Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies

合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构

基本信息

  • 批准号:
    1642143
  • 负责人:
  • 金额:
    $ 49.98万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2017
  • 资助国家:
    美国
  • 起止时间:
    2017-01-01 至 2021-04-30
  • 项目状态:
    已结题

项目摘要

As data-intensive science becomes the norm in many fields of science, high-performance data transfer is rapidly becoming a standard cyberinfrastructure requirement. To meet this requirement, an increasingly large number of university campuses have deployed Science DMZs. A Science DMZ is a portion of the network, built at or near the edge of the campus or laboratory's network, that is designed such that the equipment, configuration, and security policies are optimized for high-performance scientific applications rather than for general-purpose computing. This project develops a secure and resilient architecture called SciGuard that addresses the security challenges and the inherent weaknesses in Science DMZs. SciGuard is based on two emerging networking paradigms, Software-Defined Networking (SDN) and Network Function Virtualization (NFV), both of which enable the granularity, flexibility and elasticity needed to secure Science DMZs. Two core security functions, an SDN firewall application and a virtual Intrusion Detection System (IDS), coexist in SciGuard for protecting Science DMZs. The SDN firewall application is a software-based, in-line security function running atop the SDN controller. It can scale well without bypassing the firewall using per-flow/per-connection network traffic processing. It is also separated from the institutional hardware-based firewalls to enforce tailored security policies for the science-only traffic sent to Science DMZs. The virtual IDS is an NFV-based, passive security function, which can be quickly instantiated and elastically scaled to deal with attack traffic variations in Science DMZs, while significantly reducing both equipment and operational costs. In addition to these functions, the researchers also design a cloud-based federation mechanism for SciGuard to support security policy automatic testing and security intelligence sharing. The new mechanisms developed in this project are robust, scalable, low cost, easily managed, and optimally provisioned, therefore substantially enhancing the security of Science DMZs. This research encourages the diversity of students involved in the project by active recruitment of women and other underrepresented groups for participation in the project. The project has substantial involvement of graduate students in research, and trains promising undergraduate students in the implementation and experiments of the proposed approach. Moreover, the project enhances academic curricula by integrating the research findings into new and existing courses.
随着数据密集型科学成为许多科学领域的常态,高性能数据传输正迅速成为网络基础设施的标准要求。为了满足这一要求,越来越多的大学校园部署了科学 DMZ。科学 DMZ 是网络的一部分,构建在校园或实验室网络边缘或附近,其设计目的是针对高性能科学应用而不是通用目的优化设备、配置和安全策略计算。该项目开发了一种名为 SciGuard 的安全且有弹性的架构,可解决科学 DMZ 中的安全挑战和固有弱点。 SciGuard 基于两种新兴的网络范例:软件定义网络 (SDN) 和网络功能虚拟化 (NFV),这两种范例都能够实现保护 Science DMZ 所需的粒度、灵活性和弹性。 SciGuard 中共存了两个核心安全功能:SDN 防火墙应用程序和虚拟入侵检测系统 (IDS),用于保护 Science DMZ。 SDN 防火墙应用程序是运行在 SDN 控制器之上的基于软件的内联安全功能。它可以使用每流/每连接网络流量处理来很好地扩展,而无需绕过防火墙。 它还与基于硬件的机构防火墙分开,为发送到科学 DMZ 的纯科学流量实施定制的安全策略。虚拟IDS是一种基于NFV的被动安全功能,可以快速实例化和弹性扩展,以应对Science DMZ中的攻击流量变化,同时显着降低设备和运营成本。除了这些功能之外,研究人员还为SciGuard设计了基于云的联邦机制,以支持安全策略自动测试和安全情报共享。该项目开发的新机制强大、可扩展、成本低、易于管理且配置最佳,因此大大增强了科学 DMZ 的安全性。这项研究通过积极招募女性和其他代表性不足的群体参与该项目,鼓励参与该项目的学生的多样性。该项目让研究生大量参与研究,并培训有前途的本科生实施和实验所提出的方法。此外,该项目通过将研究成果整合到新课程和现有课程中来增强学术课程。

项目成果

期刊论文数量(24)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Enabling NFV Elasticity Control With Optimized Flow Migration
  • DOI:
    10.1109/jsac.2018.2869953
  • 发表时间:
    2018-09
  • 期刊:
  • 影响因子:
    16.4
  • 作者:
    Chen Sun;J. Bi;Zili Meng;Tong Yang;Xiao Zhang;Hongxin Hu
  • 通讯作者:
    Chen Sun;J. Bi;Zili Meng;Tong Yang;Xiao Zhang;Hongxin Hu
SmartChain: Enabling High-Performance Service Chain Partition between SmartNIC and CPU
  • DOI:
    10.1109/icc40277.2020.9149136
  • 发表时间:
    2020-06
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Shuhe Wang;Zili Meng;Chen Sun;Minhu Wang;Mingwei Xu;J. Bi;Tong Yang;Qun Huang;Hongxin Hu
  • 通讯作者:
    Shuhe Wang;Zili Meng;Chen Sun;Minhu Wang;Mingwei Xu;J. Bi;Tong Yang;Qun Huang;Hongxin Hu
Teaching SDN Security Using Hands-on Labs in CloudLab
使用 CloudLab 中的动手实验室教授 SDN 安全性
FastFE: Accelerating ML-based Traffic Analysis with Programmable Switches
FastFE:利用可编程交换机加速基于 ML 的流量分析
Towards Efficient Traffic Monitoring for Science DMZ with Side-Channel based Traffic Winnowing
利用基于侧信道的流量风选实现科学 DMZ 的高效流量监控
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Hongxin Hu其他文献

