Collaborative Research: CICI: Secure and Resilient Architecture: NetSecOps - Policy-Driven, Knowledge-Centric, Holistic Network Security Operations Architecture
协作研究:CICI:安全和弹性架构:NetSecOps - 策略驱动、以知识为中心的整体网络安全运营架构
基本信息
- 批准号:1642158
- 负责人:
- 金额:$ 49.99万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2016
- 资助国家:美国
- 起止时间:2016-09-01 至 2020-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Network infrastructure at University campuses is complex and sophisticated, often supporting a mix of enterprise, academic, student, research, and healthcare data, each having its own distinct security, privacy, and priority policies. Securing this complex and highly dynamic environment is extremely challenging, particularly since campus infrastructures are increasingly under attack from malicious actors on the Internet and (often unknowingly) internal campus devices. Different parts of the campus have very different policies and regulations that govern its treatment of sensitive data (e.g., private student/employee information, health care data, financial transactions, etc.). Furthermore, data-intensive scientific research traffic often requires exceptions to normal security policies, resulting in ad-hoc solutions that bypass standard operational procedures and leave both the scientific workflow and the campus as a whole vulnerable to attack. In short, state-of-the-art campus security operations still heavily rely on human domain experts to interpret high level policy documents, implement those policies through low-level mechanisms, create exceptions to accommodate scientific workflows, interpret reports and alerts, and be able to react to security events in near real time on a 24-by-7 basis.This project addresses these challenges through a collaborative research effort, called NetSecOps (Network Security Operations), that assists information technology (IT) security teams by automating many of the operational tasks that are tedious, error-prone, and otherwise problematic in current campus networks. NetSecOps is policy-driven in that the framework encodes high-level human-readable policies into systematic policy specifications that drive the actual configuration and operation of the infrastructure. NetSecOps is knowledge-centric in that the framework captures data, information, and knowledge about the infrastructure in a central knowledge store that informs and guides IT operational tasks. The proposed NetSecOps architecture has the following unique capabilities: (1) the ability to capture campus network security policies systematically; (2) the ability to create new fine-grained network control abstractions that leverage existing security capabilities and emerging software defined networks (SDN) to implement security policies, including policies related to both scientific workflows and IT domains; (3) the ability to implement policy traceability tools that verify whether these network abstractions maintain the integrity of the high-level policies; (4) the ability to implement knowledge-discovery tools that enable reasoning across data from existing security point-solutions, including security monitoring tools and authentication and authorization frameworks; and (5) the ability to automatically adjust the network?s security posture based on detected security events. Research results and tools from the project will be released into the public domain allowing academic institutions to utilize the resources as part of their best-practice IT security operations.
大学校园的网络基础设施复杂而精密,通常支持企业、学术、学生、研究和医疗保健数据的混合,每个数据都有自己独特的安全、隐私和优先级策略。 确保这种复杂且高度动态的环境的安全极具挑战性,特别是因为园区基础设施越来越多地受到互联网上的恶意行为者和(通常在不知不觉中)内部园区设备的攻击。校园的不同部分有非常不同的政策和法规来管理敏感数据的处理(例如,私人学生/员工信息、医疗保健数据、金融交易等)。此外,数据密集型科学研究流量通常需要对正常安全策略进行例外处理,从而导致临时解决方案绕过标准操作程序,并使科学工作流程和整个校园都容易受到攻击。简而言之,最先进的校园安全运营仍然严重依赖人类领域专家来解释高级策略文件,通过低级机制实施这些策略,创建例外以适应科学工作流程,解释报告和警报,并能够以 24×7 的方式近乎实时地对安全事件做出反应。该项目通过名为 NetSecOps(网络安全操作)的协作研究工作来解决这些挑战,该工作通过自动化许多工作来帮助信息技术 (IT) 安全团队的操作任务是当前校园网络中存在繁琐、容易出错等问题。 NetSecOps 是策略驱动的,因为该框架将高级人类可读策略编码为系统策略规范,以驱动基础设施的实际配置和操作。 NetSecOps 以知识为中心,因为该框架在中央知识存储中捕获有关基础设施的数据、信息和知识,通知和指导 IT 操作任务。所提出的NetSecOps架构具有以下独特功能:(1)系统捕获校园网络安全策略的能力; (2) 创建新的细粒度网络控制抽象的能力,利用现有的安全功能和新兴的软件定义网络 (SDN) 来实施安全策略,包括与科学工作流程和 IT 领域相关的策略; (3) 能够实施策略可追溯工具,验证这些网络抽象是否保持高级策略的完整性; (4) 实施知识发现工具的能力,这些工具能够对现有安全点解决方案的数据进行推理,包括安全监控工具以及身份验证和授权框架; (5) 根据检测到的安全事件自动调整网络安全态势的能力。该项目的研究成果和工具将发布到公共领域,允许学术机构利用这些资源作为其最佳实践 IT 安全运营的一部分。
