HECURA: Exploiting Asymmetry in Performance and Security Requirements for I/O in High-end Computing
HECURA: Exploiting Asymmetry in Performance and Security Requirements for I/O in High-end Computing
批准号:
0621429
负责人:
Anand Sivasubramaniam
金额:
$69.97万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-08-15 至 2010-07-31
中文摘要
处理速度和I/O性能之间越来越大的差距仍然是限制大型科学应用程序可伸缩性的一个因素。应用程序变得越来越数据密集,需要大的存储容量和高带宽访问这些存储。此外,应用科学更具协作性,数据集共享不仅在单个组织的用户/应用程序之间变得普遍,而且跨组织也对存储系统提出了更高的性能要求。考虑到许多这些应用程序的敏感性,除了性能要求外,还迫切需要保护这些数据免受对抗性攻击。安全漏洞的后果可能会产生深远的影响,远远超出检测和调查此类漏洞的成本。同时,不能在物理上完全限制数据,因为这些数据需要由来自不同管理域的协作应用程序共享。法规还要求维护审计记录和数据来源。这项研究的动机是需要安全的存储系统,以满足高端应用的需求,同时满足其严格的性能要求。这两个目标——性能和安全性——通常是相互矛盾的,优化其中一个的机制通常是以牺牲另一个为代价的。在建议的DataVault框架中,认识到不同的环境:(i)具有不同的存储架构,(ii)需要防范不同类型的威胁,并且可能(iii)在实施安全机制时对相关性能开销有不同的容忍度。而不是有一个解决方案适合所有的方法,pi建议调查丰富的设计空间-威胁,存储架构,执行机制,性能-提供有洞察力的选择,可以在部署/定制存储系统时有用。DataVault还将包括一个可用的目标驱动策略接口,用于为给定的安全和性能需求配置系统,同时为安全管理提供方便的可视化仪表板。
英文摘要
The growing disparity between processing speeds and I/O performance continues to be a limiting factor in the scalability of large scientific applications. Applications are becoming more data intensive, requiring large storage capacities and high bandwidth access to this storage. Further, application sciences are more collaborative, with sharing of data sets becoming prevalent not just between users/applications of a single organization, but across organizations as well placing even higher performance requirements on the storage system. Given the sensitive nature of many of these applications, in addition to the performance demands, there is an impending need to secure such data from adversarial attacks. The consequences of security breaches can have far reaching consequences, over and beyond the costs of detecting and investigating such breaches. At the same time, one cannot fully confine the data physically since these need to be shared by collaborative applications from different administrative domains. Regulations are also mandating the maintenance of audit records and provenance of data.The motivation for this research is driven by the need to secure storage systems which cater to the demands of high-end applications, while meeting their stringent performance requirements. These two goals - performance and security - are often contradictory, with the mechanisms for optimizing one usually coming at the expense of the other. In the proposed DataVault framework, it is recognized that different environments: (i) have diverse storage architectures, (ii) need to guard against different kinds of threats, and may (iii) have different tolerances for the associated performance overheads when implementing the security mechanisms. Rather than have a one-solution-fits-all approach, The PIs propose to investigate the rich design space - threats, storage architecture, enforcement mechanism, performance - to offer insightful choices that can be useful when deploying/customizing storage systems. DataVault will also include a usable objective-driven policy interface to configure the system for a given set of security and performance needs, while offering a convenient visualization dashboard for security management.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
FoMR: Shrinking the Control and Data Flow Latencies of Single Thread Executions for Emerging Workloads
-
批准号:1912495
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2019
-
负责人:Anand Sivasubramaniam
-
依托单位:
SHF:Small: Integrated Hardware-Software Power Regulation, Allocation and Isolation in Consolidated Servers
-
批准号:1714389
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2017
-
负责人:Anand Sivasubramaniam
-
依托单位:
SHF: Small: Virtualizing Coordinated Resource Management of Flows on Handhelds with VIADUCT
-
批准号:1526750
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2015
-
负责人:Anand Sivasubramaniam
-
依托单位:
CSR: Medium: Provisioning and Harnessing Energy Storage for Datacenter Demand Response
-
批准号:1302225
-
项目类别:Continuing Grant
-
资助金额:$99.85万
-
财政年份:2013
-
负责人:Anand Sivasubramaniam
-
依托单位:
Collaborative Research: Application-adaptive I/O Stack for Data-intensive Scientific Computing
-
批准号:0621427
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2006
-
负责人:Anand Sivasubramaniam
-
依托单位:
Collaborative Research: CSR---SMA+AES: Pro-Active Runtime Health Enhancement of Large-Scale Parallel Systems Using PROGNOSIS
-
批准号:0615097
-
项目类别:Continuing Grant
-
资助金额:$35.69万
-
财政年份:2006
-
负责人:Anand Sivasubramaniam
-
依托单位:
Collaborative Research: CSR-SMA+AES: PROGNOSIS to Enhance the Runtime Health of Large Scale Parallel Systems
-
批准号:0509234
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2005
-
负责人:Anand Sivasubramaniam
-
依托单位:
Tools and Techniques for Integrated Power Management of Server Disks
-
批准号:0429500
-
项目类别:Continuing Grant
-
资助金额:$19.0万
-
财政年份:2004
-
负责人:Anand Sivasubramaniam
-
依托单位:
ITR: Data-Driven Autonomic Performance Modulation for Servers
-
批准号:0325056
-
项目类别:Continuing Grant
-
资助金额:$55.06万
-
财政年份:2003
-
负责人:Anand Sivasubramaniam
-
依托单位:
CISE Research Resources: From High Performance to Low Power: Infrastructure for Ubiquitous Computing
-
批准号:0130143
-
项目类别:Standard Grant
-
资助金额:$4.96万
-
财政年份:2002
-
负责人:Anand Sivasubramaniam
-
依托单位:
NGS: POWERful Software for Power Constrained Systems
-
批准号:0103583
-
项目类别:Continuing Grant
-
资助金额:$60.07万
-
财政年份:2001
-
负责人:Anand Sivasubramaniam
-
依托单位:
Scheduling Support for High Performance Clusters
-
批准号:9988164
-
项目类别:Continuing Grant
-
资助金额:$19.5万
-
财政年份:2000
-
负责人:Anand Sivasubramaniam
-
依托单位:
CAREER: Realizing Cost-effective Parallel Systems Using an Application-driven Approach
-
批准号:9701475
-
项目类别:Standard Grant
-
资助金额:$22.29万
-
财政年份:1997
-
负责人:Anand Sivasubramaniam
-
依托单位:
海外基金