Project Grant 2533773
- This $600,000 Project Grant from the National Science Foundation's Computer and Information Science and Engineering program (CFDA 47.070) supports research at the University of California, Davis to address security vulnerabilities in cloud computing infrastructure and develop defenses against targeted microarchitectural attacks. Over a four-year period from July 2022 to June 2026, the university will conduct a comprehensive threat analysis of cloud schedulers and investigate software-based and...
- The National Science Foundation (NSF) Office of Advanced Cyberinfrastructure awarded a $1.2M Project Grant to Northeastern University from October 1, 2023 to September 30, 2026 under the Computer and Information Science and Engineering (CISE) program (CFDA 47.070). The grant supports research to develop next-generation resilient cloud infrastructure to secure scientific cyberinfrastructures including network-attached accelerators. Key focus areas include identifying advanced network-layer attack...
- This five-year CAREER award of $486,579, funded by the National Science Foundation's Division of Computer and Network Systems under the Computer and Information Science and Engineering (CFDA 47.070) program, supports research and development of NICOS, a novel operating system designed to enable programmable Network Interface Cards (NICs) to function as efficiently shared, multi-tenant resources in cloud computing environments. The primary deliverable is the NICOS operating system itself, which...
- This $194,999 Project Grant award, funded by the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program (CFDA 47.070), supports research to enforce expressive security policies using trusted execution environments. The project aims to advance the state-of-the-art for building secure systems by automatically placing security-critical application components within secure enclaves, reducing the programming challenges. The work includes developing a...
- This Project Grant from the National Science Foundation's Computer and Information Science and Engineering program provides $299,788 to Sri International for research and development activities from January 2023 through December 2025. The award aims to accelerate serverless cloud network performance through a cross-layered approach optimizing function chain communication in serverless cloud environments. Sri International will develop a new QUIC-based network substrate to simultaneously...
- The National Science Foundation (NSF) awarded a $299,995 Project Grant under the Computer and Information Science and Engineering (CFDA 47.070) program to the University of Massachusetts (UMass) to develop novel security approaches for protecting field-programmable gate arrays (FPGAs) used in cloud computing environments. The key objectives of this 3-year project are to introduce secure operating mechanisms and a security and queue management unit (SQMU) to enable controlled sharing of FPGAs...
- This $250,000 Project Grant from the National Science Foundation's Computer and Information Science and Engineering program will fund research at Northeastern University to improve the security of machine learning models in multi-tenant cloud field programmable gate array (FPGA) environments. The three-year award aims to advance understanding of vulnerabilities in cloud-FPGAs shared by multiple tenants, where a malicious actor could potentially manipulate another tenant's machine learning...
- This $324,275 project grant from the National Science Foundation's Computer and Information Science and Engineering program will fund the development of a scalable and deployable container orchestration cyberinfrastructure toolkit. Virginia Polytechnic Institute and State University will receive the funding to create a lightweight tool for detecting inter-container correlations in containerized big data analytics applications deployed in public clouds. Researchers will also develop a scalable...
- Federal Project Grant Award Summary The National Science Foundation's Division of Computer and Network Systems awarded $164,999 to the Research Foundation of the City University of New York (performing at City College in New York, NY) under the Computer and Information Science and Engineering program (CFDA 47.070) effective July 1, 2025, through June 30, 2027. This CRII (Computer Research Initiation for Excellence) award supports research aimed at reducing the computational costs and overhead...
- Federal Grant Award Summary The National Science Foundation (NSF) Division of Computer and Network Systems awarded $347,985 to The Trustees of the Stevens Institute of Technology under the Computer and Information Science and Engineering (CISE) program (CFDA 47.070) for a CAREER award titled "Privacy-Aware Just-In-Time Compilation." Funded from October 1, 2025, through September 30, 2030, this project will develop a security-aware just-in-time (JIT) compilation framework designed to...
