A DATA DRIVEN ORCHESTRATION FRAMEWORK IN SOFTWARE DEFINED SECURITY

被引:0
|
作者
Wang, Weijia [1 ]
Qiu, Xiaofeng [1 ]
Sun, Li [1 ]
Zhao, Rui [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Beijing 100876, Peoples R China
关键词
Software-Defined Security; cyber threat information; Security Device Orchestration Framework; STIX; uniform interfaces; orchestration scenario;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Software-Defined Security (SDS), which provides a flexible and centralized security solution by abstracting the security mechanisms from the hardware layer into a software layer, attracts many researchers to study the detail of this conception. One of the key challenges of SDS is how to schedule and orchestrate security appliances according to huge and heterogeneous threat information, especially when they are still lack of standardized interfaces. In this paper, we present a data driven Security Device Orchestration Framework (SDOF) for SDS. In SDOF, we put forward uniform interfaces for security devices so that they could be orchestrated by software and their data could be collected and processed centrally. The complex Structured Threat information eXpression (STIX) ontology and corresponding tools are tailored for SDOF to standardize and centralize all data in SDS. These two achievements makes real-time dynamic orchestration possible in SDS. We also provide an orchestration scenario to demonstrate how SDOF works and evaluated its performance.
引用
收藏
页码:34 / 39
页数:6
相关论文
共 50 条
  • [21] Intelligent Requests Orchestration for Microservice Management Based on Blockchain in Software Defined Networking: a Security Guarantee
    Zhang, Yasheng
    Li, Chengcheng
    Chen, Ning
    Zhang, Peiying
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2022, : 254 - 259
  • [22] Model driven security framework for software design and verification
    Deveci, Engin
    Caglayan, Mehmet U.
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (16) : 2768 - 2792
  • [23] QoS-Aware Orchestration of Network Intensive Software Utilities within Software Defined Data Centres
    Pascinski, Uros
    Trnkoczy, Jernej
    Stankovski, Vlado
    Cigale, Matej
    Gec, Sandi
    [J]. JOURNAL OF GRID COMPUTING, 2018, 16 (01) : 85 - 112
  • [24] ScienceSDS: A Novel Software Defined Security Framework for Large-scale Data-intensive Science
    Anantha, Deepak Nadig
    Ramamurthy, Byrav
    [J]. SDN-NFVSEC'17: PROCEEDINGS OF THE ACM INTERNATIONAL WORKSHOP ON SECURITY IN SOFTWARE DEFINED NETWORKS & NETWORK FUNCTION VIRTUALIZATION, 2017, : 13 - 18
  • [25] A Security-Constrained Reinforcement Learning Framework for Software Defined Networks
    Mudgerikar, Anand
    Bertino, Elisa
    Lobo, Jorge
    Verma, Dinesh
    [J]. IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2021), 2021,
  • [26] VARMAN: Multi-plane security framework for software defined networks
    Krishnan, Prabhakar
    Duttagupta, Subhasri
    Achuthan, Krishnashree
    [J]. COMPUTER COMMUNICATIONS, 2019, 148 : 215 - 239
  • [27] MLSNet: A Policy Complying Multilevel Security Framework for Software Defined Networking
    Achleitner, Stefan
    Burke, Quinn
    McDaniel, Patrick
    Jaeger, Trent
    La Porta, Thomas
    Krishnamurthy, Srikanth
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (01): : 729 - 744
  • [28] A security and trust framework for virtualized networks and software-defined networking
    Yan, Zheng
    Zhang, Peng
    Vasilakos, Athanasios V.
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (16) : 3059 - 3069
  • [29] A Collaborative Security Framework for Software-Defined Wireless Sensor Networks
    Miranda, Christian
    Kaddoum, Georges
    Bou-Harb, Elias
    Garg, Sahil
    Kaur, Kuljeet
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 2602 - 2615
  • [30] A Software Defined Network-Based Security Assessment Framework for CloudIoT
    Han, Zhuobing
    Li, Xiaohong
    Huang, Keman
    Feng, Zhiyong
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2018, 5 (03): : 1424 - 1434