CAREER: Programmable In-network Security
职业:可编程网络安全
基本信息
- 批准号:1942219
- 负责人:
- 金额:$ 55万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2020
- 资助国家:美国
- 起止时间:2020-01-15 至 2024-03-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Attacks on the Internet cost the economy billions of dollars. While today’s Internet was developed to provide widespread connectivity to individuals and businesses across the world, the networks that support the Internet do not have built-in security mechanisms. This project is focused on solving that problem by investigating future network designs based on new network technology that would support security and provide defense across a wide variety of attacks. The project vision is to develop Programmable In-network Security, or ‘Poise’. Poise aims to design and integrate a wide range of defenses directly inside the network, leveraging the technology trend of network programmability. If successful, a Poise network would support security as naturally as today’s networks support connectivity. This project will develop new scientific foundations for network security, investigate practical use cases, release open-source tools, and produce educational materials. The potential impact of Poise is to make future networks fundamentally more secure than they are today. This project presents a vision of Programmable In-network Security, or ‘Poise’, informed by the recent trend that network devices are becoming increasingly programmable, and with a goal of supporting security as a first-class network attribute. The project plans to take a three-pronged approach to realizing this goal. First, Poise aims to transform a programmable switch into a defense platform by designing a wide range of security applications that reside in the switch. Second, Poise aims to transform a network of programmable switches into a defense fleet, by architecting defense applications into the network paths and synchronizing them for whole-network defense. Third, Poise seeks to ensure that the defense applications, individually and collectively, are themselves secure against attacks. In its ultimate embodiment, a Poise network would toggle a wide array of defenses rapidly on and off as traffic flows through, mitigating attacks in real time. This project will advance the state of the art in network security in the above three dimensions and will produce scientific foundations and reusable system prototypes.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
互联网的攻击损失了经济数十亿美元。虽然今天的互联网是为了向全世界的个人和企业提供宽度连接,但支持互联网的网络没有内置的安全机制。该项目的重点是通过基于新的网络技术研究未来的网络设计来解决该问题,该技术将支持安全性并在各种攻击中提供防御。该项目愿景是开发可编程的网络内安全性或“保持平衡”。 Porise旨在直接在网络内部设计和集成各种防御,利用网络编程的技术趋势。如果成功的话,一个平衡的网络将自然地支持当今网络支持连接的安全性。该项目将为网络安全开发新的科学基础,调查实际用例,释放开源工具并生产教育材料。平衡的潜在影响是使未来的网络从根本上比今天更加安全。该项目提出了可编程的网络内安全性或“保持平衡”的愿景,这是由于最近的趋势所启示的,即网络设备变得越来越多,并且目的是支持安全性作为一流的网络属性。该项目计划采取三方面的方法来实现这一目标。首先,Porise旨在通过设计驻留在开关中的广泛的安全应用程序,将可编程开关转换为防御平台。其次,Porise旨在通过将防御应用程序架构为网络路径并将其同步以进行整个网络防御,将可编程交换机网络转换为防御车队。第三,镇定旨在确保辩护申请单独和集体地保护自己免受攻击。在其最终实施方案中,一个平衡的网络将随着交通流量的流动而迅速打开和关闭各种防御能力,从而实时减轻攻击。该项目将在上述三个维度上推进网络安全性的最新技术,并将产生科学基础和可重复使用的系统原型。该奖项反映了NSF的法定任务,并通过评估该基金会的知识分子和更广泛的影响来审查标准。
项目成果
期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Probabilistic Profiling of Stateful Data Planes for Adversarial Testing
用于对抗性测试的状态数据平面的概率分析
- DOI:
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Qiao, K;Xing, J;Qiu, Y;Chen, A
- 通讯作者:Chen, A
Stargaze: A LEO Constellation Emulator for Security Experimentation
- DOI:10.1145/3560826.3563382
- 发表时间:2022-11
- 期刊:
- 影响因子:0
- 作者:Patrick Tser Jern Kon;Diogo Barradas;Ang Chen
- 通讯作者:Patrick Tser Jern Kon;Diogo Barradas;Ang Chen
Remote Direct Memory Introspection
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Hongyi Liu;Jiarong Xing;Yibo Huang;Danyang Zhuo;S. Devadas;Ang Chen
- 通讯作者:Hongyi Liu;Jiarong Xing;Yibo Huang;Danyang Zhuo;S. Devadas;Ang Chen
A Feasibility Study on Time-aware Monitoring with Commodity Switches
- DOI:10.1145/3405669.3405821
- 发表时间:2020-08
- 期刊:
- 影响因子:0
- 作者:Yiming Qiu;Kuo-Feng Hsu;Jiarong Xing;Ang Chen
- 通讯作者:Yiming Qiu;Kuo-Feng Hsu;Jiarong Xing;Ang Chen
NetWarden: Mitigating Network Covert Channels while Preserving Performance
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Jiarong Xing;Qiao Kang;Ang Chen
- 通讯作者:Jiarong Xing;Qiao Kang;Ang Chen
共 7 条
- 1
- 2
Ang Chen其他文献
Single-phase dielectric compounds in the BaO-rich corner of the BaO-Re203-Ti02 ternary system (Re = Y, Nd, and Sm)
BaO-Re2O3-Ti02 三元系统(Re = Y、Nd 和 Sm)的富含 BaO 角的单相介电化合物
- DOI:10.1007/bf0024079110.1007/bf00240791
- 发表时间:19961996
- 期刊:
- 影响因子:0
- 作者:Ang Chen;Y. Zhi;V. Ferreira;P. Vilarinho;J. BaptistaAng Chen;Y. Zhi;V. Ferreira;P. Vilarinho;J. Baptista
- 通讯作者:J. BaptistaJ. Baptista
Three-Year Trajectory of Interest in Learning Physical Activity Knowledge: Influences of Gender and Prior Knowledge
学习体育活动知识的三年兴趣轨迹:性别和先验知识的影响
- DOI:10.1123/jtpe.2020-000910.1123/jtpe.2020-0009
- 发表时间:20202020
- 期刊:
- 影响因子:2.8
- 作者:Yubing Wang;Tan Zhang;Ang ChenYubing Wang;Tan Zhang;Ang Chen
- 通讯作者:Ang ChenAng Chen
Interactive Impact of Intrinsic Motivators and Extrinsic Rewards on Behavior and Motivation Outcomes
内在激励因素和外在奖励对行为和激励结果的交互影响
- DOI:
- 发表时间:20052005
- 期刊:
- 影响因子:0
- 作者:Ping Xiang;Ang Chen;A. BruenePing Xiang;Ang Chen;A. Bruene
- 通讯作者:A. BrueneA. Bruene
An Examination of Learning Profiles in Physical Education.
