CSR: Medium: Security and Isolation in the Era of Microservices
CSR:中:微服务时代的安全与隔离
基本信息
- 批准号:1763810
- 负责人:
- 金额:$ 120万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-08-01 至 2022-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Years ago, applications such as news, e-commerce, or banking websites ran on computers deployed at organizations owning them. Today, with the advent of "cloud computing", such applications instead run in a far-away server farm operated by third-parties. Because the computers are shared by many applications, it is crucial to ensure that one application in the cloud, such as a news website, does not compromise the confidentiality or integrity of another application (e.g., a banking website) running on the same set of computers. The goal of this project is to develop systems that ensure cloud applications are suitably protected without sacrificing their performance and ability to grow/shrink. This goal will be realized by developing two core building blocks to achieve optimal trade-offs between isolation and performance/agility. The first is variable isolation, where we automatically determine the least privilege and best isolation techniques needed for components of an application, and deploy the highest (weakest) isolation where needed most (least). The second is isolation-aware replication, where tenants selectively replicate their compute and storage within higher-isolation sandboxes. Finally, the project will develop new programming models for correct distributed execution of microservices-based applications.The research, if successful, will improve both the performance and the security posture of cloud-based applications. Research outcomes of the project, including the experimental harnesses and datasets, will be released open-source, enabling others in research and industry to directly build on them. The project will lead to the development of new courses and boot camps that focus on microservices, lambda-style computation, and isolation. The course/boot camp material will be made publicly available. The project aims to integrate the research into outreach efforts aimed at women, under-represented minorities, non-traditional students, and high school students.The project and its research artifacts will be hosted at https://bitbucket.org/uw-madison-networking-research/isolation. This site will include research publications, software, datasets, presentations, and tutorials. This site will be kept up to date for the entire duration of the project and for 2-3 years immediately following the project's culmination.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
几年前,新闻,电子商务或银行网站等应用程序运行在拥有它们的组织部署的计算机上。如今,随着“云计算”的出现,此类应用程序而不是在第三方经营的遥远服务器农场中运行。由于计算机是由许多应用程序共享的,因此必须确保云中的一个应用程序(例如新闻网站)不会损害另一个应用程序(例如,银行网站)在同一计算机集上运行的另一个应用程序的机密性或完整性。该项目的目的是开发系统,以确保云应用程序得到适当保护,而不会牺牲其性能和成长/收缩的能力。通过开发两个核心构建块,以实现隔离和性能/敏捷性之间的最佳权衡,可以实现这一目标。第一个是可变隔离,在其中我们会自动确定应用程序组件所需的最低特权和最佳隔离技术,并在最需要的情况下(最少)部署最高(最弱的)隔离。第二个是隔离感知的复制,其中租户选择性地将其计算和存储在更高分离的沙箱中。最后,该项目将开发新的编程模型,以正确的基于微服务的应用程序的分布式执行。如果成功的话,将改善基于云的应用程序的性能和安全姿势。该项目的研究成果,包括实验线束和数据集,将被发布开源,使研究和行业中的其他人能够直接建立在其基础上。该项目将导致开发新课程和新兵训练营,这些课程专注于微服务,兰巴达风格的计算和隔离。该课程/新兵训练营的资料将公开提供。该项目旨在将针对妇女,代表性不足的少数民族,非传统学生和高中生的外展努力进行研究。该项目及其研究文物将于https://bitbucket.org/uw-madison-networking-research-research/isolation举办。该站点将包括研究出版物,软件,数据集,演示文稿和教程。该网站将在项目的整个过程中保持最新状态,并在该项目的高潮结束后立即进行2 - 3年。该奖项反映了NSF的法定任务,并且使用基金会的知识分子优点和更广泛的影响审查标准,认为值得通过评估值得支持。
项目成果
期刊论文数量(5)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Can Applications Recover from fsync Failures?
应用程序可以从 fsync 失败中恢复吗?
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Rebello, Anthony;Patel, Yuvraj;Alagappan, Ramnatthan;Arpaci-Dusseau, Andrea;Arpaci-Dusseau, Remzi
- 通讯作者:Arpaci-Dusseau, Remzi
Strong and Efficient Consistency with Consistency-Aware Durability
强大而高效的一致性以及一致性感知的持久性
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Ganesan, Aishwarya;Alagappan, Ramnatthan;Arpaci-Dusseau, Andrea;Arpaci-Dusseau, Remzi
- 通讯作者:Arpaci-Dusseau, Remzi
Blending containers and virtual machines: a study of firecracker and gVisor
混合容器和虚拟机:Firecracker 和 gVisor 的研究
- DOI:10.1145/3381052.3381315
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Anjali, FNU;Caraza-Harter, Tyler;Swift, Michael M.
- 通讯作者:Swift, Michael M.
Avoiding Scheduler Subversion using Scheduler–Cooperative Locks
使用 Scheduler 合作锁避免 Scheduler 颠覆
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Patel, Yuvraj;Yang, Leon;Arulraj, Leo;Arpaci-Dusseau, Andrea;Arpaci-Dusseau, Remzi;Swift, Michael
- 通讯作者:Swift, Michael
Read as Needed: Building WiSER, a Flash-Optimized Search Engine
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Jun He;Kan Wu;Sudarsun Kannan;Andrea C. Arpaci-Dusseau;Remzi H. Arpaci-Dusseau
- 通讯作者:Jun He;Kan Wu;Sudarsun Kannan;Andrea C. Arpaci-Dusseau;Remzi H. Arpaci-Dusseau
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Aditya Akella其他文献
From Dumb Pipes to Rivers of Money: a Network Payment System
从愚蠢的管道到金钱的河流:网络支付系统
- DOI:
- 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Cristian Estan;Suman Banerjee;Aditya Akella;Yi Pan - 通讯作者:
Yi Pan
Handheld vs. Non-Handheld Traffic: Implications for Campus WiFi Networks
手持设备与非手持设备流量:对校园 WiFi 网络的影响
- DOI:
- 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
Aaron Gember;Ashok Anand;Aditya Akella - 通讯作者:
Aditya Akella
Using strongly typed networking to architect for tussle
使用强类型网络来构建斗争
- DOI:
10.1145/1868447.1868456 - 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
C. Muthukrishnan;V. Paxson;M. Allman;Aditya Akella - 通讯作者:
Aditya Akella
Toward Representative Internet Measurements
迈向具有代表性的互联网测量
- DOI:
- 发表时间:
2003 - 期刊:
- 影响因子:0
- 作者:
Aditya Akella;S. Seshan - 通讯作者:
S. Seshan
Redundancy elimination as a primitive
冗余消除作为原语
- DOI:
- 发表时间:
2012 - 期刊:
- 影响因子:0
- 作者:
Aditya Akella;Ashok Anand - 通讯作者:
Ashok Anand
Aditya Akella的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Aditya Akella', 18)}}的其他基金
Collaborative Research: CNS Core: Medium: Innovating Volumetric Video Streaming with Motion Forecasting, Intelligent Upsampling, and QoE Modeling
合作研究:CNS 核心:中:通过运动预测、智能上采样和 QoE 建模创新体积视频流
- 批准号:
2212297 - 财政年份:2022
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Large: Runtime Programmable Networks
合作研究:CNS 核心:大型:运行时可编程网络
- 批准号:
2214015 - 财政年份:2022
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Medium: Systems Support for Federated Learning
协作研究:CNS 核心:中:联邦学习的系统支持
- 批准号:
2105890 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
NeTS: Large: Collaborative Research: Design Principles for a Future-Proof Internet Control Plane
NetS:大型:协作研究:面向未来的互联网控制平面的设计原则
- 批准号:
2202649 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
CSR: Medium: Security and Isolation in the Era of Microservices
CSR:中:微服务时代的安全与隔离
- 批准号:
2203152 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
NeTS: Small: New Abstractions for First-hop Networking in Cloud Data Centers
NeTS:小型:云数据中心第一跳网络的新抽象
- 批准号:
2203167 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Medium: Systems Support for Federated Learning
协作研究:CNS 核心:中:联邦学习的系统支持
- 批准号:
2207317 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
EAGER: Collaborative Research: Inexactness and Data-Awareness in Network Stacks for Distributed Machine Learning
EAGER:协作研究:分布式机器学习网络堆栈中的不精确性和数据感知
- 批准号:
1940109 - 财政年份:2019
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
NeTS: Small: New Abstractions for First-hop Networking in Cloud Data Centers
NeTS:小型:云数据中心第一跳网络的新抽象
- 批准号:
1717039 - 财政年份:2017
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Workshop titled "Toward a Research Agenda for Cloud 3.0"
题为“迈向云 3.0 研究议程”的研讨会
- 批准号:
1749528 - 财政年份:2017
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
相似国自然基金
复合低维拓扑材料中等离激元增强光学响应的研究
- 批准号:12374288
- 批准年份:2023
- 资助金额:52 万元
- 项目类别:面上项目
基于管理市场和干预分工视角的消失中等企业:特征事实、内在机制和优化路径
- 批准号:72374217
- 批准年份:2023
- 资助金额:41.00 万元
- 项目类别:面上项目
托卡马克偏滤器中等离子体的多尺度算法与数值模拟研究
- 批准号:12371432
- 批准年份:2023
- 资助金额:43.5 万元
- 项目类别:面上项目
中等质量黑洞附近的暗物质分布及其IMRI系统引力波回波探测
- 批准号:12365008
- 批准年份:2023
- 资助金额:32 万元
- 项目类别:地区科学基金项目
中等垂直风切变下非对称型热带气旋快速增强的物理机制研究
- 批准号:42305004
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: CPS: Medium: Enabling Data-Driven Security and Safety Analyses for Cyber-Physical Systems
协作研究:CPS:中:为网络物理系统实现数据驱动的安全和安全分析
- 批准号:
2414176 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Hardware Security Insights: Analyzing Hardware Designs to Understand and Assess Security Weaknesses and Vulnerabilities
协作研究:SaTC:核心:中:硬件安全见解:分析硬件设计以了解和评估安全弱点和漏洞
- 批准号:
2247755 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CyberTraining: Implementation: Medium: Cross-Disciplinary Training for Joint Cyber-Physical Systems and IoT Security
协作研究:网络培训:实施:中:联合网络物理系统和物联网安全的跨学科培训
- 批准号:
2230086 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CyberTraining: Implementation: Medium: Cross-Disciplinary Training for Joint Cyber-Physical Systems and IoT Security
协作研究:网络培训:实施:中:联合网络物理系统和物联网安全的跨学科培训
- 批准号:
2230087 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Security and Robustness for Intermittent Computing Using Cross-Layer Post-CMOS Approaches
协作研究:SaTC:CORE:中:使用跨层后 CMOS 方法的间歇计算的安全性和鲁棒性
- 批准号:
2303115 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant