CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
职业:通过安全高效的网络安全功能虚拟化迈向弹性安全
基本信息
- 批准号:1846291
- 负责人:
- 金额:$ 50万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2019
- 资助国家:美国
- 起止时间:2019-10-01 至 2021-06-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Traditional network security functions are generally implemented on vendor proprietary appliances or middleboxes, which usually lack a general programming interface, and their versatility and flexibility are also very poor. These traditional network security appliances often need to be placed at fixed network entry points and have a constant capacity with respect to the maximum amount of traffic they can process. Such rigid nature makes them inefficient in protecting today's prevailing programmable and virtualizable environments. Network Function Virtualization (NFV) and Software-Defined Networking (SDN) are two emerging networking paradigms that offer the potential to address those limitations and are able to facilitate elastic security with the design of a new breed of network security functions called virtual Network Security Functions (vNSFs). The major goal of this project is to extend the understanding and science of virtual Network Security Functions. It will develop new technology for virtual Network Security Functions where security microservices can be deployed elastically, safely and efficiently, on demand, tailored to the needs of the situation. It addresses major challenges inherent in the management, design, deployment, and execution of virtual Network Security Functions that currently prevent the full use of their benefits. This project will also integrate a comprehensive education plan with the proposed research to train the next generation workforce in computational sciences. The project will foster the diversity of students by active recruitment of women and other under-represented groups for participation in the research.This project will first propose a new firewall architecture to address challenges in virtual firewall scaling. This project will then explore solutions to facilitate safe and efficient virtualization of both traditional and Artificial Neural Network (ANN)-based Intrusion Detection Systems. Finally, this project will develop a general framework, OpenNSFV, for supporting safe and efficient virtualization of network security functions. The proposed solutions of this project will be flexible, scalable, trustworthy, and optimal, and will substantially enhance the security of programmable and virtualizable network infrastructure. To demonstrate the practicality and feasibility of the proposed solutions, the project will implement, deploy, and evaluate the proposed security mechanisms in real production environments.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
通常在供应商专有设备或中间箱(通常缺乏一般编程接口)上实现传统的网络安全功能,其多功能性和灵活性也很差。这些传统的网络安全设备通常需要放置在固定网络入口点上,并且对于可以处理的最大流量量具有恒定的容量。这种僵化的性质使它们在保护当今盛行的可编程和虚拟化环境方面效率低下。网络功能虚拟化(NFV)和软件定义的网络(SDN)是两个新兴的网络范式,可通过设计新的网络安全函数(称为虚拟网络安全函数(VNSF))来促进这些限制的潜力,并能够促进弹性安全性。该项目的主要目标是扩展虚拟网络安全功能的理解和科学。 它将为虚拟网络安全函数开发新技术,在这些技术中,可以根据情况量身定制安全微服务,安全,安全,安全地按需部署。它解决了虚拟网络安全功能的管理,设计,部署和执行中固有的主要挑战,这些功能目前阻止了其福利的全部使用。该项目还将将一项综合教育计划与拟议的研究融合,以培训计算科学领域的下一代劳动力。该项目将通过积极招募妇女和其他代表性不足的群体来促进学生的多样性。该项目将首先提出一种新的防火墙架构,以应对虚拟防火墙缩放的挑战。然后,该项目将探索解决方案,以促进基于传统神经网络(ANN)的入侵检测系统的安全有效虚拟化。最后,该项目将开发一个通用框架OpenNSFV,以支持网络安全功能的安全有效虚拟化。该项目的拟议解决方案将是灵活的,可扩展的,可信赖的和最佳的,并将大大提高可编程和虚拟化网络基础结构的安全性。为了证明所提出的解决方案的实用性和可行性,该项目将在实际生产环境中实施,部署和评估所提出的安全机制。该奖项反映了NSF的法定任务,并被认为是通过基金会的知识分子优点和更广泛的审查标准通过评估来评估的。
项目成果
期刊论文数量(8)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
SmartChain: Enabling High-Performance Service Chain Partition between SmartNIC and CPU
- DOI:10.1109/icc40277.2020.9149136
- 发表时间:2020-06
- 期刊:
- 影响因子:0
- 作者:Shuhe Wang;Zili Meng;Chen Sun;Minhu Wang;Mingwei Xu;J. Bi;Tong Yang;Qun Huang;Hongxin Hu
- 通讯作者:Shuhe Wang;Zili Meng;Chen Sun;Minhu Wang;Mingwei Xu;J. Bi;Tong Yang;Qun Huang;Hongxin Hu
Poseidon: Mitigating Volumetric DDoS Attacks with Programmable Switches
Poseidon:利用可编程开关缓解容量 DDoS 攻击
- DOI:10.14722/ndss.2020.24007
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Zhang, M.;Li, G.;Wang, S.;Liu, C.;Chen, A.;Hu, H.;Gu, G.;Li, Q.;Xu, M.;Wu, J.
- 通讯作者:Wu, J.
