SDSA: A Framework of a Software-Defined Security Architecture

被引:0
|
作者
Liu Yanbing [1 ]
Lu Xingyu [1 ]
Jian Yi [1 ]
Xiao Yunpeng [1 ]
机构
[1] Chongqing Univ Posts & Telecommun, Chongqing Engn Lab Network & Informat Secur, Chongqing 400065, Peoples R China
基金
美国国家科学基金会;
关键词
information security; network security; security architecture; software-defined security; WIRELESS; VIRTUALIZATION; PROTOCOL;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The fact that the security facilities within a system are closely coupled and the security facilities between systems are unconnected results in an isolated protection structure for systems, and gives rise to a serious challenge to system security integrations and system controls. Also, the need for diversified services and flexible extensions of network security asks for more considerations and contributions from the perspective of software engineering in the process of designing and constructing security systems. Based on the essence of the virtualization technique and the idea of software-defined networks, we in this paper propose a novel software-defined security architecture for systems. By abstracting the traditional security facilities and techniques, the proposed security architecture provides a new, simple, effective, and programmable framework in which security operations and security controls can be decoupled, and thereby reduces the software module sizes, decreases the intensity of software developments, and improves the security extensibility of systems.
引用
收藏
页码:178 / 188
页数:11
相关论文
共 50 条
  • [21] IOFlow: A Software-Defined Storage Architecture
    Thereska, Eno
    Ballani, Hitesh
    O'Shea, Greg
    Karagiannis, Thomas
    Rowstron, Antony
    Talpey, Tom
    Black, Richard
    Zhu, Timothy
    [J]. SOSP'13: PROCEEDINGS OF THE TWENTY-FOURTH ACM SYMPOSIUM ON OPERATING SYSTEMS PRINCIPLES, 2013, : 182 - 196
  • [22] Software-Defined QoE Measurement Architecture
    Chu, Yu-Huang
    Lin, Wei-Ting
    Hsieh, Ching-Tzu
    Cheng, Kai-Mao
    Wang, Yao-Chun
    Yang, Ya-Lun
    [J]. 2014 16TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2014,
  • [23] EXPERIENCE WITH A SOFTWARE-DEFINED MACHINE ARCHITECTURE
    WALL, DW
    [J]. ACM TRANSACTIONS ON PROGRAMMING LANGUAGES AND SYSTEMS, 1992, 14 (03): : 299 - 338
  • [24] Software-Defined Networking: An Evolving Network Architecture-Programmability and Security Perspective
    Kaliyamurthy, Nitheesh Murugan
    Taterh, Swapnesh
    Shanmugasundaram, Suresh
    Saxena, Ankit
    Cheikhrouhou, Omar
    Ben Elhadj, Hadda
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [25] Security Analysis as Software-defined Security for SDN Environment
    El Moussaid, Nadya
    Toumanari, Ahmed
    El Azhari, Maryam
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 87 - 92
  • [26] SAFE: Software-defined Authentication FramEwork
    Kamath, Aditya V.
    Sudarshan, S.
    Kataoka, Kotaro
    Vijayvergiya, Nishant
    Reddy, G. Bhargav
    Phatale, Samrat
    [J]. ASIAN INTERNET ENGINEERING CONFERENCE (AINTEC 2016), 2016, : 57 - 63
  • [27] An LSTM Framework for Software-Defined Measurement
    Lazaris, Aggelos
    Prasanna, Viktor K.
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (01): : 855 - 869
  • [28] Verification Framework for Software-Defined Networking
    Kang, Miyoung
    Cho, Jong Jin
    [J]. 2022 24TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ARITIFLCIAL INTELLIGENCE TECHNOLOGIES TOWARD CYBERSECURITY, 2022, : 518 - 523
  • [29] A Security Evaluation Framework for Software-Defined Network Architectures in Data Center Environments
    Ivkic, Igor
    Thiede, Dominik
    Race, Nicholas
    Broadbent, Matthew
    Gouglidis, Antonios
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2023, 2023, : 277 - 288
  • [30] On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter
    Sallam, Ahmed
    Refaey, Ahmed
    Shami, Abdallah
    [J]. IEEE ACCESS, 2019, 7 : 146577 - 146587