首页> 外文会议>2017 IEEE Conference on Network Function Virtualization and Software Defined Networks >Component integrity guarantees in software-defined networking infrastructure
【24h】

Component integrity guarantees in software-defined networking infrastructure

机译:软件定义的网络基础架构中的组件完整性保证

获取原文
获取原文并翻译 | 示例

摘要

Operating system level virtualization containers are commonly used to deploy virtual network functions (VNFs) which access the centralized network controller in software-defined networking (SDN) infrastructure. While this allows flexible network configuration, it also increases the attack surface, as sensitive information is transmitted between the controller and the virtual network functions. In this work we propose a mechanism for bootstrapping secure communication between the SDN controller and deployed network applications. The proposed mechanism relies on platform integrity evaluation and execution isolation mechanisms, such as Linux Integrity Measurement Architecture and Intel Software Guard Extensions. To validate the feasibility of the proposed approach, we have implemented a proof of concept which was further tested and evaluated to assess its performance. The prototype can be seen as the first step into providing users with security guarantees regarding the integrity of components in the SDN infrastructure.
机译:操作系统级虚拟化容器通常用于部署虚拟网络功能(VNF),这些功能访问软件定义网络(SDN)基础结构中的集中式网络控制器。尽管这允许灵活的网络配置,但由于在控制器和虚拟网络功能之间传输敏感信息,因此也增加了攻击面。在这项工作中,我们提出了一种用于引导SDN控制器与已部署的网络应用程序之间的安全通信的机制。所提出的机制依赖于平台完整性评估和执行隔离机制,例如Linux完整性度量体系结构和Intel Software Guard Extensions。为了验证所提出方法的可行性,我们已经实施了概念验证,并对其进行了进一步的测试和评估,以评估其性能。该原型可以看作是为用户提供有关SDN基础结构中组件完整性的安全性保证的第一步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号