A First Step Towards Security Extension for NFV Orchestrator

被引:16
|
作者
Pattaranantakul, Montida [1 ,2 ]
Tseng, Yuchia [3 ]
He, Ruan [4 ]
Zhang, Zonghua [1 ]
Meddahi, Ahmed [1 ]
机构
[1] Inst Mines Telecom TELECOM SudParis, Evry, France
[2] Inst Mines Telecom, IMT Lille Douai, Lille, France
[3] Paris Descartes Univ, Paris, France
[4] Orange Labs, Chatilion, France
关键词
Network Functions Virtualization (NFV); data model; service orchestration; security management; VIRTUALIZATION; CHALLENGES;
D O I
10.1145/3040992.3040995
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network Functions Virtualization (NFV) has recently emerged as one of the new networking paradigms to significantly change the way that the networks and services are deployed, managed, and operated. One of the major advantages of NFV is to reduce hardware cost, meanwhile increasing service agility and scalability. Recently, there are many platforms for NFV management and orchestration (MANO) are available, however few of them contains dedicated modules or components for security management. This paper is intended to study the feasibility of extending the current NFV orchestrator to have the capability of managing security mechanisms. To do that, we propose a security extension module based on TOSCA data model which is commonly used by NFV MANO architecture. We then develop an access control use case to illustrate the usage of our proposed security extension. Specifically, we integrate the security extension into the Moon framework, which can automatically verify security attributes, generate access control policies, and further enforce the policies through the underlying infrastructure according to the high-level security policies. The preliminary results show that our security extension can work together with the NFV orchestrator to enable finegrained access control to protect resources and services.
引用
收藏
页码:25 / 30
页数:6
相关论文
共 50 条
  • [1] Security Orchestrator Introducing a Security Orchestrator in the context of the ETSI NFV Reference Architecture
    Jaeger, Bernd
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 1255 - 1260
  • [2] Towards a Security Reference Architecture for NFV
    Alnaim, Abdulrahman Khalid
    Alwakeel, Ahmed Mahmoud
    Fernandez, Eduardo B.
    [J]. SENSORS, 2022, 22 (10)
  • [3] SENATUS: an experimental SDN/NFV Orchestrator
    Troia, Sebastian
    Rodriguez, Alberto
    Alvizu, Rodolfo
    Maier, Guido
    [J]. 2018 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2018,
  • [4] A First Step Towards Security for Internet of Small Things
    Kang, Namhi
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (06): : 13 - 21
  • [5] A First Step towards Security Policy Compliance of Connectors
    Sun Meng
    [J]. FUNDAMENTALS OF SOFTWARE ENGINEERING, 2010, 5961 : 447 - 454
  • [6] NFV Orchestrator Placement for Geo-Distributed Systems
    Abu-Lebdeh, Mohammad
    Naboulsi, Diala
    Glitho, Roch
    Tchouati, Constant Wette
    [J]. 2017 IEEE 16TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2017, : 447 - 451
  • [7] Dependability of the NFV Orchestrator: State of the Art and Research Challenges
    Gonzalez, Andres J.
    Nencioni, Gianfranco
    Kamisinski, Andrzej
    Helvik, Bjarne E.
    Heegaard, Poul E.
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (04): : 3307 - 3329
  • [8] A first Step towards a Protection Profile for the Security Evaluation of Consensus Mechanisms
    Hennebert, Christine
    [J]. 2020 7TH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS: SYSTEMS, MANAGEMENT AND SECURITY (IOTSMS), 2020,
  • [9] A first step towards formal verification of security policy properties for RBAC
    Drouineaud, M
    Bortin, M
    Torrini, P
    Sohr, K
    [J]. QSIC 2004: PROCEEDINGS OF THE FOURTH INTERNATIONAL CONFERENCE ON QUALITY SOFTWARE, 2004, : 60 - 67
  • [10] Orchestrator Model for System Security
    Goutam, Aradhana
    Rajkamal
    Ingle, Maya
    [J]. ADVANCES IN COMPUTING, COMMUNICATION AND CONTROL, 2011, 125 : 195 - +