PALANTIR: An NFV-Based Security-as-a-Service Approach for Automating Threat Mitigation

被引:4
|
作者
Compastie, Maxime [1 ]
Martinez, Antonio Lopez [2 ]
Fernandez, Carolina [1 ,3 ]
Perez, Manuel Gil [2 ]
Tsarsitalidis, Stylianos [4 ]
Xylouris, George [5 ]
Mlakar, Izidor [6 ,7 ]
Kourtis, Michail Alexandros [5 ]
Safran, Valentino [6 ]
机构
[1] i2CAT Fdn, Cybersecur Dept, Barcelona 08034, Spain
[2] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
[3] Univ Pompeu Fabra, Dept Informat & Commun Technol, Barcelona 08018, Spain
[4] UBITECH Ubiquitous Solut, Athens 15231, Greece
[5] ORION Innovat PC, Athens 11744, Greece
[6] Univ Maribor, Fac Elect Engn & Comp Sci, Maribor 2000, Slovenia
[7] Sfera IT Doo, Maribor 2000, Slovenia
关键词
Security-as-a-Service; security orchestration; policy-driven management; virtual network functions; finite state machines; constraints programming; ARCHITECTURE; NETWORKS;
D O I
10.3390/s23031658
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Small and medium enterprises are significantly hampered by cyber-threats as they have inherently limited skills and financial capacities to anticipate, prevent, and handle security incidents. The EU-funded PALANTIR project aims at facilitating the outsourcing of the security supervision to external providers to relieve SMEs/MEs from this burden. However, good practices for the operation of SME/ME assets involve avoiding their exposure to external parties, which requires a tightly defined and timely enforced security policy when resources span across the cloud continuum and need interactions. This paper proposes an innovative architecture extending Network Function Virtualisation to externalise and automate threat mitigation and remediation in cloud, edge, and on-premises environments. Our contributions include an ontology for the decision-making process, a Fault-and-Breach-Management-based remediation policy model, a framework conducting remediation actions, and a set of deployment models adapted to the constraints of cloud, edge, and on-premises environment(s). Finally, we also detail an implementation prototype of the framework serving as evaluation material.
引用
收藏
页数:37
相关论文
共 50 条
  • [21] Deep Reinforcement Learning for NFV-based Service Function Chaining in Multi-Service Networks
    Ning, Zili
    Wang, Ning
    Tafazolli, Rahim
    2020 IEEE 21ST INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (IEEE HPSR), 2020,
  • [22] Migrating to a NFV-based Home Gateway: introducing a Surrogate vNF approach
    Herbaut, Nicolas
    Negru, Daniel
    Xilouris, George
    Chen, Yiping
    2015 6TH INTERNATIONAL CONFERENCE ON THE NETWORK OF THE FUTURE (NOF), 2015,
  • [23] SDN/NFV-based Scalable Mobile Service Integration for Gradual Network Evolution
    Kyung, Yeunwoong
    Park, Sungho
    Park, Jinwoo
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2017, 19 (06) : 569 - 576
  • [24] EasyOrchestrator: A NFV-based Network Service Creation Platform for End-users
    Yue, Yi
    Cheng, Bo
    2018 IEEE 37TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2018,
  • [25] An access control model for a grid environment employing security-as-a-service approach
    Olatunji, E.K.
    Adigun, M.O.
    Jembere, E.
    Lecture Notes in Electrical Engineering, 2015, 313 : 103 - 110
  • [26] A Joint Optimization Approach to Security-as-a-Service Allocation and Cyber Insurance Management
    Chaisiri, Sivadon
    Ko, Ryan K. L.
    Niyato, Dusit
    2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 426 - 433
  • [27] A Scalable Approach to Joint Cyber Insurance and Security-as-a-Service Provisioning in Cloud Computing
    Chase, Jonathan
    Niyato, Dusit
    Wang, Ping
    Chaisiri, Sivadon
    Ko, Ryan K. L.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (04) : 565 - 579
  • [28] NFV-Based Scalable Guaranteed-Bandwidth Multicast Service for Software Defined ISP Networks
    Soni, Hardik
    Dabbous, Walid
    Turletti, Thierry
    Asaeda, Hitoshi
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (04): : 1157 - 1170
  • [29] Energy efficient and delay aware deployment of parallelized service function chains in NFV-based networks
    Chintapalli, Venkatarami Reddy
    Partani, Rajat
    Tamma, Bheemarjuna Reddy
    Murthy, C. Siva Ram
    COMPUTER NETWORKS, 2024, 248
  • [30] Service Orchestration in NFV-Based Traditional and Emerging Cloud Environments: State of the Art and Research Challenges
    Spinnewyn, Bart
    Latre, Steven
    Botero, Juan Felipe
    IEEE COMMUNICATIONS MAGAZINE, 2020, 58 (08) : 76 - 81