Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
批准号:
2128607
负责人:
Hongxin Hu
金额:
$49.98万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-04-01 至 2022-03-31
中文摘要
随着数据密集型科学在许多科学领域成为常态,高性能数据传输正迅速成为标准的网络基础设施要求。为了满足这一要求,越来越多的大学校园部署了科学DMZ。科学DMZ是构建在园区或实验室网络边缘或边缘附近的网络的一部分,其设计使设备、配置和安全策略针对高性能科学应用而不是通用计算进行优化。该项目开发了一个名为SciGuard的安全和弹性架构,以应对科学非军事区的安全挑战和固有弱点。SciGuard基于两种新兴的网络模式,即软件定义网络(SDN)和网络功能虚拟化(NFV),这两种模式都支持保护科学非军事区所需的粒度、灵活性和弹性。两个核心安全功能,SDN防火墙应用程序和虚拟入侵检测系统(IDS)共存于SciGuard中,用于保护科学非军事区。SDN防火墙应用程序是在SDN控制器上运行的基于软件的在线安全功能。它可以很好地扩展,而无需使用按流/按连接的网络流量处理绕过防火墙。它还与基于硬件的机构防火墙分离,为发送到科学DMZ的纯科学流量实施量身定制的安全策略。虚拟入侵检测系统是一种基于NFV的被动安全功能,可以快速实例化和灵活扩展,以应对科学非军事区中的攻击流量变化,同时显著降低设备和运营成本。除了这些功能外,研究人员还为SciGuard设计了基于云的联邦机制,以支持安全策略自动测试和安全情报共享。在这个项目中开发的新机制是健壮的、可扩展的、低成本的、易于管理的和最佳配置的,因此大大增强了科学非军事区的安全性。这项研究通过积极招募妇女和其他代表性不足的群体参与该项目,鼓励参与该项目的学生的多样性。该项目有大量的研究生参与研究,并培养有前途的本科生实施和实验所提出的方法。此外,该项目通过将研究成果纳入新的和现有的课程来改进学术课程。
英文摘要
As data-intensive science becomes the norm in many fields of science, high-performance data transfer is rapidly becoming a standard cyberinfrastructure requirement. To meet this requirement, an increasingly large number of university campuses have deployed Science DMZs. A Science DMZ is a portion of the network, built at or near the edge of the campus or laboratory's network, that is designed such that the equipment, configuration, and security policies are optimized for high-performance scientific applications rather than for general-purpose computing. This project develops a secure and resilient architecture called SciGuard that addresses the security challenges and the inherent weaknesses in Science DMZs. SciGuard is based on two emerging networking paradigms, Software-Defined Networking (SDN) and Network Function Virtualization (NFV), both of which enable the granularity, flexibility and elasticity needed to secure Science DMZs. Two core security functions, an SDN firewall application and a virtual Intrusion Detection System (IDS), coexist in SciGuard for protecting Science DMZs. The SDN firewall application is a software-based, in-line security function running atop the SDN controller. It can scale well without bypassing the firewall using per-flow/per-connection network traffic processing. It is also separated from the institutional hardware-based firewalls to enforce tailored security policies for the science-only traffic sent to Science DMZs. The virtual IDS is an NFV-based, passive security function, which can be quickly instantiated and elastically scaled to deal with attack traffic variations in Science DMZs, while significantly reducing both equipment and operational costs. In addition to these functions, the researchers also design a cloud-based federation mechanism for SciGuard to support security policy automatic testing and security intelligence sharing. The new mechanisms developed in this project are robust, scalable, low cost, easily managed, and optimally provisioned, therefore substantially enhancing the security of Science DMZs. This research encourages the diversity of students involved in the project by active recruitment of women and other underrepresented groups for participation in the project. The project has substantial involvement of graduate students in research, and trains promising undergraduate students in the implementation and experiments of the proposed approach. Moreover, the project enhances academic curricula by integrating the research findings into new and existing courses.
