A DATA DRIVEN ORCHESTRATION FRAMEWORK IN SOFTWARE DEFINED SECURITY

被引:0
|
作者
Wang, Weijia [1 ]
Qiu, Xiaofeng [1 ]
Sun, Li [1 ]
Zhao, Rui [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Beijing 100876, Peoples R China
关键词
Software-Defined Security; cyber threat information; Security Device Orchestration Framework; STIX; uniform interfaces; orchestration scenario;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Software-Defined Security (SDS), which provides a flexible and centralized security solution by abstracting the security mechanisms from the hardware layer into a software layer, attracts many researchers to study the detail of this conception. One of the key challenges of SDS is how to schedule and orchestrate security appliances according to huge and heterogeneous threat information, especially when they are still lack of standardized interfaces. In this paper, we present a data driven Security Device Orchestration Framework (SDOF) for SDS. In SDOF, we put forward uniform interfaces for security devices so that they could be orchestrated by software and their data could be collected and processed centrally. The complex Structured Threat information eXpression (STIX) ontology and corresponding tools are tailored for SDOF to standardize and centralize all data in SDS. These two achievements makes real-time dynamic orchestration possible in SDS. We also provide an orchestration scenario to demonstrate how SDOF works and evaluated its performance.
引用
收藏
页码:34 / 39
页数:6
相关论文
共 50 条
  • [1] Orchestration of Software-Defined Security Services
    Luo, Song
    Ben Salem, Malek
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC), 2016, : 436 - 441
  • [2] Software Defined IoT Security Framework
    Salman, Ola
    Elhajj, Imad
    Chehab, Ali
    Kayssi, Ayman
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 75 - 80
  • [3] SDSecurity: A Software Defined Security Experimental Framework
    Darabseh, Ala'
    Al-Ayyoub, Mahmoud
    Jararweh, Yaser
    Benkhelifa, Elhadj
    Vouk, Mladen
    Rindos, Andy
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATION WORKSHOP (ICCW), 2015, : 1871 - 1876
  • [4] A Novel Software Defined Security Framework for SDN
    Basu, Srijita
    Raun, Neha Firdaush
    Ghosal, Avishek
    Chatterjee, Debanjan
    Maitra, Debarghya
    Mazumdar, Chandan
    [J]. RISKS AND SECURITY OF INTERNET AND SYSTEMS, CRISIS 2023, 2023, 14529 : 216 - 230
  • [5] Cloud and Network Service Orchestration in Software Defined Data Centers
    Adami, Davide
    Martini, Barbara
    Callegari, Christian
    Donatini, Lisa
    Giordano, Stefano
    Sgambelluri, Andrea
    Gharbaoui, Molka
    Castoldi, Piero
    [J]. PROCEEDINGS OF THE 2015 INTERNATIONAL SYMPOSIUM ON PERFORMANCE EVALUATION OF COMPUTER AND TELECOMMUNICATION SYSTEMS (SPECTS), 2015,
  • [6] A Framework for Security Driven Software Evolution
    Guan, Hui
    Yang, Hongji
    Wang, Xuan
    [J]. PROCEEDINGS OF THE 2014 20TH INTERNATIONAL CONFERENCE ON AUTOMATION AND COMPUTING (ICAC'14), 2014, : 194 - +
  • [7] An Autonomous Service-Oriented Orchestration Framework for Software Defined Mobile Networks
    Xuan-Thuy Dang
    Khan, Manzoor Ahmed
    Sivrikaya, Fikret
    [J]. PROCEEDINGS OF THE 2019 22ND CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS (ICIN), 2019, : 277 - 284
  • [8] SDSA: A Framework of a Software-Defined Security Architecture
    Liu Yanbing
    Lu Xingyu
    Jian Yi
    Xiao Yunpeng
    [J]. CHINA COMMUNICATIONS, 2016, 13 (02) : 178 - 188
  • [9] Security Policy Transition Framework for Software Defined Networks
    Cox, Jacob H., Jr.
    Clark, Russell J.
    Owen, Henry L.
    [J]. 2016 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2016, : 56 - 61
  • [10] A Security Evaluation Framework for Software-Defined Network Architectures in Data Center Environments
    Ivkic, Igor
    Thiede, Dominik
    Race, Nicholas
    Broadbent, Matthew
    Gouglidis, Antonios
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2023, 2023, : 277 - 288