Automated Security Management for Virtual Services

被引:0
|
作者
Repetto, M. [1 ]
Carrega, A. [1 ]
Yusupov, J. [2 ]
Valenza, F. [2 ]
Risso, F. [2 ]
Lamanna, G. [3 ]
机构
[1] CNIT, S2N Lab, Genoa, Italy
[2] Politecn Torino, DAUIN, Turin, Italy
[3] Infocom Srl, Genoa, Italy
关键词
D O I
10.1109/nfv-sdn47374.2019.9040069
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The virtualization of applications and network functions facilitates the dynamic creation of compound services, automating both the provisioning of computing/networking/storage resources and their life-cycle management. Virtualization of security appliances is a common approach to protect such services, but can neither offer broad visibility across the whole deployed service nor implement coordinated and fine-grained enforcement actions. This paper proposes a novel security framework based on the integration of lightweight and programmable monitoring and enforcement hooks in each virtual function, which are collectively controlled by a common logic for prevention, detection, reaction, and mitigation of security threats. Our framework keeps direct control over the functionalities of the security hooks, and leverages standard orchestration tools for management actions on the service graph. It can be automatically instantiated by common orchestration operations. hence seamlessly integrating with the deployment process of service graphs.
引用
收藏
页数:2
相关论文
共 50 条
  • [41] Logic-based management of security in web services
    Tziviskou, Christina
    Di Nitto, Elisabetta
    2007 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2007, : 228 - +
  • [42] A security management framework with roaming coordinator for pervasive services
    Lee, Minsoo
    Park, Sehyun
    Jun, Sungik
    AUTONOMIC AND TRUSTED COMPUTING, PROCEEDINGS, 2006, 4158 : 302 - 311
  • [43] A risk management framework for security and integrity of networks and services
    Mayer, Nicolas
    Aubert, Jocelyn
    JOURNAL OF RISK RESEARCH, 2021, 24 (08) : 987 - 998
  • [44] Enabling Enhanced Data Security for Aquaculture Management Services
    Piplani, Divya
    Sharma, Rahul
    Singh, Dinesh Kumar
    Aleembaig, M.
    PROCEEDINGS OF THE 2017 THIRD INTERNATIONAL CONFERENCE ON MOBILE AND SECURE SERVICES (MOBISECSERV), 2017,
  • [45] A network management viewpoint on security in e-services
    Boutaba, R
    Ishibashi, B
    Shihada, B
    CERTIFICATION AND SECURITY IN E-SERVICES: FROM E-GOVERNMENT TO E-BUSINESS, 2003, 127 : 17 - 45
  • [46] A trust management framework suitable for web services security
    Ping, AI
    Mao, YC
    DCABES 2004, PROCEEDINGS, VOLS, 1 AND 2, 2004, : 469 - 473
  • [47] QoS Management and Traffic Engineering for Virtual SDN Services
    Yucel, Sakir
    2019 6TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI 2019), 2019, : 1448 - 1453
  • [48] Basic services for the management of virtual enterprises - A case study
    Spinosa, LM
    Hofmann, ACM
    Rabelo, RJ
    Pereira, AA
    INTELLIGENT SYSTEMS FOR MANUFACTURING: MULTI-AGENT SYSTEMS AND VIRTUAL ORGANIZATION, 1998, : 197 - 206
  • [49] In-VIGO virtual networks and virtual application services: Automated grid-enabling and deployment of applications
    Tsugawa, M
    Matsunaga, A
    Zhu, LP
    Sanjeepan, V
    Lam, H
    Figueiredo, RJ
    Fortes, JAB
    14TH IEEE INTERNATIONAL SYMPOSIUM ON HIGH PERFORMANCE DISTRIBUTED COMPUTING, PROCEEDINGS, 2005, : 312 - 313
  • [50] Discover and safe: an automated security management system for educational institutions
    Kandhro, Irfan Ali
    Khan, Umer
    Memon, Shahrukh
    Yasir, Mohammad
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2023, 15 (02) : 158 - 176