Security Techniques for Virtualized Networks
虚拟化网络的安全技术
基本信息
- 批准号:RGPIN-2018-05323
- 负责人:
- 金额:$ 2.48万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Discovery Grants Program - Individual
- 财政年份:2019
- 资助国家:加拿大
- 起止时间:2019-01-01 至 2020-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The trend to move network management from hardware-based to software-based "virtualized" networks is rapidly getting stronger for economic, technical, and environmental reasons. In virtualized networks, hardware-based network nodes (routers, switches, firewalls, etc.) are replaced with software-based systems that are hosted in virtual machines in the cloud. There is a significant promise of cost reduction and higher resource utilization. Moreover, as this trend relies on software for setup and operation, virtualization is expected to expedite the processes of creating and changing computing and network services. It should also make it easier to create services that were not easily implementable in traditional infrastructures due to cost or scale. This area is of tremendous importance to supporting innovation and economic growth in Canada and elsewhere.******Network virtualization will be prevalent in different types of networks: private, public, and hybrid. At the heart of this trend is a significant concern about information security while network elements do not obey the traditional security principles where a physical security perimeter could be established. This proposed research program investigates new techniques for securing virtualized infrastructures from a computer networking perspective.******Building on my expertise and my ongoing research program that started with my first Discovery Grant in 2004, the proposed research program will pursue the following distinct themes:*** Threat modelling and defining an alternative security perimeter for virtual networks. In this theme, we will investigate the creation of a substitute for a security perimeter in software-based virtual networks.*** Building resilience to attacks into the design of virtualized networks. This gives these networks the ability to sustain attacks and continue to function at a certain level during attacks while other means of defences are being sought. *** Creating new security evaluation techniques for network applications in virtual networks to be able to assess the security impact of new network applications in these environments. ******This contributes significantly to fundamental network security research. These defences that emanate from within the network should stop the attacks closer to their sources and reduce attack amplification. Another important benefit of doing this research in creating resilient networking architecture rather than creating a new defence for every type of attack is the prevention of the arms-race situation that we are currently facing. By the time solutions and patches are created, new attacks are appearing again and creating an arms-race like situation. Finally, this program will provide a number of highly qualified personnel with network security skills that are much needed in many industries.
出于经济、技术和环境原因,将网络管理从基于硬件的“虚拟化”网络转移到基于软件的“虚拟化”网络的趋势正在迅速增强。在虚拟化网络中,基于硬件的网络节点(路由器、交换机、防火墙等)被托管在云中虚拟机中的基于软件的系统所取代。有一个显着的承诺,降低成本和更高的资源利用。此外,由于这一趋势依赖于软件进行设置和操作,虚拟化有望加快创建和更改计算和网络服务的过程。它还应该使创建由于成本或规模而在传统基础设施中不易实现的服务变得更容易。这一领域对支持加拿大和其他地方的创新和经济增长至关重要。网络虚拟化将在不同类型的网络中流行:私有网络、公共网络和混合网络。这种趋势的核心是对信息安全的重大关注,而网络元素不遵守传统的安全原则,可以建立物理安全边界。该研究计划从计算机网络的角度研究保护虚拟化基础设施的新技术。**基于我的专业知识和我在2004年获得第一笔发现基金后开始的正在进行的研究计划,拟议的研究计划将追求以下不同的主题:* 威胁建模和定义虚拟网络的替代安全边界。在本主题中,我们将研究在基于软件的虚拟网络中创建安全边界的替代品。*在虚拟化网络的设计中建立抵御攻击的能力。这使这些网络能够承受攻击,并在攻击期间继续在一定程度上发挥作用,同时正在寻求其他防御手段。*** 为虚拟网络中的网络应用程序创建新的安全评估技术,以便能够评估新网络应用程序在这些环境中的安全影响。** 这对基础网络安全研究有重大贡献。这些来自网络内部的防御应该在更接近其来源的地方阻止攻击,并减少攻击放大。在创建弹性网络架构而不是为每种类型的攻击创建新的防御方面进行这项研究的另一个重要好处是防止我们目前面临的军备竞赛局面。当解决方案和补丁被创建时,新的攻击再次出现,并创造了一个类似军备竞赛的局面。最后,该计划将提供一些高素质的人员与网络安全技能,是许多行业急需的。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Matrawy, Ashraf其他文献
Routing Attacks and Mitigation Methods for RPL-Based Internet of Things
- DOI:
10.1109/comst.2018.2885894 - 发表时间:
2019-01-01 - 期刊:
- 影响因子:35.6
- 作者:
Raoof, Ahmed;Matrawy, Ashraf;Lung, Chung-Horng - 通讯作者:
Lung, Chung-Horng
On the Impact of Network State Collection on the Performance of SDN Applications
- DOI:
10.1109/lcomm.2015.2496955 - 发表时间:
2016-01-01 - 期刊:
- 影响因子:0
