Management and enforcement of secured E2E network slices across transport domains

被引:5
|
作者
Alemany, Pol [1 ]
Molina, Alejandro [2 ]
Dangerville, Cyril [3 ]
Asensio, Rodrigo [2 ]
Ayed, Dhouha [3 ]
Munoz, Raul [1 ]
Casellas, Ramon [1 ]
Martinez, Ricardo [1 ]
Skarmeta, Antonio [2 ]
Vilalta, Ricard [1 ]
机构
[1] Ctr Tecnol Telecomunicac Catalunya CTTC CERCA, Carl Friedrich Gauss Av 7, Castelldefels 08860, Catalonia, Spain
[2] Univ Murcia, Comp Sci Fac, Campus Espinardo, Murcia 30100, Spain
[3] Thales, 1 Av Augustin Fresnel, F-91120 Palaiseau, Essonne, France
关键词
Network slicing; Security service level agreement; Network function virtualisation; Quality of service; PROTECTION;
D O I
10.1016/j.yofte.2022.103010
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Due to the fact that the current variability of services is brought by the current networks and the new possibilities that will appear thanks to the near-future networks, Network Slicing has become one of the key elements to allow the co-existence of multiple computing and transportservices with different requirements (i.e., performance, security, isolation) over the same infrastructure in multi-tenant and multi-domain (i.e., edge, transport, core) scenarios. The use of this and other technologies allow to have only one generic infrastructure (e.g., an optical transport domain) despite the services differences, instead of needing specific resources (e.g., on single optical fiber) for each type of service. Multiple works have been published about Network Slicing, Network Function Virtualization and Software Defined Networks using multiple computing and transport domains but, based on our literature research, there is one important aspect with a low amount of attention: the security management around network slices and their enforcement. It is essential to ensure that the expected Quality of Security (QoSec) is accomplished based on the correct deployment and posterior monitoring of the security metrics defined in the agreed Security Service Level Agreement (SSLA) between the service requester and the provider. This article aims to present an architecture designed to manage and control the life-cycle of secured End-to -End (E2E) network slices involving multiple domains based on the SSLA requirements. The security management architecture is described with its components together with the deployment and monitoring processes and the data objects used. Finally, an experimental validation is described using the use case of a DoS attack scenario and its resolution.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] 5G E2E Network Slicing Management with ONAP
    Rodriguez, Veronica Quintuna
    Guillemin, Fabrice
    Boubendir, Amina
    [J]. 2020 23RD CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS (ICIN 2020), 2020, : 87 - 94
  • [2] VPN over satellite: Performance improving of E2E secured TCP flows
    Parichehreh, A.
    Eliasi, B.
    [J]. 2008 IFIP INTERNATIONAL CONFERENCE ON WIRELESS AND OPTICAL COMMUNICATIONS NETWORKS, 2008, : 21 - 24
  • [3] Intent-Based E2E Network Slice Management for Industry 4.0
    Chirivella-Perez, Enrique
    Salva-Garcia, Pablo
    Ricart-Sanchez, Ruben
    Calero, Jose Alcaraz
    Wang, Qi
    [J]. 2021 JOINT EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS & 6G SUMMIT (EUCNC/6G SUMMIT), 2021, : 353 - 358
  • [4] Dynamic Resource Allocation for E2E Network Slicing with Both Public and Non-Public Slices
    Wang, Yuxing
    Liu, Nan
    Pan, Zhiwen
    You, Xiaohu
    [J]. 2024 5TH INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKS AND INTERNET OF THINGS, CNIOT 2024, 2024, : 166 - 174
  • [5] E2E Traffic Engineering Routing for Transport SDN
    Iovanna, Paola
    Ubaldi, Fabio
    Di Michele, Francesco
    Fernandez-Palacios Gimenez, Juan Pedro
    Lopez, Victor
    [J]. 2014 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION (OFC), 2014,
  • [6] E2E Transport API demonstration in hierarchical scenarios
    Lopez, V.
    Maor, I.
    Sethuraman, K.
    Mayoral, A.
    Ong, L.
    Szwedowski, R.
    Marques, F.
    Sharma, A.
    Bosisio, F.
    de Dios, O. Gonzalez
    Gerstel, O.
    Druesedau, F.
    Vilalta, R.
    Silva, H.
    Autenrieth, A.
    Borges, N.
    Liou, C.
    Cazzaniga, G.
    Fernandez-Palacios, J. P.
    [J]. 2017 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION (OFC), 2017,
  • [7] AI-Based Resource Allocation in E2E Network Slicing with Both Public and Non-Public Slices
    Wang, Yuxing
    Liu, Nan
    Pan, Zhiwen
    You, Xiaohu
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (22):
  • [8] Generic Intent -based Networking Platform for E2E Network Slice Orchestration & Lifecycle Management
    Khan, Talha Ahmed
    Abbass, Khizar
    Rafique, Adeel
    Muhammad, Afaq
    Song, Wang-Cheol
    [J]. APNOMS 2020: 2020 21ST ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2020, : 49 - 54
  • [9] Measurement System Architecture for Measuring Network Parameters of e2e Services
    Kulik, Vyacheslav
    Kirichek, Ruslan
    Borodin, Alexey
    Koucheryavy, Andrey
    [J]. DISTRIBUTED COMPUTER AND COMMUNICATION NETWORKS (DCCN 2017), 2017, 700 : 291 - 306
  • [10] Deep Neural Network Calibration for E2E Speech Recognition System
    Lee, Mun-Hak
    Chang, Joon-Hyuk
    [J]. INTERSPEECH 2021, 2021, : 4064 - 4068