CAREER: Programmable In-network Security

职业:可编程网络安全

基本信息

  • 批准号:
    1942219
  • 负责人:
  • 金额:
    $ 55万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2020
  • 资助国家:
    美国
  • 起止时间:
    2020-01-15 至 2024-03-31
  • 项目状态:
    已结题

项目摘要

Attacks on the Internet cost the economy billions of dollars. While today’s Internet was developed to provide widespread connectivity to individuals and businesses across the world, the networks that support the Internet do not have built-in security mechanisms. This project is focused on solving that problem by investigating future network designs based on new network technology that would support security and provide defense across a wide variety of attacks. The project vision is to develop Programmable In-network Security, or ‘Poise’. Poise aims to design and integrate a wide range of defenses directly inside the network, leveraging the technology trend of network programmability. If successful, a Poise network would support security as naturally as today’s networks support connectivity. This project will develop new scientific foundations for network security, investigate practical use cases, release open-source tools, and produce educational materials. The potential impact of Poise is to make future networks fundamentally more secure than they are today. This project presents a vision of Programmable In-network Security, or ‘Poise’, informed by the recent trend that network devices are becoming increasingly programmable, and with a goal of supporting security as a first-class network attribute. The project plans to take a three-pronged approach to realizing this goal. First, Poise aims to transform a programmable switch into a defense platform by designing a wide range of security applications that reside in the switch. Second, Poise aims to transform a network of programmable switches into a defense fleet, by architecting defense applications into the network paths and synchronizing them for whole-network defense. Third, Poise seeks to ensure that the defense applications, individually and collectively, are themselves secure against attacks. In its ultimate embodiment, a Poise network would toggle a wide array of defenses rapidly on and off as traffic flows through, mitigating attacks in real time. This project will advance the state of the art in network security in the above three dimensions and will produce scientific foundations and reusable system prototypes.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
互联网的攻击损失了经济数十亿美元。虽然今天的互联网是为了向全世界的个人和企业提供宽度连接,但支持互联网的网络没有内置的安全机制。该项目的重点是通过基于新的网络技术研究未来的网络设计来解决该问题,该技术将支持安全性并在各种攻击中提供防御。该项目愿景是开发可编程的网络内安全性或“保持平衡”。 Porise旨在直接在网络内部设计和集成各种防御,利用网络编程的技术趋势。如果成功的话,一个平衡的网络将自然地支持当今网络支持连接的安全性。该项目将为网络安全开发新的科学基础,调查实际用例,释放开源工具并生产教育材料。平衡的潜在影响是使未来的网络从根本上比今天更加安全。该项目提出了可编程的网络内安全性或“保持平衡”的愿景,这是由于最近的趋势所启示的,即网络设备变得越来越多,并且目的是支持安全性作为一流的网络属性。该项目计划采取三方面的方法来实现这一目标。首先,Porise旨在通过设计驻留在开关中的广泛的安全应用程序,将可编程开关转换为防御平台。其次,Porise旨在通过将防御应用程序架构为网络路径并将其同步以进行整个网络防御,将可编程交换机网络转换为防御车队。第三,镇定旨在确保辩护申请单独和集体地保护自己免受攻击。在其最终实施方案中,一个平衡的网络将随着交通流量的流动而迅速打开和关闭各种防御能力,从而实时减轻攻击。该项目将在上述三个维度上推进网络安全性的最新技术,并将产生科学基础和可重复使用的系统原型。该奖项反映了NSF的法定任务,并通过评估该基金会的知识分子和更广泛的影响来审查标准。

项目成果

期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Probabilistic Profiling of Stateful Data Planes for Adversarial Testing
用于对抗性测试的状态数据平面的概率分析
  • DOI:
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Qiao, K;Xing, J;Qiu, Y;Chen, A
  • 通讯作者:
    Chen, A
Stargaze: A LEO Constellation Emulator for Security Experimentation
Remote Direct Memory Introspection
  • DOI:
  • 发表时间:
    2023
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Hongyi Liu;Jiarong Xing;Yibo Huang;Danyang Zhuo;S. Devadas;Ang Chen
  • 通讯作者:
    Hongyi Liu;Jiarong Xing;Yibo Huang;Danyang Zhuo;S. Devadas;Ang Chen
A Feasibility Study on Time-aware Monitoring with Commodity Switches
NetWarden: Mitigating Network Covert Channels while Preserving Performance
  • DOI:
  • 发表时间:
    2020
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jiarong Xing;Qiao Kang;Ang Chen
  • 通讯作者:
    Jiarong Xing;Qiao Kang;Ang Chen
共 7 条
  • 1
  • 2
前往

