首页> 外文会议>IEEE Network Operations and Management Symposium >OrchSec: An Orchestrator-Based Architecture For Enhancing Network-Security Using Network Monitoring And SDN Control Functions
【24h】

OrchSec: An Orchestrator-Based Architecture For Enhancing Network-Security Using Network Monitoring And SDN Control Functions

机译:OrchSEC:使用网络监控和SDN控制功能增强网络安全的基于协调架构

获取原文

摘要

The original design of the Internet did not take network security aspects into consideration, instead it aimed to facilitate the process of information exchange between end-hosts. Consequently, many protocols that are part of the Internet infrastructure expose a set of vulnerabilities that can be exploited by attackers. To reduce these vulnerabilities, several security approaches were introduced as a form of add-ons to the existing Internet architecture. However, these approaches have their drawbacks (e.g., lack of centralized control, and automation). In this paper, to address these drawbacks, the features provided by Software Defined Networking (SDN) such as network-visibility, centralized management and control are considered for developing security applications. Although the SDN architecture provides features that can aid in the process of network security, it has some deficiencies when it comes to using SDN for security. To address these deficiencies, several architectural requirements are derived to adapt the SDN architecture for security use cases. For this purpose, OrchSec, an Orchestrator-based architecture that utilizes Network Monitoring and SDN Control functions to develop security applications is proposed. The functionality of the proposed architecture is demonstrated, tested, and validated using a security application.
机译:互联网的原始设计没有考虑网络安全方面,而是旨在促进最终主机之间的信息交换过程。因此,许多作为互联网基础架构的一部分的协议都公开了一组攻击者可以利用的一组漏洞。为降低这些漏洞,将若干安全方法作为附加组件的形式引入到现有的Internet架构。然而,这些方法具有它们的缺点(例如,缺乏集中控制和自动化)。在本文中,为了解决这些缺点,通过软件定义网络(SDN)提供的功能,例如网络可见性,集中管理和控制,用于开发安全应用程序。虽然SDN架构提供了可以帮助网络安全过程的功能,但在使用SDN以进行安全性时,它具有一些缺陷。为解决这些缺陷,导出了几种架构要求以使SDN架构适应安全用例。为此,提出了利用网络监控和SDN控制功能来开发安全应用程序的基于协调的基于协调的基于协调的架构。使用安全应用程序对所提出的体系结构的功能进行演示,测试和验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号