NSF Convergence Accelerator Track: G: Security Services for the 5G Software-Defined Edge
NSF Convergence Accelerator Track: G: Security Services for the 5G Software-Defined Edge
批准号:
2226443
负责人:
Phillip Porras
金额:
$74.87万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
已结题
起止时间:
2022-07-15 至 2023-06-30
中文摘要
该项目将专注于创建一个深入的安全架构,直接集成到市场领先的5G软件定义无线电接入网络(SD-RAN)参考标准中,该标准目前由领先的国际5G行业联盟(O-RAN)开发。该项目引入了一个跨层安全架构,利用新的5G软件定义架构的模块化可扩展性,包括服务、应用和协议扩展,以实现5G边缘到核心操作的全面运行时安全管理。它将通过低级应用程序监控、机器学习、内联安全合规性执行、身份管理和数据来源来增强和扩展而不是取代现有的SD-RAN参考实施。该项目是在5G生命周期的关键时刻启动的,特别是随着5G应用越来越多地针对高度敏感的计算环境(例如军事、政府、工业应用和关键基础设施)进行开发。该项目将剖析SD-RAN设计中出现的新的5G攻击面,并将引入来自经验丰富的INFOSEC研究人员团队的安全解决方案,以及能够加速这些解决方案向美国市场过渡的行业合作伙伴。它将5G网络安全的挑战分解为三个重点领域:用户到RAN的攻击面,RAN控制平面内的威胁,以及通过分析RAN到核心(5G和互联网之间的网关)操作而表现出来的威胁。这个融合加速器项目的主题领域被分解为三个互补的技术重点。首先,该项目将解决旨在攻击RAN操作的敌对用户设备(UE)所产生的威胁。它将调查跨越用户边缘的特定于5G的隐私和安全攻击,从5G手机,物联网和传感器网络到汽车。 将分析针对SD-RAN的UE攻击,并提出对RAN的新安全服务增强,以检测和对抗这些攻击。其次,该项目将设计5G SD-RAN控制平面的安全扩展,基于深入的5G特定安全遥测,自动化策略生成,基于ML的建模,运行时策略执行和基于出处的数据流保护的框架。最后,该项目将设计支持5G的P4安全服务,这些服务可以与SD-RAN控制层相互作用,提供新颖且可扩展的方法来集成核心到边缘防御。这个项目的好处是多方面的。主要目标是为不同的社区改善5G UE边缘安全性,包括关键基础设施提供商、美国国防部和全国范围的社会。安全增强的SD-RAN将提供对解决国防部、美国政府和关键基础设施运营环境中普遍存在的合规指令至关重要的功能。另一个重要的项目好处是它对未来美国劳动力的教育和多样性的贡献。该团队由一个教育机构和一个研究实验室组成,他们积极准备保护美国免受网络攻击所需的下一代计算机科学家。特别是,该提案纳入了一项详细的教育和参与计划,鼓励研究生,特别是妇女和少数民族的参与,并将建立在与一个非营利组织的持续合作基础上,该非营利组织的重点是留住劳动力中从事研发工作的妇女。在整个项目中,学生将帮助进行拟议的研究,学术论文,并支持我们的收敛材料的准备。该项目将涉及多名研究生和本科生研究人员,并纳入具体计划,以接触代表性不足的群体,并鼓励他们直接参与拟议的研究。该奖项反映了NSF的法定使命,并已被认为是值得通过使用基金会的智力价值和更广泛的影响审查标准进行评估的支持。
英文摘要
This project will focus on the creation of an in-depth security architecture that integrates directly into the market-leading 5G Software-Defined Radio Access Network (SD-RAN) reference standard, currently in development by the leading international 5G industry consortium (O-RAN). The project introduces a cross-layer security architecture that leverages the modular extensibility of the new 5G software-defined architecture with services, applications, and protocol extensions to achieve a comprehensive runtime security management of 5G edge-to-core operations. It will augment and extend, not replace, the existing SD-RAN reference implementation with low-level application monitoring, machine learning, inline security compliance enforcement, identity management, and data provenance. The project is initiated at a critical moment in the 5G life cycle, particularly as 5G applications are increasingly developed for highly sensitive computing environments, such as military, government, industrial applications, and critical infrastructure. The project will dissect new 5G attack surfaces that have emerged from the SD-RAN design and will introduce security solutions from an experienced team of INFOSEC researchers, and an industry partner well-positioned to accelerate the transition of these solutions into the U.S. market. It decomposes the challenges of securing 5G networks into three focus areas: the User-to-RAN attack surface, threats against and within the RAN control plane, and threats that manifest through an analysis of RAN-to-core (the gateway between 5G and the Internet) operations.The topic areas for this Convergence Accelerator project are decomposed into three complementary technical thrusts. First, the project will address threats that arise from hostile user equipment (UE) designed to attack RAN operations. It will investigate 5G-specific privacy and security attacks that span across the user edge, from 5G phones, IoTs, and sensor nets to automotive. UE attacks against SD-RANs will be analyzed, and new security