首页> 外文会议>IEEE Conference on Network Softwarization >A TOSCA-Oriented Software-Defined Security Approach for Unikernel-Based Protected Clouds
【24h】

A TOSCA-Oriented Software-Defined Security Approach for Unikernel-Based Protected Clouds

机译:针对基于Unikernel的受保护云的面向TOSCA的软件定义安全性方法

获取原文

摘要

Cloud infrastructures provide new facilities to build elaborated added-value services by composing and configuring a large variety of computing resources, from virtualized hardware devices to software products. In the meantime, they are further exposed to security attacks than traditional environments. The complexity of security management tasks has been increased by the multi-tenancy, heterogeneity and geographical distribution of these resources. They introduce critical issues for cloud service providers and their customers, with respect to security programmability and scenarios of adaptation to contextual changes. In this paper, we propose a software-defined security approach based on the TOSCA language, to enable unikernel-based protected clouds. We first introduce extensions of this language to describe unikernels and specify security constraints for their orchestrations. We then describe an architecture exploiting this extended version of TOSCA for automatically generating, deploying and adjusting cloud resources in the form of protected unikernels with a low attack surface. We finally detail a proof-of-concept prototype, and evaluate the proposed solution through extensive series of experiments.
机译:云基础架构通过组合和配置从虚拟化硬件设备到软件产品的各种计算资源,提供了用于构建详尽的增值服务的新设施。同时,与传统环境相比,它们更容易受到安全攻击。这些资源的多租户,异质性和地理分布增加了安全管理任务的复杂性。他们向云服务提供商及其客户介绍了有关安全可编程性和适应上下文变化的方案的关键问题。在本文中,我们提出了一种基于TOSCA语言的软件定义的安全方法,以启用基于unikernel的受保护云。我们首先介绍该语言的扩展,以描述Unikernels并为其编排指定安全性约束。然后,我们描述一种利用TOSCA扩展版本的体系结构,该体系以受保护的unikernel的形式自动生成,部署和调整云资源,攻击面低。最后,我们详细介绍了概念验证的原型,并通过一系列的实验评估了提出的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号