课题基金 / 基金详情

CAREER: Colony: A Framework for Bespoke Virtual Execution Contexts

CAREER: Colony: A Framework for Bespoke Virtual Execution Contexts
职业:Colony:定制虚拟执行上下文的框架
批准号:
2239757
负责人:
Kyle Hale
金额:
$63.22万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-05-01 至 2028-04-30

项目摘要

项目成果

Kyle Hale的其他基金

相似基金

相关文献

中文摘要
翻译
在共享计算基础设施(例如云数据中心)上运行的软件中存在的漏洞可能导致重大的经济损失,泄露用户数据,并削弱国家安全,如果这些基础设施没有在安全、隔离的隔间中适当地将程序彼此分开。虽然确实存在确保这种隔离的技术,但它们通常会增加程序员的工程负担,或者牺牲性能换取安全性,从而限制了它们的有效性和覆盖范围。今天,程序员正在以越来越细粒度的单元(例如,无服务器计算)在共享计算基础设施上部署代码,随着时间的推移,这种权衡变得更加严重。现成的技术,比如构建隔离框架的容器,并不是为这种细粒度用例设计的。因此,该项目旨在通过使用新颖的操作系统、编译器、编程语言和虚拟化技术,从头开始设计新的隔离机制,从而确保在云基础设施上运行的代码的性能和安全性。该项目将有助于产生更健壮的云计算基础设施,这些基础设施不易受到攻击,不太可能泄露敏感的用户数据,并且对程序员来说更高效。如果成功,潜在的影响包括减少基础设施受损造成的经济损失,加强国家安全,以及增加使用云服务的更广泛公众的隐私。该计划亦会在教育方面作出贡献,并透过提升教育内容、在课程中加入与业界相关及实用的内容、增加不同背景人士参与电脑系统研究、重振大专院校的电脑系统课程,以及鼓励大学生参与研究工作。这个项目提出了Colony,这是一个轻量级的、定制的、虚拟化执行环境的新软件框架。Colony利用了为单个应用程序定制的新颖的执行抽象,并为性能和隔离而设计。使用编译器分析来合成群体上下文,并通过一组丰富的编程抽象和编程语言扩展来公开。Colony建立在隔离函数执行的新抽象、虚拟子例程或虚拟程序以及可嵌入管理程序的基础上。Colony项目的目标是为各种应用程序中单独隔离的功能上下文实现高性能和强隔离。该项目将探索各种机制来实现定制环境,包括为优化启动性能而增强的虚拟化机制,以及具有新型语言/编译器支持的编程模型。这些定制上下文可用于比托管语言更轻量级的隔离,使它们广泛适用于操作系统内核驱动程序、第三方库和数据库用户定义函数等领域,以及更新生的无服务器计算范例。提议的工作有可能在操作系统、虚拟化、编译器和系统安全性方面开辟新的研究方向。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Vulnerabilities present in software running on shared computing infrastructure (e.g., cloud datacenters) can result in significant economic losses, compromised user data, and weakened national security when such infrastructure does not properly separate programs from one another in secure, isolated compartments. While techniques do exist to ensure such isolation, they typically increase the engineering burden on programmers or trade off performance for security, limiting their effectiveness and reach. Today, programmers are deploying code on shared computing infrastructure in increasingly fine-grained units (e.g., serverless computing), making this trade off more severe over time. The off-the-shelf technologies, such as containers that isolation frameworks are often built on, were not designed for this fine-grained use case. This project thus aims to ensure both performance and security for code running on cloud infrastructure by designing new isolation mechanisms from the ground up using novel operating system, compiler, programming language, and virtualization technologies. The project will help produce more robust cloud computing infrastructure that is less susceptible to attack, less likely to leak sensitive user data, and more productive for programmers. If successful, potential impacts include reduced economic losses from compromised infrastructure, strengthened national security, and increased privacy for the broader public using cloud services. The project will also make contributions in education and broadening participation in the computing profession by enhancing educational content, injecting industry-relevant and applied content into the curriculum, increasing the representation of people from diverse backgrounds in computer systems research, revitalizing the computer systems curriculum at the PI’s institution, and fostering undergraduate research engagement. This project proposes Colony, a new software framework for lightweight, bespoke, virtualized execution contexts. Colony leverages novel execution abstractions customized for individual applications and designed for both performance and isolation. Colony contexts are synthesized using compiler analyses, and are exposed through a rich set of programming abstractions and programming language extensions. Colony builds on a new abstraction for isolated function execution, the virtualized subroutine, or virtine, along with an embeddable hypervisor. The goal of the Colony project is to achieve both high performance and strong isolation for individually isolated function contexts in a variety of applications. The project will explore various mechanisms to enable bespoke contexts, including virtualization mechanisms enhanced for optimized start-up performance, and programming models with novel language/compiler support. These bespoke contexts can be used for lighter-weight isolation than managed languages, giving them broad applicability to areas such as OS kernel drivers, third-party libraries, and database user-defined functions, as well as the more nascent serverless computing paradigm. The proposed work has potential to open up new lines of research in operating systems, virtualization, compilers, and system security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: PPoSS: Planning: Unifying Software and Hardware to Achieve Performant and Scalable Zero-cost Parallelism in the Heterogeneous Future
  • 批准号:
    2028958
  • 项目类别:
    Standard Grant
  • 资助金额:
    $4.16万
  • 财政年份:
    2020
  • 负责人:
    Kyle Hale
  • 依托单位:
CSR: Medium: Collaborative Research: Interweaving the Parallel Software/Hardware Stack
  • 批准号:
    1763612
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $30.56万
  • 财政年份:
    2018
  • 负责人:
    Kyle Hale
  • 依托单位:
CSR: Small: Collaborative Research: Flexible Resource Management and Coordination Schemes for Lightweight, Rapidly Deployable OS/Rs
  • 批准号:
    1718252
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.98万
  • 财政年份:
    2017
  • 负责人:
    Kyle Hale
  • 依托单位:
海外基金