Interface to Network Security Functions for Cloud-Based Security Services

被引:30
|
作者
Hyun, Sangwon [1 ]
Kim, Jinyong [2 ]
Kim, Hyoungshick [1 ]
Jeong, Jaehoon [3 ]
Hares, Susan [4 ]
Dunbar, Linda [4 ]
Farrel, Adrian [5 ]
机构
[1] Sungkyunkwan Univ, Seoul, South Korea
[2] Sungkyunkwan Univ, Dept Comp Sci & Engn, Seoul, South Korea
[3] Sungkyunkwan Univ, Dept Software, Seoul, South Korea
[4] Huawei, Shenzhen, Peoples R China
[5] Juniper Networks, Sunnyvale, CA USA
关键词
D O I
10.1109/MCOM.2018.1700662
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Network functions virtualization and cloudbased security services will become increasingly common in enterprise network systems to reduce the system operation costs and take advantage of the diverse network security functions (NSFs) developed by multiple vendors. In such a network environment, standardizing the interfaces to the NSFs of different vendors is essential to simplify the management of these heterogeneous NSFs. In addition, software-defined networking can be imposed to optimize the security service process in such cloud-based service environments by enforcing some types of packet filtering rules at the SDN switches, instead of NSFs possibly placed in remote clouds. The Interface to Network Security Functions (I2NSF) Working Group, which is part of the Internet Engineering Task Force, is currently developing a set of standard interfaces to such heterogeneous NSFs. In this article, we present the design and development of an I2NSF architecture and propose improving its efficiency by integrating it with SDN. In our work, we implement the SDN-integrated I2NSF architecture and its security applications. This article also discusses several standardization and research challenges for I2NSF.
引用
收藏
页码:171 / 178
页数:8
相关论文
共 50 条
  • [1] CBSS: Cloud-Based Security System with Interface to Network Security Functions
    Jeong, Jaehoon
    Lingga, Patrick
    2023 FOURTEENTH INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND UBIQUITOUS NETWORK, ICMU, 2023,
  • [2] SPT: Security Policy Translator for Network Security Functions in Cloud-Based Security Services
    Lingga, Patrick
    Jeong, Jaehoon
    Yang, Jinhyuk
    Kim, Jeonghyeon
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (06) : 5156 - 5169
  • [3] SDN-based Security Services using Interface to Network Security Functions
    Kim, Jinyong
    Firoozjaei, Mahdi Daghmehchi
    Jeong, Jaehoon
    Kim, Hyoungshick
    Park, Jung-Soo
    2015 INTERNATIONAL CONFERENCE ON ICT CONVERGENCE (ICTC), 2015, : 526 - 529
  • [4] A Robust Security Framework for Cloud-based Logistics Services
    Srinivasan, Kathiravan
    Gupta, Takshi
    Agarwal, Punjal
    Nema, Anant
    PROCEEDINGS OF 4TH IEEE INTERNATIONAL CONFERENCE ON APPLIED SYSTEM INNOVATION 2018 ( IEEE ICASI 2018 ), 2018, : 162 - 165
  • [5] Toward the SIEM Architecture for Cloud-based Security Services
    Lee, Jong-Hoon
    Kim, Young Soo
    Kim, Jong Hyun
    Kim, Ik Kyun
    2017 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2017, : 398 - 399
  • [6] Cloud-Based Virtual Laboratory for Network Security Education
    Xu, Le
    Huang, Dijiang
    Tsai, Wei-Tek
    IEEE TRANSACTIONS ON EDUCATION, 2014, 57 (03) : 145 - 150
  • [7] Preserving user query privacy in cloud-based security services
    Chen, Yen-Chung
    Wu, Yu-Sung
    Tzeng, Wen-Guey
    JOURNAL OF COMPUTER SECURITY, 2014, 22 (06) : 997 - 1024
  • [8] An On-Demand Security Mechanism for Cloud-Based Telecommunications Services
    Zhaoji Lin
    ZTECommunications, 2011, 9 (01) : 37 - 40
  • [9] Implementing Chinese Wall Security Model for Cloud-based Services
    Basu, Srijita
    Sengupta, Anirban
    Mazumdar, Chandan
    2015 INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND INTERNET OF THINGS (ICGCIOT), 2015, : 1083 - 1089
  • [10] Towards Cloud-Based Compositions of Security Functions For Mobile Devices
    Hurel, Gaetan
    Badonnel, Remi
    Lahmadi, Abdelkader
    Festor, Olivier
    PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 578 - 584