首页> 外文期刊>Tsinghua Science and Technology >Research and practice of dynamic network security architecture for IaaS platforms
【24h】

Research and practice of dynamic network security architecture for IaaS platforms

机译:IaaS平台动态网络安全架构的研究与实践

获取原文
获取原文并翻译 | 示例
       

摘要

Network security requirements based on virtual network technologies in IaaS platforms and corresponding solutions were reviewed. A dynamic network security architecture was proposed, which was built on the technologies of software defined networking, Virtual Machine (VM) traffic redirection, network policy unified management, software defined isolation networks, vulnerability scanning, and software updates. The proposed architecture was able to obtain the capacity for detection and access control for VM traffic by redirecting it to configurable security appliances, and ensured the effectiveness of network policies in the total life cycle of the VM by configuring the policies to the right place at the appropriate time, according to the impacts of VM state transitions. The virtual isolation domains for tenants' VMs could be built flexibly based on VLAN policies or Netfilter/Iptables firewall appliances, and vulnerability scanning as a service and software update as a service were both provided as security supports. Through cooperation with IDS appliances and automatic alarm mechanisms, the proposed architecture could dynamically mitigate a wide range of network-based attacks. The experimental results demonstrate the effectiveness of the proposed architecture.
机译:审查了基于IaaS平台中的虚拟网络技术的网络安全要求以及相应的解决方案。提出了一种动态网络安全体系结构,该体系结构建立在软件定义网络,虚拟机(VM)流量重定向,网络策略统一管理,软件定义隔离网络,漏洞扫描和软件更新的技术之上。所提出的体系结构能够将虚拟机流量重定向到可配置的安全设备,从而获得检测和访问虚拟机流量的能力,并通过在虚拟机的正确位置配置策略来确保网络策略在虚拟机整个生命周期中的有效性。根据VM状态转换的影响,选择适当的时间。可以基于VLAN策略或Netfilter / Iptables防火墙设备灵活地构建用于租户VM的虚拟隔离域,并且作为安全支持提供漏洞扫描即服务和软件更新即服务。通过与IDS设备和自动警报机制的协作,所提出的体系结构可以动态缓解各种基于网络的攻击。实验结果证明了所提出体系结构的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号