PALANTIR: An NFV-Based Security-as-a-Service Approach for Automating Threat Mitigation

被引:4
|
作者
Compastie, Maxime [1 ]
Martinez, Antonio Lopez [2 ]
Fernandez, Carolina [1 ,3 ]
Perez, Manuel Gil [2 ]
Tsarsitalidis, Stylianos [4 ]
Xylouris, George [5 ]
Mlakar, Izidor [6 ,7 ]
Kourtis, Michail Alexandros [5 ]
Safran, Valentino [6 ]
机构
[1] i2CAT Fdn, Cybersecur Dept, Barcelona 08034, Spain
[2] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
[3] Univ Pompeu Fabra, Dept Informat & Commun Technol, Barcelona 08018, Spain
[4] UBITECH Ubiquitous Solut, Athens 15231, Greece
[5] ORION Innovat PC, Athens 11744, Greece
[6] Univ Maribor, Fac Elect Engn & Comp Sci, Maribor 2000, Slovenia
[7] Sfera IT Doo, Maribor 2000, Slovenia
关键词
Security-as-a-Service; security orchestration; policy-driven management; virtual network functions; finite state machines; constraints programming; ARCHITECTURE; NETWORKS;
D O I
10.3390/s23031658
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Small and medium enterprises are significantly hampered by cyber-threats as they have inherently limited skills and financial capacities to anticipate, prevent, and handle security incidents. The EU-funded PALANTIR project aims at facilitating the outsourcing of the security supervision to external providers to relieve SMEs/MEs from this burden. However, good practices for the operation of SME/ME assets involve avoiding their exposure to external parties, which requires a tightly defined and timely enforced security policy when resources span across the cloud continuum and need interactions. This paper proposes an innovative architecture extending Network Function Virtualisation to externalise and automate threat mitigation and remediation in cloud, edge, and on-premises environments. Our contributions include an ontology for the decision-making process, a Fault-and-Breach-Management-based remediation policy model, a framework conducting remediation actions, and a set of deployment models adapted to the constraints of cloud, edge, and on-premises environment(s). Finally, we also detail an implementation prototype of the framework serving as evaluation material.
引用
收藏
页数:37
相关论文
共 50 条
  • [1] SDN/NFV-Based Security Service Function Tree for Cloud
    Luo, Jing-Lun
    Yu, Shun-Zheng
    Peng, Si-Jie
    IEEE ACCESS, 2020, 8 (08): : 38538 - 38545
  • [2] SDN/NFV-based DDoS Mitigation via Pushback
    Bulbul, Nurefsan Sertbas
    Fischer, Mathias
    ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [3] Demo: NFV-based IoT Security at the ISP Level
    Afek, Yehuda
    Bremler-Barr, Anat
    Hay, David
    Shafir, Lior
    Zhaika, Ihab
    NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE, 2020,
  • [4] A NFV-based Resource Orchestration Algorithm for DDoS Mitigation in MEC
    Guo, Lei
    Xing, Yiping
    Jiang, Chunxiao
    Bai, Lin
    IWCMC 2021: 2021 17TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2021, : 961 - 967
  • [5] NFV-based network protection: the SHIELD approach
    Lioy, A.
    Gardikis, G.
    Gaston, B.
    Jacquin, L.
    De Benedictis, M.
    Angelopoulos, Y.
    Xylouris, C.
    2017 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2017, : 200 - 201
  • [6] NFV-based IoT Security for Home Networks using MUD
    Afek, Yehuda
    Bremler-Barr, Anat
    Hay, David
    Goldschmidt, Ran
    Shafir, Lior
    Avraham, Gafnit
    Shalev, Avraham
    NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE, 2020,
  • [7] Flow Scheduling of Service Chain Processing in a NFV-Based Network
    Chen, Yang
    Wu, Jie
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2021, 8 (01): : 389 - 399
  • [8] Grouping Service Chains of Multiple Flows in NFV-Based Networks
    Chen, Yang
    Wu, Jie
    Biswas, Rajorshi
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2021, 8 (01): : 377 - 388
  • [9] Service Chain Modeling and Embedding for NFV-based Content Delivery
    Herbaut, Nicolas
    Negru, Daniel
    Dietrich, David
    Papadimitriou, Panagiotis
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [10] Dynamic Service Reallocation in NFV-based Transport WDM Optical Networks
    Pages, Albert
    Agraz, Fernando
    Montero, Rafael
    Spadaro, Salvatore
    2018 PHOTONICS IN SWITCHING AND COMPUTING (PSC), 2018,