- 作者:
Aslan, Mohamed;Matrawy, Ashraf - 通讯作者:
Matrawy, Ashraf
Economic and Energy Considerations for Resource Augmentation in Mobile Cloud Computing
- DOI:
10.1109/tcc.2015.2469665 - 发表时间:
2018-01-01 - 期刊:
- 影响因子:6.5
- 作者:
Nir, Manjinder;Matrawy, Ashraf;St-Hilaire, Marc - 通讯作者:
St-Hilaire, Marc
Matrawy, Ashraf的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Matrawy, Ashraf', 18)}}的其他基金
Security Techniques for Virtualized Networks
虚拟化网络的安全技术
- 批准号:
RGPIN-2018-05323 - 财政年份:2022
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Secure Network Slicing for 5G Services
5G 服务的安全网络切片
- 批准号:
543430-2019 - 财政年份:2021
- 资助金额:
$ 2.48万 - 项目类别:
Collaborative Research and Development Grants
Security Techniques for Virtualized Networks
虚拟化网络的安全技术
- 批准号:
RGPIN-2018-05323 - 财政年份:2021
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Secure Network Slicing for 5G Services
5G 服务的安全网络切片
- 批准号:
543430-2019 - 财政年份:2020
- 资助金额:
$ 2.48万 - 项目类别:
Collaborative Research and Development Grants
Security Techniques for Virtualized Networks
虚拟化网络的安全技术
- 批准号:
RGPIN-2018-05323 - 财政年份:2020
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Secure Network Slicing for 5G Services
5G 服务的安全网络切片
- 批准号:
543430-2019 - 财政年份:2019
- 资助金额:
$ 2.48万 - 项目类别:
Collaborative Research and Development Grants
Security Techniques for Virtualized Networks
虚拟化网络的安全技术
- 批准号:
RGPIN-2018-05323 - 财政年份:2018
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Security in mobile environments
移动环境中的安全
- 批准号:
283344-2013 - 财政年份:2017
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Threat Modelling in LTE Small Cells Networks
LTE 小蜂窝网络中的威胁建模
- 批准号:
501787-2016 - 财政年份:2016
- 资助金额:
$ 2.48万 - 项目类别:
Engage Grants Program
Security in mobile environments
移动环境中的安全
- 批准号:
283344-2013 - 财政年份:2016
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
相似国自然基金
EstimatingLarge Demand Systems with MachineLearning Techniques
- 批准号:
- 批准年份:2024
- 资助金额:万元
- 项目类别:外国学者研究基金
相似海外基金
RII Track-4:NSF: Design of zeolite-encapsulated metal phthalocyanines catalysts enabled by insights from synchrotron-based X-ray techniques
RII Track-4:NSF:通过基于同步加速器的 X 射线技术的见解实现沸石封装金属酞菁催化剂的设计
- 批准号:
2327267 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Standard Grant
CAREER: Data-Driven Hardware and Software Techniques to Enable Sustainable Data Center Services
职业:数据驱动的硬件和软件技术,以实现可持续的数据中心服务
- 批准号:
2340042 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Continuing Grant
Postdoctoral Fellowship: OPP-PRF: Leveraging Community Structure Data and Machine Learning Techniques to Improve Microbial Functional Diversity in an Arctic Ocean Ecosystem Model
博士后奖学金:OPP-PRF:利用群落结构数据和机器学习技术改善北冰洋生态系统模型中的微生物功能多样性
- 批准号:
2317681 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Standard Grant
Creating a reflective, assessment workbook for University teachers to enhance teaching techniques and improve student engagement, by incorporating International Baccalaureate (IB) teaching practices
通过纳入国际文凭 (IB) 教学实践,为大学教师创建反思性评估工作簿,以提高教学技巧并提高学生参与度
- 批准号:
24K06129 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
Developing Advanced Cryptanalysis Techniques for Symmetric-key Primitives with Real-world Public-key Applications
使用现实世界的公钥应用开发对称密钥原语的高级密码分析技术
- 批准号:
24K20733 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
Development of new molecular self-temperature sensing techniques using luminescence-absorption hybrid thermometry
利用发光-吸收混合测温法开发新型分子自温度传感技术
- 批准号:
24K17691 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
Novel techniques of percutaneous sonography-guided surgical operations (SonoSurgery
经皮超声引导外科手术新技术(SonoSurgery
- 批准号:
10087309 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Collaborative R&D
ConSenT: Connected Sensing Techniques: Cooperative Radar Networks Using Joint Radar and Communication Waveforms
ConSenT:互联传感技术:使用联合雷达和通信波形的协作雷达网络
- 批准号:
EP/Y035933/1 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Fellowship
ERI: SDR Beyond Radio: Enabling Experimental Research in Multi-Node Optical Wireless Networks via Software Defined Radio Tools and Techniques
ERI:超越无线电的 SDR:通过软件定义无线电工具和技术实现多节点光无线网络的实验研究
- 批准号:
2347514 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Standard Grant
CRII: SHF: Embedding techniques for mechanized reasoning about existing programs
CRII:SHF:现有程序机械化推理的嵌入技术
- 批准号:
2348490 - 财政年份:2024
- 资助金额:
$ 2.48万 - 项目类别:
Standard Grant