CSR: Medium: Security and Isolation in the Era of Microservices
CSR:中:微服务时代的安全与隔离
基本信息
- 批准号:2203152
- 负责人:
- 金额:$ 120万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-10-01 至 2024-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Years ago, applications such as news, e-commerce, or banking websites ran on computers deployed at organizations owning them. Today, with the advent of "cloud computing", such applications instead run in a far-away server farm operated by third-parties. Because the computers are shared by many applications, it is crucial to ensure that one application in the cloud, such as a news website, does not compromise the confidentiality or integrity of another application (e.g., a banking website) running on the same set of computers. The goal of this project is to develop systems that ensure cloud applications are suitably protected without sacrificing their performance and ability to grow/shrink. This goal will be realized by developing two core building blocks to achieve optimal trade-offs between isolation and performance/agility. The first is variable isolation, where we automatically determine the least privilege and best isolation techniques needed for components of an application, and deploy the highest (weakest) isolation where needed most (least). The second is isolation-aware replication, where tenants selectively replicate their compute and storage within higher-isolation sandboxes. Finally, the project will develop new programming models for correct distributed execution of microservices-based applications.The research, if successful, will improve both the performance and the security posture of cloud-based applications. Research outcomes of the project, including the experimental harnesses and datasets, will be released open-source, enabling others in research and industry to directly build on them. The project will lead to the development of new courses and boot camps that focus on microservices, lambda-style computation, and isolation. The course/boot camp material will be made publicly available. The project aims to integrate the research into outreach efforts aimed at women, under-represented minorities, non-traditional students, and high school students.The project and its research artifacts will be hosted at https://bitbucket.org/uw-madison-networking-research/isolation. This site will include research publications, software, datasets, presentations, and tutorials. This site will be kept up to date for the entire duration of the project and for 2-3 years immediately following the project's culmination.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
多年前,新闻、电子商务或银行网站等应用程序运行在部署在拥有这些应用程序的组织的计算机上。如今,随着“云计算”的出现,此类应用程序改为在第三方运营的远程服务器场中运行。由于计算机由许多应用程序共享,因此确保云中的一个应用程序(例如新闻网站)不会损害在同一组计算机上运行的另一个应用程序(例如银行网站)的机密性或完整性至关重要。电脑。该项目的目标是开发系统,确保云应用程序得到适当的保护,而不牺牲其性能和增长/收缩的能力。这一目标将通过开发两个核心构建模块来实现,以实现隔离性和性能/敏捷性之间的最佳权衡。第一个是变量隔离,我们自动确定应用程序组件所需的最低权限和最佳隔离技术,并在最需要(最少)的地方部署最高(最弱)的隔离。第二个是隔离感知复制,租户有选择地在更高隔离度的沙箱中复制其计算和存储。最后,该项目将开发新的编程模型,以正确分布式执行基于微服务的应用程序。该研究如果成功,将提高基于云的应用程序的性能和安全状况。该项目的研究成果,包括实验工具和数据集,将开源发布,使研究和工业界的其他人能够直接在其基础上进行构建。该项目将导致新课程和训练营的开发,重点关注微服务、lambda 式计算和隔离。课程/训练营材料将公开。该项目旨在将研究整合到针对女性、代表性不足的少数族裔、非传统学生和高中生的推广工作中。该项目及其研究成果将托管在 https://bitbucket.org/uw-madison -网络研究/隔离。该网站将包括研究出版物、软件、数据集、演示文稿和教程。该网站将在整个项目期间以及项目结束后的 2-3 年内保持最新状态。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力价值和更广泛的影响进行评估,被认为值得支持审查标准。
项目成果
期刊论文数量(2)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Jiffy: elastic far-memory for stateful serverless analytics
Jiffy:用于状态无服务器分析的弹性远内存
- DOI:10.1145/3492321.3527539
- 发表时间:2022-01
- 期刊:
- 影响因子:0
- 作者:Khandelwal, Anurag;Tang, Yupeng;Agarwal, Rachit;Akella, Aditya;Stoica, Ion
- 通讯作者:Stoica, Ion
Memory deduplication for serverless computing with Medes
使用 Medes 进行无服务器计算的内存重复数据删除
- DOI:10.1145/3492321.3524272
- 发表时间:2022-01
- 期刊:
- 影响因子:0
- 作者:Saxena, Divyanshu;Ji, Tao;Singhvi, Arjun;Khalid, Junaid;Akella, Aditya
- 通讯作者:Akella, Aditya
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Aditya Akella其他文献
A First Look at Problems in the Cloud
初探云中的问题
- DOI:
- 发表时间:
2010-06-22 - 期刊:
- 影响因子:0
- 作者:
Theophilus A. Benson;S. Sahu;Aditya Akella;A. Shaikh - 通讯作者:
A. Shaikh
From Dumb Pipes to Rivers of Money: a Network Payment System