CAREER: COLONY: A FRAMEWORK FOR BESPOKE VIRTUAL EXECUTION CONTEXTS -VULNERABILITIES PRESENT IN SOFTWARE RUNNING ON SHARED COMPUTING INFRASTRUCTURE (E.G., CLOUD DATACENTERS) CAN RESULT IN SIGNIFICANT ECONOMIC LOSSES, COMPROMISED USER DATA, AND WEAKENED NATIONAL SECURITY WHEN SUCH INFRASTRUCTURE DOES NOT PROPERLY SEPARATE PROGRAMS FROM ONE ANOTHER IN SECURE, ISOLATED COMPARTMENTS. WHILE TECHNIQUES DO EXIST TO ENSURE SUCH ISOLATION, THEY TYPICALLY INCREASE THE ENGINEERING BURDEN ON PROGRAMMERS OR TRADE OFF PERFORMANCE FOR SECURITY, LIMITING THEIR EFFECTIVENESS AND REACH. TODAY, PROGRAMMERS ARE DEPLOYING CODE ON SHARED COMPUTING INFRASTRUCTURE IN INCREASINGLY FINE-GRAINED UNITS (E.G., SERVERLESS COMPUTING), MAKING THIS TRADE OFF MORE SEVERE OVER TIME. THE OFF-THE-SHELF TECHNOLOGIES, SUCH AS CONTAINERS THAT ISOLATION FRAMEWORKS ARE OFTEN BUILT ON, WERE NOT DESIGNED FOR THIS FINE-GRAINED USE CASE. THIS PROJECT THUS AIMS TO ENSURE BOTH PERFORMANCE AND SECURITY FOR CODE RUNNING ON CLOUD INFRASTRUCTURE BY DESIGNING NEW ISOLATION MECHANISMS FROM THE GROUND UP USING NOVEL OPERATING SYSTEM, COMPILER, PROGRAMMING LANGUAGE, AND VIRTUALIZATION TECHNOLOGIES. THE PROJECT WILL HELP PRODUCE MORE ROBUST CLOUD COMPUTING INFRASTRUCTURE THAT IS LESS SUSCEPTIBLE TO ATTACK, LESS LIKELY TO LEAK SENSITIVE USER DATA, AND MORE PRODUCTIVE FOR PROGRAMMERS. IF SUCCESSFUL, POTENTIAL IMPACTS INCLUDE REDUCED ECONOMIC LOSSES FROM COMPROMISED INFRASTRUCTURE, STRENGTHENED NATIONAL SECURITY, AND INCREASED PRIVACY FOR THE BROADER PUBLIC USING CLOUD SERVICES. THE PROJECT WILL ALSO MAKE CONTRIBUTIONS IN EDUCATION AND BROADENING PARTICIPATION IN THE COMPUTING PROFESSION BY ENHANCING EDUCATIONAL CONTENT, INJECTING INDUSTRY-RELEVANT AND APPLIED CONTENT INTO THE CURRICULUM, INCREASING THE REPRESENTATION OF PEOPLE FROM DIVERSE BACKGROUNDS IN COMPUTER SYSTEMS RESEARCH, REVITALIZING THE COMPUTER SYSTEMS CURRICULUM AT THE PI?S INSTITUTION, AND FOSTERING UNDERGRADUATE RESEARCH ENGAGEMENT. THIS PROJECT PROPOSES COLONY, A NEW SOFTWARE FRAMEWORK FOR LIGHTWEIGHT, BESPOKE, VIRTUALIZED EXECUTION CONTEXTS. COLONY LEVERAGES NOVEL EXECUTION ABSTRACTIONS CUSTOMIZED FOR INDIVIDUAL APPLICATIONS AND DESIGNED FOR BOTH PERFORMANCE AND ISOLATION. COLONY CONTEXTS ARE SYNTHESIZED USING COMPILER ANALYSES, AND ARE EXPOSED THROUGH A RICH SET OF PROGRAMMING ABSTRACTIONS AND PROGRAMMING LANGUAGE EXTENSIONS. COLONY BUILDS ON A NEW ABSTRACTION FOR ISOLATED FUNCTION EXECUTION, THE VIRTUALIZED SUBROUTINE, OR VIRTINE, ALONG WITH AN EMBEDDABLE HYPERVISOR. THE GOAL OF THE COLONY PROJECT IS TO ACHIEVE BOTH HIGH PERFORMANCE AND STRONG ISOLATION FOR INDIVIDUALLY ISOLATED FUNCTION CONTEXTS IN A VARIETY OF APPLICATIONS. THE PROJECT WILL EXPLORE VARIOUS MECHANISMS TO ENABLE BESPOKE CONTEXTS, INCLUDING VIRTUALIZATION MECHANISMS ENHANCED FOR OPTIMIZED START-UP PERFORMANCE, AND PROGRAMMING MODELS WITH NOVEL LANGUAGE/COMPILER SUPPORT. THESE BESPOKE CONTEXTS CAN BE USED FOR LIGHTER-WEIGHT ISOLATION THAN MANAGED LANGUAGES, GIVING THEM BROAD APPLICABILITY TO AREAS SUCH AS OS KERNEL DRIVERS, THIRD-PARTY LIBRARIES, AND DATABASE USER-DEFINED FUNCTIONS, AS WELL AS THE MORE NASCENT SERVERLESS COMPUTING PARADIGM. THE PROPOSED WORK HAS POTENTIAL TO OPEN UP NEW LINES OF RESEARCH IN OPERATING SYSTEMS, VIRTUALIZATION, COMPILERS, AND SYSTEM SECURITY. THIS AWARD REFLECTS NSF'S STATUTORY MISSION AND HAS BEEN DEEMED WORTHY OF SUPPORT THROUGH EVALUATION USING THE FOUNDATION'S INTELLECTUAL MERIT AND BROADER IMPACTS REVIEW CRITERIA.- SUBAWARDS ARE NOT PLANNED FOR THIS AWARD.
Mod # | Description | ReasonForModification | Federal Obligation | Date |
|---|---|---|---|---|
| Not listed | $149.3k | 9/16/25 | ||
| Not listed | $175.1k | 5/15/25 |