CAREER: Programmable In-network Security
职业:可编程网络安全
基本信息
- 批准号:1942219
- 负责人:
- 金额:$ 55万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2020
- 资助国家:美国
- 起止时间:2020-01-15 至 2024-03-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Attacks on the Internet cost the economy billions of dollars. While today’s Internet was developed to provide widespread connectivity to individuals and businesses across the world, the networks that support the Internet do not have built-in security mechanisms. This project is focused on solving that problem by investigating future network designs based on new network technology that would support security and provide defense across a wide variety of attacks. The project vision is to develop Programmable In-network Security, or ‘Poise’. Poise aims to design and integrate a wide range of defenses directly inside the network, leveraging the technology trend of network programmability. If successful, a Poise network would support security as naturally as today’s networks support connectivity. This project will develop new scientific foundations for network security, investigate practical use cases, release open-source tools, and produce educational materials. The potential impact of Poise is to make future networks fundamentally more secure than they are today. This project presents a vision of Programmable In-network Security, or ‘Poise’, informed by the recent trend that network devices are becoming increasingly programmable, and with a goal of supporting security as a first-class network attribute. The project plans to take a three-pronged approach to realizing this goal. First, Poise aims to transform a programmable switch into a defense platform by designing a wide range of security applications that reside in the switch. Second, Poise aims to transform a network of programmable switches into a defense fleet, by architecting defense applications into the network paths and synchronizing them for whole-network defense. Third, Poise seeks to ensure that the defense applications, individually and collectively, are themselves secure against attacks. In its ultimate embodiment, a Poise network would toggle a wide array of defenses rapidly on and off as traffic flows through, mitigating attacks in real time. This project will advance the state of the art in network security in the above three dimensions and will produce scientific foundations and reusable system prototypes.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
尽管当今的互联网是为了向世界各地的个人和企业提供广泛的连接而开发的,但支持互联网的网络并没有内置的安全机制,该项目的重点是解决这一问题。通过研究基于新网络技术的未来网络设计来解决问题,该技术将支持安全性并提供针对各种攻击的防御。该项目的愿景是开发可编程网络内安全性,或“Poise”,旨在设计和集成广泛的网络安全性。直接在网络内部的防御范围,如果成功,Poise 网络将利用网络可编程性的技术趋势来支持安全性,就像当今的网络支持连接一样,该项目将为科学研究网络安全性、实际用例、发布开源工具并产生教育成果奠定基础。 Poise 的潜在影响是使未来的网络从根本上比现在更加安全。该项目提出了可编程网络安全(或“Poise”)的愿景,该愿景是基于网络设备变得越来越可编程的最新趋势。并目标是该项目计划采取三管齐下的方法来实现这一目标,首先,Poise 旨在通过设计驻留在网络中的广泛安全应用程序,将可编程交换机转变为防御平台。其次,Poise 旨在通过将防御应用程序构建到网络路径中并将其同步以实现整个网络防御,将可编程交换机网络转变为防御舰队。本身可以抵御攻击。在其最终实施例中,Poise 网络将在流量通过时快速打开和关闭各种防御,从而实时减轻攻击。该项目将在上述三个方面推进网络安全的最新技术,并将产生成果。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
NetWarden: Mitigating Network Covert Channels while Preserving Performance
NetWarden:在保持性能的同时减少网络隐蔽通道
- DOI:10.1109/tnsm.2021.3050091
- 发表时间:2024-09-13
- 期刊:
- 影响因子:5.3
- 作者:Jiarong Xing;Qiao Kang;Ang Chen
- 通讯作者:Ang Chen
Bedrock: Programmable Network Support for Secure RDMA Systems
Bedrock:安全 RDMA 系统的可编程网络支持
- DOI:10.1145/3579370.3594768
- 发表时间:2024-09-13
- 期刊:
- 影响因子:0
- 作者:Jiarong Xing;Kuo;Yiming Qiu;Ziyang Yang;Hongyi Liu;Ang Chen
- 通讯作者:Ang Chen
A Feasibility Study on Time-aware Monitoring with Commodity Switches
商品开关时间感知监控的可行性研究
- DOI:
- 发表时间:2020-01
- 期刊:
- 影响因子:0
- 作者:Qiu, Yiming;Hsu, Kuo;Xing, Jiarong;Chen, Ang
- 通讯作者:Chen, Ang
Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive Adversaries
Ripple:针对自适应对手的可编程、去中心化链接洪泛防御
- DOI:10.2118/124429-ms
- 发表时间:2024-09-13
- 期刊:
- 影响因子:4.1
- 作者:Jiarong Xing;Wenqing Wu;Ang Chen
- 通讯作者:Ang Chen
Probabilistic Profiling of Stateful Data Planes for Adversarial Testing
用于对抗性测试的状态数据平面的概率分析
- DOI:
- 发表时间:2021-01
- 期刊:
- 影响因子:0
- 作者:Qiao, K;Xing, J;Qiu, Y;Chen, A
- 通讯作者:Chen, A
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Ang Chen其他文献
A moso bamboo (Phyllostachys edulis) miniature inverted-repeat transposable element (MITE): the possible role of a suppressor
毛竹(Phyllostachys edulis)微型反向重复转座元件(MITE):抑制子的可能作用
- DOI:
10.1007/s11295-017-1210-4 - 发表时间:
2017-11-27 - 期刊:
- 影响因子:2.4
- 作者:
Mingbing Zhou;Ang Chen;Qianqian Zhou;D. Tang;H. Hänninen - 通讯作者:
H. Hänninen
This paper is included in the Proceedings of the 32nd USENIX Security Symposium
本文收录于第32届USENIX安全研讨会论文集
- DOI:
- 发表时间:
1970-01-01 - 期刊:
- 影响因子:0
- 作者:
Hongyi Liu;Jiarong Xing;Yibo Huang;Danyang Zhuo;Srinivas Devadas;Ang Chen - 通讯作者:
Ang Chen
A Feasibility Study on Time-aware Monitoring with Commodity Switches
商品开关时间感知监控的可行性研究
- DOI:
10.1145/3405669.3405821 - 发表时间:
2020-08-10 - 期刊:
- 影响因子:0
- 作者:
Yiming Qiu;Kuo;Jiarong Xing;Ang Chen - 通讯作者:
Ang Chen
Gender and Interest-Based Motivation in Learning Dance.