项目成果
期刊论文数量(4)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
WASPP: Workflow Automation for Security Policy Procedures
WASPP:安全策略程序的工作流程自动化
- DOI:10.23919/cnsm46954.2019.9012707
- 发表时间:2019-10
- 期刊:
- 影响因子:0
- 作者:Quinn, Ren;Holguin, Nico;Poster, Ben;Roach, Corey;Van der Merwe, Jacobus
- 通讯作者:Van der Merwe, Jacobus
Deepstitch: Deep Learning for Cross-Layer Stitching in Microservices
Deepstitch:微服务中跨层拼接的深度学习
- DOI:10.1145/3429885.3429965
- 发表时间:2020-12
- 期刊:
- 影响因子:0
- 作者:Li, Richard;Du, Min;Chang, Hyunseok;Mukherjee, Sarit;Eide, Eric
- 通讯作者:Eide, Eric
eZTrust: Network-Independent Zero-Trust Perimeterization for Microservices
eZTrust:微服务的网络独立零信任边界化
- DOI:10.1145/3314148.3314349
- 发表时间:2019-04
- 期刊:
- 影响因子:0
- 作者:Zaheer, Zirak;Chang, Hyunseok;Mukherjee, Sarit;Van der Merwe, Jacobus
- 通讯作者:Van der Merwe, Jacobus
Toward Classifying Unknown Application Traffic
对未知应用程序流量进行分类
- DOI:
- 发表时间:2024-09-14
- 期刊:
- 影响因子:0
- 作者:Ryan Baker;Ren Quinn
- 通讯作者:Ren Quinn
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Jacobus VAN DER MERWE其他文献
Jacobus VAN DER MERWE的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Jacobus VAN DER MERWE', 18)}}的其他基金
NSF Convergence Accelerator Track G: SONIC: Securely Operate through 5G Networks with Informed Control
NSF 融合加速器轨道 G:SONIC:通过 5G 网络通过知情控制安全运行
- 批准号:
2226437 - 财政年份:2022
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
Collaborative Research: SII-NRDZ: POWDER-RDZ - Spectrum sharing in the POWDER platform
合作研究:SII-NRDZ:POWDER-RDZ - POWDER 平台中的频谱共享
- 批准号:
2232463 - 财政年份:2022
- 资助金额:
$ 49.99万 - 项目类别:
Continuing Grant
US Ignite: Focus Area 1: SafeEdge - Dynamic Public Safety Response through a Municipal Software Defined Infrastructure
US Ignite:重点领域 1:SafeEdge - 通过市政软件定义基础设施实现动态公共安全响应
- 批准号:
1647264 - 财政年份:2016
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: CapNet: Secure Scientific Workloads with Capability Enabled Networks
CICI:安全数据架构:CapNet:通过能力支持的网络保护科学工作负载
- 批准号:
1547457 - 财政年份:2015
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
Student Travel Support for the Tenth Symposium on Networked Systems Design and Implementation (NSDI)
第十届网络系统设计与实现(NSDI)研讨会的学生旅行支持
- 批准号:
1333988 - 财政年份:2013
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CI-ADDO-NEW: PhantomNet: An End-to-End Mobile Network Testbed
CI-ADDO-NEW:PhantomNet:端到端移动网络测试平台
- 批准号:
1305384 - 财政年份:2013
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
TWC: Medium: TCloud: A Self-Defending, Self-Evolving and Self-Accounting Trustworthy Cloud Platform
TWC:媒介:TCloud:一个自我防御、自我进化、自我记账的可信云平台
- 批准号:
1314945 - 财政年份:2013
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
NeTS: Medium: KnowOps-Making Network Management and Operations Software Defined
NeTS:媒介:KnowOps - 定义网络管理和运营软件
- 批准号:
1302688 - 财政年份:2013
- 资助金额:
$ 49.99万 - 项目类别:
Continuing Grant
EAGER: SeaCat: An SDN End-to-End Application Containment ArchitecTure to Enable Secure Role Based Network Access in Healthcare
EAGER:SeaCat:SDN 端到端应用遏制架构,可在医疗保健领域实现基于角色的安全网络访问
- 批准号:
1343713 - 财政年份:2013
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
相似国自然基金
基于肿瘤病理图片的靶向药物敏感生物标志物识别及统计算法的研究
- 批准号:82304250
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
肠道普拉梭菌代谢物丁酸抑制心室肌铁死亡改善老龄性心功能不全的机制研究
- 批准号:82300430
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
社会网络关系对公司现金持有决策影响——基于共御风险的作用机制研究
- 批准号:72302067
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
面向图像目标检测的新型弱监督学习方法研究
- 批准号:62371157
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
面向开放域对话系统信息获取的准确性研究
- 批准号:62376067
- 批准年份:2023
- 资助金额:51 万元
- 项目类别:面上项目
相似海外基金
CICI:TCR: Enhancing Security and Privacy of Community Cyberinfrastructures for Collaborative Research
CICI:TCR:增强社区网络基础设施的安全性和隐私性以进行协作研究
- 批准号:
2319988 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
- 批准号:
2128607 - 财政年份:2021
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
- 批准号:
2128607 - 财政年份:2021
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
- 批准号:
1642143 - 财政年份:2017
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Regional: SouthEast SciEntific Cybersecurity for University Research (SouthEast SECURE)
合作研究:CICI:区域:东南大学研究科学网络安全 (SouthEast SECURE)
- 批准号:
1812404 - 财政年份:2017
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant