Security automation for multi-cluster orchestration in Kubernetes

被引:2
|
作者
Bringhenti, Daniele [1 ]
Sisto, Riccardo [1 ]
Valenza, Fulvio [1 ]
机构
[1] Politecn Torino, Dip Automat & Informat, Turin, Italy
关键词
security automation; cloud orchestration; Kubernetes;
D O I
10.1109/NetSoft57336.2023.10175419
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the latest years, multi-domain Kubernetes architectures composed of multiple clusters have been getting more frequent, so as to provide higher workload isolation, resource availability flexibility and scalability for application deployment. However, manually configuring their security may lead to inconsistencies among policies defined in different clusters, or it may require knowledge that the administrator of each domain cannot have. Therefore, this paper proposes an automatic approach for the automatic generation of the network security policies to be deployed in each cluster of a multi-domain Kubernetes deployment. The objectives of this approach are to reduce of configuration errors that human administrators commonly make, and to create transparent cross-cluster communications. This approach has been implemented as a framework named Multi-Cluster Orchestrator, which has been validated in realistic use cases to assess its benefits to Kubernetes orchestration.
引用
收藏
页码:480 / 485
页数:6
相关论文
共 50 条
  • [41] Cooperative learning model of agents in multi-cluster grid
    Chen, Qingkui
    [J]. PROCEEDINGS OF THE 2007 11TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN, VOLS 1 AND 2, 2007, : 418 - 423
  • [42] Design and implementation of an efficient multi-cluster GridRPC system
    Ho, QT
    Cai, WT
    Ong, YS
    [J]. 2005 IEEE INTERNATIONAL SYMPOSIUM ON CLUSTER COMPUTING AND THE GRID, VOLS 1 AND 2, 2005, : 358 - 365
  • [43] A Multi-Vocal Review of Security Orchestration
    Islam, Chadni
    Babar, Muhammad Ali
    Nepal, Surya
    [J]. ACM COMPUTING SURVEYS, 2019, 52 (02)
  • [44] Container orchestration on HPC systems through Kubernetes
    Zhou, Naweiluo
    Georgiou, Yiannis
    Pospieszny, Marcin
    Zhong, Li
    Zhou, Huan
    Niethammer, Christoph
    Pejak, Branislav
    Marko, Oskar
    Hoppe, Dennis
    [J]. JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2021, 10 (01):
  • [45] A high-throughput Multi-Cluster NoC architecture
    Freitas, Henrique C.
    Navaux, Philippe O. A.
    [J]. CSE 2008:11TH IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING, PROCEEDINGS, 2008, : 56 - 63
  • [46] Multi-cluster dynamics in coupled phase oscillator networks
    Ismail, Asma
    Ashwin, Peter
    [J]. DYNAMICAL SYSTEMS-AN INTERNATIONAL JOURNAL, 2015, 30 (01): : 122 - 135
  • [47] A distributed hierarchical algorithm for multi-cluster constrained optimization
    Guo, Fanghong
    Wen, Changyun
    Mao, Jianfeng
    Li, Guoqi
    Song, Yong-Duan
    [J]. AUTOMATICA, 2017, 77 : 230 - 238
  • [48] Interference Utilization Precoding in Multi-Cluster IoT Networks
    Wang, Yuanchen
    Lim, Eng Gee
    Xue, Xiaoping
    Zhu, Guangyu
    Pei, Rui
    Wei, Zhongxiang
    [J]. FRONTIERS IN SIGNAL PROCESSING, 2021, 1
  • [49] Novel Architecture of Security Orchestration, Automation and Response in Internet of Blended Environment
    Lee, Minkyung
    Jang-Jaccard, Julian
    Kwak, Jin
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 73 (01): : 199 - 223
  • [50] Efficient multi-cluster feature selection on text data
    Gupta, Ananya
    Begum, Shahin Ara
    [J]. JOURNAL OF INFORMATION & OPTIMIZATION SCIENCES, 2019, 40 (08): : 1583 - 1598