Ang Chen其他文献

Single-phase dielectric compounds in the BaO-rich corner of the BaO-Re203-Ti02 ternary system (Re = Y, Nd, and Sm)
BaO-Re2O3-Ti02 三元系统(Re = Y、Nd 和 Sm)的富含 BaO 角的单相介电化合物
Three-Year Trajectory of Interest in Learning Physical Activity Knowledge: Influences of Gender and Prior Knowledge
学习体育活动知识的三年兴趣轨迹:性别和先验知识的影响
Interactive Impact of Intrinsic Motivators and Extrinsic Rewards on Behavior and Motivation Outcomes
内在激励因素和外在奖励对行为和激励结果的交互影响
  • DOI:
  • 发表时间:
    2005
    2005
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Ping Xiang;Ang Chen;A. Bruene
    Ping Xiang;Ang Chen;A. Bruene
  • 通讯作者:
    A. Bruene
    A. Bruene
An Examination of Learning Profiles in Physical Education.
体育学习概况检查。
Static and dynamic mechanical behavior of high-strength 22SiMn2TiB armor steel and welded structure
  • DOI:
    10.1016/j.jmrt.2024.10.175
    10.1016/j.jmrt.2024.10.175
  • 发表时间:
    2024-11-01
    2024-11-01
  • 期刊:
  • 影响因子:
  • 作者:
    Jitang Fan;Ang Chen;Yongqiang Wang;Ke Bao;Yue Liu;Aiying Chen;Tao Fu;Linli Zhu
    Jitang Fan;Ang Chen;Yongqiang Wang;Ke Bao;Yue Liu;Aiying Chen;Tao Fu;Linli Zhu
  • 通讯作者:
    Linli Zhu
    Linli Zhu
共 44 条
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 9
前往

Ang Chen的其他基金

Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
合作研究:CNS 核心:媒介:Splitkernel 分解的数据密集型系统中的计算和数据移动
  • 批准号:
    2406598
    2406598
  • 财政年份:
    2023
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant
Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
协作研究:CNS 核心:中:具有自适应优化的可重构内核数据路径
  • 批准号:
    2345339
    2345339
  • 财政年份:
    2023
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Standard Grant
    Standard Grant
I-Corps: A Learned Cloud Infrastructure-as-Code (IaC) Linter
I-Corps:学习型云基础设施即代码 (IaC) Linter
  • 批准号:
    2344828
    2344828
  • 财政年份:
    2023
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Standard Grant
    Standard Grant
CAREER: Programmable In-network Security
职业:可编程网络安全
  • 批准号:
    2420309
    2420309
  • 财政年份:
    2023
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant
Collaborative Research: CNS Core: Large: Runtime Programmable Networks
合作研究:CNS 核心:大型:运行时可编程网络
  • 批准号:
    2214272
    2214272
  • 财政年份:
    2022
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant
Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
合作研究:CNS 核心:媒介:Splitkernel 分解的数据密集型系统中的计算和数据移动
  • 批准号:
    2106388
    2106388
  • 财政年份:
    2021
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant
Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
协作研究:CNS 核心:中:具有自适应优化的可重构内核数据路径
  • 批准号:
    2106751
    2106751
  • 财政年份:
    2021
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Standard Grant
    Standard Grant
NeTS: Medium: Streaming Data Analytics over Programmable Datacenter Networks
NeTS:媒介:通过可编程数据中心网络进行流数据分析
  • 批准号:
    1801884
    1801884
  • 财政年份:
    2018
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant

相似国自然基金

可编程网络中基于Sketch的通用和动态网络测量技术研究
  • 批准号:
    62302410
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
基于可编程网络的分布式训练在网加速研究
  • 批准号:
    62372426
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目
非线性的可编程超表面衍射神经网络
  • 批准号:
    62301147
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
面向异构可编程数据平面的网络功能优化问题研究
  • 批准号:
    62172189
  • 批准年份:
    2021
  • 资助金额:
    59.00 万元
  • 项目类别:
    面上项目
面向异构可编程数据平面的网络功能优化问题研究
  • 批准号:
  • 批准年份:
    2021
  • 资助金额:
    59 万元
  • 项目类别:
    面上项目

相似海外基金

CAREER: Designing Next-Generation Programmable Switches for Stateful In-Network Computing
职业:设计用于状态网络计算的下一代可编程交换机
  • 批准号:
    2239829
    2239829
  • 财政年份:
    2023
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant
CAREER: DeepMatter: A Scalable and Programmable Embedded Deep Neural Network
职业:DeepMatter:可扩展且可编程的嵌入式深度神经网络
  • 批准号:
    2348983
    2348983
  • 财政年份:
    2023
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant
CAREER: Programmable In-network Security
职业:可编程网络安全
  • 批准号:
    2420309
    2420309
  • 财政年份:
    2023
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant
CAREER: A Programmable Measurement Architecture for Network Operations
职业生涯:用于网络运营的可编程测量架构
  • 批准号:
    1834263
    1834263
  • 财政年份:
    2017
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant
CAREER: DeepMatter: A Scalable and Programmable Embedded Deep Neural Network
职业:DeepMatter:可扩展且可编程的嵌入式深度神经网络
  • 批准号:
    1652703
    1652703
  • 财政年份:
    2017
  • 资助金额:
    $ 55万
    $ 55万
  • 项目类别:
    Continuing Grant
    Continuing Grant