CICI: RSARC: DICE - Data Insurance in the Cluster Environment
CICI: RSARC: DICE - Data Insurance in the Cluster Environment
批准号:
1738912
负责人:
Zhi Wang
金额:
$59.03万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-15 至 2022-07-31
中文摘要
高性能、分布式计算在解决复杂的科学、工程和业务问题方面已经变得不可或缺。计算机集群中生成和存储的数据的完整性对科学研究和商业智能具有无可争议的重要性,因为受损的数据可能导致错误的结论和决策。不幸的是,用于高性能和分布式计算系统的现有安全机制非常复杂、不一致、不安全且难以部署。许多利用当前安全机制的系统根本不能提供足够的保护,甚至容易受到微不足道的攻击。例如,最近的研究发现,数千个未受保护的数据库安装和计算机集群遭到了黑客攻击。因此,迫切需要提高高性能和分布式计算系统的安全性。该项目为高性能和分布式计算系统开发了一个安全框架,该框架采用强大的现代加密算法,易于推理、部署和使用,不需要冗长且容易出错的配置。该项目由三个主要组件组成:一个基于容器的虚拟集群,一个防御侧通道攻击的组件,以及一个用于审计的安全执行分类账。第一个组件是在不牺牲可用性或性能的情况下为集群启用身份验证、授权和数据保护的关键。项目团队将基于流行的Docker容器构建虚拟集群,并通过灵活的密钥管理、减少攻击面和安全强化(包括防御侧通道攻击)对其进行增强。虚拟集群节点之间的通信和I/O操作是透明加密的,以保护传输中的数据和静态数据。安全执行分类账提供了整个系统中程序执行的全局整体视图,允许审计单个用户和用户组的行为。通过紧密集成这三个组件,该项目力求实现对集群数据安全四大支柱的有力支持。认证、授权、审计和数据保护。
英文摘要
High-performance, distributed computing has become indispensable in solving complex scientific, engineering, and business problems. The integrity of the data generated and stored on computer clusters is of undisputed importance to scientific research and business intelligence, as compromised data can lead to incorrect conclusions and decisions. Unfortunately, existing security mechanisms for high-performance and distributed computing systems are complex, inconsistent, insecure, and difficult to deploy. Many systems utilizing the current security mechanisms simply do not provide sufficient protection and remain vulnerable to even trivial attacks. For example, recent studies have found that thousands of unprotected database installations and computer clusters have been hacked. As such, there is a pressing need to improve the security of high-performance and distributed computing systems. This project develops a security framework for high-performance and distributed computing systems that employs strong modern cryptographic algorithms, and is easy to reason, deploy, and use without lengthy and error-prone configurations. The project consists of three major components: a container-based virtual cluster, a component to defend against side-channel attacks, and a secure execution ledger for auditing. The first component is the key to enabling authentication, authorization, and data protection for clusters without sacrificing usability or performance. The project team will build the virtual cluster based on the popular Docker container but enhance it with flexible key management, attack surface reduction, and security hardening, including defenses against side-channel attacks. Communications among nodes of a virtual cluster and I/O operations are transparently encrypted to protect the data in transition and at rest. The secure execution ledger provides a global holistic view of program execution in the whole system, allowing auditing the behavior of individual users as well as user groups. By tightly integrating these three components, the project seeks to achieve strong support for the four pillars of the cluster data security ? authentication, authorization, auditing, and data protection.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Topology-custom UGAL routing on dragonfly
Dragonfly 上的拓扑自定义 UGAL 路由
DOI:
10.1145/3295500.3356208
发表时间:
2019
期刊:
Storage and Analysis
影响因子:
--
作者:
[Rahman, Md Shafayat, Bhowmik, Saptarshi, Ryasnianskiy, Yevgeniy, Yuan, Xin, Lang, Michael]
通讯作者:
Lang, Michael
Encrypted All-reduce on Multi-core Clusters
多核集群上的加密 All-reduce
DOI:
10.1109/ipccc51483.2021.9679399
发表时间:
2021
期刊:
and Communications Conference (IPCCC
影响因子:
--
作者:
[Gavahi, Mohsen, Naser, Abu, Wu, Cong, Lahijani, Mehran Sadeghi, Wang, Zhi, Yuan, Xin]
通讯作者:
Yuan, Xin
DOI:
10.1109/cluster.2019.8891033
发表时间:
2019
期刊:
IEEE International Conference on Cluster Computing (CLUSTER
影响因子:
--
作者:
[Naser, Abu, Gavahi, Mohsen, Wu, Cong, Hoang, Viet Tung, Wang, Zhi, Yuan, Xin]
通讯作者:
Yuan, Xin
DOI:
--
发表时间:
2022
期刊:
影响因子:
--
作者:
[V. Hoang;Cong Wu;Xin Yuan]
通讯作者:
V. Hoang;Cong Wu;Xin Yuan
DOI:
10.1145/3133956.3133995
发表时间:
2017-10
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[M. Bellare;V. Hoang]
通讯作者:
M. Bellare;V. Hoang
共 9 条
CAREER: Towards Trustworthy Operating Systems
-
批准号:1453020
-
项目类别:Continuing Grant
-
资助金额:$49.97万
-
财政年份:2015
-
负责人:Zhi Wang
-
依托单位:
海外基金