返回
A framework for enabling security services collaboration across multiple domains
DOI:10.1016/j.compeleceng.2018.02.026.png)
摘要
En 中文
Network function virtualization opens a new era for security, allowing on-demand instantiation of defense appliances via technologies such as SDN (Software Defined Networking) and Service Function Chaining (SFC). Taking full advantage of such capabilities, however, requires collaboration among Security Service Functions (SSFs) distributed throughout the network. Indeed, collaboration among SSFs is expected to become as essential to SECaaS (SECurity as a Service) as elasticity is to IaaS (Infrastructure as a Service), enabling the efficient allocation of resources for handling large scale attacks. In this paper, we propose a framework leveraging SDN and SFC to improve collaboration among SSFs, allowing SSFs from different domains to negotiate and dynamically control the amount of resources dedicated to collaboration (called a best-effort mode). The feasibility, efficiency and scalability of the solution is experimentally assessed, showing that it incurs low overhead, increases the amount of traffic treated by SSFs before packets start being dropped. (C) 2018 Elsevier Ltd. All rights reserved.
Keyword:
Cloud computing
Multi-domain networks
Collaborative security
Service Function Chaining
Network function virtualization
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
4.9
论文数:
6.7K
被引数:
1.3W
机构
引用论文
A Survey of Defense Mechanisms Against Distributed Denial of Service (DDoS) Flooding Attacks分布式拒绝服务 (DDoS) 洪水攻击防御机制综述