Interpreting Deep Learning-Based Networking Systems
- DOI:10.1145/3387514.3405859
- 发表时间:2019-10
- 期刊:
- 影响因子:0
- 作者:Zili Meng;Minhu Wang;Jia-Ju Bai;Mingwei Xu;Hongzi Mao;Hongxin Hu
- 通讯作者:Zili Meng;Minhu Wang;Jia-Ju Bai;Mingwei Xu;Hongzi Mao;Hongxin Hu
When NFV Meets ANN: Rethinking Elastic Scaling for ANN-based NFs
- DOI:10.1109/icnp.2019.8888133
- 发表时间:2019-10
- 期刊:
- 影响因子:0
- 作者:Menghao Zhang;Jia-Ju Bai;Guanyu Li;Zili Meng;Hongda Li;Hongxin Hu;Mingwei Xu
- 通讯作者:Menghao Zhang;Jia-Ju Bai;Guanyu Li;Zili Meng;Hongda Li;Hongxin Hu;Mingwei Xu
S-Blocks: Lightweight and Trusted Virtual Security Function With SGX
- DOI:10.1109/tcc.2020.2985045
- 发表时间:2022-04
- 期刊:
- 影响因子:6.5
- 作者:Juan Wang;Shirong Hao;Hongxin Hu;Bo Zhao;Hongda Li;Wenhui Zhang;Jun Xu;Peng Liu;Jing Ma
- 通讯作者:Juan Wang;Shirong Hao;Hongxin Hu;Bo Zhao;Hongda Li;Wenhui Zhang;Jun Xu;Peng Liu;Jing Ma
共 8 条
- 1
- 2
Hongxin Hu其他文献
Dynamic Audit Services for Outsourced Storages in Clouds
云中外包存储的动态审计服务
- DOI:10.1109/tsc.2011.5110.1109/tsc.2011.51
- 发表时间:2013-042013-04
- 期刊:
- 影响因子:8.1
- 作者:Hongxin Hu;Stephen S. Yau;Ho G. An;Chang-Jun HuHongxin Hu;Stephen S. Yau;Ho G. An;Chang-Jun Hu
- 通讯作者:Chang-Jun HuChang-Jun Hu
Tripod: Towards a Scalable, Efficient and Resilient Cloud Gateway
Tripod:迈向可扩展、高效且有弹性的云网关
- DOI:10.1109/jsac.2019.289418910.1109/jsac.2019.2894189
- 发表时间:2019-022019-02
- 期刊:
- 影响因子:0
- 作者:Menghao Zhang;Jun Bi;Kai Gao;Yi Qiao;Guanyu Li;Xiao Kong;Zhaogeng Li;Hongxin HuMenghao Zhang;Jun Bi;Kai Gao;Yi Qiao;Guanyu Li;Xiao Kong;Zhaogeng Li;Hongxin Hu
- 通讯作者:Hongxin HuHongxin Hu
Enabling Collaborative Data Sharing in Google + ( Technical Report , SEFCOM , March 2012 )
在 Google 中实现协作数据共享(技术报告,SEFCOM,2012 年 3 月)
- DOI:
- 发表时间:20122012
- 期刊:
- 影响因子:0
- 作者:Hongxin Hu;Gail;Jan JorgensenHongxin Hu;Gail;Jan Jorgensen
- 通讯作者:Jan JorgensenJan Jorgensen
Effectiveness and Users’ Experience of Face Blurring as a Privacy Protection for Sharing Photos via Online Social Networks
面部模糊作为在线社交网络共享照片隐私保护的有效性和用户体验
- DOI:10.1177/154193121360169410.1177/1541931213601694
- 发表时间:20172017
- 期刊:
- 影响因子:0
- 作者:Yifang Li;Nishant Vishwamitra;Hongxin Hu;Bart P. Knijnenburg;Kelly E. CaineYifang Li;Nishant Vishwamitra;Hongxin Hu;Bart P. Knijnenburg;Kelly E. Caine
- 通讯作者:Kelly E. CaineKelly E. Caine
MCDefender: Toward Effective Cyberbullying Defense in Mobile Online Social Networks
MCDefender:在移动在线社交网络中实现有效的网络欺凌防御
- DOI:10.1145/3041008.304101310.1145/3041008.3041013
- 发表时间:20172017
- 期刊:
- 影响因子:0
- 作者:Nishant Vishwamitra;Xiang Zhang;Jonathan Tong;Hongxin Hu;Feng Luo;Robin M. Kowalski;Joseph P. MazerNishant Vishwamitra;Xiang Zhang;Jonathan Tong;Hongxin Hu;Feng Luo;Robin M. Kowalski;Joseph P. Mazer
- 通讯作者:Joseph P. MazerJoseph P. Mazer
共 30 条
- 1
- 2
- 3
- 4
- 5
- 6
Hongxin Hu的其他基金
Collaborative Research: SAI-R: Integrative Cyberinfrastructure for Enhancing and Accelerating Online Abuse Research
合作研究:SAI-R:用于加强和加速在线滥用研究的综合网络基础设施
- 批准号:22286172228617
- 财政年份:2022
- 资助金额:$ 50万$ 50万
- 项目类别:Standard GrantStandard Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
- 批准号:21281072128107
- 财政年份:2021
- 资助金额:$ 50万$ 50万
- 项目类别:Continuing GrantContinuing Grant
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
职业:通过安全高效的网络安全功能虚拟化迈向弹性安全
- 批准号:21291642129164
- 财政年份:2021
- 资助金额:$ 50万$ 50万
