A Policy-based Interaction Protocol between Software Defined Security Controller and Virtual Security Functions
Title | A Policy-based Interaction Protocol between Software Defined Security Controller and Virtual Security Functions |
Publication Type | Conference Paper |
Year of Publication | 2020 |
Authors | Farahmandian, S., Hoang, D. B. |
Conference Name | 2020 4th Cyber Security in Networking Conference (CSNet) |
Date Published | Oct. 2020 |
Publisher | IEEE |
ISBN Number | 978-1-6654-0458-7 |
Keywords | cloud computing, Cloud Security, control systems, Monitoring, Network Security Architecture, NFV, policy-based governance, Predictive models, Protocols, pubcrawl, SDN, security, security policies, security protocol, Software, software defined security service, virtual security function |
Abstract | Cloud, Software-Defined Networking (SDN), and Network Function Virtualization (NFV) technologies have introduced a new era of cybersecurity threats and challenges. To protect cloud infrastructure, in our earlier work, we proposed Software Defined Security Service (SDS2) to tackle security challenges centered around a new policy-based interaction model. The security architecture consists of three main components: a Security Controller, Virtual Security Functions (VSF), and a Sec-Manage Protocol. However, the security architecture requires an agile and specific protocol to transfer interaction parameters and security messages between its components where OpenFlow considers mainly as network routing protocol. So, The Sec-Manage protocol has been designed specifically for obtaining policy-based interaction parameters among cloud entities between the security controller and its VSFs. This paper focuses on the design and the implementation of the Sec-Manage protocol and demonstrates its use in setting, monitoring, and conveying relevant policy-based interaction security parameters. |
URL | https://ieeexplore.ieee.org/document/9265460 |
DOI | 10.1109/CSNet50428.2020.9265460 |
Citation Key | farahmandian_policy-based_2020 |