service enhancements to the RAN will be proposed to detect and counter these attacks. Second, the project will design security extensions to the 5G SD-RAN control plane, based on a framework of in-depth 5G-specific security telemetry, automated policy generation, ML-based modeling, runtime policy enforcement, and provenance-based data flow protection. Finally, the project will design 5G-aware P4-enabled security services that can interplay with the SD-RAN control layer, offering novel and scalable methods to integrate core-to-edge defenses. The benefits of this project are multi-faceted. A primary goal is to improve 5G UE-edge security for diverse communities, including critical infrastructure providers, US DoD, and the society at a national scale. The security-enhanced SD-RAN will deliver features that are vital for addressing compliance directives that are pervasive within the DoD, U.S. government, and critical infrastructure operating environments. Another crucial project benefit is its contribution to the education and diversity of the future U.S. workforce. The team is composed of an educational institution and a research laboratory that are active in the preparation of the next generation of computer scientists needed to protect the U.S. from cyber attacks. In particular, the proposal incorporates a detailed education and participation plan that encourages the inclusion of graduate students, particularly women and minorities, and will build upon an ongoing collaboration with a non-profit focused on retaining women in R&D in the workforce. Throughout this project, students will help conduct the proposed research, academic papers, and support the preparation of our convergence material. This project will involve multiple graduate and undergraduate researchers, and incorporate specific plans to reach out to under-represented groups and encourage their direct participation in the proposed research.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF Convergence Accelerator Track: G: The Security-Enhanced Radio Access Network (SE-RAN)
-
批准号:2326882
-
项目类别:Cooperative Agreement
-
资助金额:$499.96万
-
财政年份:2023
-
负责人:Phillip Porras
-
依托单位:
EAGER: Visualizing Cyber Defense Networks
-
批准号:1824258
-
项目类别:Standard Grant
-
资助金额:$29.99万
-
财政年份:2018
-
负责人:Phillip Porras
-
依托单位:
Exploring the Transition of Research-Derived Cyber-Threat Data
-
批准号:1640386
-
项目类别:Standard Grant
-
资助金额:$62.97万
-
财政年份:2016
-
负责人:Phillip Porras
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ
-
批准号:1642150
-
项目类别:Standard Grant
-
资助金额:$34.98万
-
财政年份:2016
-
负责人:Phillip Porras
-
依托单位:
EAGER: ACI: A Software-Defined Network (SDN) WAN Security Testbed
-
批准号:1547206
-
项目类别:Standard Grant
-
资助金额:$24.96万
-
财政年份:2015
-
负责人:Phillip Porras
-
依托单位:
EAGER: ACI: Secure and Effective Policy Enforcement in Software-Defined WANs
-
批准号:1446426
-
项目类别:Standard Grant
-
资助金额:$29.97万
-
财政年份:2014
-
负责人:Phillip Porras
-
依托单位:
TC: Medium: Collaborative Research: Multi-Perspective Bayesian Learning for Automated Diagnosis of Advanced Malware
-
批准号:0905518
-
项目类别:Standard Grant
-
资助金额:$24.75万
-
财政年份:2009
-
负责人:Phillip Porras
-
依托单位:
Collaborative Research: CT-L: CLEANSE: Cross-Layer Large-Scale Efficient Analysis of Network Activities to Secure the Internet
-
批准号:0831170
-
项目类别:Continuing Grant
-
资助金额:$17.5万
-
财政年份:2008
-
负责人:Phillip Porras
-
依托单位:
Collaborative Research: CT-T: Logic and Data Flow Extraction for Live and Informed Malware Execution
-
批准号:0716612
-
项目类别:Continuing Grant
-
资助金额:$44.0万
-
财政年份:2007
-
负责人:Phillip Porras
-
依托单位:
海外基金