The research and practice of dynamic network security architecture for IaaS platform

来源 :第八届中国可信计算与信息安全学术会议 | 被引量 : 0次 | 上传用户:wofucyou4444
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
  The network security requirements based on virtual network technologies in IaaS platforms and corresponding solutions were reviewed A dvnamic network securitv architecture was proposed.which was built on the technologies of software defined networking.VM (virtual machinel traffic redirection network policy unified management.sofiware defined isolation network.vulnerabilitv scanning and sofiware update.The proposed architecture was able to obtain the capacitiesof detection and access control for VM traffic bv redirecting VM traffic to configurable security appliances.and ensure the effectiveness of network policies in total life cvcle of VM by configuring the policies to right place at the appropriate hme point according to the impacts that brought by VM state transitions The virtual isolation domains for tenants VMs could be built flexiblv based on VLAN policies or Netfilterilptables firewall appliances.and vulnerabilitv scanning as a service and sofiware update as a ser- vice were provided as security supports Through cooperation with IDS appliances and automatic alarm mechanisms.the proposed architecture could mitigate a wide range of network-based attacks dvnamicallv The experimental results demonstrated the effectiveness of the proposed architecture.
其他文献
配网工程的建设和改造是电力系统中一个很重要的部分,主要是它直接与用户相连,承担着为用户供电的责任.在宏观层面上,通过配网工程的改造和升级,能够全面满足用户用电需求,提
目的 分析综合干预措施对ICU肺癌术后患者睡眠质量的影响.方法 选取院内2019年8月~2020年8月收治的78例ICU肺癌术后患者分组研究,对照组采用常规护理方法,观察组采用综合护理
随着我国工业化水平的不断提升,电力行业所面临的服务压力与风险也在不断增加,能源消耗规模迅速扩张,对于电力系统自身的完善性有着更高的考验.电气自动化技术应用于电力系统
数字化所带来的“读图时代”,正日新月异地丰富着我们的视觉语态,以往的教学模式和方法,已无法适应数字化带来的信息急剧膨胀这一新现实。如何在教学实践中帮助学生逐步廓清
智能技术是一种新型控制技术,属于计算机科学发展的衍生产物,依托其独特性及优越性,得到了众多行业的青睐和应用,未来发展空间极为广阔.电子工程自动化控制作为关键领域,其对
目的 讨论中重度牙周病伴错颌畸形患者中施以固定正畸结合牙周组织再生术(GTR)治疗的临床效果.方法 择2019年11月-2020年11月我院中重度牙周病伴错颌畸形患者80例,随机划为2
  Information monitoring system in the greenhouse will often deploy multiple redundant collection nodes in the same region in order to gather environmental pa
会议
琯溪蜜柚原产福建省平和县小溪镇,具有果形美观、果大、皮薄、核少,果肉白色如玉、清甜微酸、化渣等特点,已列入世界名柚行列。为推广这一优良品种,改善西双版纳的柚类品种结构,西
软件老化现象常常出现在长期运行的软件系统中,其常常表现为系统性能下降、服务暂停、甚至是系统失效.为了阻止软件老化和失效,一种称为软件抗衰技术被提出:停止软件服务,清
我区地处北亚热带南缘,中亚热带北缘,对照全 国柑桔生态区划指标,我区属柑桔栽培次适宜区。 柑桔是我区果树主栽树种之一。多年来,我们在生 产实践中不断探索和研究北缘地区柑桔