Software Defined Perimeter Monitoring and Blockchain-Based Verification of Policy Mapping

被引:0
|
作者
Akbar, Waleed [1 ]
Rivera, Javier Jose Diaz [1 ]
Ahmed, Khan Talha [1 ]
Muhammad, Afaq [1 ]
Song, Wang-Cheol [1 ]
机构
[1] Jeju Natl Univ, Dept Comp Engn, Jeju Si, South Korea
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the emergence of Zero Trust (ZT) Architecture, industry leaders have been drawn to the technology because of its potential to handle a high level of security threats. The Zero Trust Architecture (ZTA) is paving the path for a security industrial revolution by eliminating location-based implicant access and focusing on asset, user, and resource security. Software Defined Perimeter (SDP) is a secure overlay network technology that can be used to implement a Zero Trust framework. SDP is a next-generation network technology that allows network architecture to be hidden from the outside world. It also hides the overlay communication from the underlay network by employing encrypted communications. With encrypted information, detecting abnormal behavior of entities on an overlay network becomes exceedingly difficult. Therefore, an automated system is required. We proposed a method in this paper for understanding the normal behavior of deployed polices by mapping network usage behavior to the policy. An Apache Spark collects and processes the streaming overlay monitoring data generated by the built-in fabric API in order to do this mapping. It sends extracted metrics to Prometheus for storage, and then uses the data for machine learning training and prediction. The cluster-id of the link that it belongs to is predicted by the model, and the cluster-ids are mapped onto the policies. To validate the legitimacy of policy, the labeled polices hash is compared to the actual polices hash that is obtained from blockchain. Unverified policies are notified to the SDP controller for additional action, such as defining new policy behavior or marking uncertain policies.
引用
收藏
页码:407 / 410
页数:4
相关论文
共 50 条
  • [41] IoT and Blockchain-Based Method for Device Identity Verification
    Laroiya, Chetna
    Bhatia, Manjot K.
    Madan, Suman
    Komalavalli, C.
    INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING AND COMMUNICATIONS, ICICC 2022, VOL 1, 2023, 473 : 269 - 280
  • [42] Blockchain-based random auditor committee for integrity verification
    Chen, Lanxiang
    Fu, Qingxiao
    Mu, Yi
    Zeng, Lingfang
    Rezaeibagha, Fatemeh
    Hwang, Min-Shiang
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 131 : 183 - 193
  • [43] Improved blockchain-based ECDSA batch verification scheme
    Wu, Guangfu
    Zhou, Jiandong
    Fu, Xiaoyan
    FRONTIERS IN BLOCKCHAIN, 2025, 8
  • [44] Blockchain-based fake news traceability and verification mechanism
    Wang, Xiaowan
    Xie, Huiyin
    Ji, Shan
    Liu, Liang
    Huang, Ding
    HELIYON, 2023, 9 (07)
  • [45] Formal Verification for Blockchain-based Insurance Claims Processing
    Neupane, Roshan Lal
    Bonnah, Ernest
    Bhusal, Bishnu
    Neupane, Kiran
    Hoque, Khaza Anuarul
    Calyam, Prasad
    PROCEEDINGS OF 2024 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, NOMS 2024, 2024,
  • [46] A Blockchain-based DNSSEC Public Key Verification Scheme
    Chen W.-Y.
    Li X.-D.
    Yang X.
    Xu Y.-Z.
    Zidonghua Xuebao/Acta Automatica Sinica, 2023, 49 (04): : 731 - 743
  • [47] Enhancing the security of blockchain-based software defined networking through trust-based traffic fusion and filtration
    Meng, Weizhi
    Li, Wenjuan
    Zhou, Jianying
    INFORMATION FUSION, 2021, 70 : 60 - 71
  • [48] Blockchain-Based Distributed Software-Defined Vehicular Networks via Deep Q-Learning
    Qiu, Chao
    Yu, F. Richard
    Xu, Fangmin
    Yao, Haipeng
    Zhao, Chenglin
    DIVANET'18: PROCEEDINGS OF THE 8TH ACM SYMPOSIUM ON DESIGN AND ANALYSIS OF INTELLIGENT VEHICULAR NETWORKS AND APPLICATIONS, 2018, : 8 - 14
  • [49] EDISON: A Blockchain-based Secure and Auditable Orchestration Framework for Multi-domain Software Defined Networks
    Balachandran, Chandrasekar
    Puneet, A. C.
    Ramachandran, Gowri
    Krishnamachari, Bhaskar
    2020 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN (BLOCKCHAIN 2020), 2020, : 144 - 153
  • [50] A blockchain-based secure data-sharing framework for Software Defined Wireless Body Area Networks
    Hasan, Khalid
    Chowdhury, Mohammad Jabed Morshed
    Biswas, Kamanashis
    Ahmed, Khandakar
    Islam, Md. Saiful
    Usman, Muhammad
    COMPUTER NETWORKS, 2022, 211