Published November 14, 2019 | Version v1
Conference paper Open

Automated Security Management for Virtual Services

  • 1. CNIT
  • 2. Politecnico di Torino
  • 3. Infocom Srl

Description

The virtualization of applications and network func- tions facilitates the dynamic creation of compound services, au- tomating both the provisioning of computing/networking/storage resources and their life-cycle management. Virtualization of security appliances is a common approach to protect such services, but can neither offer broad visibility across the whole deployed service nor implement coordinated and fine-grained enforcement actions.

This paper proposes a novel security framework based on the integration of lightweight and programmable monitoring and enforcement hooks in each virtual function, which are collectively controlled by a common logic for prevention, detection, reaction, and mitigation of security threats. Our framework keeps direct control over the functionalities of the security hooks, and lever- ages standard orchestration tools for management actions on the service graph. It can be automatically instantiated by common orchestration operations, hence seamlessly integrating with the deployment process of service graphs.

Files

nfvsdn19demo-1.pdf

Files (119.3 kB)

Name Size Download all
md5:2ecf52e9276e73ac2ae33a5595d3b47f
119.3 kB Preview Download

Additional details

Funding

ASTRID – AddreSsing ThReats for virtualIseD services 786922
European Commission
GUARD – A cybersecurity framework to GUArantee Reliability and trust for Digital service chains 833456
European Commission