open-source, enabling others in research and industry to directly build on them. The project will lead to the development of new courses and boot camps that focus on microservices, lambda-style computation, and isolation. The course/boot camp material will be made publicly available. The project aims to integrate the research into outreach efforts aimed at women, under-represented minorities, non-traditional students, and high school students.The project and its research artifacts will be hosted at https://bitbucket.org/uw-madison-networking-research/isolation. This site will include research publications, software, datasets, presentations, and tutorials. This site will be kept up to date for the entire duration of the project and for 2-3 years immediately following the project's culmination.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
几年前,新闻、电子商务或银行网站等应用程序在拥有它们的组织部署的计算机上运行。如今,随着“云计算”的出现,这些应用程序转而在由第三方运营的远程服务器群中运行。由于计算机由许多应用程序共享,因此确保云中的一个应用程序(例如新闻网站)不会损害另一个应用程序的机密性或完整性(例如,银行网站)在同一组计算机上运行。该项目的目标是开发系统,确保云应用程序得到适当的保护,而不会牺牲其性能和增长/收缩的能力。这一目标将通过开发两个核心构建块来实现,以实现隔离和性能/灵活性之间的最佳权衡。第一个是变量隔离,我们自动确定应用程序组件所需的最小特权和最佳隔离技术,并在最需要(最不需要)的地方部署最高(最弱)的隔离。第二种是隔离感知复制,其中租户选择性地在更高隔离度的沙箱中复制其计算和存储。最后,该项目将为基于微服务的应用程序的正确分布式执行开发新的编程模型。如果研究成功,将提高基于云的应用程序的性能和安全状况。该项目的研究成果,包括实验工具和数据集,将以开源方式发布,使研究和工业界的其他人能够直接在其基础上进行开发。该项目将导致新课程和靴子营地的开发,重点是微服务,分布式计算和隔离。课程/靴子营材料将公开提供。该项目旨在将研究纳入针对妇女、代表性不足的少数民族、非传统学生和高中生的外展工作中。该项目及其研究成果将在https://bitbucket.org/uw-madison-networking-research/isolation上托管。该网站将包括研究出版物,软件,数据集,演示文稿和教程。该网站将在整个项目期间和项目结束后的2-3年内保持更新。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(2)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Memory deduplication for serverless computing with Medes
使用 Medes 进行无服务器计算的内存重复数据删除
- DOI:10.1145/3492321.3524272
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Saxena, Divyanshu;Ji, Tao;Singhvi, Arjun;Khalid, Junaid;Akella, Aditya
- 通讯作者:Akella, Aditya
Jiffy: elastic far-memory for stateful serverless analytics
- DOI:10.1145/3492321.3527539
- 发表时间:2022-03
- 期刊:
- 影响因子:0
- 作者:Anurag Khandelwal;Yupeng Tang;R. Agarwal;Aditya Akella;I. Stoica
- 通讯作者:Anurag Khandelwal;Yupeng Tang;R. Agarwal;Aditya Akella;I. Stoica
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Aditya Akella其他文献
From Dumb Pipes to Rivers of Money: a Network Payment System
从愚蠢的管道到金钱的河流:网络支付系统
- DOI:
- 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Cristian Estan;Suman Banerjee;Aditya Akella;Yi Pan - 通讯作者:
Yi Pan
Using strongly typed networking to architect for tussle
使用强类型网络来构建斗争
- DOI:
10.1145/1868447.1868456 - 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
C. Muthukrishnan;V. Paxson;M. Allman;Aditya Akella - 通讯作者:
Aditya Akella
Toward Representative Internet Measurements
迈向具有代表性的互联网测量
- DOI:
- 发表时间:
2003 - 期刊:
- 影响因子:0
- 作者:
Aditya Akella;S. Seshan - 通讯作者:
S. Seshan
Handheld vs. Non-Handheld Traffic: Implications for Campus WiFi Networks
手持设备与非手持设备流量:对校园 WiFi 网络的影响
- DOI:
- 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
Aaron Gember;Ashok Anand;Aditya Akella - 通讯作者:
Aditya Akella
Running BGP in Data Centers at Scale
在数据中心大规模运行 BGP
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
Anubhavnidhi Abhashkumar;Kausik Subramanian;A. Andreyev;Hyojeong Kim;Nanda Kishore Salem;Jingyi Yang;Petr Lapukhov;Aditya Akella;Hongyi Zeng - 通讯作者:
Hongyi Zeng
Aditya Akella的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Aditya Akella', 18)}}的其他基金
Collaborative Research: CNS Core: Medium: Innovating Volumetric Video Streaming with Motion Forecasting, Intelligent Upsampling, and QoE Modeling
合作研究:CNS 核心:中:通过运动预测、智能上采样和 QoE 建模创新体积视频流
- 批准号:
2212297 - 财政年份:2022
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Large: Runtime Programmable Networks
合作研究:CNS 核心:大型:运行时可编程网络
- 批准号:
2214015 - 财政年份:2022
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Medium: Systems Support for Federated Learning
协作研究:CNS 核心:中:联邦学习的系统支持
- 批准号:
2105890 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
NeTS: Large: Collaborative Research: Design Principles for a Future-Proof Internet Control Plane
NetS:大型:协作研究:面向未来的互联网控制平面的设计原则
- 批准号:
2202649 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
NeTS: Small: New Abstractions for First-hop Networking in Cloud Data Centers
NeTS:小型:云数据中心第一跳网络的新抽象
- 批准号:
2203167 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Medium: Systems Support for Federated Learning
协作研究:CNS 核心:中:联邦学习的系统支持
- 批准号:
2207317 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
EAGER: Collaborative Research: Inexactness and Data-Awareness in Network Stacks for Distributed Machine Learning
EAGER:协作研究:分布式机器学习网络堆栈中的不精确性和数据感知
- 批准号:
1940109 - 财政年份:2019
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
CSR: Medium: Security and Isolation in the Era of Microservices
CSR:中:微服务时代的安全与隔离
- 批准号:
1763810 - 财政年份:2018
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
NeTS: Small: New Abstractions for First-hop Networking in Cloud Data Centers
NeTS:小型:云数据中心第一跳网络的新抽象
- 批准号:
1717039 - 财政年份:2017
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Workshop titled "Toward a Research Agenda for Cloud 3.0"
题为“迈向云 3.0 研究议程”的研讨会
- 批准号:
1749528 - 财政年份:2017
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
相似海外基金
Collaborative Research: CyberTraining: Implementation: Medium: Cross-Disciplinary Training for Joint Cyber-Physical Systems and IoT Security
协作研究:网络培训:实施:中:联合网络物理系统和物联网安全的跨学科培训
- 批准号:
2230086 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Hardware Security Insights: Analyzing Hardware Designs to Understand and Assess Security Weaknesses and Vulnerabilities
协作研究:SaTC:核心:中:硬件安全见解:分析硬件设计以了解和评估安全弱点和漏洞
- 批准号:
2247755 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CPS: Medium: Enabling Data-Driven Security and Safety Analyses for Cyber-Physical Systems
协作研究:CPS:中:为网络物理系统实现数据驱动的安全和安全分析
- 批准号:
2414176 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Collaborative Research: CyberTraining: Implementation: Medium: Cross-Disciplinary Training for Joint Cyber-Physical Systems and IoT Security
协作研究:网络培训:实施:中:联合网络物理系统和物联网安全的跨学科培训
- 批准号:
2230087 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Security and Robustness for Intermittent Computing Using Cross-Layer Post-CMOS Approaches
协作研究:SaTC:CORE:中:使用跨层后 CMOS 方法的间歇计算的安全性和鲁棒性
- 批准号:
2303115 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Audacity of Exploration: Toward Automated Discovery of Security Flaws in Networked Systems through Intelligent Documentation Analysis
协作研究:SaTC:核心:中:大胆探索:通过智能文档分析自动发现网络系统中的安全缺陷
- 批准号:
2409269 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Hardware Security Insights: Analyzing Hardware Designs to Understand and Assess Security Weaknesses and Vulnerabilities
协作研究:SaTC:核心:中:硬件安全见解:分析硬件设计以了解和评估安全弱点和漏洞
- 批准号:
2247756 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Security and Robustness for Intermittent Computing Using Cross-Layer Post-CMOS Approaches
协作研究:SaTC:CORE:中:使用跨层后 CMOS 方法的间歇计算的安全性和鲁棒性
- 批准号:
2303114 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Enhancing Cyber Resilience of Small and Medium-sized Enterprises through Cyber Security Communities of Support
通过网络安全支持社区增强中小企业的网络弹性
- 批准号:
EP/X037282/1 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Research Grant
SaTC: CORE: Medium: Physically Unclonable Wireless Systems (PUWS) for RF Fingerprinting and Physical Layer Security
SaTC:核心:中:用于射频指纹识别和物理层安全的物理不可克隆无线系统 (PUWS)
- 批准号:
2233774 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Standard Grant