Research and Practice of Dynamic Network Security Architecture for IaaS Platforms

来源 :Tsinghua Science and Technology | 被引量 : 0次 | 上传用户:feiyulaile
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Network security requirements based on virtual network technologies in IaaS platforms and corresponding solutions were reviewed.A dynamic network security architecture was proposed,which was built on the technologies of software defined networking,Virtual Machine(VM)traffic redirection,network policy unified management,software defined isolation networks,vulnerability scanning,and software updates.The proposed architecture was able to obtain the capacity for detection and access control for VM traffic by redirecting it to configurable security appliances,and ensured the effectiveness of network policies in the total life cycle of the VM by configuring the policies to the right place at the appropriate time,according to the impacts of VM state transitions.The virtual isolation domains for tenants’VMs could be built flexibly based on VLAN policies or Netfilter/Iptables firewall appliances,and vulnerability scanning as a service and software update as a service were both provided as security supports.Through cooperation with IDS appliances and automatic alarm mechanisms,the proposed architecture could dynamically mitigate a wide range of network-based attacks.The experimental results demonstrate the effectiveness of the proposed architecture. Network security requirements based on virtual network technologies in IaaS platforms and corresponding solutions were reviewed. A dynamic network security architecture was proposed, which was built on the technologies of software defined networking, virtual machine (VM) traffic redirection, network policy unified management, software defined isolation networks, vulnerability scanning, and software updates. proposed proposed architecture was able to obtain the capacity for detection and access control for VM traffic by redirecting it to configurable security appliances, and secured the effectiveness of network policies in the total life cycle of the VM by configuring the policies to the right place at the appropriate time, according to the impacts of VM state transitions. The virtual isolation domains for tenants’ VMs could be built flexibly based on VLAN policies or Netfilter / Iptables firewall appliances, and vulnerability scanning as a service and software update as a service were both provided as sec urity supports. Through cooperation with IDS appliances and automatic alarm mechanisms, the proposed architecture could dynamically mitigate a wide range of network-based attacks. The experimental results demonstrate the effectiveness of the proposed architecture.
其他文献
In the previous construction of attributed-based encryption for circuits on lattices,the secret key size was exponential to the number of AND gates of the circu
苹果的产品既美观又好用,这投射出苹果的品牌理念。所以苹果的每一款产品也就定义并强化了其品牌。如果有一天苹果的产品不如我们所期望的美观、好用了,我们也许会顺口说出:
期刊
为探究吕家坨井田地质构造格局,根据钻孔勘探资料,采用分形理论和趋势面分析方法,研究了井田7
Several public-key encryption schemes used to solve the problem of ciphertext data processing on the fly are discussed.A new targeted fully homomorphic encrypti
期刊
[摘要]医院信息系统(Hospital Information System, HIS) 的开发与应用推动了医院管理的深刻变革,计算机网络技术和数据技术的不断发展,为医院管理的变革在更大范围、更深层次上进行提供了更高、更强的支持。然而,尽管医院信息系统在全国各级医院得到了大力推广,但它的积极作用、深刻意义还远远没有体现和发挥出来,有必要进行深入的分析。  [关键词]信息系统;微机室;技术路线;完善
物理是一门注重实验的学科,而其实验的目的不仅仅是让学生掌握扎实的实践技能,还重在培养学生的思维能力与创新能力.高中物理一直被学生公认为是比较难的学科,再加上受传统教学模式的影响,导致了学生对物理没有太大的兴趣,甚至还会出现抵触情绪,造成了学校教育的困难,同时也给学生的发展带来了影响.  一、高中物理创新实验的设计  1.演示实验的设计  在物理实验教学过程中,教师一般都会在学生动手操作之前进