Tripod: Towards a Scalable, Efficient and Resilient Cloud Gateway
Tripod:迈向可扩展、高效且有弹性的云网关
Dynamic Audit Services for Outsourced Storages in Clouds
云中外包存储的动态审计服务
  • DOI:
    10.1109/tsc.2011.51
  • 发表时间:
    2013-04
  • 期刊:
  • 影响因子:
    8.1
  • 作者:
    Hongxin Hu;Stephen S. Yau;Ho G. An;Chang-Jun Hu
  • 通讯作者:
    Chang-Jun Hu
Enabling Collaborative Data Sharing in Google + ( Technical Report , SEFCOM , March 2012 )
在 Google 中实现协作数据共享(技术报告,SEFCOM,2012 年 3 月)
  • DOI:
  • 发表时间:
    2012
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Hongxin Hu;Gail;Jan Jorgensen
  • 通讯作者:
    Jan Jorgensen
Effectiveness and Users’ Experience of Face Blurring as a Privacy Protection for Sharing Photos via Online Social Networks
面部模糊作为在线社交网络共享照片隐私保护的有效性和用户体验
MCDefender: Toward Effective Cyberbullying Defense in Mobile Online Social Networks
MCDefender:在移动在线社交网络中实现有效的网络欺凌防御

Hongxin Hu的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Hongxin Hu', 18)}}的其他基金

Collaborative Research: SAI-R: Integrative Cyberinfrastructure for Enhancing and Accelerating Online Abuse Research
合作研究:SAI-R:用于加强和加速在线滥用研究的综合网络基础设施
  • 批准号:
    2228617
  • 财政年份:
    2022
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
  • 批准号:
    2128107
  • 财政年份:
    2021
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Continuing Grant
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
职业:通过安全高效的网络安全功能虚拟化迈向弹性安全
  • 批准号:
    2129164
  • 财政年份:
    2021
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Continuing Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    2128607
  • 财政年份:
    2021
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
Collaborative Research: EAGER: SaTC-EDU: Learning Platform and Education Curriculum for Artificial Intelligence-Driven Socially-Relevant Cybersecurity
合作研究:EAGER:SaTC-EDU:人工智能驱动的社会相关网络安全的学习平台和教育课程
  • 批准号:
    2114982
  • 财政年份:
    2021
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
职业:通过安全高效的网络安全功能虚拟化迈向弹性安全
  • 批准号:
    1846291
  • 财政年份:
    2019
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Continuing Grant
NSF Student Travel Grant for 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization (SDN-NFV Security)
NSF 学生旅费补助金用于 2018 年 ACM 软件定义网络和网络功能虚拟化安全(SDN-NFV 安全)国际研讨会
  • 批准号:
    1807103
  • 财政年份:
    2018
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
SaTC: EDU: Collaborative: Enhancing Security Education through Transiting Research on Security in Emerging Network Technologies
SaTC:EDU:协作:通过新兴网络技术安全的过渡研究加强安全教育
  • 批准号:
    1723663
  • 财政年份:
    2017
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
  • 批准号:
    1700499
  • 财政年份:
    2017
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Continuing Grant
EAGER: Defending Against Visual Cyberbullying Attacks in Emerging Mobile Social Networks
EAGER:防御新兴移动社交网络中的视觉网络欺凌攻击
  • 批准号:
    1537924
  • 财政年份:
    2015
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant

相似国自然基金

基于FRET受体上升时间的单分子高精度测量方法研究
  • 批准号:
    22304184
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
脂质多聚复合物mRNA纳米疫苗的构筑及抗肿瘤治疗研究
  • 批准号:
    52373161
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目
屏障突破型原位线粒体基因递送系统用于治疗Leber遗传性视神经病变的研究
  • 批准号:
    82304416
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
细胞硬度介导口腔鳞癌细胞与CD8+T细胞间力学对话调控免疫杀伤的机制研究
  • 批准号:
    82373255
  • 批准年份:
    2023
  • 资助金额:
    48 万元
  • 项目类别:
    面上项目
乙酸钙不动杆菌上调DUOX2激活PERK/ATF4内质网应激在炎症性肠病中的作用机制研究
  • 批准号:
    82300623
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

CICI:TCR: Enhancing Security and Privacy of Community Cyberinfrastructures for Collaborative Research
CICI:TCR:增强社区网络基础设施的安全性和隐私性以进行协作研究
  • 批准号:
    2319988
  • 财政年份:
    2023
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    2128607
  • 财政年份:
    2021
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    1642031
  • 财政年份:
    2017
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Regional: SouthEast SciEntific Cybersecurity for University Research (SouthEast SECURE)
合作研究:CICI:区域:东南大学研究科学网络安全 (SouthEast SECURE)
  • 批准号:
    1812404
  • 财政年份:
    2017
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
CICI: Data Provenance: Collaborative Research: Provenance Assurance Using Currency Primitives
CICI:数据来源:协作研究:使用货币基元的来源保证
  • 批准号:
    1821926
  • 财政年份:
    2017
  • 资助金额:
    $ 49.98万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了