A Framework for Enabling Security Services Collaboration Across Multiple Domains.

Computers & Electrical Engineering(2018)

引用 20|浏览77
暂无评分
摘要
Network function virtualization opens a new era for security, allowing on-demand instantiation of defense appliances via technologies such as SDN (Software Defined Networking) and Service Function Chaining (SFC). Taking full advantage of such capabilities, however, requires collaboration among Security Service Functions (SSFs) distributed throughout the network. Indeed, collaboration among SSFs is expected to become as essential to SECaaS (SECurity as a Service) as elasticity is to IaaS (Infrastructure as a Service), enabling the efficient allocation of resources for handling large scale attacks. In this paper, we propose a framework leveraging SDN and SFC to improve collaboration among SSFs, allowing SSFs from different domains to negotiate and dynamically control the amount of resources dedicated to collaboration (called a “best-effort” mode). The feasibility, efficiency and scalability of the solution is experimentally assessed, showing that it incurs low overhead, increases the amount of traffic treated by SSFs before packets start being dropped.
更多
查看译文
关键词
Cloud computing,Multi-domain networks,Collaborative security,Service Function Chaining,Network function virtualization
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要