【24h】

Towards Automated Provisioning of Secure Virtualized Networks

机译:迈为自动配置安全虚拟化网络

获取原文

摘要

We describe a secure network virtualization framework that helps realize the abstraction of Trusted Virtual Domains (TVDs), a security-enhanced variant of virtualized network zones. The framework allows groups of related virtual machines running on separate physical machines to be connected together as though there were on their own separate network fabric and, at the same time, helps enforce cross-group security requirements such as isolation, confidentiality, security, and information flow control. The framework uses existing network virtualization technologies, such as Ethernet encapsulation, VLAN tagging, and VPNs, and combines and orchestrates them appropriately to implement TVDs. Our framework aims at automating the instantiation and deployment of the appropriate security mechanism and network virtualization technologies based on an input security model that specifies the required level of isolation and permitted network flows. We have implemented a prototype of the framework based on the Xen hypervisor. Experimental evaluation of the prototype shows that the performance of our virtual networking extensions is comparable to that of the standard Xen configuration.
机译:我们描述了一个安全的网络虚拟化框架,有助于实现可信虚拟域(TVDS)的抽象,虚拟化网络区域的安全增强型变体。该框架允许在单独的物理计算机上运行的相关虚拟机组连接在一起,只要在自己的单独网络结构上,同时,有助于强制执行跨组安全要求,例如隔离,机密性,安全性和信息流控制。该框架使用现有的网络虚拟化技术,例如以太网封装,VLAN标记和VPN,并结合并协调并适当地协调它们以实现TVD。我们的框架旨在基于输入安全模型来自动化和部署适当的安全机制和网络虚拟化技术,该输入安全模型指定所需的隔离级别和允许的网络流量。我们已经基于Xen虚拟机管理程序实现了框架的原型。原型的实验评估表明,我们的虚拟网络扩展的性能与标准Xen配置的性能相当。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号