体育学习概况检查。
- DOI:10.1123/jtpe.26.2.14510.1123/jtpe.26.2.145
- 发表时间:20072007
- 期刊:
- 影响因子:2.8
- 作者:Bo Shen;Ang ChenBo Shen;Ang Chen
- 通讯作者:Ang ChenAng Chen
Static and dynamic mechanical behavior of high-strength 22SiMn2TiB armor steel and welded structure
- DOI:10.1016/j.jmrt.2024.10.17510.1016/j.jmrt.2024.10.175
- 发表时间:2024-11-012024-11-01
- 期刊:
- 影响因子:
- 作者:Jitang Fan;Ang Chen;Yongqiang Wang;Ke Bao;Yue Liu;Aiying Chen;Tao Fu;Linli ZhuJitang Fan;Ang Chen;Yongqiang Wang;Ke Bao;Yue Liu;Aiying Chen;Tao Fu;Linli Zhu
- 通讯作者:Linli ZhuLinli Zhu
共 44 条
- 1
- 2
- 3
- 4
- 5
- 6
- 9
Ang Chen的其他基金
Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
合作研究:CNS 核心:媒介:Splitkernel 分解的数据密集型系统中的计算和数据移动
- 批准号:24065982406598
- 财政年份:2023
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant
Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
协作研究:CNS 核心:中:具有自适应优化的可重构内核数据路径
- 批准号:23453392345339
- 财政年份:2023
- 资助金额:$ 55万$ 55万
- 项目类别:Standard GrantStandard Grant
I-Corps: A Learned Cloud Infrastructure-as-Code (IaC) Linter
I-Corps:学习型云基础设施即代码 (IaC) Linter
- 批准号:23448282344828
- 财政年份:2023
- 资助金额:$ 55万$ 55万
- 项目类别:Standard GrantStandard Grant
CAREER: Programmable In-network Security
职业:可编程网络安全
- 批准号:24203092420309
- 财政年份:2023
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant
Collaborative Research: CNS Core: Large: Runtime Programmable Networks
合作研究:CNS 核心:大型:运行时可编程网络
- 批准号:22142722214272
- 财政年份:2022
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant
Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
合作研究:CNS 核心:媒介:Splitkernel 分解的数据密集型系统中的计算和数据移动
- 批准号:21063882106388
- 财政年份:2021
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant
Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
协作研究:CNS 核心:中:具有自适应优化的可重构内核数据路径
- 批准号:21067512106751
- 财政年份:2021
- 资助金额:$ 55万$ 55万
- 项目类别:Standard GrantStandard Grant
NeTS: Medium: Streaming Data Analytics over Programmable Datacenter Networks
NeTS:媒介:通过可编程数据中心网络进行流数据分析
- 批准号:18018841801884
- 财政年份:2018
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant
相似国自然基金
可编程网络中基于Sketch的通用和动态网络测量技术研究
- 批准号:62302410
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于可编程网络的分布式训练在网加速研究
- 批准号:62372426
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
非线性的可编程超表面衍射神经网络
- 批准号:62301147
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
面向异构可编程数据平面的网络功能优化问题研究
- 批准号:62172189
- 批准年份:2021
- 资助金额:59.00 万元
- 项目类别:面上项目
面向异构可编程数据平面的网络功能优化问题研究
- 批准号:
- 批准年份:2021
- 资助金额:59 万元
- 项目类别:面上项目
相似海外基金
CAREER: Designing Next-Generation Programmable Switches for Stateful In-Network Computing
职业:设计用于状态网络计算的下一代可编程交换机
- 批准号:22398292239829
- 财政年份:2023
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant
CAREER: DeepMatter: A Scalable and Programmable Embedded Deep Neural Network
职业:DeepMatter:可扩展且可编程的嵌入式深度神经网络
- 批准号:23489832348983
- 财政年份:2023
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant
CAREER: Programmable In-network Security
职业:可编程网络安全
- 批准号:24203092420309
- 财政年份:2023
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant
CAREER: A Programmable Measurement Architecture for Network Operations
职业生涯:用于网络运营的可编程测量架构
- 批准号:18342631834263
- 财政年份:2017
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant
CAREER: DeepMatter: A Scalable and Programmable Embedded Deep Neural Network
职业:DeepMatter:可扩展且可编程的嵌入式深度神经网络
- 批准号:16527031652703
- 财政年份:2017
- 资助金额:$ 55万$ 55万
- 项目类别:Continuing GrantContinuing Grant