首页> 外文期刊>IEEE Network >Software-Defined Perimeter (SDP): State of the Art Secure Solution for Modern Networks
【24h】

Software-Defined Perimeter (SDP): State of the Art Secure Solution for Modern Networks

机译:软件定义的边界(SDP):现代网络的最新安全解决方案

获取原文
获取原文并翻译 | 示例
           

摘要

The boom in the evolution and adoption of new technologies, architectures, and paradigms such as cloud computing, SDN, and NFV in recent years has led to a new set of security and privacy challenges and concerns. These challenges/ concerns include proper authentication, access control, data privacy, and data integrity, among others. SDP has been proposed as a security model/framework to protect modern networks in a dynamic manner. This framework follows a need-to-know model where a device's identity is first verified and authenticated before gaining access to the application infrastructure. In this article, a brief discussion of the security and privacy challenges/concerns facing modern cloud-based networks is presented along with some of the related work from the literature. The SDP concept, architecture, possible implementations, and challenges are described. An SDP-based framework adopting a client-gateway architecture is proposed with its performance being evaluated using a virtualized network testbed for an internal enterprise scenario as a use case. To the best of our knowledge, no previous work has provided a quantitative performance evaluation of such a framework. Performance evaluation results show that the SDP-secured network is resilient to denial of service attacks and port scanning attacks despite needing longer initial connection setup time. The achieved results confirm the promising potential of SDP as a security model/framework that can dynamically protect current and future networks.
机译:近年来,诸如云计算,SDN和NFV之类的新技术,体系结构和范例的发展和采用的迅猛发展,带来了一系列新的安全和隐私挑战和担忧。这些挑战/关注点包括正确的身份验证,访问控制,数据隐私和数据完整性等。已提出将SDP作为安全模型/框架来以动态方式保护现代网络。该框架遵循需要了解的模型,在该模型中,首先对设备的身份进行验证和身份验证,然后才能访问应用程序基础结构。在本文中,简要介绍了现代基于云的网络所面临的安全性和隐私挑战/关注点,以及文献中的一些相关工作。描述了SDP概念,体系结构,可能的实现方式和挑战。提出了一种采用客户端网关体系结构的基于SDP的框架,并使用针对内部企业场景的虚拟化网络测试床作为用例来评估其性能。据我们所知,以前没有工作对这种框架进行定量的绩效评估。性能评估结果表明,尽管需要更长的初始连接建立时间,但受SDP保护的网络可以抵抗拒绝服务攻击和端口扫描攻击。取得的成果证实了SDP作为可动态保护当前和未来网络的安全模型/框架的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号