CICI: Secure and Resilient Architecture: Effective and Economical Protection for High-Performance Research and Education Networks
CICI: Secure and Resilient Architecture: Effective and Economical Protection for High-Performance Research and Education Networks
批准号:
1642161
负责人:
Johanna Amann
金额:
$99.95万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-10-01 至 2022-09-30
中文摘要
科学研究需要全世界合作者之间自由交流信息和想法。为此,科学家们严重依赖互联网的全面开放。然而,在当今世界,这种开放访问也使网站面临不断的网络攻击,如信息盗窃,寄生资源消耗,或遭受(或无意中参与)拒绝服务(DOS)攻击。如今,一些最强大的网络仍然特别难以防御:100G环境和骨干网促进了现代数据密集型科学-物理学,天文学,医学,气候研究-证明对最轻微的干扰非常敏感。对于这些网络,传统的企业解决方案,如防火墙和入侵检测系统(IDS),仍然是不可行的,因为他们不能在如此高的速度可靠地运行。该项目开发了一个新颖的综合框架,将软件和硬件集成在一起,以经济地保护关键的高性能科学基础设施。该项目通过将低级操作从软件卸载到硬件(如交换机和计算机网络接口卡)来提高网络监控的性能。该项目使网络监控系统能够与正在开发的硬件卸载相结合。此外,该项目还扩大了网络监测系统的能力,使科学网络具有可见性,例如,增加了对用于高速科学数据传输的协议的支持。它还扩展了对恶意活动(如拒绝服务攻击)的主动响应支持。该项目在开源Bro网络安全监控器中实现了这些功能,该监控器被全国许多NSF支持的组织用于保护其科学网络基础设施。
英文摘要
Scientific research requires the free exchange of information and ideas among collaborators worldwide. For this, scientists depend critically on full and open access to the Internet. Yet in today's world, such open access also exposes sites to incessant network attacks like theft of information, parasitic resource consumption, or suffering from (or inadvertently participating in) denial-of-service (DOS) attacks. Some of the most powerful networks today remain particularly hard to defend: the 100G environments and backbones that facilitate modern data-intensive sciences - physics, astronomy, medicine, climate research - prove extremely sensitive to the slightest disturbances. For these networks, traditional enterprise solutions such as firewalls and intrusion detection systems (IDS), remain infeasible as they cannot operate reliably at such high speeds. This project develops a novel, comprehensive framework that integrates software and hardware for the economical protection of critical high-performance science infrastructure.The project increases the performance of network monitoring by offloading low-level operations from software into hardware, such as switches and computer network interface cards. The project enables network monitoring systems to tie into the hardware offloading being developed. Furthermore, the project expands the capabilities of network monitoring systems to create visibility into science networks, for example, by adding support for the protocols used for high-speed scientific data transfers. It also extends support for responding actively to malicious activity like denial-of-service attacks. This project implements these capabilities in the open-source Bro network security monitor utilized by many NSF-supported organizations nationwide to protect their scientific cyberinfrastructure.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Viable Protection of High-Performance Networks through Hardware/Software Co-Design
通过硬件/软件协同设计对高性能网络提供可行的保护
DOI:
10.1145/3040992.3041003
发表时间:
2017
期刊:
Proceedings of the ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization
影响因子:
--
作者:
[Amann, Johanna, Sommer, Robin]
通讯作者:
Sommer, Robin
TWC: TTP Option: Small: Understanding the State of TLS Using Large-scale Passive Measurements
-
批准号:1528156
-
项目类别:Standard Grant
-
资助金额:$66.36万
-
财政年份:2015
-
负责人:Johanna Amann
-
依托单位:
A Bro Center of Expertise for the NSF Community
-
批准号:1348077
-
项目类别:Standard Grant
-
资助金额:$336.01万
-
财政年份:2013
-
负责人:Johanna Amann
-
依托单位:
海外基金