SDSA: A Framework of a Software-Defined Security Architecture

被引:0
|
作者
Liu Yanbing [1 ]
Lu Xingyu [1 ]
Jian Yi [1 ]
Xiao Yunpeng [1 ]
机构
[1] Chongqing Univ Posts & Telecommun, Chongqing Engn Lab Network & Informat Secur, Chongqing 400065, Peoples R China
基金
美国国家科学基金会;
关键词
information security; network security; security architecture; software-defined security; WIRELESS; VIRTUALIZATION; PROTOCOL;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The fact that the security facilities within a system are closely coupled and the security facilities between systems are unconnected results in an isolated protection structure for systems, and gives rise to a serious challenge to system security integrations and system controls. Also, the need for diversified services and flexible extensions of network security asks for more considerations and contributions from the perspective of software engineering in the process of designing and constructing security systems. Based on the essence of the virtualization technique and the idea of software-defined networks, we in this paper propose a novel software-defined security architecture for systems. By abstracting the traditional security facilities and techniques, the proposed security architecture provides a new, simple, effective, and programmable framework in which security operations and security controls can be decoupled, and thereby reduces the software module sizes, decreases the intensity of software developments, and improves the security extensibility of systems.
引用
收藏
页码:178 / 188
页数:11
相关论文
共 50 条
  • [1] SDSA: A Framework of a Software-Defi ned Security Architecture
    LIU Yanbing
    LU Xingyu
    JIAN Yi
    XIAO Yunpeng
    [J]. China Communications, 2016, (02) : 178 - 188
  • [2] SDSA: A Framework of a Software-Defi ned Security Architecture
    LIU Yanbing
    LU Xingyu
    JIAN Yi
    XIAO Yunpeng
    [J]. 中国通信., 2016, 13 (02) - 188
  • [3] A Software-Defined Networking Security Controller Architecture
    Shang, Fengjun
    Fu, Qiang
    [J]. PROCEEDINGS OF THE 2016 4TH INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND COMPUTING TECHNOLOGY, 2016, 60 : 229 - 234
  • [4] A comprehensive security assessment framework for software-defined networks
    Lee, Seungsoo
    Kim, Jinwoo
    Woo, Seungwon
    Yoon, Changhoon
    Scott-Hayward, Sandra
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    [J]. COMPUTERS & SECURITY, 2020, 91
  • [5] DELTA: A Security Assessment Framework for Software-Defined Networks
    Lee, Seungsoo
    Yoon, Changhoon
    Lee, Chanhee
    Shin, Seungwon
    Yegneswaran, Vinod
    Porras, Phillip
    [J]. 24TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2017), 2017,
  • [6] A Framework for Security Services based on Software-Defined Networking
    Jeong, Jaehoon
    Seo, Jihyeok
    Cho, Geumhwan
    Kim, Hyoungshick
    Park, Jung-Soo
    [J]. 2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 150 - 153
  • [7] SODA: A software-defined security framework for IoT environments
    Kim, Yeonkeun
    Nam, Jaehyun
    Park, Taejune
    Scott-Hayward, Sandra
    Shin, Seungwon
    [J]. COMPUTER NETWORKS, 2019, 163
  • [8] A Security-aware Software-defined IoT Network Architecture
    Zuo, Xinbin
    Pang, Xue
    Zhang, Pengping
    Zhang, Junsan
    Dong, Tao
    Zhang, Peiying
    [J]. 2020 IEEE COMPUTING, COMMUNICATIONS AND IOT APPLICATIONS (COMCOMAP), 2021,
  • [9] Design and Implementation of a Security Control Architecture for Software-Defined Networking
    Liu, Tie-jun
    Lin, Zhao-wen
    Xu, Jie
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND COMMUNICATION TECHNOLOGY (CNCT 2016), 2016, 54 : 779 - 785
  • [10] A Policy-Based Security Architecture for Software-Defined Networks
    Varadharajan, Vijay
    Karmakar, Kallol
    Tupakula, Uday
    Hitchens, Michael
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (04) : 897 - 912