Visible to the public A Policy-based Interaction Protocol between Software Defined Security Controller and Virtual Security Functions

TitleA Policy-based Interaction Protocol between Software Defined Security Controller and Virtual Security Functions
Publication TypeConference Paper
Year of Publication2020
AuthorsFarahmandian, S., Hoang, D. B.
Conference Name2020 4th Cyber Security in Networking Conference (CSNet)
Date Published Oct. 2020
PublisherIEEE
ISBN Number978-1-6654-0458-7
Keywordscloud computing, Cloud Security, control systems, Monitoring, Network Security Architecture, NFV, policy-based governance, Predictive models, Protocols, pubcrawl, SDN, security, security policies, security protocol, Software, software defined security service, virtual security function
Abstract

Cloud, Software-Defined Networking (SDN), and Network Function Virtualization (NFV) technologies have introduced a new era of cybersecurity threats and challenges. To protect cloud infrastructure, in our earlier work, we proposed Software Defined Security Service (SDS2) to tackle security challenges centered around a new policy-based interaction model. The security architecture consists of three main components: a Security Controller, Virtual Security Functions (VSF), and a Sec-Manage Protocol. However, the security architecture requires an agile and specific protocol to transfer interaction parameters and security messages between its components where OpenFlow considers mainly as network routing protocol. So, The Sec-Manage protocol has been designed specifically for obtaining policy-based interaction parameters among cloud entities between the security controller and its VSFs. This paper focuses on the design and the implementation of the Sec-Manage protocol and demonstrates its use in setting, monitoring, and conveying relevant policy-based interaction security parameters.

URLhttps://ieeexplore.ieee.org/document/9265460
DOI10.1109/CSNet50428.2020.9265460
Citation Keyfarahmandian_policy-based_2020