首页> 外文期刊>Quality Control, Transactions >SDN/NFV-Based Security Service Function Tree for Cloud
【24h】

SDN/NFV-Based Security Service Function Tree for Cloud

机译:基于SDN / NFV的安全服务功能树用于云

获取原文
获取原文并翻译 | 示例
           

摘要

Network security for cloud computing is very important. Service function chain (SFC) that integrates software defined network (SDN) and network function virtualization (NFV) can provide a new approach for solving the network security issues for cloud computing. In this paper, we combine multiple SFCs into a security service function tree (or SecSFT, for short) to reduce requirement for resources in allocating virtual security functions. According to the idea of decision tree used for classification, we assign decision rules and detection rules to the nodes of the SecSFT so that they can identify and split suspicious flows from the mixed traffic and detect/prevent intrusions in the suspicious ones. The nodes of the SecSFT implement various virtualized functions including security-related network functions (e.g., load balancing, and traffic shaping), network security functions (e.g., intrusion detection, firewall), and virtualized network security hardware. Finally, we build a SecSFT in an experiment cloud and test and validate its security services in detection and mitigation of network attacks.
机译:云计算的网络安全非常重要。整合软件定义网络(SDN)和网络功能虚拟化(NFV)的服务功能链(SFC)可以提供一种用于解决云计算网络安全问题的新方法。在本文中,我们将多个SFC组合成安全服务功能树(或SECSFT,短暂),以减少对分配虚拟安全功能的资源的要求。根据用于分类的决策树的想法,我们将决策规则和检测规则分配给SECSFT的节点,以便它们可以从混合流量和检测/防止可疑的流量识别和拆分可疑流。 SECSFT的节点实现了各种虚拟化功能,包括与安全相关的网络功能(例如,负载平衡和流量整形),网络安全功能(例如,入侵检测,防火墙)和虚拟化网络安全硬件。最后,我们在实验云中建立了一个SECSFT,并在检测和减轻网络攻击时验证其安全服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号