CICI: UCSS: Secure Containers in High-Performance Computing Infrastructure
CICI:UCSS:高性能计算基础设施中的安全容器
基本信息
- 批准号:2319975
- 负责人:
- 金额:$ 60万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-08-01 至 2026-07-31
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Ensuring the security and privacy of high-performance computing (HPC) infrastructures is of utmost importance due to their handling of sensitive data and critical scientific computations. HPC infrastructures commonly employ containers, which provide lightweight and isolated environments for running applications. Nevertheless, containers in HPC infrastructures encounter security challenges, including insecure container images and vulnerabilities related to isolation. Existing container image scanners face a major challenge of low coverage, while current container runtimes struggle to ensure both security and performance for HPC workloads simultaneously. This project addresses these challenges by developing secure containers specifically tailored for HPC infrastructures. The project introduces innovative solutions, including the development of an efficient image vulnerability scanner and a secure container runtime. These systems incorporate various customized optimizations for security and performance targeting HPC workloads. Additionally, educational efforts are made to integrate the research findings into graduate and undergraduate curriculum development. Outreach activities are conducted to encourage participation from underrepresented groups and promote cybersecurity awareness and HPC expertise in the states of Texas and Delaware.The project consists of two primary tasks. The first task focuses on designing an efficient image vulnerability scanner using innovative and feasible techniques. The research team designs a novel method for container image vulnerability detection based on cross-language code similarity detection. This approach combines graph neural networks with a language-agnostic code representation that leverages natural language processing techniques. Furthermore, it designs an efficient and scalable online search solution. The second task involves developing a secure and high-performance container runtime by utilizing a lightweight virtual machine hypervisor. Additionally, the runtime is optimized based on the characteristics of HPC workloads with the goal of improving both security and performance.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
由于高性能计算 (HPC) 基础设施处理敏感数据和关键科学计算,因此确保其安全和隐私至关重要。 HPC 基础设施通常采用容器,为运行应用程序提供轻量级且隔离的环境。然而,HPC 基础设施中的容器遇到了安全挑战,包括不安全的容器镜像和与隔离相关的漏洞。现有的容器镜像扫描仪面临着覆盖率低的重大挑战,而当前的容器运行时很难同时确保 HPC 工作负载的安全性和性能。该项目通过开发专为 HPC 基础设施定制的安全容器来解决这些挑战。该项目引入了创新的解决方案,包括开发高效的图像漏洞扫描器和安全的容器运行时。这些系统结合了针对 HPC 工作负载的安全性和性能的各种定制优化。此外,教育部门还努力将研究成果纳入研究生和本科生课程的开发中。开展外展活动是为了鼓励代表性不足的群体参与,并提高德克萨斯州和特拉华州的网络安全意识和 HPC 专业知识。该项目包括两项主要任务。第一项任务侧重于使用创新且可行的技术设计高效的图像漏洞扫描器。研究团队设计了一种基于跨语言代码相似度检测的容器镜像漏洞检测新方法。这种方法将图神经网络与利用自然语言处理技术的与语言无关的代码表示相结合。此外,它还设计了一个高效且可扩展的在线搜索解决方案。第二项任务涉及利用轻量级虚拟机管理程序开发安全且高性能的容器运行时。此外,运行时还根据 HPC 工作负载的特征进行了优化,目标是提高安全性和性能。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力优点和更广泛的影响审查标准进行评估,认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Yuede Ji其他文献
SWARMGRAPH: Analyzing Large-Scale In-Memory Graphs on GPUs
SARMGRAPH:分析 GPU 上的大规模内存中图
- DOI:
10.1109/hpcc-smartcity-dss50907.2020.00008 - 发表时间:
2020-12-01 - 期刊:
- 影响因子:0
- 作者:
Yuede Ji;Hang Liu;H. H. Huang - 通讯作者:
H. H. Huang
Illuminati: Towards Explaining Graph Neural Networks for Cybersecurity Analysis
光明会:解释用于网络安全分析的图神经网络
- DOI:
10.1109/eurosp53844.2022.00013 - 发表时间:
2022-06-01 - 期刊:
- 影响因子:0
- 作者:
Haoyu He;Yuede Ji;H. H. Huang - 通讯作者:
H. H. Huang
Discovering unknown advanced persistent threat using shared features mined by neural networks
使用神经网络挖掘的共享特征发现未知的高级持续威胁
- DOI:
10.1016/j.comnet.2021.107937 - 发表时间:
2021-04-01 - 期刊:
- 影响因子:0
- 作者:
Longkang Shang;Dong Guo;Yuede Ji;Qiang Li - 通讯作者:
Qiang Li
Vestige: Identifying Binary Code Provenance for Vulnerability Detection
Vestige:识别二进制代码来源以进行漏洞检测
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
Yuede Ji;Lei Cui;H. H. Huang - 通讯作者:
H. H. Huang
iSpan: Parallel Identification of Strongly Connected Components with Spanning Trees
iSpan:使用生成树并行识别强连通分量
- DOI:
10.1145/3543542 - 发表时间:
2018-11-01 - 期刊:
- 影响因子:0
- 作者:
Yuede Ji;Hang Liu;Yang Hu;H. H. Huang - 通讯作者:
H. H. Huang
Yuede Ji的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Yuede Ji', 18)}}的其他基金
Collaborative Research: SHF: Small: LEGAS: Learning Evolving Graphs At Scale
协作研究:SHF:小型:LEGAS:大规模学习演化图
- 批准号:
2331301 - 财政年份:2024
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
相似海外基金
CICI: UCSS: Maximizing Data Utility and Participant Privacy through Usable, Secure Data Workflows for Human-Centered AI Research
CICI:UCSS:通过可用、安全的数据工作流程实现以人为本的人工智能研究,最大限度地提高数据效用和参与者隐私
- 批准号:
2232690 - 财政年份:2023
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
CICI:UCSS: ARMOR: Secure Querying of Massive Scientific Datasets
CICI:UCSS: ARMOR:海量科学数据集的安全查询
- 批准号:
2232813 - 财政年份:2023
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
- 批准号:
2115107 - 财政年份:2021
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
- 批准号:
2139358 - 财政年份:2021
- 资助金额:
$ 60万 - 项目类别:
Standard Grant
CICI: UCSS: Enhancing Integrity and Confidentiality for Secure Distributed Data Sharing
CICI:UCSS:增强安全分布式数据共享的完整性和保密性
- 批准号:
2114202 - 财政年份:2021
- 资助金额:
$ 60万 - 项目类别:
Standard Grant