期刊论文(17)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3427228.3427250
发表时间:
2020-07
期刊:
Proceedings of the 36th Annual Computer Security Applications Conference
影响因子:
--
作者:
[Song Liao;Christin Wilson;Long Cheng;Hongxin Hu;Huixing Deng]
通讯作者:
Song Liao;Christin Wilson;Long Cheng;Hongxin Hu;Huixing Deng
DOI:
10.1145/3488932.3517423
发表时间:
2022-05
期刊:
Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security
影响因子:
--
作者:
[Hongda Li;Qiqing Huang;Fei Ding;Hongxin Hu;Long Cheng;G. Gu;Ziming Zhao]
通讯作者:
Hongda Li;Qiqing Huang;Fei Ding;Hongxin Hu;Long Cheng;G. Gu;Ziming Zhao
Teaching SDN Security Using Hands-on Labs in CloudLab
使用 CloudLab 中的动手实验室教授 SDN 安全性
DOI:
--
发表时间:
2020
期刊:
Journal of the Colloquium for Information System Security Education
影响因子:
--
作者:
[Yuan, Xiaohong, Liu, Zhipeng, Park, Younghee, Hu, Hongxin, Li, Hongda]
通讯作者:
Li, Hongda
Building a Security OS With Software Defined Infrastructure
使用软件定义基础设施构建安全操作系统
DOI:
10.1145/3124680.3124720
发表时间:
2017
期刊:
Proceedings of the 8th Asia-Pacific Workshop on Systems
影响因子:
--
作者:
[Gu, Guofei, Hu, Hongxin, Keller, Eric, Lin, Zhiqiang, Porter, Donald E.]
通讯作者:
Porter, Donald E.
On the Safety and Efficiency of Virtual Firewall Elasticity Control
虚拟防火墙弹性控制的安全性和高效性
DOI:
--
发表时间:
2017
期刊:
24th Network and Distributed System Security Symposium (NDSS 2017
影响因子:
--
作者:
[Juan Deng, Hongda Li]
通讯作者:
Juan Deng, Hongda Li
共 15 条
Collaborative Research: SAI-R: Integrative Cyberinfrastructure for Enhancing and Accelerating Online Abuse Research
-
批准号:2228617
-
项目类别:Standard Grant
-
资助金额:$37.5万
-
财政年份:2022
-
负责人:Hongxin Hu
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:2128107
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
-
批准号:2129164
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
Collaborative Research: EAGER: SaTC-EDU: Learning Platform and Education Curriculum for Artificial Intelligence-Driven Socially-Relevant Cybersecurity
-
批准号:2114982
-
项目类别:Standard Grant
-
资助金额:$7.0万
-
财政年份:2021
-
负责人:Hongxin Hu
-
依托单位:
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
-
批准号:1846291
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2019
-
负责人:Hongxin Hu
-
依托单位:
NSF Student Travel Grant for 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization (SDN-NFV Security)
-
批准号:1807103
-
项目类别:Standard Grant
-
资助金额:$0.56万
-
财政年份:2018
-
负责人:Hongxin Hu
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
-
批准号:1642143
-
项目类别:Standard Grant
-
资助金额:$49.98万
-
财政年份:2017
-
负责人:Hongxin Hu
-
依托单位:
SaTC: EDU: Collaborative: Enhancing Security Education through Transiting Research on Security in Emerging Network Technologies
-
批准号:1723663
-
项目类别:Standard Grant
-
资助金额:$8.0万
-
财政年份:2017
-
负责人:Hongxin Hu
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:1700499
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2017
-
负责人:Hongxin Hu
-
依托单位:
III: Small: Collaborative Research: Privacy-Aware Collaborative Data Sharing in Human-Centered Social Networks
-
批准号:1527421
-
项目类别:Standard Grant
-
资助金额:$29.98万
-
财政年份:2015
-
负责人:Hongxin Hu
-
依托单位:
EAGER: Defending Against Visual Cyberbullying Attacks in Emerging Mobile Social Networks
-
批准号:1537924
-
项目类别:Standard Grant
-
资助金额:$23.97万
-
财政年份:2015
-
负责人:Hongxin Hu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: