Automated Security Management for Virtual Services

被引:0
|
作者
Repetto, M. [1 ]
Carrega, A. [1 ]
Yusupov, J. [2 ]
Valenza, F. [2 ]
Risso, F. [2 ]
Lamanna, G. [3 ]
机构
[1] CNIT, S2N Lab, Genoa, Italy
[2] Politecn Torino, DAUIN, Turin, Italy
[3] Infocom Srl, Genoa, Italy
关键词
D O I
10.1109/nfv-sdn47374.2019.9040069
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The virtualization of applications and network functions facilitates the dynamic creation of compound services, automating both the provisioning of computing/networking/storage resources and their life-cycle management. Virtualization of security appliances is a common approach to protect such services, but can neither offer broad visibility across the whole deployed service nor implement coordinated and fine-grained enforcement actions. This paper proposes a novel security framework based on the integration of lightweight and programmable monitoring and enforcement hooks in each virtual function, which are collectively controlled by a common logic for prevention, detection, reaction, and mitigation of security threats. Our framework keeps direct control over the functionalities of the security hooks, and leverages standard orchestration tools for management actions on the service graph. It can be automatically instantiated by common orchestration operations. hence seamlessly integrating with the deployment process of service graphs.
引用
收藏
页数:2
相关论文
共 50 条
  • [1] Discover and Secure (DaS): An Automated Virtual Machine Security Management Framework
    Navamani, Beaulah A.
    Yue, Chuan
    Zhou, Xiaobo
    2018 IEEE 37TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2018,
  • [2] Automated Security Configuration Management
    Ehab Al-Shaer
    Charles R. Kalmanek
    Felix Wu
    Journal of Network and Systems Management, 2008, 16 : 231 - 233
  • [3] Automated Security Configuration Management
    Al-Shaer, Ehab
    Kalmanek, Charles R.
    Wu, Felix
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2008, 16 (03) : 231 - 233
  • [4] Security Management in Municipal Services
    Kozera, Andrzej
    MANAGEMENT 2012: RESEARCH IN MANAGEMENT AND BUSINESS IN THE LIGHT OF PRACTICAL NEEDS, 2012, : 283 - 287
  • [5] Security management of web services
    Malek, M
    Harmantzis, F
    NOMS 2004: IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, APPLICATION SESSIONS: MANAGING NEXT GENERATION CONVERGENCE NETWORKS AND SERVICES, 2004, : 175 - 189
  • [6] Integrated Security for Services Hosted in Virtual Environments
    Jayarathna, Dilshan
    Varadharajan, Vijay
    Tupakula, Udaya
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 82 - 89
  • [7] Rigorous automated network security management
    Guttman J.D.
    Herzog A.L.
    International Journal of Information Security, 2005, 4 (1-2) : 29 - 48
  • [8] Virtual enterprise risk and security management
    Feglar, T
    ISC'2005: 3rd Industrial Simulation Conference 2005, 2005, : 145 - 149
  • [9] Management of Virtual Environments with Emphasis on Security
    Mendes, Andre
    OPTIMIZATION, LEARNING ALGORITHMS AND APPLICATIONS, OL2A 2022, 2022, 1754 : 93 - 106
  • [10] MANAGEMENT OF SECURITY POLICIES IN VIRTUAL ORGANISATIONS
    Aziz, Benjamin
    Arenas, Alvaro
    Johnson, Ian
    Artac, Matej
    Cernivec, Ales
    Robinson, Philip
    SECRYPT 2010: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2010, : 467 - 477