Enforcement of global security policies in federated cloud networks with virtual network functions
Title | Enforcement of global security policies in federated cloud networks with virtual network functions |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Massonet, P., Dupont, S., Michot, A., Levin, A., Villari, M. |
Conference Name | 2016 IEEE 15th International Symposium on Network Computing and Applications (NCA) |
Date Published | oct |
ISBN Number | 978-1-5090-3216-7 |
Keywords | application program interfaces, cloud computing, Collaboration, Communication networks, Encryption, federated cloud network, global security policy enforcement, governance, Government, IP networks, network function virtualization, network security function, OpenStack cloud platform, policy, policy-based governance, pubcrawl, security of data, security policies, service function chaining API, software architecture, system architecture, Trusted Computing, untrusted cloud, Virtual machining, virtual network function, virtualisation, VNF |
Abstract | Federated cloud networks are formed by federating virtual network segments from different clouds, e.g. in a hybrid cloud, into a single federated network. Such networks should be protected with a global federated cloud network security policy. The availability of network function virtualisation and service function chaining in cloud platforms offers an opportunity for implementing and enforcing global federated cloud network security policies. In this paper we describe an approach for enforcing global security policies in federated cloud networks. The approach relies on a service manifest that specifies the global network security policy. From this manifest configurations of the security functions for the different clouds of the federation are generated. This enables automated deployment and configuration of network security functions across the different clouds. The approach is illustrated with a case study where communications between trusted and untrusted clouds, e.g. public clouds, are encrypted. The paper discusses future work on implementing this architecture for the OpenStack cloud platform with the service function chaining API. |
URL | https://ieeexplore.ieee.org/document/7778597 |
DOI | 10.1109/NCA.2016.7778597 |
Citation Key | massonet_enforcement_2016 |
- Policy
- VNF
- virtualisation
- virtual network function
- Virtual machining
- untrusted cloud
- Trusted Computing
- system architecture
- Software Architecture
- service function chaining API
- security policies
- security of data
- pubcrawl
- policy-based governance
- application program interfaces
- OpenStack cloud platform
- network security function
- network function virtualization
- IP networks
- Government
- Governance
- global security policy enforcement
- federated cloud network
- encryption
- Communication networks
- collaboration
- Cloud Computing