学习舞蹈中的性别和基于兴趣的动机。
- DOI:
10.1123/jtpe.22.4.396 - 发表时间:
2003-07-01 - 期刊:
- 影响因子:2.8
- 作者:
Bo Shen;Ang Chen;Hope Tolley;K. A. Scrabis - 通讯作者:
K. A. Scrabis
Goals, Interests, and Learning in Physical Education
体育教育的目标、兴趣和学习
- DOI:
- 发表时间:
2004 - 期刊:
- 影响因子:0
- 作者:
Ang Chen;C. Ennis - 通讯作者:
C. Ennis
Ang Chen的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Ang Chen', 18)}}的其他基金
Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
合作研究:CNS 核心:媒介:Splitkernel 分解的数据密集型系统中的计算和数据移动
- 批准号:
2406598 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
协作研究:CNS 核心:中:具有自适应优化的可重构内核数据路径
- 批准号:
2345339 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
CAREER: Programmable In-network Security
职业:可编程网络安全
- 批准号:
2420309 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
I-Corps: A Learned Cloud Infrastructure-as-Code (IaC) Linter
I-Corps:学习型云基础设施即代码 (IaC) Linter
- 批准号:
2344828 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Large: Runtime Programmable Networks
合作研究:CNS 核心:大型:运行时可编程网络
- 批准号:
2214272 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Medium: Movement of Computation and Data in Splitkernel-disaggregated, Data-intensive Systems
合作研究:CNS 核心:媒介:Splitkernel 分解的数据密集型系统中的计算和数据移动
- 批准号:
2106388 - 财政年份:2021
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Medium: Reconfigurable Kernel Datapaths with Adaptive Optimizations
协作研究:CNS 核心:中:具有自适应优化的可重构内核数据路径
- 批准号:
2106751 - 财政年份:2021
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
NeTS: Medium: Streaming Data Analytics over Programmable Datacenter Networks
NeTS:媒介:通过可编程数据中心网络进行流数据分析
- 批准号:
1801884 - 财政年份:2018
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
相似国自然基金
非线性的可编程超表面衍射神经网络
- 批准号:62301147
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
可编程网络中基于Sketch的通用和动态网络测量技术研究
- 批准号:62302410
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于可编程网络的分布式训练在网加速研究
- 批准号:62372426
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
面向异构可编程数据平面的网络功能优化问题研究
- 批准号:
- 批准年份:2021
- 资助金额:59 万元
- 项目类别:面上项目
面向下一代网络的可编程测量架构及关键测量方法
- 批准号:
- 批准年份:2020
- 资助金额:58 万元
- 项目类别:面上项目
相似海外基金
CAREER: Programmable In-network Security
职业:可编程网络安全
- 批准号:
2420309 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
CAREER: Designing Next-Generation Programmable Switches for Stateful In-Network Computing
职业:设计用于状态网络计算的下一代可编程交换机
- 批准号:
2239829 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
CAREER: DeepMatter: A Scalable and Programmable Embedded Deep Neural Network
职业:DeepMatter:可扩展且可编程的嵌入式深度神经网络
- 批准号:
2348983 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
CAREER: A Programmable Measurement Architecture for Network Operations
职业生涯:用于网络运营的可编程测量架构
- 批准号:
1834263 - 财政年份:2017
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
CAREER: DeepMatter: A Scalable and Programmable Embedded Deep Neural Network
职业:DeepMatter:可扩展且可编程的嵌入式深度神经网络
- 批准号:
1652703 - 财政年份:2017
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant