CAREER: Programmable In-network Security
CAREER: Programmable In-network Security
批准号:
2420309
负责人:
Ang Chen
金额:
$55.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
已结题
起止时间:
2023-10-01 至 2024-12-31
中文摘要
对互联网的攻击造成了数十亿美元的经济损失。虽然今天的互联网是为了向世界各地的个人和企业提供广泛的连接而开发的,但支持互联网的网络并没有内置的安全机制。该项目的重点是通过研究基于新网络技术的未来网络设计来解决该问题,这些新网络技术将支持安全性并提供跨各种攻击的防御。该项目的愿景是开发可编程网络安全,或“Poise”。Poise旨在利用网络可编程性的技术趋势,直接在网络内设计和集成广泛的防御。如果成功,Poise网络将支持安全性,就像今天的网络支持连接性一样自然。该项目将为网络安全开发新的科学基础,调查实际用例,发布开源工具,并制作教育材料。Poise的潜在影响是使未来的网络从根本上比现在更安全。该项目提出了可编程网络安全的愿景,或“平衡”,根据最近的趋势,网络设备变得越来越可编程,并以支持安全作为一流的网络属性为目标。该项目计划采取三管齐下的方法来实现这一目标。首先,Poise旨在通过设计驻留在交换机中的各种安全应用程序,将可编程交换机转变为防御平台。其次,Poise旨在通过将防御应用程序架构到网络路径中并同步它们以实现全网防御,将可编程交换机网络转变为防御舰队。第三,Poise寻求确保防御应用程序(单独和集体)本身免受攻击。在其最终体现中,Poise网络将在流量通过时快速切换各种防御,实时减轻攻击。该项目将在上述三个方面推进网络安全的最新技术,并将产生科学基础和可重用系统原型。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Attacks on the Internet cost the economy billions of dollars. While today’s Internet was developed to provide widespread connectivity to individuals and businesses across the world, the networks that support the Internet do not have built-in security mechanisms. This project is focused on solving that problem by investigating future network designs based on new network technology that would support security and provide defense across a wide variety of attacks. The project vision is to develop Programmable In-network Security, or ‘Poise’. Poise aims to design and integrate a wide range of defenses directly inside the network, leveraging the technology trend of network programmability. If successful, a Poise network would support security as naturally as today’s networks support connectivity. This project will develop new scientific foundations for network security, investigate practical use cases, release open-source tools, and produce educational materials. The potential impact of Poise is to make future networks fundamentally more secure than they are today. This project presents a vision of Programmable In-network Security, or ‘Poise’, informed by the recent trend that network devices are becoming increasingly programmable, and with a goal of supporting security as a first-class network attribute. The project plans to take a three-pronged approach to realizing this goal. First, Poise aims to transform a programmable switch into a defense platform by designing a wide range of security applications that reside in the switch. Second, Poise aims to transform a network of programmable switches into a defense fleet, by architecting defense applications into the network paths and synchronizing them for whole-network defense. Third, Poise seeks to ensure that the defense applications, individually and collectively, are themselves secure against attacks. In its ultimate embodiment, a Poise network would toggle a wide array of defenses rapidly on and off as traffic flows through, mitigating attacks in real time. This project will advance the state of the art in network security in the above three dimensions and will produce scientific foundations and reusable system prototypes.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
-
批准号:2406598
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2023
-
负责人:Ang Chen
-
依托单位:
Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
-
批准号:2345339
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2023
-
负责人:Ang Chen
-
依托单位:
I-Corps: A Learned Cloud Infrastructure-as-Code (IaC) Linter
-
批准号:2344828
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2023
-
负责人:Ang Chen
-
依托单位:
Collaborative Research: CNS Core: Large: Runtime Programmable Networks
-
批准号:2214272
-
项目类别:Continuing Grant
-
资助金额:$120.0万
-
财政年份:2022
-
负责人:Ang Chen
-
依托单位:
Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
-
批准号:2106388
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2021
-
负责人:Ang Chen
-
依托单位:
Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
-
批准号:2106751
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2021
-
负责人:Ang Chen
-
依托单位:
CAREER: Programmable In-network Security
-
批准号:1942219
-
项目类别:Continuing Grant
-
资助金额:$55.0万
-
财政年份:2020
-
负责人:Ang Chen
-
依托单位:
NeTS: Medium: Streaming Data Analytics over Programmable Datacenter Networks
-
批准号:1801884
-
项目类别:Continuing Grant
-
资助金额:$120.0万
-
财政年份:2018
-
负责人:Ang Chen
-
依托单位:
海外基金