首页> 外文会议>2017 IEEE 16th International Symposium on Network Computing and Applications >SDS2: A novel software-defined security service for protecting cloud computing infrastructure
【24h】

SDS2: A novel software-defined security service for protecting cloud computing infrastructure

机译:SDS 2 :一种新颖的软件定义的安全服务,用于保护云计算基础架构

获取原文
获取原文并翻译 | 示例

摘要

Software-Defined Infrastructure (SDI) is a resource sharing infrastructure that embraces the concept of separation of the network control plane from its data plane, and software realization of network functions from the underlying hardware appliances through the virtualization technology in emerging infrastructures such as Cloud, Network Function Virtualization (NFV), and Software-Defined Networking (SDN). Virtualization and virtualized infrastructures bring with them new challenges regarding security and virtual resources protection. Traditional security measures and endpoint security are no longer adequate due to invisible boundaries created among shared logical and virtual entities among numerous users. This paper introduces a software-defined security service (SDS2) for protecting cloud infrastructures. SDS2 focuses on defining security concerns regarding physical and virtual boundaries of data, resources, tenants and detecting security breaches through violations of boundaries. Boundaries are defined by security policies and security violations by attackers are predicted, monitored, and detected when boundaries are crossed. This paper describes SDS2 and presents its initial implementation. The paper provides examples of policy-defined boundaries and shows the effectiveness and feasibility of our design in detecting invisible security boundaries through simulation of a security control structure and agile, dynamic, and intelligent VSFs.
机译:软件定义基础架构(SDI)是一种资源共享基础架构,它包含以下概念:将网络控制平面与其数据平面分离,并通过新兴的基础架构(例如Cloud)中的虚拟化技术从底层硬件设备实现网络功能的软件实现,网络功能虚拟化(NFV)和软件定义的网络(SDN)。虚拟化和虚拟化基础架构给安全性和虚拟资源保护带来了新的挑战。由于众多用户之间共享逻辑和虚拟实体之间创建了不可见的边界,因此传统的安全措施和端点安全性不再足够。本文介绍了一种用于保护云基础架构的软件定义的安全服务(SDS 2 )。 SDS 2 专注于定义有关数据,资源,租户的物理和虚拟边界的安全问题,并通过违反边界来检测安全漏洞。边界由安全策略定义,跨边界时会预测,监视和检测攻击者的安全违规行为。本文介绍了SDS 2 并介绍了其初始实现。本文提供了策略定义的边界示例,并通过模拟安全控制结构以及敏捷,动态和智能的VSF,展示了我们的设计在检测隐形安全边界方面的有效性和可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号