首页> 外文会议>International Symposium on Stabilization, Safety, and Security of Distributed Systems >Formal Verification of Security Preservation for Migrating Virtual Machines in the Cloud
【24h】

Formal Verification of Security Preservation for Migrating Virtual Machines in the Cloud

机译:用于迁移云中虚拟机的安全保留的正式验证

获取原文

摘要

Firewalls are a prerequisite for securing any communication network. In cloud computing environments, virtual machines are dynamically and frequently migrated across data centers. This frequent modification in the topology requires frequent reconfiguration of security appliances, particularly firewalls. In this paper, we address the issue of security policy preservation in a distributed firewall configuration within a highly dynamic context. Thus, we propose a systematic procedure to verify security compliance of firewall policies after VM migration. First, the distributed firewall configurations in the involved data centers are defined according to the network topology expressed using Cloud Calculus. Then, these configurations are expressed as propositional constraints and used to build a verification model based on the constraint satisfaction problem framework, which allows reasoning on security policy preservation. Finally, we present a case study inspired from Amazon EC2 to show the applicability and usefulness of our approach.
机译:防火墙是保护任何通信网络的先决条件。在云计算环境中,虚拟机动态地跨数据中心迁移。拓扑中的这种频繁修改需要频繁地重新配置安全设备,特别是防火墙。在本文中,我们在高动态上下文中解决了分布式防火墙配置中的安全策略保存问题。因此,我们提出了一个系统的过程,以验证VM迁移后防火墙策略的安全顺应性。首先,根据使用云微积分表达的网络拓扑定义了所涉及的数据中心中的分布式防火墙配置。然后,这些配置表示为命题约束,并用于基于约束满足问题框架构建验证模型,这允许推理安全策略保存。最后,我们展示了一个案例研究,从亚马逊EC2启发,以展示我们方法的适用性和有用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号