SDI-CSCS: Collaborative Research: S2OS Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS 通过 SDI 实现基础设施范围内的可编程安全性
基本信息
- 批准号:1834216
- 负责人:
- 金额:$ 39.34万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-01-01 至 2022-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Traditionally, many of our critical systems have been developed with security as a reactive add-on, rather than a by default design. As a result, existing security mechanisms are often fragmented, hard to configure or verify, which makes it difficult to defend against various cyber attacks. This project will build the "holy grail" for enterprise/cloud/data-center security management with software-defined infrastructure (SDI): a unified framework for security and management of disparate resources, ranging from processes to storage to networking. Cloud computing is now an essential part of our national cyberinfrastructure; the proposed work will lower the total cost of ownership for clouds - further unlocking economic and environmental benefits - as well as improving the security of today's clouds.This project proposes S2OS (SDI-defined Security Operating System), which abstracts security capabilities and primitives at both the host Operating System (OS) and network levels and offers an easy-to-use and programmable security model for monitoring and dynamically securing applications. This project will explore new techniques to transparently compose software into a unified enterprise, even if the individual pieces were never explicitly designed to inter-operate, similar in a way a traditional operating system managing various hardware resources for upper-layer user applications. Further, this project will contribute new ways to leverage global information for making effective local security management decisions. Finally, this project enables new innovations in programming dynamic, host-network coordinated, and intelligent security applications to protect the entire infrastructure.This project will make significant contributions to how enterprise, data centers and cloud computing are securely built and managed. The project's PIs will engage in educational and outreach activities to train the next generation talent. In particular, the PIs plan to integrate the interdisciplinary research ideas into courses spanning networking, systems and security. The project will also actively encourage participation from underrepresented groups and transfer technology to industry partners.
传统上,我们的许多关键系统都是将安全性作为反应性附加组件开发的,而不是默认设计。因此,现有的安全机制往往比较分散,难以配置或验证,难以防御各种网络攻击。该项目将通过软件定义基础设施(SDI)构建企业/云/数据中心安全管理的“圣杯”:一个用于安全和管理不同资源(从流程到存储再到网络)的统一框架。云计算现在是我们国家网络基础设施的重要组成部分;拟议的工作将降低云的总体拥有成本,进一步释放经济和环境效益,并提高当今云的安全性。该项目提出了 S2OS(SDI 定义的安全操作系统),它抽象了安全功能和原语主机操作系统 (OS) 和网络级别,并提供易于使用且可编程的安全模型,用于监控和动态保护应用程序。该项目将探索新技术,以透明地将软件组合成一个统一的企业,即使各个部分从未明确设计为可互操作,类似于传统操作系统为上层用户应用程序管理各种硬件资源的方式。此外,该项目还将提供利用全球信息做出有效的本地安全管理决策的新方法。最后,该项目在动态编程、主机网络协调和智能安全应用程序方面实现了新的创新,以保护整个基础设施。该项目将为企业、数据中心和云计算的安全构建和管理做出重大贡献。该项目的 PI 将参与教育和外展活动,以培训下一代人才。特别是,PI 计划将跨学科研究思想整合到网络、系统和安全领域的课程中。该项目还将积极鼓励代表性不足的群体参与,并向行业合作伙伴转让技术。
项目成果
期刊论文数量(9)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile Apps
使用移动应用程序中的静态 UUID 对易受攻击的 BLE IoT 设备进行自动指纹识别
- DOI:10.1145/3319535.3354240
- 发表时间:2019-11-06
- 期刊:
- 影响因子:0
- 作者:Chaoshun Zuo;Haohuang Wen;Zhiqiang Lin;Yinqian Zhang
- 通讯作者:Yinqian Zhang
vSGX: Virtualizing SGX Enclaves on AMD SEV
vSGX:在 AMD SEV 上虚拟化 SGX Enclave
- DOI:10.1109/sp46214.2022.9833694
- 发表时间:2022-05-01
- 期刊:
- 影响因子:0
- 作者:Shixuan Zhao;Mengyuan Li;Yinqian Zhang;Zhiqiang Lin
- 通讯作者:Zhiqiang Lin
CrossLine: Breaking "Security-by-Crash" based Memory Isolation in AMD SEV
CrossLine:打破 AMD SEV 中基于“安全崩溃”的内存隔离
- DOI:10.1145/3460120.3485253
- 发表时间:2020-08-01
- 期刊:
- 影响因子:0
- 作者:Mengyuan Li;Yinqian Zhang;Zhiqiang Lin
- 通讯作者:Zhiqiang Lin
Exploiting Unprotected I/O Operations in AMD's Secure Encrypted Virtualization
利用 AMD 安全加密虚拟化中未受保护的 I/O 操作
- DOI:
- 发表时间:2024-09-14
- 期刊:
- 影响因子:0
- 作者:Mengyuan Li;Yinqian Zhang;Zhiqiang Lin;Yan Solihin
- 通讯作者:Yan Solihin
Towards Memory Safe Enclave Programming with Rust-SGX
使用 Rust-SGX 实现内存安全 Enclave 编程
- DOI:10.1145/3319535.3354241
- 发表时间:2019-11-06
- 期刊:
- 影响因子:0
- 作者:Huibo Wang;Pei Wang;Yu Ding;Mingshen Sun;Yiming Jing;Ran Duan;Long Li;Yulong Zhang;Tao W
- 通讯作者:Tao W
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Zhiqiang Lin其他文献
Efficient Explicit Constructions of Multipartite Secret Sharing Schemes
多方秘密共享方案的高效显式构建
- DOI:
10.1007/978-3-030-34621-8_18 - 发表时间:
2019-12-08 - 期刊:
- 影响因子:2.5
- 作者:
Qi Chen;Chunming Tang;Zhiqiang Lin - 通讯作者:
Zhiqiang Lin
Carbon Nanotubes: Three‐Dimensional Carbon Nanotube Sponge‐Array Architectures with High Energy Dissipation (Adv. Mater. 8/2014)
碳纳米管:具有高能量耗散的三维碳纳米管海绵阵列架构(Adv. Mater. 8/2014)
- DOI:
10.1002/adma.201470052 - 发表时间:
2014-02-01 - 期刊:
- 影响因子:29.4
- 作者:
Xuchun Gui;Zhiping Zeng;Yuan Zhu;Hongbian Li;Zhiqiang Lin;Qiming Gan;R. Xiang;A. Cao;Zikang Tang - 通讯作者:
Zikang Tang
Data flow sensitive driver vulnerability mining method
数据流敏感驱动漏洞挖掘方法
- DOI:
10.1145/3501409.3501631 - 发表时间:
2021-10-22 - 期刊:
- 影响因子:0
- 作者:
Yechuan Bi;Jianshan Peng;Zhiqiang Lin - 通讯作者:
Zhiqiang Lin
Probabilistic Disassembly
概率反汇编
- DOI:
10.1109/icse.2019.00121 - 发表时间:
2019-05-01 - 期刊:
- 影响因子:0
- 作者:
Kenneth A. Miller;Yonghwi Kwon;Yi Sun;Zhuo Zhang;X. Zhang;Zhiqiang Lin - 通讯作者:
Zhiqiang Lin
Data-Centric OS Kernel Malware Characterization
以数据为中心的操作系统内核恶意软件特征
- DOI:
10.1109/tifs.2013.2291964 - 发表时间:
2024-09-14 - 期刊:
- 影响因子:6.8
- 作者:
J. Rhee;Ryan D. Riley;Zhiqiang Lin;Xuxian Jiang;Dongyan Xu - 通讯作者:
Dongyan Xu
Zhiqiang Lin的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Zhiqiang Lin', 18)}}的其他基金
