首页> 外文期刊>IEEE transactions on dependable and secure computing >Leveraging Network Functions Virtualization Orchestrators to Achieve Software-Defined Access Control in the Clouds
【24h】

Leveraging Network Functions Virtualization Orchestrators to Achieve Software-Defined Access Control in the Clouds

机译:利用网络功能虚拟化协调器实现云中的软件定义的访问控制

获取原文
获取原文并翻译 | 示例
       

摘要

Network Functions Virtualization (NFV) has been widely recognized as an effective way to implement and consolidate hardware-based network functions by using software-based approaches, with a potential to significantly reducing CAPEX and OPEX. In particular, NFV orchestrators (e.g., Tacker, Cloudify, and ONAP) play a vital role in managing and orchestrating various virtualized network resources (e.g., VMs, Virtualized Network Functions), and TOSCA is one of the standard data models to fulfil such a role. However, it remains unclear how the security mechanisms can be seamlessly integrated into the entire lifecycle of those virtualized network assets. Starting with a comparative analysis on the available NFV orchestrators, we extend the TOSCA model to incorporate security attributes of interest, and leverage the extended model to create access control policies at cloud scale. Specifically, a security orchestrator is developed, which contains a TOSCA-parser and a novel tenant-specific access control paradigm. One of the salient features of our security orchestrator is that it allows to dynamically generate access control models and policies for different tenant domains, resulting in a flexible and scalable protection coverage that is across different NFV layers and multiple data centers. To validate its feasibility and effectiveness, we develop a security orchestrator prototype and test its performance with respect to throughput, scalability, and adaptability. The experimental results demonstrate that all the desirable properties can be achieved, and the throughput of our security orchestrator can be maintained at a satisfactory level regardless of the varying number of tenants, users, or objects that are deployed in the cloud.
机译:网络功能虚拟化(NFV)已被广泛地被识别为通过使用基于软件的方法实现和整合基于硬件的网络功能的有效方法,其有可能显着减少CAPEX和OPEX。特别地,NFV协调器(例如,Tacker,Cliberify和Onap)在管理和协调各种虚拟化网络资源(例如,VM,虚拟化网络功能)中发挥着至关重要的作用,并且TOSCA是满足这样一个的标准数据模型之一角色。但是,它仍然尚不清楚安全机制如何无缝集成到这些虚拟化网络资产的整个生命周期中。从可用NFV协调器的比较分析开始,我们扩展了TOSCA模型以合并感兴趣的安全属性,并利用扩展模型来创建云标度的访问控制策略。具体地,开发了一种安全令人信服,其中包含TOSCA解析器和新颖的租户特定访问控制范例。我们的安全orchestrator的一个突出功能是它允许动态地为不同的租户域动态生成访问控制模型和策略,从而产生跨越不同NFV层和多个数据中心的灵活且可扩展的保护覆盖范围。为了验证其可行性和有效性,我们开发安全乐队原型并对吞吐量,可扩展性和适应性进行测试。实验结果表明,可以实现所有理想的属性,并且无论在云中部署的不同数量的租户,用户或对象,都可以保持令人满意的级别的吞吐量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号