Security automation for multi-cluster orchestration in Kubernetes

被引:2
|
作者
Bringhenti, Daniele [1 ]
Sisto, Riccardo [1 ]
Valenza, Fulvio [1 ]
机构
[1] Politecn Torino, Dip Automat & Informat, Turin, Italy
关键词
security automation; cloud orchestration; Kubernetes;
D O I
10.1109/NetSoft57336.2023.10175419
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the latest years, multi-domain Kubernetes architectures composed of multiple clusters have been getting more frequent, so as to provide higher workload isolation, resource availability flexibility and scalability for application deployment. However, manually configuring their security may lead to inconsistencies among policies defined in different clusters, or it may require knowledge that the administrator of each domain cannot have. Therefore, this paper proposes an automatic approach for the automatic generation of the network security policies to be deployed in each cluster of a multi-domain Kubernetes deployment. The objectives of this approach are to reduce of configuration errors that human administrators commonly make, and to create transparent cross-cluster communications. This approach has been implemented as a framework named Multi-Cluster Orchestrator, which has been validated in realistic use cases to assess its benefits to Kubernetes orchestration.
引用
收藏
页码:480 / 485
页数:6
相关论文
共 50 条
  • [1] Towards IoT Security Automation and Orchestration
    Zheng, Yifeng
    Pal, Arindam
    Abuadbba, Sharif
    Pokhrel, Shiva Raj
    Nepal, Surya
    Janicke, Helge
    [J]. 2020 SECOND IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2020), 2020, : 55 - 63
  • [2] mck8s: An orchestration platform for geo-distributed multi-cluster environments
    Tamiru, Mulugeta Ayalew
    Pierre, Guillaume
    Tordsson, Johan
    Elmroth, Erik
    [J]. 30TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2021), 2021,
  • [3] ClusterLink: A Multi-Cluster Application Interconnect
    Toledo, Kfir
    Kannan, Pravein G.
    Malka, M.
    Lev-Ran, E.
    Barabash, K.
    Bortnikov, V
    [J]. PROCEEDINGS OF THE 16TH ACM INTERNATIONAL SYSTEMS AND STORAGE CONFERENCE, SYSTOR 2023, 2023, : 138 - 138
  • [4] Multi-cluster visualization and live reporting of Static Analysis Security Testing (SAST) warnings
    Pathak, Abhishek
    Sivakumar, Kaarthik
    Haque, Mazhar
    Ganesan, Prasanna
    [J]. 2019 IEEE SECURE DEVELOPMENT (SECDEV 2019), 2019, : 145 - 145
  • [5] Multi-cluster decay of atomic nuclei
    Kartavtsev, OI
    [J]. FEW-BODY SYSTEMS, 2004, 34 (1-3) : 39 - 44
  • [6] Fragment configurations in multi-cluster fission
    Poenaru, DN
    Greiner, W
    Hamilton, JH
    Ramayya, AV
    [J]. JOURNAL OF PHYSICS G-NUCLEAR AND PARTICLE PHYSICS, 2001, 27 (04) : L19 - L28
  • [7] Scheduling Workflows in Multi-Cluster Environments
    Stanzani, Silvio Luiz
    Sato, Liria Matsumoto
    Netto, Marco A. S.
    [J]. 2013 IEEE 27TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS (WAINA), 2013, : 560 - 565
  • [8] Workload characteristics of a multi-cluster supercomputer
    Li, H
    Groep, D
    Wolters, L
    [J]. JOB SCHEDULING STRATEGIES FOR PARALLEL PROCESSING, 2005, 3277 : 176 - 193
  • [9] Synchronization of multi-cluster complex networks
    Chen, Tianping
    [J]. NEURAL NETWORKS, 2022, 156 : 239 - 243
  • [10] Tuning application in a multi-cluster environment
    Argollo, Eduardo
    Gaudiani, Adriana
    Rexachs, Dolores
    Luque, Emilio
    [J]. EURO-PAR 2006 PARALLEL PROCESSING, 2006, 4128 : 78 - 88