Collaborative Research: EAGER: Towards Safeguarding the Emerging Miniapp Paradigm in Mobile Super Apps
合作研究:EAGER:捍卫移动超级应用中新兴的小应用范式
- 批准号:
2330264 - 财政年份:2023
- 资助金额:
$ 39.34万 - 项目类别:
Standard Grant
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
- 批准号:
2207202 - 财政年份:2022
- 资助金额:
$ 39.34万 - 项目类别:
Continuing Grant
Collaborative Research: PPoSS: Planning: Scaling Autonomous Vehicle Systems at the Edge: from On-Board Processing to Cloud Infrastructure
合作研究:PPoSS:规划:扩展边缘自主车辆系统:从车载处理到云基础设施
- 批准号:
2118491 - 财政年份:2021
- 资助金额:
$ 39.34万 - 项目类别:
Standard Grant
EDU: Collaborative: Using Virtual Machine Introspection for Deep Cyber Security Education
EDU:协作:使用虚拟机自省进行深度网络安全教育
- 批准号:
1834214 - 财政年份:2018
- 资助金额:
$ 39.34万 - 项目类别:
Standard Grant
CAREER: A Dual-VM Binary Code Reuse Based Framework for Automated Virtual Machine Introspection
职业:基于双虚拟机二进制代码重用的自动化虚拟机自省框架
- 批准号:
1834215 - 财政年份:2018
- 资助金额:
$ 39.34万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1834213 - 财政年份:2018
- 资助金额:
$ 39.34万 - 项目类别:
Standard Grant
EDU: Collaborative: Using Virtual Machine Introspection for Deep Cyber Security Education
EDU:协作:使用虚拟机自省进行深度网络安全教育
- 批准号:
1834214 - 财政年份:2018
- 资助金额:
$ 39.34万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1834213 - 财政年份:2018
- 资助金额:
$ 39.34万 - 项目类别:
Standard Grant
CAREER: A Dual-VM Binary Code Reuse Based Framework for Automated Virtual Machine Introspection
职业:基于双虚拟机二进制代码重用的自动化虚拟机自省框架
- 批准号:
1834215 - 财政年份:2018
- 资助金额:
$ 39.34万 - 项目类别:
Continuing Grant
SDI-CSCS: Collaborative Research: S2OS Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS 通过 SDI 实现基础设施范围内的可编程安全性
- 批准号:
1700507 - 财政年份:2017
- 资助金额:
$ 39.34万 - 项目类别:
Continuing Grant
相似国自然基金
脾虚内环境下调RDH5激活Hippo/YAP通路调控肝癌CSCs干性及健脾中药干预的机制
- 批准号:82304944
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于BNIP3/HIF-1α通路介导CSCs干性维持探讨夏枯草总黄酮抑制肝癌复发的作用机制
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
BMSCs外泌体circRNA竞争性激活WIF1/Wnts通路介导胰腺癌CSCs去干性化机制
- 批准号:
- 批准年份:2021
- 资助金额:55 万元
- 项目类别:面上项目
基于SHP-1探讨增免抑瘤方调控CSCs与肿瘤相关巨噬细胞交互作用抑制卵巢癌复发的分子机制
- 批准号:82174428
- 批准年份:2021
- 资助金额:55 万元
- 项目类别:面上项目
毛果杨次生壁CesAs敲除对木材形成和CSCs复合体的影响
- 批准号:31770637
- 批准年份:2017
- 资助金额:60.0 万元
- 项目类别:面上项目
相似海外基金
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
- 批准号:
2128107 - 财政年份:2021
- 资助金额:
$ 39.34万 - 项目类别:
Continuing Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
- 批准号:
2128107 - 财政年份:2021
- 资助金额:
$ 39.34万 - 项目类别:
Continuing Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
- 批准号:
1700527 - 财政年份:2017
- 资助金额:
$ 39.34万 - 项目类别:
Continuing Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
- 批准号:
1700512 - 财政年份:2017
- 资助金额:
$ 39.34万 - 项目类别:
Continuing Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
- 批准号:
1700544 - 财政年份:2017
- 资助金额:
$ 39.34万 - 项目类别:
Continuing Grant