从愚蠢的管道到金钱的河流:网络支付系统
- DOI:
- 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Cristian Estan;Suman Banerjee;Aditya Akella;Yi Pan - 通讯作者:
Yi Pan
Your Programmable NIC Should be a Programmable Switch
您的可编程 NIC 应该是可编程交换机
- DOI:
10.1145/3286062.3286068 - 发表时间:
2018-11-15 - 期刊:
- 影响因子:0
- 作者:
Brent E. Stephens;Aditya Akella;M. Swift - 通讯作者:
M. Swift
Using strongly typed networking to architect for tussle
使用强类型网络来构建斗争
- DOI:
10.1145/1868447.1868456 - 发表时间:
2010-10-20 - 期刊:
- 影响因子:0
- 作者:
C. Muthukrishnan;V. Paxson;M. Allman;Aditya Akella - 通讯作者:
Aditya Akella
Whiz: A Fast and Flexible Data Analytics System
Whiz:快速灵活的数据分析系统
- DOI:
- 发表时间:
2017-03-29 - 期刊:
- 影响因子:0
- 作者:
Robert Gr;l;l;Arjun Singhvi;Raajay Viswanathan;Aditya Akella - 通讯作者:
Aditya Akella
Aditya Akella的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Aditya Akella', 18)}}的其他基金
Collaborative Research: CNS Core: Medium: Innovating Volumetric Video Streaming with Motion Forecasting, Intelligent Upsampling, and QoE Modeling
合作研究:CNS 核心:中:通过运动预测、智能上采样和 QoE 建模创新体积视频流
- 批准号:
2212297 - 财政年份:2022
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Large: Runtime Programmable Networks
合作研究:CNS 核心:大型:运行时可编程网络
- 批准号:
2214015 - 财政年份:2022
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Medium: Systems Support for Federated Learning
协作研究:CNS 核心:中:联邦学习的系统支持
- 批准号:
2207317 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
NeTS: Small: New Abstractions for First-hop Networking in Cloud Data Centers
NeTS:小型:云数据中心第一跳网络的新抽象
- 批准号:
2203167 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
NeTS: Large: Collaborative Research: Design Principles for a Future-Proof Internet Control Plane
NetS:大型:协作研究:面向未来的互联网控制平面的设计原则
- 批准号:
2202649 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Medium: Systems Support for Federated Learning
协作研究:CNS 核心:中:联邦学习的系统支持
- 批准号:
2105890 - 财政年份:2021
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
EAGER: Collaborative Research: Inexactness and Data-Awareness in Network Stacks for Distributed Machine Learning
EAGER:协作研究:分布式机器学习网络堆栈中的不精确性和数据感知
- 批准号:
1940109 - 财政年份:2019
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
CSR: Medium: Security and Isolation in the Era of Microservices
CSR:中:微服务时代的安全与隔离
- 批准号:
1763810 - 财政年份:2018
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Workshop titled "Toward a Research Agenda for Cloud 3.0"
题为“迈向云 3.0 研究议程”的研讨会
- 批准号:
1749528 - 财政年份:2017
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
NeTS: Small: New Abstractions for First-hop Networking in Cloud Data Centers
NeTS:小型:云数据中心第一跳网络的新抽象
- 批准号:
1717039 - 财政年份:2017
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
相似国自然基金
基于机器学习和经典电动力学研究中等尺寸金属纳米粒子的量子表面等离激元
- 批准号:22373002
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
基于挥发性分布和氧化校正的大气半/中等挥发性有机物来源解析方法构建
- 批准号:42377095
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
中等质量黑洞附近的暗物质分布及其IMRI系统引力波回波探测
- 批准号:12365008
- 批准年份:2023
- 资助金额:32 万元
- 项目类别:地区科学基金项目
复合低维拓扑材料中等离激元增强光学响应的研究
- 批准号:12374288
- 批准年份:2023
- 资助金额:52 万元
- 项目类别:面上项目
中等垂直风切变下非对称型热带气旋快速增强的物理机制研究
- 批准号:42305004
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: CyberTraining: Implementation: Medium: Cross-Disciplinary Training for Joint Cyber-Physical Systems and IoT Security
协作研究:网络培训:实施:中:联合网络物理系统和物联网安全的跨学科培训
- 批准号:
2230086 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Physically Unclonable Wireless Systems (PUWS) for RF Fingerprinting and Physical Layer Security
SaTC:核心:中:用于射频指纹识别和物理层安全的物理不可克隆无线系统 (PUWS)
- 批准号:
2233774 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Standard Grant
Collaborative Research: CyberTraining: Implementation: Medium: Cross-Disciplinary Training for Joint Cyber-Physical Systems and IoT Security
协作研究:网络培训:实施:中:联合网络物理系统和物联网安全的跨学科培训
- 批准号:
2230087 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: CyberTraining: Implementation: Medium: Cross-Disciplinary Training for Joint Cyber-Physical Systems and IoT Security
协作研究:网络培训:实施:中:联合网络物理系统和物联网安全的跨学科培训
- 批准号:
2230087 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Hardware Security Insights: Analyzing Hardware Designs to Understand and Assess Security Weaknesses and Vulnerabilities
协作研究:SaTC:核心:中:硬件安全见解:分析硬件设计以了解和评估安全弱点和漏洞
- 批准号:
2247756 - 财政年份:2023
- 资助金额:
$ 120万 - 项目类别:
Continuing Grant