NFV-based network protection: the SHIELD approach

被引:0
|
作者
Lioy, A. [1 ]
Gardikis, G. [2 ]
Gaston, B. [3 ]
Jacquin, L. [4 ]
De Benedictis, M. [1 ]
Angelopoulos, Y. [5 ]
Xylouris, C. [6 ]
机构
[1] Politecn Torino, Turin, Italy
[2] Space Hellas, Athens, Greece
[3] Fundacio I2CAT, Barcelona, Spain
[4] Hewlett Packard Labs, Bristol, Avon, England
[5] Natl Ctr Sci Res Demokritos, Athens, Greece
[6] Orion Innovat PC, Athens, Greece
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
This demo showcases some of the capabilities foreseen for the security infrastructure designed by the H2020 SHIELD project. SHIELD exploits NFV for adaptive monitoring of an IT infrastructure and for feeding the data to an analytics engine to detect attacks in real time. An intelligent reaction system is then activated to reconfigure the SDN/NFV infrastructure so that the attacks are thwarted. The SDN/NFV infrastructure itself is protected from attacks thanks to trusted computing techniques, that permit to quickly identify misbehaving nodes. The proposed demo will present detection and reaction to a DDoS attack (by on-the-fly deployment of new virtual network security functions and/or change of network paths), as well as detection of software attacks against virtual network functions (executed in Docker containers) and unauthorized modification of the SDN switching tables and NFV configurations.
引用
收藏
页码:200 / 201
页数:2
相关论文
共 50 条
  • [1] SHIELD: A Novel NFV-based Cybersecurity Framework
    Gardikis, G.
    Tzoulas, K.
    Tripolitis, K.
    Bartzas, A.
    Costicoglou, S.
    Gaston, B.
    Fernandez, C.
    Davila, C.
    Jacquin, L.
    Attak, H.
    Katsianis, D.
    Neokosmidis, I.
    Batista, T.
    Preto, R.
    Lioy, Antonio
    Litke, A.
    Papadakis, N.
    Papadopoulos, D.
    Pastor, A.
    Nunez, J.
    Davri, N.
    Xylouris, G.
    Kafetzakis, M.
    Terranova, M.
    Giustozzi, C.
    Trouva, E.
    Angelopoulos, Y.
    Kourtis, A.
    [J]. 2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [2] Implementation and Evaluation of IPSec in an NFV-Based Network
    Nhu Q Tran
    Khanh D L Nguyen
    Chan D T Thai
    [J]. COMMUNICATION AND INTELLIGENT SYSTEMS, VOL 1, ICCIS 2023, 2024, 967 : 53 - 65
  • [3] Minimizing Transmission and Processing Delay in a NFV-based Network
    Chen, Yang
    Wu, Jie
    [J]. 2019 IEEE 20TH INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM), 2019,
  • [4] LTE Edge Network Enhancement with NFV-based Core Functionalities
    Giannoulakis, Ioannis
    Kafetzakis, Emmanouil
    Kourtis, Michail Alexandros
    Xylouris, George
    Kourtis, Anastasios
    Makris, Dimitrios
    [J]. 2017 IEEE 22ND INTERNATIONAL WORKSHOP ON COMPUTER AIDED MODELING AND DESIGN OF COMMUNICATION LINKS AND NETWORKS (CAMAD), 2017,
  • [5] Flow Scheduling of Service Chain Processing in a NFV-Based Network
    Chen, Yang
    Wu, Jie
    [J]. IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2021, 8 (01): : 389 - 399
  • [6] SDN/NFV-based Network Infrastructure for Enhancing IoT Gateways
    Sinh, Do
    Luong-Vy Le
    Lin, Bao-Shuh Paul
    Tung, Li-Ping
    [J]. 2019 INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2019, : 1135 - 1142
  • [7] Providing Flexible Services for Heterogeneous Vehicles: An NFV-Based Approach
    Zhu, Ming
    Cao, Jiannong
    Cai, Zhiping
    He, Zongjian
    Xu, Ming
    [J]. IEEE NETWORK, 2016, 30 (03): : 64 - 71
  • [8] Providing flexible services for heterogeneous vehicles: An NFV-based approach
    [J]. 2016, Institute of Electrical and Electronics Engineers Inc., United States (30):
  • [9] A Quantitative Approach for Refactoring NFV-based Mobile Core Networks
    Chiang, Wei-Kuo
    Chen, He-Xin
    [J]. 2019 IEEE 30TH INTERNATIONAL CONFERENCE ON APPLICATION-SPECIFIC SYSTEMS, ARCHITECTURES AND PROCESSORS (ASAP 2019), 2019, : 135 - 135
  • [10] Poster: A SDN/NFV-Based IoT Network Slicing Creation System
    Wang, Meng
    Cheng, Bo
    Liu, Xuan
    Yue, Yi
    Li, Biyi
    Chen, Junliang
    [J]. MOBICOM'18: PROCEEDINGS OF THE 24TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING, 2018, : 666 - 668