Towards Automated Provisioning of Secure Virtualized Networks

被引:0
|
作者
Cabuk, Serdar [1 ]
Dalton, Chris I. [1 ]
Ramasamy, HariGovind [1 ]
Schunter, Matthias [1 ]
机构
[1] Hewlett Packard Labs, Bristol BS12 6QZ, Avon, England
关键词
Network security; network virtualization; automated security provisioning; security policies; trusted virtual domains;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We describe a secure network virtualization framework that helps realize the abstraction of Trusted Virtual Domains (TVDs), a security-enhanced variant of virtualized network zones. The framework allows groups of related virtual machines running on separate physical machines to be connected together as though there were on their own separate network fabric and, at the same time, helps enforce cross-group security requirements such as isolation, confidentiality; security; and information flow control. The framework uses existing network virtualization technologies, such as Ethernet encapsulation, VLAN tagging, and VPNs, and combines and orchestrates them appropriately to implement TVDs. Our framework aims at automating the instantiation and deployment of the appropriate security mechanism and network virtualization technologies based on an input security model that specifies the required level of isolation and permitted network flows. We have implemented a prototype of the framework based on the Xen hypervisor. Experimental evaluation of the prototype shows that the performance of our virtual networking extensions is comparable to that of the standard Xen configuration.
引用
收藏
页码:235 / +
页数:2
相关论文
共 50 条
  • [1] Towards Secure Multi-tenant Virtualized Networks
    Paladi, Nicolae
    Gehrmann, Christian
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 1180 - 1185
  • [2] Application-Aware Adaptive Provisioning in Virtualized Networks
    Esteves, Rafael Pereira
    Granville, Lisandro Zambenedetti
    [J]. PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 1107 - 1113
  • [3] A Framework for Ontology Provisioning in Virtualized Wireless Sensor Networks
    Jafrin, Rifat
    Khan, Imran
    Sahoo, Jagruti
    Glitho, Roch
    [J]. 2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 743 - 749
  • [4] Joint Resource Provisioning and Admission Control in Wireless Virtualized Networks
    Parsaeefard, Saeedeh
    Jumba, Vikas
    Derakhshani, Mahsa
    Le-Ngoc, Tho
    [J]. 2015 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2015, : 2020 - 2025
  • [5] Resource Allocation for Efficient Bandwidth Provisioning in Virtualized Wireless Networks
    Thinh Duy Tran
    Le, Long Bao
    [J]. 2017 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2017,
  • [6] Automated Dynamic Resource Provisioning and Monitoring in Virtualized Large-scale Datacenter
    Abar, Sameera
    Lemarinier, Pierre
    Theodoropoulos, Georgios K.
    O'Hare, Gregory M. P.
    [J]. 2014 IEEE 28TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2014, : 961 - 970
  • [7] Energy-Efficient Robust Resource Provisioning in Virtualized Wireless Networks
    Jumba, Vikas
    Parsaeefard, Saeedeh
    Derakhshani, Mahsa
    Tho Le-Ngoc
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON UBIQUITOUS WIRELESS BROADBAND (ICUWB), 2015,
  • [8] Dynamic Resource Provisioning with Stable Queue Control for Wireless Virtualized Networks
    Jumba, Vikas
    Parsaeefard, Saeedeh
    Derakhshami, Mahsa
    Tho Le-Ngoc
    [J]. 2015 IEEE 26TH ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR, AND MOBILE RADIO COMMUNICATIONS (PIMRC), 2015, : 1856 - 1860
  • [9] Resource Provisioning in Wireless Virtualized Networks via Massive-MIMO
    Jumba, Vikas
    Parsaeefard, Saeedeh
    Derakhshani, Mahsa
    Tho Le-Ngoc
    [J]. IEEE WIRELESS COMMUNICATIONS LETTERS, 2015, 4 (03) : 237 - 240
  • [10] MDP Modeling of Resource Provisioning in Virtualized Content-Delivery Networks
    Haghighi, Ali A.
    Heydari, Shahram Shah
    ShaltbazPanahi, Shahram
    [J]. 2017 IEEE 25TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2017,