Dynamic Multi-Method Allocation for Intent-based Security Orchestration

被引:0
|
作者
Robles-Enciso, Alberto [1 ]
Murcia, Jose Manuel Bernabe [1 ]
Zarca, Alejandro Molina [2 ]
Gomez, Antonio Skarmeta [1 ]
机构
[1] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Murcia, Spain
[2] Spanish Air Force Acad, Univ Ctr Def, San Javier 30720, Murcia, Spain
关键词
Orchestration; AI; Intent-based; Security; Optimal allocation;
D O I
10.1007/s10922-024-09896-8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's dynamic cybersecurity landscape, static and deterministic services orchestration which does not consider security as part of the orchestration process are proving insufficient against the evolving threat landscape. Security must be an intrinsic part of the orchestration processes. In this regard, this paper introduces an innovative paradigm shift: Intent & AI-based Optimized Security Orchestration. On the one hand, leveraging the capabilities of an Intent-based solution, this approach enables proactive and reactive threat mitigation in next generation heterogenous environments of the computing continuum, abstracting and homogenizing the complexity of underlying technologies. On the other hand, leveraging the capabilities of a dynamic allocation approach that applies different techniques for selecting the most suitable enforcement point (hardware/software) as well as the most suitable allocation for deploying/configuring them, always considering security properties during decision stages. Thus, the solution allows organizations adaptively optimizing resource allocation considering intent-based security requirements. The implementation considers different algorithms to perform the allocation decision depending on a variety of parameters. The performance has been also provided for validating the proposed solution. The results show that combining the security orchestrator with a Dynamic Allocation Engine improves the efficiency of decision making due to the ability to dynamically choose which algorithm is the most appropriate to solve the assignment problem in the best possible way and in the shortest possible time.
引用
收藏
页数:28
相关论文
共 50 条
  • [1] A network protocol for distributed orchestration using intent-based forwarding
    Auge, Jordan
    Enguehard, Marcel
    2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019, : 718 - 719
  • [2] Intent-based Network Management and Orchestration for Smart Distribution Grids
    Mehmood, Kashif
    Mendis, H. V. Kalpanie
    Kralevska, Katina
    Heegaard, Poul E.
    2021 28TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (ICT), 2021, : 120 - 125
  • [3] Flow Allocation in Industrial Intent-based Networks
    Saha, Barun Kumar
    Haab, Luca
    Podleski, Lukasz
    13TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATION SYSTEMS (IEEE ANTS), 2019,
  • [4] Intent-Based End-to-End Network Service Orchestration System for Multi-Platforms
    Rafiq, Adeel
    Mehmood, Asif
    Khan, Talha Ahmed
    Abbas, Khizar
    Afaq, Muhammad
    Song, Wang-Cheol
    SUSTAINABILITY, 2020, 12 (07)
  • [5] Security in Intent-Based Networking: Challenges and Solutions
    Ahmad, Ijaz
    Malinen, Jere
    Christou, Filippos
    Porambage, Pawani
    Kirstaedter, Andreas
    Suomalainen, Jani
    2023 IEEE CONFERENCE ON STANDARDS FOR COMMUNICATIONS AND NETWORKING, CSCN, 2023, : 296 - 301
  • [6] Dynamic Security Provisioning for Cloud-Native Networks: An Intent-Based Approach
    Settanni, Francesco
    Zamponi, Alessandro
    Basile, Cataldo
    2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2024, : 321 - 328
  • [7] Intent-Based Management and Orchestration of Heterogeneous OpenFlow/IoT SDN Domains
    Cerroni, Walter
    Buratti, Chiara
    Cerboni, Simone
    Davoli, Gianluca
    Contoli, Chiara
    Foresta, Francesco
    Callegati, Franco
    Verdone, Roberto
    2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [8] IBCS: Intent-Based Cloud Services for Security Applications
    Kim, Jinyong
    Kim, Eunsoo
    Yang, Jinhyuk
    Jeong, Jaehoon
    Kim, Hyoungshick
    Hyun, Sangwon
    Yang, Hyunsik
    Oh, Jaewook
    Kim, Younghan
    Hares, Susan
    Dunbar, Linda
    IEEE COMMUNICATIONS MAGAZINE, 2020, 58 (04) : 45 - 51
  • [9] IBN@Cloud: An Intent-based Cloud and Overlay Network Orchestration System
    Sarwar, Mir Muhammad Suleman
    Muhammad, Afaq
    Song, Wang-Cheol
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2024, 26 (01) : 131 - 146
  • [10] Intent-Based Orchestration of Network Slices and Resource Assurance using Machine Learning
    Khan, Talha Ahmed
    Mehmood, Asif
    Ravera, Javier Jose Diaz
    Muhammad, Afaq
    Abbas, Khizar
    Song, Wang-Cheol
    NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE, 2020,