Collaborative Research: SaTC: CORE: Medium: ONSET: Optics-enabled Network Defenses for Extreme Terabit DDoS Attacks
协作研究:SaTC:核心:中:ONSET:针对极端太比特 DDoS 攻击的光学网络防御
基本信息
- 批准号:2132639
- 负责人:
- 金额:$ 40万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2022
- 资助国家:美国
- 起止时间:2022-01-01 至 2025-12-31
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Distributed Denial of Service (DDoS) attacks continue to present a clear and imminent danger to critical network infrastructures. DDoS attacks have increased in sophistication with advanced strategies to continuously adapt (e.g., changing threat postures dynamically) and induce collateral damage (i.e., higher latency and loss for legitimate traffic). Furthermore, advanced attacks may also employ reconnaissance (e.g., mapping the network to find bottleneck links) to target the network infrastructure itself. In light of these trends, state-of-art defenses (e.g., advanced scrubbing, emerging software-defined defenses, and programmable switching hardware) have fundamental shortcomings. This project will develop a new framework, referred to as "Optics-enabled In-Network defenSe for Extreme Terabit DDoS attacks" (ONSET). The framework makes a case for new dimensions of defense agility that can programmatically control the topology of the network (in addition to the processing behavior) to tackle advanced and future attacks. The project will facilitate the use of optical technologies as an exciting visual medium for engaging K-12 students via suitable channels for dissemination. The project will also result in new course materials at the intersection of optical networking, software-defined networking, and network security to enable students to become domain experts in this emerging problem space. The project will take an interdisciplinary approach spanning security, optics, systems, and networks, to address fundamental challenges along three thrusts: (1) novel "data plane" solutions to rapidly reconfigure the wavelengths and switches and new capabilities in programmable switches to rapidly identify malicious vs. benign traffic at line rate; (2) novel "control plane" orchestration mechanisms for scalable resource management algorithms and coordinated control across optical networking and programmable switches; and (3) new "northbound application programming interfaces (APIs)" to express novel defenses to combat current and future DDoS attacks (e.g., with reconnaissance). This project will develop a new framework, referred to as "Optics-enabled In-Network defenSe for Extreme Terabit DDoS attacks" (ONSET). The research efforts will result in end-to-end prototypes using open-source and standardized interfaces to demonstrate the novel defense capabilities of ONSET. The efficacy of ONSET will be evaluated using pilot studies on operational networks to create a roadmap to practical deployment, using real testbeds and large-scale simulations. The project outcomes will be released as open-source software tools, models, and simulation frameworks that will inform industry and academic work.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
分布式拒绝服务 (DDoS) 攻击继续对关键网络基础设施构成明显且迫在眉睫的危险。 DDoS 攻击的复杂性不断提高,采用了先进的策略来不断适应(例如,动态改变威胁态势)并引发附带损害(即合法流量的延迟和丢失更高)。此外,高级攻击还可能采用侦察(例如,映射网络以查找瓶颈链接)来瞄准网络基础设施本身。鉴于这些趋势,最先进的防御(例如高级清理、新兴的软件定义防御和可编程交换硬件)具有根本性的缺点。该项目将开发一个新框架,称为“针对极端太比特 DDoS 攻击的光学网络内防御”(ONSET)。该框架为防御敏捷性的新维度提供了案例,可以以编程方式控制网络拓扑(除了处理行为之外)以应对高级和未来的攻击。该项目将促进光学技术作为令人兴奋的视觉媒介的使用,通过适当的传播渠道吸引 K-12 学生。该项目还将推出光网络、软件定义网络和网络安全交叉领域的新课程材料,使学生能够成为这个新兴问题领域的领域专家。该项目将采用涵盖安全、光学、系统和网络的跨学科方法,以解决三个方面的基本挑战:(1) 新颖的“数据平面”解决方案,可快速重新配置波长和交换机,以及可编程交换机的新功能,可快速识别线速下的恶意流量与良性流量; (2)新颖的“控制平面”编排机制,用于可扩展的资源管理算法以及跨光网络和可编程交换机的协调控制; (3) 新的“北向应用程序编程接口 (API)”,用于表达新颖的防御措施,以对抗当前和未来的 DDoS 攻击(例如,侦察)。该项目将开发一个新框架,称为“针对极端太比特 DDoS 攻击的光学网络内防御”(ONSET)。研究工作将产生使用开源和标准化接口的端到端原型,以展示 ONSET 的新颖防御能力。 ONSET 的功效将通过对运营网络的试点研究进行评估,以使用真实的测试平台和大规模模拟来创建实际部署的路线图。该项目成果将作为开源软件工具、模型和模拟框架发布,为行业和学术工作提供信息。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力价值和更广泛的影响审查进行评估,被认为值得支持标准。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Vyas Sekar其他文献
