课题基金 / 基金详情

CAREER: Programmable In-network Security

CAREER: Programmable In-network Security
职业:可编程网络安全
批准号:
2420309
负责人:
Ang Chen
金额:
$55.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
已结题
起止时间:
2023-10-01 至 2024-12-31

项目摘要

项目成果

Ang Chen的其他基金

相似基金

相关文献

中文摘要
翻译
对互联网的攻击给经济造成了数十亿美元的损失。虽然今天的互联网是为了向世界各地的个人和企业提供广泛的连接而开发的,但支持互联网的网络没有内置的安全机制。该项目的重点是通过调查基于新网络技术的未来网络设计来解决这一问题,新网络技术将支持安全并针对各种攻击提供防御。该项目的愿景是开发可编程的网络内安全,或‘Poise’。Poise的目标是利用网络可编程性的技术趋势,直接在网络内设计和集成各种防御措施。如果成功,一个稳定的网络将支持安全,就像今天的网络支持连接一样。该项目将为网络安全开发新的科学基础,调查实际使用案例,发布开源工具,并制作教育材料。Poise的潜在影响是使未来的网络从根本上比今天更安全。这个项目提出了可编程网络安全的愿景,或称“Poise”,受最近的趋势启发,网络设备正变得越来越可编程,并以支持安全为一流的网络属性为目标。该项目计划采取三管齐下的方法来实现这一目标。首先,Poise的目标是通过设计驻留在交换机中的各种安全应用程序,将可编程交换机转变为防御平台。其次,Poise的目标是将可编程交换机网络转变为防御舰队,方法是将防御应用程序构建到网络路径中,并使它们同步以进行全网络防御。第三,Poise寻求确保防御应用程序本身不受攻击,无论是单独的还是集体的。在其终极实施例中,平衡网络将在流量流经时快速开启和关闭广泛的防御系统,从而实时减轻攻击。该项目将在上述三个方面推进网络安全的最新发展,并将产生科学基础和可重复使用的系统原型。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Attacks on the Internet cost the economy billions of dollars. While today’s Internet was developed to provide widespread connectivity to individuals and businesses across the world, the networks that support the Internet do not have built-in security mechanisms. This project is focused on solving that problem by investigating future network designs based on new network technology that would support security and provide defense across a wide variety of attacks. The project vision is to develop Programmable In-network Security, or ‘Poise’. Poise aims to design and integrate a wide range of defenses directly inside the network, leveraging the technology trend of network programmability. If successful, a Poise network would support security as naturally as today’s networks support connectivity. This project will develop new scientific foundations for network security, investigate practical use cases, release open-source tools, and produce educational materials. The potential impact of Poise is to make future networks fundamentally more secure than they are today. This project presents a vision of Programmable In-network Security, or ‘Poise’, informed by the recent trend that network devices are becoming increasingly programmable, and with a goal of supporting security as a first-class network attribute. The project plans to take a three-pronged approach to realizing this goal. First, Poise aims to transform a programmable switch into a defense platform by designing a wide range of security applications that reside in the switch. Second, Poise aims to transform a network of programmable switches into a defense fleet, by architecting defense applications into the network paths and synchronizing them for whole-network defense. Third, Poise seeks to ensure that the defense applications, individually and collectively, are themselves secure against attacks. In its ultimate embodiment, a Poise network would toggle a wide array of defenses rapidly on and off as traffic flows through, mitigating attacks in real time. This project will advance the state of the art in network security in the above three dimensions and will produce scientific foundations and reusable system prototypes.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
I-Corps: A Learned Cloud Infrastructure-as-Code (IaC) Linter
Collaborative Research: CNS Core: Large: Runtime Programmable Networks
  • 批准号:
    2214272
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $120.0万
  • 财政年份:
    2022
  • 负责人:
    Ang Chen
  • 依托单位:
海外基金