Connectivity Graph Reconstruction for Networking Cloud Infrastructures

被引:0
|
作者
Mensah, Pernelle [1 ,2 ,3 ]
Dubus, Samuel [1 ]
Kanoun, Wael [1 ]
Morin, Christine [2 ]
Piolle, Guillaume [2 ,3 ]
Totel, Eric [2 ,3 ]
机构
[1] Nokia Bell Labs, Cybersecur Paris Saclay, Nozay, France
[2] INRIA, Rennes, France
[3] Cent Supelec, CIDRE, Cesson Sevigne, France
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud providers have an incomplete view of their hosted virtual infrastructures managed by a Cloud Management System (CMS) and a Software Defined Network (SDN) controller. For various security reasons (e.g. isolation verification, modeling attack paths in the network), it is necessary to know which virtual machines can interact via network protocols. This requires building a connectivity graph between the virtual machines, that we can extract with the knowledge of the overall topology and the deployed network security policy. Existing methodologies for building such models for physical networks produce incomplete results. Moreover, they are not suitable for cloud infrastructures due to either their intrusiveness or lack of connectivity discovery. We propose a method to compute the connectivity graph, relying on information provided by both the CMS and the SDN controller. Connectivity can first be extracted from knowledge databases, then dynamically updated on the occurrence of cloud-related events. This approach shows an exact, complete and up-to-date connectivity graphs computation on a representative infrastructure, in reasonable time.
引用
收藏
页码:81 / 89
页数:9
相关论文
共 50 条
  • [1] Connectivity Extraction in Cloud Infrastructures
    Mensah, Pernelle
    Dubus, Samuel
    Kanoun, Wael
    Morin, Christine
    Piolle, Guillaume
    Totel, Eric
    [J]. 2017 13TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2017,
  • [2] Towards the Realization of Converged Cloud, Edge and Networking Infrastructures in Smart MegaCities
    Kokkinos, Panagiotis
    [J]. 2022 27TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2022), 2022,
  • [3] On Resource Description Capabilities of On-Board Tools for Resource Management in Cloud Networking and NFV Infrastructures
    Tutschku, Kurt
    Mehri, Vida Ahmadi
    Carlsson, Anders
    Chivukula, Krishna Varaynya
    Christenson, Johan
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC), 2016, : 442 - 447
  • [4] Multi-site Connectivity for Edge Infrastructures DIMINET:DIstributed Module for Inter-site NETworking
    Sarmiento, David Espinel
    Lebre, Adrien
    Nussbaum, Lucas
    Chari, Abdelhadi
    [J]. 2020 20TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND INTERNET COMPUTING (CCGRID 2020), 2020, : 121 - 130
  • [5] Improvement of Incomplete Multiview Clustering by the Tensor Reconstruction of the Connectivity Graph
    Zhang, H.
    Chen, X.
    Zhu, Yu.
    Matveev, I. A.
    [J]. JOURNAL OF COMPUTER AND SYSTEMS SCIENCES INTERNATIONAL, 2023, 62 (03) : 469 - 491
  • [6] Improvement of Incomplete Multiview Clustering by the Tensor Reconstruction of the Connectivity Graph
    H. Zhang
    X. Chen
    Yu. Zhu
    I. A. Matveev
    [J]. Journal of Computer and Systems Sciences International, 2023, 62 : 469 - 491
  • [7] Private cloud infrastructures and cloud platforms
    Baun C.
    Kunze M.
    Kurze T.
    Mauch V.
    [J]. Informatik-Spektrum, 2011, 34 (3) : 242 - 254
  • [8] Graph-based analysis of cloud connectivity at the internet protocol level
    Dombrowski, Sebastian
    Ermakova, Tatiana
    Fabian, Benjamin
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2019, 23 (01) : 117 - 142
  • [9] Infrastructures for Online Social Networking Services
    Datta, Anwitaman
    Dikaiakos, Marios D.
    Haridi, Seif
    Iftode, Liviu
    [J]. IEEE INTERNET COMPUTING, 2012, 16 (03) : 10 - 12
  • [10] Quantum Advancements in Securing Networking Infrastructures
    Salloum, Hadi
    Alawir, Murhaf
    Alatasi, Mohammad Anas
    Asekrea, Saleem
    Mazzara, Manuel
    Bahrami, Mohammad Reza
    [J]. ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 6, AINA 2024, 2024, 204 : 354 - 363