2019 IEEE Conference on Network Softwarization (NetSoft) 2019
DOI: 10.1109/netsoft.2019.8806623
|View full text |Cite
|
Sign up to set email alerts
|

A TOSCA-Oriented Software-Defined Security Approach for Unikernel-Based Protected Clouds

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
7
0

Year Published

2019
2019
2024
2024

Publication Types

Select...
5
2
2

Relationship

4
5

Authors

Journals

citations
Cited by 12 publications
(7 citation statements)
references
References 16 publications
(17 reference statements)
0
7
0
Order By: Relevance
“…Existing solutions to protect cloud resources include endogenous security mechanisms that directly impact the resources, such as generating specific cloud images with a low attack surface, modifying the internal parametrization to prevent vulnerable configurations, and exploiting certification techniques for guaranteeing the resource behaviours. For instance, the authors of [11] propose to extend an orchestration language to drive the generation of protected unikernel images, corresponding to lightweight virtual machines composed of only the strict necessary packages and libraries. In this case, any configuration changes require the re-generation of new virtual machines.…”
Section: Related Workmentioning
confidence: 99%
“…Existing solutions to protect cloud resources include endogenous security mechanisms that directly impact the resources, such as generating specific cloud images with a low attack surface, modifying the internal parametrization to prevent vulnerable configurations, and exploiting certification techniques for guaranteeing the resource behaviours. For instance, the authors of [11] propose to extend an orchestration language to drive the generation of protected unikernel images, corresponding to lightweight virtual machines composed of only the strict necessary packages and libraries. In this case, any configuration changes require the re-generation of new virtual machines.…”
Section: Related Workmentioning
confidence: 99%
“…The security enforcement can be carried out through heterogeneous approaches: it can be either thought as a complementary mechanism on top of an already existing virtualised environment running network services [25] or as a mean in itself, where security capabilities are enforced to protect the infrastructure. This enforcement can be defined to extend low-level data models (e.g., the VNFD [26] used by the NFVO) with specific parameters or either add separate security-related data models. In PALANTIR we follow the latter approach (direct protection of the infrastructure and separate security-related data models), since this approach permits decoupling both the aim of the infrastructure and of the default network services from the PALANTIR platform, without modifying the current state.…”
Section: Beyond the State Of The Artmentioning
confidence: 99%
“…It enhances system reliability with respect to anomaly or security attacks and helps in recovering the system functionalities within minimal time. Similarly, in [91], the Topology and Orchestration Specification for Cloud Applications (TOSCA)language has been extended to support the creation and orchestration of unikernels with security constraints. It also enables the unikernels to offer on-demand network Fig.…”
Section: Unikernel Network Functionsmentioning
confidence: 99%