课题基金 / 基金详情

II-EN: High-Performance Network Monitoring Infrastructure For Research in a Large-Scale Operational Environment

II-EN: High-Performance Network Monitoring Infrastructure For Research in a Large-Scale Operational Environment
II-EN:用于大规模运营环境研究的高性能网络监控基础设施
批准号:
0855125
负责人:
Robin Sommer
金额:
$20.79万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-08-01 至 2011-07-31

项目摘要

项目成果

Robin Sommer的其他基金

相似基金

相关文献

中文摘要
翻译
该奖项是根据2009年美国复苏和再投资法案(公法111-5)资助的。开发安全监控以强有力地保护大型站点免受互联网攻击,提出了异常困难的研究挑战。在部门局域网(通常用于学术研究的评估)等小规模环境中检测攻击者与在大型站点的规模中检测攻击者之间存在着天壤之别。在少量背景流量下工作良好的算法在面对两个数量级的背景流量时可能会变得完全无用,原因是性能和由更大的多样性引起的误报。该提案的总体目标是大大加强我们加州大学伯克利分校监控校园边境交通的基础设施,以促进与该国最大的学术网络环境之一的运营需求相关的安全研究的继续进行。提出的新集群将作为许多未来研究的强大研究平台,为深入分析大规模作战网络提供前所未有的能力。此外,在技术层面上,它将允许主要研究人员(pi)系统地评估我们的集群方法对更大网络负载的可伸缩性,并确定为其他环境提供深度监控功能所需的内容。智力优势:智力优势:本提案支持的仪器基础设施将成为一系列研究的关键推动者,否则不可能以同等规模进行研究。这些跨越:(1)在高度多样化的背景流量中稳健运行的检测算法;(2)对非常广泛的现代网络应用进行深度语义分析;(3)高效记录用于取证分析的大容量流量流;(4)可扩展性评估用于实现高性能监控的聚类和多核技术;(5)与加州大学伯克利分校网络安全人员建立联系,对部署网络防御时出现的新研究问题进行调查。更广泛的影响:实时监控大型流量流的能力对互联网安全具有重要意义,因为它是确保大型互联网站点安全的关键组件。这一努力将使一系列研究能够直接建立在高性能、高容量场地的业务基础上,由于后勤和技术方面的重大困难,这种环境在实地只得到很少的处理。监测系统将实现比我们所知的任何现有部署提供的更大数量级的分析能力。因此,它不仅可以作为以前无法实现的规模的网络安全研究平台,还可以作为其他人如何构建和操作此类系统的范例。因此,这项工作有可能使保护大容量网络环境的新发现成为可能,并促进更广泛地使用这种技术来更好地保护和运行高速网络。最后,这项资助的基础设施将为博士生提供在该领域无与伦比的环境中进行研究的无与伦比的机会。
英文摘要
This award is funded under the American Recovery and Reinvestment Act of 2009 (Public Law 111-5).Developing security monitoring to robustly protect large sites against Internet attacks presents exceptionally difficult research challenges. There is a world of difference between detecting attackers in a small-scale environment such as a departmental LAN (as is often used for evaluation of academic studies) and doing so at the scale of a large site. Algorithms that work fine in the presence of a modicum of background traffic can be rendered completely useless when faced with two orders of magnitude more background traffic, for reasons of both performance and false positives induced by the much greater diversity. The overall objective of this proposal is to greatly enhance our UC Berkeley infrastructure that monitors the campus border traffic in order to facilitate the continuation of security research tied to the operational requirements of one of the largest academic network environments in the country. The proposed new cluster will serve as a powerful research platform for many future studies, providing unprecedented capabilities for analyzing a large-scale operational network in depth. Furthermore, on a technical level it will allow the principal investigators (PIs) to systematically assess the scalability of the our clusterized approach to larger network loads and determine what is required to provide in-depth monitoring capabilities for other environments. Intellectual merit: Intellectual Merit: The instrumentation infrastructure supported by this proposal will serve as the key enabler for a range of research otherwise not possible to undertake at an equivalent scale. These span: (1) detection algorithms that operate robustly in the presence of highly diverse background traffic, (2) indepth semantic analysis of the very broad range of modern network applications, (3) efficient recording of high-volume traffic streams for forensic analysis, (4) scalability assessment of clustering and multicore techniques for achieving high performance monitoring, and (5) ties with the UC Berkeley cybersecurity staff leading to investigation of new research problems that arise when deploying network defenses operationally. Broader impact: The ability to richly monitor large traffic streams in real-time has major implications for Internet security, as it is a key component for securing large Internet sites. This effort will enable a range of research directly grounded in the operations of a high-performance, high-volume site, a type of environment only very lightly addressed in the field due to its significant logistical and technical difficulties. The monitoring system will realize an order of magnitude more power for such analysis than to our knowledge any existing deployment provides. As such, it will serve not only as a platform for network security research at scales previously unattainable, but also as an exemplar for how others can construct and operate such systems. Thus, this effort has the potential both to enable new discoveries regarding protecting high-volume network environments, and to facilitate the broader use of such technology for better securing and operating high-speed networks. Finally, the infrastructure from this grant will provide doctoral students with an unparalleled opportunity for undertaking research in an environment unmatched by any other in the field.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: Option: Medium: Collaborative: Semantic Security Monitoring for Industrial Control Systems
TWC: Phase: Medium: Collaborative Proposal: Understanding and Exploiting Parallelism in Deep Packet Inspection on Concurrent Architectures
TC: Medium: Understanding and Managing the Impact of Global Inference on Online Privacy
SDCI Sec Improvement: Enhancing Bro for Operational Network Security Monitoring in Scientific Environments
国内基金
海外基金
微尺度横移近场直写仿生支架阻断En1-YAP通路促进创面无瘢痕愈合的作用及机制研究
  • 批准号:
    JCZRQNB202600572
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
  • 依托单位:
EN1通过USP18去泛素化调控ACLY蛋白稳定性诱导脂质代谢重编程促进膀胱癌进展的机制研究
  • 批准号:
    2025JJ50549
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    尹焯
  • 依托单位:
儿童 IBD 采用EN 联合微生态制剂治疗的临床疗效及对肠道菌群、微炎症状态与免疫系统的影响
  • 批准号:
    2024JJ7051
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
微流控集成3D打印构建毛囊嵌合器官芯片通过乳酸/Bmp2/En1轴介导创面毛囊再生及无瘢痕愈合
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    15.0万元
  • 批准年份:
    2024
  • 负责人:
    黄俊飞
  • 依托单位: