2017
DOI: 10.1007/978-3-319-60774-0_4
|View full text |Cite
|
Sign up to set email alerts
|

Towards a Software-Defined Security Framework for Supporting Distributed Cloud

Abstract: Abstract. Cloud computing provides new facilities for building elaborated services hosted through various infrastructures over the Internet. In the meantime, these ones pose new important challenges in terms of security due to their intrinsic nature. We propose in this paper to detail a software-defined security framework supporting the protection of these services, in the context of distributed cloud. These ones require security mechanisms able to cope with their multi-tenancy and multi-cloud properties. The … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
5
0

Year Published

2018
2018
2023
2023

Publication Types

Select...
3
2

Relationship

3
2

Authors

Journals

citations
Cited by 5 publications
(5 citation statements)
references
References 11 publications
0
5
0
Order By: Relevance
“…The software-defined security concept [ 34 ] sets out to uncouple the security management from the resources needing protection to propose unified security supervision. In [ 35 ], the authors applied this approach to multi-tenant and multi-cloud infrastructures by leveraging the programmability of security enforcers.…”
Section: Related Workmentioning
confidence: 99%
“…The software-defined security concept [ 34 ] sets out to uncouple the security management from the resources needing protection to propose unified security supervision. In [ 35 ], the authors applied this approach to multi-tenant and multi-cloud infrastructures by leveraging the programmability of security enforcers.…”
Section: Related Workmentioning
confidence: 99%
“…Approaches such as [7] support modular security functions that can be then composed into security chains to protect resources, but are often limited to specific enforcers. We showed in our previous work [3] an architecture for programmable security mechanisms in cloud infrastructures. It relies on the generation of specific resources based on unikernels, that integrate security mechanisms [4].…”
Section: Related Workmentioning
confidence: 99%
“…The first one corresponds to the control plane which takes charge of security decisions, while the second one stands for the resource plane which includes the resources to be protected together with dedicated programmable security mechanisms (such as firewalls, intrusion detection systems, control access mechanisms) [2]. We have already analyzed the feasibility of such a security programmability layer for addressing multi-cloud and multi-tenant environments, through different realistic scenarios in [3]. The foundation of this layer relies on the SDSec logic to express and propagate security policies to the considered cloud resources, and on the autonomic paradigm to dynamically configure and adjust these mechanisms to distributed cloud constraints.…”
Section: Introductionmentioning
confidence: 99%
“…The author of [6] proposes a cloud management framework caping with multi-tenancy, but this one is limited to access control policies and cannot support other security mechanisms. We have already argued in favor of a SDSec framework for distributed computing in [7] where we described the main building blocks and analyzed its benefits.…”
Section: Related Workmentioning
confidence: 99%