...
首页> 外文期刊>Tsinghua Science and Technology >Collaborative network security in multi-tenant data center for cloud computing
【24h】

Collaborative network security in multi-tenant data center for cloud computing

机译:多租户数据中心中用于云计算的协作网络安全

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

A data center is an infrastructure that supports Internet service. Cloud computing is rapidly changing the face of the Internet service infrastructure, enabling even small organizations to quickly build Web and mobile applications for millions of users by taking advantage of the scale and flexibility of shared physical infrastructures provided by cloud computing. In this scenario, multiple tenants save their data and applications in shared data centers, blurring the network boundaries between each tenant in the cloud. In addition, different tenants have different security requirements, while different security policies are necessary for different tenants. Network virtualization is used to meet a diverse set of tenant-specific requirements with the underlying physical network, enabling multi-tenant datacenters to automatically address a large and diverse set of tenants requirements. In this paper, we propose the system implementation of vCNSMS, a collaborative network security prototype system used in a multi-tenant data center. We demonstrate vCNSMS with a centralized collaborative scheme and deep packet inspection with an open source UTM system. A security level based protection policy is proposed for simplifying the security rule management for vCNSMS. Different security levels have different packet inspection schemes and are enforced with different security plugins. A smart packet verdict scheme is also integrated into vCNSMS for intelligence flow processing to protect from possible network attacks inside a data center network.
机译:数据中心是支持Internet服务的基础结构。云计算正在迅速改变互联网服务基础架构的面貌,从而使小型企业也可以利用云计算提供的共享物理基础架构的规模和灵活性,快速为数百万用户构建Web和移动应用程序。在这种情况下,多个租户将其数据和应用程序保存在共享数据中心中,从而模糊了云中每个租户之间的网络边界。另外,不同的租户有不同的安全要求,而不同的租户需要不同的安全策略。网络虚拟化用于通过基础物理网络满足一系列特定于租户的需求,从而使多租户数据中心能够自动满足大量多样的租户需求。在本文中,我们提出了vCNSMS的系统实现,vCNSMS是一种用于多租户数据中心的协作网络安全原型系统。我们通过集中协作方案演示了vCNSMS,并使用开源UTM系统演示了深度数据包检查。为了简化vCNSMS的安全规则管理,提出了一种基于安全级别的保护策略。不同的安全级别具有不同的数据包检查方案,并使用不同的安全插件来实施。 vCNSMS中还集成了智能数据包判决方案,用于智能流处理,以防止数据中心网络内部可能发生的网络攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号