首页> 外文期刊>Journal of Parallel and Distributed Computing >SEAPP: A secure application management framework based on REST API access control in SDN-enabled cloud environment
【24h】

SEAPP: A secure application management framework based on REST API access control in SDN-enabled cloud environment

机译:SEAPP:基于REST API访问控制的安全应用管理框架在支持SDN的云环境中

获取原文
获取原文并翻译 | 示例
           

摘要

Cloud computing provides scalable network services and makes network management more flexible by combining Software-Defined Networking (SDN). Through the northbound interface (e.g., REST API) offered by the SDN controller, users can easily deploy diversified applications to access the network resources. However, exploiting the openness of the northbound interface, malicious applications abuse APIs to launch hostile attacks, which poses serious threats to the network. In this paper, we propose SEAPP, a secure application management framework based on REST API access control. Our main idea is to granularly manage application permissions and encrypt REST API calls to defend against malicious attacks. SEAPP includes two components: 1) permissions detection engine identifies the facticity of application permissions by analyzing permission manifests and byte codes and further identifies the legality of permissions with constructed sensitive API list; 2) registration authorization engine executes encrypted registration between applications and controller by virtue of NTRU algorithm and authorizes applications to call the requested REST APIs based on their risk levels after securely authenticating them. Besides, SEAPP is a lightweight logic architecture between application plane and control plane and supports quick deployment and reconfiguration in runtime. Both theoretical analysis and evaluation results show the security and effectiveness of SEAPP. Besides, SEAPP introduces negligible CPU and memory overheads.
机译:云计算提供可扩展的网络服务,并通过组合软件定义的网络(SDN)使网络管理更灵活。通过SDN控制器提供的北行界面(例如,REST API),用户可以轻松地部署多样化的应用程序来访问网络资源。然而,利用北行界面的开放性,恶意应用程序滥用API启动敌对攻击,这会对网络构成严重威胁。本文提出了基于REST API访问控制的安全应用管理框架Seapp。我们的主要思想是要粒度管理应用程序权限,并加密REST API调用来防御恶意攻击。 SEAPP包括两个组件:1)权限检测引擎通过分析许可情况和字节代码来识别应用程序权限的事实,并进一步识别构造敏感API列表的权限的合法性; 2)通过NTRU算法凭借NTRU算法,注册授权引擎在应用程序和控制器之间执行加密注册,并授权应用程序根据安全验证后的风险级别调用所请求的REST API。此外,SEAPP是应用程序平面和控制平面之间的轻量级逻辑架构,并在运行时支持快速部署和重新配置。理论分析和评估结果都表明了SEAPP的安全性和有效性。此外,SEAPP引入了可忽略不计的CPU和内存开销。

著录项

  • 来源
    《Journal of Parallel and Distributed Computing》 |2021年第1期|108-123|共16页
  • 作者单位

    National Digital Switching System Engineering and Technological Research Center China Information Engineering University China;

    National Digital Switching System Engineering and Technological Research Center China;

    National Digital Switching System Engineering and Technological Research Center China;

    Information Engineering University China;

    Information Engineering University China;

    Information Engineering University China;

    National Digital Switching System Engineering and Technological Research Center China;

    National Digital Switching System Engineering and Technological Research Center China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Cloud; Software-Defined Networking; Network security; Application; REST API;

    机译:云;软件定义网络;网络安全;应用;休息API.;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号