A novel approach for integrating security policy enforcement with dynamic network virtualization

被引:33
作者
Basile, Cataldo [1 ]
Lioy, Antonio [1 ]
Pitscheider, Christian [1 ]
Valenza, Fulvio [1 ]
Vallini, Marco [1 ]
机构
[1] Politecn Torino, Dip Automat & Informat, Turin, Italy
来源
2015 1ST IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT) | 2015年
关键词
D O I
10.1109/NETSOFT.2015.7116152
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Network function virtualization (NFV) is a new networking paradigm that virtualizes single network functions. NFV introduces several advantages compared to classical approaches, such as the dynamic provisioning of functionality or the implementation of scalable and reliable services (e.g., adding a new instance to support demands). NFV also allows the deployment of security controls, like firewalls or VPN gateways, as virtualized network functions. However, currently there is not an automatic way to select the security functions to enable and to configure the selected ones according to a set of user's security requirements. This paper presents a first approach towards the integration of network and security policy management into the NFV framework. By adding to the NFV architecture a new software component, the Policy Manager, we provide NFV with an easy and effective way for users to specify their security requirements and a process that hides all the details of the correct deployment and configuration of security functions. To perform its tasks, the Policy Manager uses policy refinement techniques.
引用
收藏
页数:5
相关论文
共 17 条
[1]  
[Anonymous], 2013, POSECCO DELIVERABLE
[2]   Firmato:: A novel firewall management toolkit [J].
Bartal, Y ;
Mayer, A ;
Nissim, K ;
Wool, A .
ACM TRANSACTIONS ON COMPUTER SYSTEMS, 2004, 22 (04) :381-420
[3]  
Basile C., 2010, J INFO ASSURANCE SEC, V5, P437
[4]  
Bishop M., 2006, TECH REP
[5]  
European Telecommunications Standards Institute, 2013, TECH REP
[6]  
Garcia-Alfaro J, 2011, LECT NOTES COMPUT SC, V6514, P203, DOI 10.1007/978-3-642-19348-4_15
[7]  
Godik S., 2013, TECH REP
[8]  
Koslovski GP, 2009, L N INST COMP SCI SO, V2, P138
[9]  
Martins J., 2014, Proceedings of the 11th USENIX Conference on Networked Systems Design and Implementation, P459
[10]   Policy hierarchies of distributed systems management [J].
Moffett, Jonathan D. ;
Sloman, Morris S. .
IEEE Journal on Selected Areas in Communications, 1993, 11 (09) :1404-1414