Towards Automated Provisioning of Secure Virtualized Networks

被引:0
作者
Cabuk, Serdar [1 ]
Dalton, Chris I. [1 ]
Ramasamy, HariGovind [1 ]
Schunter, Matthias [1 ]
机构
[1] Hewlett Packard Labs, Bristol BS12 6QZ, Avon, England
来源
CCS'07: PROCEEDINGS OF THE 14TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2007年
关键词
Network security; network virtualization; automated security provisioning; security policies; trusted virtual domains;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We describe a secure network virtualization framework that helps realize the abstraction of Trusted Virtual Domains (TVDs), a security-enhanced variant of virtualized network zones. The framework allows groups of related virtual machines running on separate physical machines to be connected together as though there were on their own separate network fabric and, at the same time, helps enforce cross-group security requirements such as isolation, confidentiality; security; and information flow control. The framework uses existing network virtualization technologies, such as Ethernet encapsulation, VLAN tagging, and VPNs, and combines and orchestrates them appropriately to implement TVDs. Our framework aims at automating the instantiation and deployment of the appropriate security mechanism and network virtualization technologies based on an input security model that specifies the required level of isolation and permitted network flows. We have implemented a prototype of the framework based on the Xen hypervisor. Experimental evaluation of the prototype shows that the performance of our virtual networking extensions is comparable to that of the standard Xen configuration.
引用
收藏
页码:235 / +
页数:2
相关论文
共 22 条
[1]   An investigation of factors affecting how engineers and scientists seek information [J].
Anderson, CJ ;
Glassman, M ;
McAfee, RB ;
Pinelli, T .
JOURNAL OF ENGINEERING AND TECHNOLOGY MANAGEMENT, 2001, 18 (02) :131-155
[2]  
Barham P., 2003, Operating Systems Review, V37, P164, DOI 10.1145/1165389.945462
[3]  
BAVIER A, 2004, P 1 S NETW SYST DES
[4]  
Bussani A., 2005, 23792 RC IBM RES
[5]   Spawning networks [J].
Campbell, AT ;
Kounavis, ME ;
Villela, DA ;
Vicente, JB ;
De Meer, HG ;
Miki, K ;
Kalaichelvan, KS .
IEEE NETWORK, 1999, 13 (04) :16-29
[6]  
CAMPBELL AT, 1999, P 1 INT WORK C ACT N, V1653, P249
[7]  
DALTON CI, 2005, VIRTUALIZATION SECUR
[8]  
DAVOLI R, 2005, TRIDENTCOM 05, P213, DOI DOI 10.1109/TRIDNT.2005.38
[9]   BladeCenter networking [J].
Hunter, SW ;
Strole, NC ;
Cosby, DW ;
Green, DM .
IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2005, 49 (06) :905-919
[10]  
*IEEE, 8021Q2003 IEEE