Dynamic Multi-Method Allocation for Intent-based Security Orchestration

被引:0
|
作者
Robles-Enciso, Alberto [1 ]
Murcia, Jose Manuel Bernabe [1 ]
Zarca, Alejandro Molina [2 ]
Gomez, Antonio Skarmeta [1 ]
机构
[1] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Murcia, Spain
[2] Spanish Air Force Acad, Univ Ctr Def, San Javier 30720, Murcia, Spain
关键词
Orchestration; AI; Intent-based; Security; Optimal allocation;
D O I
10.1007/s10922-024-09896-8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's dynamic cybersecurity landscape, static and deterministic services orchestration which does not consider security as part of the orchestration process are proving insufficient against the evolving threat landscape. Security must be an intrinsic part of the orchestration processes. In this regard, this paper introduces an innovative paradigm shift: Intent & AI-based Optimized Security Orchestration. On the one hand, leveraging the capabilities of an Intent-based solution, this approach enables proactive and reactive threat mitigation in next generation heterogenous environments of the computing continuum, abstracting and homogenizing the complexity of underlying technologies. On the other hand, leveraging the capabilities of a dynamic allocation approach that applies different techniques for selecting the most suitable enforcement point (hardware/software) as well as the most suitable allocation for deploying/configuring them, always considering security properties during decision stages. Thus, the solution allows organizations adaptively optimizing resource allocation considering intent-based security requirements. The implementation considers different algorithms to perform the allocation decision depending on a variety of parameters. The performance has been also provided for validating the proposed solution. The results show that combining the security orchestrator with a Dynamic Allocation Engine improves the efficiency of decision making due to the ability to dynamically choose which algorithm is the most appropriate to solve the assignment problem in the best possible way and in the shortest possible time.
引用
收藏
页数:28
相关论文
共 50 条
  • [21] APSET, an Android aPplication SEcurity Testing tool for detecting intent-based vulnerabilities
    Sébastien Salva
    Stassia R. Zafimiharisoa
    International Journal on Software Tools for Technology Transfer, 2015, 17 : 201 - 221
  • [22] Towards Intent-based Scheduling for Performance and Security in Edge-to-Cloud Networks
    Santos, Jose
    Truyen, Eddy
    Baumann, Christoph
    De Turck, Filip
    Budigiri, Gerald
    Joosen, Wouter
    PROCEEDINGS OF THE 27TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS, ICIN, 2024, : 222 - 227
  • [23] APSET, an Android aPplication SEcurity Testing tool for detecting intent-based vulnerabilities
    Salva, Sebastien
    Zafimiharisoa, Stassia R.
    INTERNATIONAL JOURNAL ON SOFTWARE TOOLS FOR TECHNOLOGY TRANSFER, 2015, 17 (02) : 201 - 221
  • [24] Intent-Based Automation Networks Toward a Common Reference Model for the Self-Orchestration of Industrial Intranets
    Schulz, Dirk
    PROCEEDINGS OF THE IECON 2016 - 42ND ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2016, : 4651 - 4658
  • [25] Intent-based Decentralized Orchestration for Green Energy-aware Provisioning of Fog-native Workflows
    Al-Naday, Mays
    Goethals, Tom
    Volckaert, Bruno
    2022 18TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM 2022): INTELLIGENT MANAGEMENT OF DISRUPTIVE NETWORK TECHNOLOGIES AND SERVICES, 2022, : 184 - 190
  • [26] An Intent-Based Automation Framework for Securing Dynamic Consumer IoT Infrastructures
    Nagendra, Vasudevan
    Bhattacharya, Arani
    Yegneswaran, Vinod
    Rahmati, Amir
    Das, Samir
    WEB CONFERENCE 2020: PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE (WWW 2020), 2020, : 1625 - 1636
  • [27] ICSC: Intent-Based Closed-Loop Security Control System for Cloud-Based Security Services
    Lingga, Patrick
    Jeong, Jaehoon Paul
    Dunbar, Linda
    IEEE COMMUNICATIONS MAGAZINE, 2024,
  • [28] Ensemble Learning-based Network Data Analytics for Network Slice Orchestration and Management: An Intent-Based Networking Mechanism
    Abbas, Khizar
    Khan, Talha Ahmed
    Afaq, Muhammad
    Song, Wang-Cheol
    PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022, 2022,
  • [29] Optimizing Key Value Indicators in Intent-Based Networks through Digital Twins aided service orchestration mechanisms
    de Trizio, Federica
    Sciddurlo, Giancarlo
    Cianci, Ilaria
    Piro, Giuseppe
    Boggia, Gennaro
    COMPUTER COMMUNICATIONS, 2024, 228
  • [30] VNF Placement Problem: A Multi-Tenant Intent-Based Networking Approach
    Leivadeas, Aris
    Falkner, Matthias
    2021 24TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS (ICIN), 2021,