Collaborative Research: SaTC: CORE: Medium: ONSET: Optics- enabled Network Defenses for Extreme Terabit DDoS Attacks

协作研究:SaTC:核心:中:ONSET:针对极端太比特 DDoS 攻击的光学网络防御

基本信息

  • 批准号:
    2132651
  • 负责人:
  • 金额:
    $ 40万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2022
  • 资助国家:
    美国
  • 起止时间:
    2022-01-01 至 2025-12-31
  • 项目状态:
    未结题

项目摘要

Distributed Denial of Service (DDoS) attacks continue to present a clear and imminent danger to critical network infrastructures. DDoS attacks have increased in sophistication with advanced strategies to continuously adapt (e.g., changing threat postures dynamically) and induce collateral damage (i.e., higher latency and loss for legitimate traffic). Furthermore, advanced attacks may also employ reconnaissance (e.g., mapping the network to find bottleneck links) to target the network infrastructure itself. In light of these trends, state-of-art defenses (e.g., advanced scrubbing, emerging software-defined defenses, and programmable switching hardware) have fundamental shortcomings. This project will develop a new framework, referred to as "Optics-enabled In-Network defenSe for Extreme Terabit DDoS attacks" (ONSET). The framework makes a case for new dimensions of defense agility that can programmatically control the topology of the network (in addition to the processing behavior) to tackle advanced and future attacks. The project will facilitate the use of optical technologies as an exciting visual medium for engaging K-12 students via suitable channels for dissemination. The project will also result in new course materials at the intersection of optical networking, software-defined networking, and network security to enable students to become domain experts in this emerging problem space. The project will take an interdisciplinary approach spanning security, optics, systems, and networks, to address fundamental challenges along three thrusts: (1) novel "data plane" solutions to rapidly reconfigure the wavelengths and switches and new capabilities in programmable switches to rapidly identify malicious vs. benign traffic at line rate; (2) novel "control plane" orchestration mechanisms for scalable resource management algorithms and coordinated control across optical networking and programmable switches; and (3) new "northbound application programming interfaces (APIs)" to express novel defenses to combat current and future DDoS attacks (e.g., with reconnaissance). This project will develop a new framework, referred to as "Optics-enabled In-Network defenSe for Extreme Terabit DDoS attacks" (ONSET). The research efforts will result in end-to-end prototypes using open-source and standardized interfaces to demonstrate the novel defense capabilities of ONSET. The efficacy of ONSET will be evaluated using pilot studies on operational networks to create a roadmap to practical deployment, using real testbeds and large-scale simulations. The project outcomes will be released as open-source software tools, models, and simulation frameworks that will inform industry and academic work.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
分布式拒绝服务(DDOS)攻击继续对关键网络基础设施构成明显而迫在眉睫的危险。 DDOS攻击的复杂性增加了,以不断适应(例如,动态变化威胁姿势)并造成附带损害(即合法流量的延迟和损失)。此外,高级攻击也可以采用侦察(例如,映射网络以找到瓶颈链接)来针对网络基础架构本身。鉴于这些趋势,最先进的防御能力(​​例如,高级擦洗,新兴软件定义的防御和可编程的切换硬件)具有根本的缺点。该项目将开发一个新的框架,称为“极端Terabit DDOS攻击的网络内部防御”(发作)。该框架为防御敏捷性的新维度提供了一个例子,该维度可以通过编程方式控制网络的拓扑(除了处理行为之外),以应对高级和未来的攻击。该项目将促进光学技术用作令人兴奋的视觉媒介,以通过合适的渠道传播K-12学生。该项目还将在光学网络,软件定义的网络和网络安全的交集中产生新的课程材料,以使学生能够成为这个新兴问题领域的领域专家。该项目将采用跨学科的方法,涵盖安全性,光学,系统和网络,以解决三个推力的基本挑战:(1)新颖的“数据平面”解决方案,以快速重新配置可编程开关中的波长和开关以及新功能,以快速识别恶意交通,以识别以线的态度和良性流量; (2)用于可扩展资源管理算法和跨光学网络和可编程开关的可扩展资源管理算法和协调控制的新颖的“控制平面”编排机制; (3)新的“ Northbound应用程序编程接口(API)”来表达新颖的防御能力,以打击当前和未来的DDOS攻击(例如,侦察)。该项目将开发一个新的框架,称为“极端Terabit DDOS攻击的网络内部防御”(发作)。研究工作将导致使用开源和标准化界面的端到端原型,以证明发作的新型防御能力。使用操作网络的试点研究将对发作的功效进行评估,以使用实际的测试床和大规模模拟来创建实用部署的路线图。该项目成果将作为开源软件工具,模型和模拟框架发布,这些框架将为行业和学术工作提供依据。该奖项反映了NSF的法定任务,并使用基金会的知识分子优点和更广泛的影响审查标准,认为值得通过评估来获得支持。