Verifiable resource accounting for cloud computing services
云计算服务的可验证资源核算
- DOI:
10.1145/2046660.2046666 - 发表时间:
2011-10-21 - 期刊:
- 影响因子:0
- 作者:
Vyas Sekar;Petros Maniatis - 通讯作者:
Petros Maniatis
Oh, What a Fragile Web We Weave: Third-party Service Dependencies In Modern Webservices and Implications
哦,我们编织的网络多么脆弱:现代 Web 服务中的第三方服务依赖性及其影响
- DOI:
- 发表时间:
2018-06-21 - 期刊:
- 影响因子:0
- 作者:
Aqsa Kashaf;Carolina Zarate;Hanrou Wang;Yuvraj Agarwal;Vyas Sekar - 通讯作者:
Vyas Sekar
Measuring user confidence in smartphone security and privacy
衡量用户对智能手机安全和隐私的信心
- DOI:
10.1145/2335356.2335358 - 发表时间:
2012-07-11 - 期刊:
- 影响因子:0
- 作者:
Erika Chin;A. Felt;Vyas Sekar;D. Wagner - 通讯作者:
D. Wagner
CICADAS: Congesting the Internet with Coordinated and Decentralized Pulsating Attacks
CICADAS:通过协调和分散的脉动攻击拥塞互联网
- DOI:
- 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Yu;Chih;H. Hsiao;A. Perrig;Vyas Sekar - 通讯作者:
Vyas Sekar
Enhancing Video Accessibility and Availability Using Information-Bound References
使用信息绑定参考增强视频的可访问性和可用性
- DOI:
10.1109/tnet.2015.2413352 - 发表时间:
2016-04-01 - 期刊:
- 影响因子:0
- 作者:
Ashok An;Athula Balach;ran;ran;Aditya Akella;Vyas Sekar;S. Seshan - 通讯作者:
S. Seshan
Vyas Sekar的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Vyas Sekar', 18)}}的其他基金
Collaborative Research: CNS: Medium: Scalable Learning from Distributed Data for Wireless Network Management
合作研究:CNS:媒介:无线网络管理的分布式数据可扩展学习
- 批准号:
2106214 - 财政年份:2021
- 资助金额:
$ 40万 - 项目类别:
Continuing Grant
NSF NeTS Early-Career Investigators Workshop 2017
NSF NetS 早期职业研究者研讨会 2017
- 批准号:
1743525 - 财政年份:2017
- 资助金额:
$ 40万 - 项目类别:
Standard Grant
NSF NeTS Early-Career Investigators Workshop 2017
NSF NetS 早期职业研究者研讨会 2017
- 批准号:
1743525 - 财政年份:2017
- 资助金额:
$ 40万 - 项目类别:
Standard Grant
CAREER: Checking Dynamic Policies in Stateful Next-Generation Networks
职业:检查有状态的下一代网络中的动态策略
- 批准号:
1552481 - 财政年份:2016
- 资助金额:
$ 40万 - 项目类别:
Continuing Grant
I-Corps: Exploring Commercialization Opportunities for a Software-Defined Approach for Securing Internet of Things
I-Corps:探索保护物联网的软件定义方法的商业化机会
- 批准号:
1644587 - 财政年份:2016
- 资助金额:
$ 40万 - 项目类别:
Standard Grant
TWC: Medium: Handling a Trillion Unfixable Flaws on Billions of Internet-of-Things
TWC:Medium:处理数十亿个物联网上的万亿个无法修复的缺陷
- 批准号:
1564009 - 财政年份:2016
- 资助金额:
$ 40万 - 项目类别:
Standard Grant
AitF: FULL: Collaborative Research: Practical Foundations for Software-Defined Network Optimization
AitF:完整:协作研究:软件定义网络优化的实践基础
- 批准号:
1536002 - 财政年份:2015
- 资助金额:
$ 40万 - 项目类别:
Standard Grant
Proposal to Support Student Travel for the ACM SIGCOMM 2015 Conference
支持学生参加 ACM SIGCOMM 2015 会议的旅行提案
- 批准号:
1538878 - 财政年份:2015
- 资助金额:
$ 40万 - 项目类别:
Standard Grant
NeTS: Medium: Collaborative Research: Flexible All-Wireless Inter-Rack Fabric for Datacenters Using Free-Space Optics
NeTS:媒介:协作研究:使用自由空间光学的数据中心灵活的全无线机架间结构
- 批准号:
1513764 - 财政年份:2015
- 资助金额:
$ 40万 - 项目类别:
Standard Grant
TWC: Frontier: Collaborative: Rethinking Security in the Era of Cloud Computing
TWC:前沿:协作:重新思考云计算时代的安全性
- 批准号:
1440065 - 财政年份:2014
- 资助金额:
$ 40万 - 项目类别:
Continuing Grant
相似国自然基金
IGF-1R调控HIF-1α促进Th17细胞分化在甲状腺眼病发病中的机制研究
- 批准号:82301258
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
CTCFL调控IL-10抑制CD4+CTL旁观者激活促口腔鳞状细胞癌新辅助免疫治疗抵抗机制研究
- 批准号:82373325
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
RNA剪接因子PRPF31突变导致人视网膜色素变性的机制研究
- 批准号:82301216
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
血管内皮细胞通过E2F1/NF-kB/IL-6轴调控巨噬细胞活化在眼眶静脉畸形中的作用及机制研究
- 批准号:82301257
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于多元原子间相互作用的铝合金基体团簇调控与强化机制研究
- 批准号:52371115
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 40万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 40万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 40万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330941 - 财政年份:2024
- 资助金额:
$ 40万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 40万 - 项目类别:
Continuing Grant