- 项目类别:Continuing GrantContinuing Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
- 批准号:21286072128607
- 财政年份:2021
- 资助金额:$ 50万$ 50万
- 项目类别:Standard GrantStandard Grant
Collaborative Research: EAGER: SaTC-EDU: Learning Platform and Education Curriculum for Artificial Intelligence-Driven Socially-Relevant Cybersecurity
合作研究:EAGER:SaTC-EDU:人工智能驱动的社会相关网络安全的学习平台和教育课程
- 批准号:21149822114982
- 财政年份:2021
- 资助金额:$ 50万$ 50万
- 项目类别:Standard GrantStandard Grant
NSF Student Travel Grant for 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization (SDN-NFV Security)
NSF 学生旅费补助金用于 2018 年 ACM 软件定义网络和网络功能虚拟化安全(SDN-NFV 安全)国际研讨会
- 批准号:18071031807103
- 财政年份:2018
- 资助金额:$ 50万$ 50万
- 项目类别:Standard GrantStandard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
- 批准号:16421431642143
- 财政年份:2017
- 资助金额:$ 50万$ 50万
- 项目类别:Standard GrantStandard Grant
SaTC: EDU: Collaborative: Enhancing Security Education through Transiting Research on Security in Emerging Network Technologies
SaTC:EDU:协作:通过新兴网络技术安全的过渡研究加强安全教育
- 批准号:17236631723663
- 财政年份:2017
- 资助金额:$ 50万$ 50万
- 项目类别:Standard GrantStandard Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
- 批准号:17004991700499
- 财政年份:2017
- 资助金额:$ 50万$ 50万
- 项目类别:Continuing GrantContinuing Grant
III: Small: Collaborative Research: Privacy-Aware Collaborative Data Sharing in Human-Centered Social Networks
III:小:协作研究:以人为本的社交网络中的隐私意识协作数据共享
- 批准号:15274211527421
- 财政年份:2015
- 资助金额:$ 50万$ 50万
- 项目类别:Standard GrantStandard Grant
相似国自然基金
SHP2调控Treg向Th2-like Treg的可塑性转化在变应性鼻炎中的作用与机制研究
- 批准号:82301281
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
EAST高极向比压运行模式下芯部与边界兼容机制的数值模拟研究
- 批准号:12375228
- 批准年份:2023
- 资助金额:53 万元
- 项目类别:面上项目
CXCR5依赖的边缘区B细胞向滤泡树突状细胞呈递外泌体引发心脏移植排斥的研究
- 批准号:82300460
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
Dlx2通过调控Tspan13影响上颌突间充质干细胞骨向分化的机制研究
- 批准号:82301008
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
糖尿病心肌病心室重构的新机制:高糖诱导巨噬细胞脂质代谢重编程通过活性脂质MA调控心脏成纤维细胞向肌成纤维细胞转分化的机制研究
- 批准号:82300404
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Design approach for patients who continue to wear elastic stockings for the treatment of lymphedema
继续穿弹力袜治疗淋巴水肿患者的设计方法
- 批准号:22K1268822K12688
- 财政年份:2022
- 资助金额:$ 50万$ 50万
- 项目类别:Grant-in-Aid for Scientific Research (C)Grant-in-Aid for Scientific Research (C)
Study on free vibration and elastic stability of axially functionally graded materials
轴向功能梯度材料自由振动及弹性稳定性研究
- 批准号:22K0429622K04296
- 财政年份:2022
- 资助金额:$ 50万$ 50万
- 项目类别:Grant-in-Aid for Scientific Research (C)Grant-in-Aid for Scientific Research (C)
Towards Mechanical Resonators With Zero Leakage Using Elastic Metastructures
使用弹性超结构实现零泄漏机械谐振器
- 批准号:20274552027455
- 财政年份:2021
- 资助金额:$ 50万$ 50万
- 项目类别:Standard GrantStandard Grant
CAREER: Towards Elastic Security with Safe and Efficient Network Security Function Virtualization
职业:通过安全高效的网络安全功能虚拟化迈向弹性安全
- 批准号:21291642129164
- 财政年份:2021
- 资助金额:$ 50万$ 50万
- 项目类别:Continuing GrantContinuing Grant
Towards 'bare glass': a software definied elastic optical network capable Tbit/s transciever
迈向“裸玻璃”:软件定义的弹性光网络功能 Tbit/s 收发器
- 批准号:517886-2017517886-2017
- 财政年份:2019
- 资助金额:$ 50万$ 50万
- 项目类别:Vanier Canada Graduate Scholarship Tri-Council - Doctoral 3 yearsVanier Canada Graduate Scholarship Tri-Council - Doctoral 3 years