Collaborative Research: NeTS: JUNO3: Leveraging Heterogeneous Programmable Data Planes for Security and Privacy of Cellular Networks, 5G & Beyond

合作研究:NetS:JUNO3:利用异构可编程数据平面实现蜂窝网络、5G 的安全和隐私

基本信息

  • 批准号:
    2210380
  • 负责人:
  • 金额:
    $ 22.5万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2022
  • 资助国家:
    美国
  • 起止时间:
    2022-09-01 至 2025-08-31
  • 项目状态:
    未结题

项目摘要

Securing “5G and beyond” cellular networks is critical to support the growing traffic from mobile and IoT devices. Significant parts of the cellular network infrastructure are being implemented on software-based environments. The shift to a disaggregated, virtualized cellular core network may result in an increased attack surface and greater vulnerability. Slow attacks, which attempt to avoid notice, can be damaging as they cannot be easily detected, and generally require the memory and computational capacity of end-host security middleboxes to detect or prevent them. Likewise, attackers seeking to violate user-privacy by eavesdropping on communication, cannot be easily prevented, especially at large scale. These threats leave both cellular users and operators vulnerable to attacks. This joint US-Japan project seeks to provide strong security monitoring and privacy protection solutions that exploit the high speed of programmable switches, the increased capabilities of programmable network interface cards, and the memory/computational capacity of end-host servers. By leveraging the strengths of each of these data plane components, the project will develop an efficient and performant cellular network security solution. To achieve this goal, this joint US-Japan project will pursue technical tasks that will be collaboratively pursued by the PIs based in the US and Japan. First, the team will design a heterogeneous data plane framework that cohesively combines multiple data plane devices for network function processing. The approach will use a collaborative filtering system, where most of the traffic is processed only by high-speed programmable switches that can easily extract aggregated, coarse-grained metrics. Suspicious traffic will be redirected to programmable network interface cards, or the host as necessary, for further inspection and metrics collection. Second, the project will develop real-time monitoring of cellular traffic, leveraging the cellular core network as a key vantage point. Monitoring at the cellular core can not only effectively detect and thwart data plane-based attacks, but also those on the control plane. It is in the unique position of being able to correlate between data and control plane state to further improve upon existing approaches to detect security attacks. Finally, the project will design privacy protection mechanisms that ensure anonymity of users in the face of fingerprinting attacks. The approach will leverage traffic morphing techniques that leverage the entire range of capabilities of a multi-tier, programmable, heterogeneous data plane framework, to enable high-speed operation. The proposed techniques will have significant societal impact by providing strong threat prevention and privacy preservation for cellular network users and their traffic.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
确保“5G及以上”蜂窝网络的安全对于支持移动和物联网设备日益增长的流量至关重要。蜂窝网络基础设施的大部分都是在基于软件的环境中实施的。向分散的、虚拟化的蜂窝核心网络的转变可能会导致更大的受攻击面和更大的脆弱性。试图躲避注意的缓慢攻击可能是破坏性的,因为它们不容易被检测到,并且通常需要终端主机安全中间盒的内存和计算能力来检测或防止它们。同样,试图通过窃听通信来侵犯用户隐私的攻击者也不容易阻止,特别是在大规模情况下。这些威胁使手机用户和运营商都容易受到攻击。这一美日联合项目旨在提供强大的安全监控和隐私保护解决方案,利用可编程开关的高速、可编程网络接口卡的增强功能以及终端主机服务器的内存/计算能力。通过利用每个数据平面组件的优势,该项目将开发高效且性能卓越的蜂窝网络安全解决方案。为了实现这一目标,这个美日联合项目将执行由美国和日本的私人投资机构合作完成的技术任务。首先,该团队将设计一个异类数据平面框架,将多个数据平面设备紧密结合在一起进行网络功能处理。该方法将使用协作过滤系统,其中大部分流量仅由高速可编程交换机处理,这些交换机可以轻松提取聚合的粗粒度指标。可疑流量将被重定向至可编程网络接口卡或主机(如有必要),以进行进一步检查和指标收集。其次,该项目将利用蜂窝核心网络作为关键优势,开发对蜂窝流量的实时监控。在蜂窝核心进行监控不仅可以有效地检测和阻止基于数据平面的攻击,而且还可以检测和阻止控制平面上的攻击。它处于能够在数据和控制平面状态之间关联的独特位置,以进一步改进现有的检测安全攻击的方法。最后,该项目将设计隐私保护机制,确保用户在面临指纹攻击时的匿名性。该方法将利用流量变形技术,该技术利用多层、可编程的异类数据平面框架的所有功能,以实现高速运营。建议的技术将产生重大的社会影响,为蜂窝网络用户及其流量提供强大的威胁防御和隐私保护。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Timothy Wood其他文献

