Tualatin: Towards Network Security Service Provision in Cloud Datacenters

被引:0
|
作者
Wang, Xiang [1 ,2 ]
Liu, Zhi [1 ,2 ]
Li, Jun [2 ,3 ]
Yang, Baohua [4 ]
Qi, Yaxuan [5 ]
机构
[1] Tsinghua Univ, Dept Automat, Beijing 100084, Peoples R China
[2] Tsinghua Univ, Res Inst Informat Technol, Beijing 100084, Peoples R China
[3] Tsinghua Natl Lab Informat Sci & Technol, Beijing, Peoples R China
[4] IBM China Res Lab, Beijing, Peoples R China
[5] Yunshan Networks Inc, Beijing, Peoples R China
关键词
Software-Defined Networking; Cloud Datacenter; Network Security;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Multi-tenant infrastructures deployed in cloud datacenters need network security protection. However, the rigid control mechanism of current security middleboxes induces inflexible orchestration, limiting the agile and on-demand security provision in virtualized datacenters. This paper presents Tualatin, a consolidated framework of delivering security services in multi-tenant datacenters. It meets security requirements of different scenarios by hardware and software co-design. Leveraging Software-Defined Networking (SDN) and OpenFlow techniques, Tualatin provides fine-grained security protection in dynamically changing network topologies, where both switches and security middleboxes are programmatically controlled by logically centralized controllers. With service-level APIs exposed, Tualatin could be easily integrated with other Cloud Management System (CMS). A proof-of-concept system has been deployed in a Tier-IV datacenter, providing customizable network security services for tenant Virtual Private Cloud (VPC) infrastructure.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Cloud–SPHERE: Towards Secure UAV Service Provision
    Mariana Rodrigues
    Kalinka Regina Lucas Jaquie Castelo Branco
    [J]. Journal of Intelligent & Robotic Systems, 2020, 97 : 249 - 268
  • [2] Customized Network Security for Cloud Service
    He, Jin
    Ota, Kaoru
    Dong, Mianxiong
    Yang, Laurence T.
    Fan, Mingyu
    Wang, Guangwei
    Yau, Stephen S.
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2020, 13 (05) : 801 - 814
  • [3] Cloud-SPHERE: Towards Secure UAV Service Provision
    Rodrigues, Mariana
    Branco, Kalinka Regina Lucas Jaquie Castelo
    [J]. JOURNAL OF INTELLIGENT & ROBOTIC SYSTEMS, 2020, 97 (01) : 249 - 268
  • [4] Towards Network-topology aware Virtual Machine Placement in Cloud Datacenters
    Yuchi, Xuebiao
    Shetty, Sachin
    [J]. Proceedings 2016 IEEE World Congress on Services - SERVICES 2016, 2016, : 95 - 96
  • [5] Towards performance evaluation of cloud service providers for cloud data security
    Ramachandran, Muthu
    Chang, Victor
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2016, 36 (04) : 618 - 625
  • [6] Towards quantification and evaluation of security of Cloud Service Providers
    Halabi, Talal
    Bellaiche, Martine
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 33 : 55 - 65
  • [7] Towards Security as a Service (SecaaS): on the modeling of Security Services for Cloud Computing
    Furfaro, Angelo
    Garro, Alfredo
    Tundis, Andrea
    [J]. 2014 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2014,
  • [8] Towards Automatic Comparison of Cloud Service Security Certifications
    Labaj, Martin
    Rastocny, Karol
    Chuda, Daniela
    [J]. THEORY AND PRACTICE OF COMPUTER SCIENCE, SOFSEM 2019, 2019, 11376 : 298 - 309
  • [9] Towards a Service Broker for Telecom Service Provision and Negociation in IMS Network
    Haddar, Imane
    Raouyane, Brahim
    Bellafkih, Mostafa
    [J]. ADVANCES IN UBIQUITOUS NETWORKING 2, 2017, 397 : 273 - 283
  • [10] Towards seamless service migration in network re-optimization for optically interconnected datacenters
    Takita, Yutaka
    Hashiguchi, Tomohiro
    Tajima, Kazuyuki
    Katagiri, Toru
    Naito, Takao
    Zhang, Qiong
    Wang, Xi
    Kim, Inwoong
    Palacharla, Paparao
    Sekiya, Motoyoshi
    [J]. OPTICAL SWITCHING AND NETWORKING, 2017, 23 : 241 - 249