首页> 外文期刊>Communications Surveys & Tutorials, IEEE >NFV Security Survey: From Use Case Driven Threat Analysis to State-of-the-Art Countermeasures
【24h】

NFV Security Survey: From Use Case Driven Threat Analysis to State-of-the-Art Countermeasures

机译:NFV安全调查:从用例驱动的威胁分析到最新对策

获取原文
获取原文并翻译 | 示例

摘要

Network functions virtualization (NFV), along with software-defined networking (SDN), drives a new change in networking infrastructure with respect to designing, deploying, and managing various network services. In particular, NFV has potential to significantly reduce the hardware cost, greatly improve operational efficiency, and dramatically shorten the development lifecycle of network service. It also makes network functions and services much more adaptive and scalable. Despite the promising advantages of NFV, security remains to be one of the vital concerns and potential hurdle, as attack surface becomes unclear and defense line turns to be blurred in the virtualization environment. This survey is therefore devoted to analyzing NFV from a security perspective. We first analyze security threats of five well-defined NFV use cases, with an objective to establishing a comprehensive layer-specific threat taxonomy. Second, we conduct in-depth comparative studies on several security mechanisms that are applied in traditional scenarios and in NFV environments. The purpose is to analyze their implicit relationships with NFV performance objectives in terms of feasibility, agility, effectiveness, and so on. Third, based on the established threat taxonomy and the analyzed security mechanisms, we provide a set of recommendations on securing NFV based services, along with the analysis on the state-of-the-art security countermeasures. A resulting holistic security framework is intended to lay a foundation for NFV service providers to deploy adaptive, scalable, and cost-effective security hardening based on their particular needs. Some future research directions are finally discussed.
机译:网络功能虚拟化(NFV)以及软件定义的网络(SDN)推动了网络基础结构在设计,部署和管理各种网络服务方面的新变化。特别是,NFV有潜力显着降低硬件成本,大大提高运营效率并大大缩短网络服务的开发生命周期。它还使网络功能和服务更具适应性和可扩展性。尽管NFV具有令人鼓舞的优势,但是安全性仍然是至关重要的问题和潜在的障碍之一,因为攻击面变得不清楚,并且在虚拟化环境中防御线变得模糊。因此,本次调查专门从安全角度分析NFV。我们首先分析五个定义明确的NFV用例的安全威胁,以建立全面的针对特定层的威胁分类法为目标。其次,我们对应用于传统方案和NFV环境中的几种安全机制进行了深入的比较研究。目的是从可行性,敏捷性,有效性等方面分析其与NFV性能目标的隐式关系。第三,基于已建立的威胁分类法和已分析的安全机制,我们提供了有关确保基于NFV的服务安全的一组建议,以及对最新安全对策的分析。由此产生的整体安全框架旨在为NFV服务提供商根据其特定需求部署自适应,可扩展且具有成本效益的安全强化奠定基础。最后讨论了一些未来的研究方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号