项目成果

期刊论文数量(4)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Improving Scalability in Traffic Engineering via Optical Topology Programming
  • DOI:
    10.1109/tnsm.2023.3335898
  • 发表时间:
    2024-04
  • 期刊:
  • 影响因子:
    5.3
  • 作者:
    Matthew Nance-Hall;P. Barford;Klaus-Tycho Foerster;Ramakrishnan Durairajan
  • 通讯作者:
    Matthew Nance-Hall;P. Barford;Klaus-Tycho Foerster;Ramakrishnan Durairajan
Dynamic Scheduling of Approximate Telemetry Queries
  • DOI:
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Chris Misa;Walt O'Connor;Ramakrishnan Durairajan;R. Rejaie;Walter Willinger
  • 通讯作者:
    Chris Misa;Walt O'Connor;Ramakrishnan Durairajan;R. Rejaie;Walter Willinger
DynATOS+: A Network Telemetry System for Dynamic Traffic and Query Workloads
  • DOI:
  • 发表时间:
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Chris Misa;Ramakrishnan Durairajan;R. Rejaie
  • 通讯作者:
    Chris Misa;Ramakrishnan Durairajan;R. Rejaie
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Ramakrishnan Durairajan其他文献

A Techno-Economic Framework for Broadband Deployment in Underserved Areas
服务欠缺地区宽带部署的技术经济框架
  • DOI:
    10.1145/2940157.2940159
  • 发表时间:
    2016
  • 期刊:
  • 影响因子:
    4.5
  • 作者:
    Ramakrishnan Durairajan;P. Barford
  • 通讯作者:
    P. Barford
On the Resilience of Internet Infrastructures in Pacific Northwest to Earthquakes
西北太平洋地区互联网基础设施的抗震能力
Internet atlas: a geographic database of the internet
互联网地图集:互联网地理数据库
  • DOI:
    10.1145/2491159.2491170
  • 发表时间:
    2013
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Ramakrishnan Durairajan;Subhadip Ghosh;Xin Tang;P. Barford;Brian Eriksson
  • 通讯作者:
    Brian Eriksson
InterTubes: A Study of the US Long-haul Fiber-optic Infrastructure
InterTubes:美国长途光纤基础设施研究
Automatic metadata generation for active measurement
自动生成元数据以进行主动测量

Ramakrishnan Durairajan的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Ramakrishnan Durairajan', 18)}}的其他基金

CAREER: Argus: A Measurement-informed Learning Approach to Managing Multi-cloud Networks
职业:Argus:管理多云网络的基于测量的学习方法
  • 批准号:
    2145813
  • 财政年份:
    2022
  • 资助金额:
    $ 40万
  • 项目类别:
    Continuing Grant
CC* Integration-Large: Bringing Code to Data: A Collaborative Approach to Democratizing Internet Data Science
CC* Integration-Large:将代码带入数据:互联网数据科学民主化的协作方法
  • 批准号:
    2126281
  • 财政年份:
    2021
  • 资助金额:
    $ 40万
  • 项目类别:
    Standard Grant
CRII: NeTS: Denoising Internet Delay Measurements using Weak Supervision
CRII:NeTS:使用弱监督对互联网延迟测量进行去噪
  • 批准号:
    1850297
  • 财政年份:
    2019
  • 资助金额:
    $ 40万
  • 项目类别:
    Standard Grant

相似国自然基金

支持二维毫米波波束扫描的微波/毫米波高集成度天线研究
  • 批准号:
    62371263
  • 批准年份:
    2023
  • 资助金额:
    52 万元
  • 项目类别:
    面上项目
腙的Heck/脱氮气重排串联反应研究
  • 批准号:
    22301211
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
水系锌离子电池协同性能调控及枝晶抑制机理研究
  • 批准号:
    52364038
  • 批准年份:
    2023
  • 资助金额:
    33 万元
  • 项目类别:
    地区科学基金项目
基于人类血清素神经元报告系统研究TSPYL1突变对婴儿猝死综合征的致病作用及机制
  • 批准号:
    82371176
  • 批准年份:
    2023
  • 资助金额:
    49 万元
  • 项目类别:
    面上项目
FOXO3 m6A甲基化修饰诱导滋养细胞衰老效应在补肾法治疗自然流产中的机制研究
  • 批准号:
    82305286
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 40万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 40万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 40万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317233
  • 财政年份:
    2024
  • 资助金额:
    $ 40万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338302
  • 财政年份:
    2024
  • 资助金额:
    $ 40万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了