Poster: Toward Zero-Trust Path-Aware Access Control
海报:走向零信任路径感知访问控制
5GPerf: profiling open source 5G RAN components under different architectural deployments
5GPerf:分析不同架构部署下的开源 5G RAN 组件
Towards a Scalable 5G RAN Central Unit
迈向可扩展的 5G RAN 中央单元
Exploring user perspectives of factors associated with use of teletrauma in rural areas.
探索用户对农村地区使用远程创伤相关因素的看法。
  • DOI:
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    1.8
  • 作者:
    Timothy Wood;Shannon Freeman;D. Banner;M. Martin;N. Hanlon;F. Flood
  • 通讯作者:
    F. Flood
Neurodevelopmental clustering of gene expression identifies lipid metabolism genes associated with neuroprotection and neurodegeneration
基因表达的神经发育聚类识别与神经保护和神经变性相关的脂质代谢基因
  • DOI:
    10.1101/2021.09.02.458277
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Akiva A. Kohane;Timothy Wood
  • 通讯作者:
    Timothy Wood

Timothy Wood的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Timothy Wood', 18)}}的其他基金

NSF Student Travel Grant for the 2019 ACM SIGCOMM Conference
2019 年 ACM SIGCOMM 会议 NSF 学生旅行补助金
  • 批准号:
    1929390
  • 财政年份:
    2019
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
CRI: CI-EN: Collaborative Research: OpenNetVM: A Software Platform Enabling Network Function Virtualization Research
CRI:CI-EN:协作研究:OpenNetVM:支持网络功能虚拟化研究的软件平台
  • 批准号:
    1823236
  • 财政年份:
    2018
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
CSR: Collaborative Research: Mobile Elastic Edge Clouds for Scalable, Low-Latency Services
CSR:协作研究:用于可扩展、低延迟服务的移动弹性边缘云
  • 批准号:
    1763548
  • 财政年份:
    2018
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
NSF Student Travel Grant for 2018 ACM/IFIP/Usenix Middleware Conference
2018 年 ACM/IFIP/Usenix 中间件会议 NSF 学生旅费补助
  • 批准号:
    1838654
  • 财政年份:
    2018
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Collaborative: Fine Grained Protection for Scalable Single-Use Services
SaTC:核心:小型:协作:可扩展一次性服务的细粒度保护
  • 批准号:
    1814234
  • 财政年份:
    2018
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
CNS: Student Travel Support for the 2017 Middleware Conference
CNS:2017 年中间件会议学生旅行支持
  • 批准号:
    1742783
  • 财政年份:
    2017
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
TWC: Small: Collaborative: EVADE: Evidence-Assisted Detection and Elimination of Security Vulnerabilities
TWC:小型:协作:EVADE:证据辅助检测和消除安全漏洞
  • 批准号:
    1525992
  • 财政年份:
    2015
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
NeTS: Small: Collaborative Research: Software Defined Network Function Virtualization (SDNFV) - Flexible, High Performance Network and Data Center Virtualization
NeTS:小型:协作研究:软件定义网络功能虚拟化 (SDNFV) - 灵活、高性能的网络和数据中心虚拟化
  • 批准号:
    1422362
  • 财政年份:
    2014
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
CAREER: Application-Agnostic, Distributed-Aware Cloud Platforms
职业:与应用程序无关的分布式感知云平台
  • 批准号:
    1253575
  • 财政年份:
    2013
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Continuing Grant

相似国自然基金

Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 批准年份:
    2024
  • 资助金额:
    0.0 万元
  • 项目类别:
    省市级项目
Cell Research
  • 批准号:
    31224802
  • 批准年份:
    2012
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research
  • 批准号:
    31024804
  • 批准年份:
    2010
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research (细胞研究)
  • 批准号:
    30824808
  • 批准年份:
    2008
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
  • 批准号:
    10774081
  • 批准年份:
    2007
  • 资助金额:
    45.0 万元
  • 项目类别:
    面上项目

相似海外基金

Collaborative Research: NeTS: Small: A Privacy-Aware Human-Centered QoE Assessment Framework for Immersive Videos
协作研究:NetS:小型:一种具有隐私意识、以人为本的沉浸式视频 QoE 评估框架
  • 批准号:
    2343619
  • 财政年份:
    2024
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NeTS: Small: A Privacy-Aware Human-Centered QoE Assessment Framework for Immersive Videos
协作研究:NetS:小型:一种具有隐私意识、以人为本的沉浸式视频 QoE 评估框架
  • 批准号:
    2343618
  • 财政年份:
    2024
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NeTS: Medium: EdgeRIC: Empowering Real-time Intelligent Control and Optimization for NextG Cellular Radio Access Networks
合作研究:NeTS:媒介:EdgeRIC:为下一代蜂窝无线接入网络提供实时智能控制和优化
  • 批准号:
    2312978
  • 财政年份:
    2023
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NeTS: Small: Digital Network Twins: Mapping Next Generation Wireless into Digital Reality
合作研究:NeTS:小型:数字网络双胞胎:将下一代无线映射到数字现实
  • 批准号:
    2312138
  • 财政年份:
    2023
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NeTS: Small: Digital Network Twins: Mapping Next Generation Wireless into Digital Reality
合作研究:NeTS:小型:数字网络双胞胎:将下一代无线映射到数字现实
  • 批准号:
    2312139
  • 财政年份:
    2023
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NeTS: Medium: Towards High-Performing LoRa with Embedded Intelligence on the Edge
协作研究:NeTS:中:利用边缘嵌入式智能实现高性能 LoRa
  • 批准号:
    2312676
  • 财政年份:
    2023
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NeTS: Medium: Black-box Optimization of White-box Networks: Online Learning for Autonomous Resource Management in NextG Wireless Networks
合作研究:NeTS:中:白盒网络的黑盒优化:下一代无线网络中自主资源管理的在线学习
  • 批准号:
    2312835
  • 财政年份:
    2023
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NeTS: Medium: An Integrated Multi-Time Scale Approach to High-Performance, Intelligent, and Secure O-RAN based NextG
合作研究:NeTS:Medium:基于 NextG 的高性能、智能和安全 O-RAN 的集成多时间尺度方法
  • 批准号:
    2312447
  • 财政年份:
    2023
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NeTS: Medium: Large Scale Analysis of Configurations and Management Practices in the Domain Name System
合作研究:NetS:中型:域名系统配置和管理实践的大规模分析
  • 批准号:
    2312711
  • 财政年份:
    2023
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NeTS: Medium: Black-box Optimization of White-box Networks: Online Learning for Autonomous Resource Management in NextG Wireless Networks
合作研究:NeTS:中:白盒网络的黑盒优化:下一代无线网络中自主资源管理的在线学习
  • 批准号:
    2312836
  • 财政年份:
    2023
  • 资助金额:
    $ 22.5万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了