A Policy-based Interaction Protocol between Software Defined Security Controller and Virtual Security Functions

被引:0
|
作者
Farahmandian, Sara [1 ]
Hoang, Doan B. [1 ]
机构
[1] Univ Technol Sydney, Dept Elect & Data Engn, Sydney, NSW, Australia
关键词
Cloud security; SDN; NFV; software defined security service; security protocol; virtual security function;
D O I
10.1109/csnet50428.2020.9265460
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud, Software-Defined Networking (SDN), and Network Function Virtualization (NFV) technologies have introduced a new era of cybersecurity threats and challenges. To protect cloud infrastructure, in our earlier work, we proposed Software Defined Security Service (SDS2) to tackle security challenges centered around a new policy-based interaction model. The security architecture consists of three main components: a Security Controller, Virtual Security Functions (VSF), and a Sec-Manage Protocol. However, the security architecture requires an agile and specific protocol to transfer interaction parameters and security messages between its components where OpenFlow considers mainly as network routing protocol. So, The Sec-Manage protocol has been designed specifically for obtaining policy-based interaction parameters among cloud entities between the security controller and its VSFs. This paper focuses on the design and the implementation of the Sec-Manage protocol and demonstrates its use in setting, monitoring, and conveying relevant policy-based interaction security parameters.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] A Policy-Based Security Architecture for Software-Defined Networks
    Varadharajan, Vijay
    Karmakar, Kallol
    Tupakula, Uday
    Hitchens, Michael
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (04) : 897 - 912
  • [2] OpenSec: Policy-Based Security Using Software-Defined Networking
    Lara, Adrian
    Ramamurthy, Byrav
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2016, 13 (01): : 30 - 42
  • [3] Analysis of Policy-Based Security Management System in Software-Defined Networks
    Sood, Keshav
    Karmakar, Kallol Krishna
    Varadharajan, Vijay
    Tupakula, Uday
    Yu, Shui
    [J]. IEEE COMMUNICATIONS LETTERS, 2019, 23 (04) : 612 - 615
  • [4] A Security Controller-based Software Defined Security Architecture
    Qiu, Xiaofeng
    Cheng, Fangyuan
    Wang, Weijia
    Zhang, Gang
    Qiu, Yangjun
    [J]. PROCEEDINGS OF THE 2017 20TH CONFERENCE ON INNOVATIONS IN CLOUDS, INTERNET AND NETWORKS (ICIN), 2017, : 191 - 195
  • [5] Virtual Security Functions and Their Placement in Software Defined Networks: A Survey
    Demirci, Sedef
    Demirci, Mehmet
    Sagiroglu, Seref
    [J]. GAZI UNIVERSITY JOURNAL OF SCIENCE, 2019, 32 (03): : 833 - 851
  • [6] An Experimental Software Defined Security Controller for Software Defined Network
    Al-Zewairi, Malek
    Suleiman, Dima
    Almajali, Sufyan
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 32 - 36
  • [7] Security checker architecture for policy-based security management
    Tishkov, A
    Kotenko, I
    Sidelnikova, E
    [J]. COMPUTER NETWORK SECURITY, PROCEEDINGS, 2005, 3685 : 460 - 465
  • [8] Network security project management: A security policy-based approach
    Krichene, Jihene
    Boudriga, Noureddine
    [J]. 2007 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS, VOLS 1-8, 2007, : 784 - 789
  • [9] An Expectation-Based Approach to Policy-Based Security of the Border Gateway Protocol
    Li, Jun
    Stein, Josh
    Zhang, Mingwei
    Maennel, Olaf
    [J]. 2016 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2016,
  • [10] A Software-Defined Networking Security Controller Architecture
    Shang, Fengjun
    Fu, Qiang
    [J]. PROCEEDINGS OF THE 2016 4TH INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND COMPUTING TECHNOLOGY, 2016, 60 : 229 - 234