NOMS 2018 - 2018 IEEE/IFIP Network Operations and Management Symposium 2018
DOI: 10.1109/noms.2018.8406155
|View full text |Cite
|
Sign up to set email alerts
|

Unikernel-based approach for software-defined security in cloud infrastructures

Abstract: The heterogeneity of cloud resources implies substantial overhead to deploy and configure adequate security mechanisms. In that context, we propose a software-defined security strategy based on unikernels to support the protection of cloud infrastructures. This approach permits to address management issues by uncoupling security policy from their enforcement through programmable security interfaces. It also takes benefits from unikernel virtualization properties to support this enforcement and provide resource… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
12
0

Year Published

2018
2018
2021
2021

Publication Types

Select...
4
1

Relationship

3
2

Authors

Journals

citations
Cited by 10 publications
(12 citation statements)
references
References 16 publications
0
12
0
Order By: Relevance
“…We showed in our previous work [3] an architecture for programmable security mechanisms in cloud infrastructures. It relies on the generation of specific resources based on unikernels, that integrate security mechanisms [4]. However, it should take advantage of orchestration languages, such as TOSCA, to drive the building and configuration of protected virtualized resources.…”
Section: Related Workmentioning
confidence: 99%
See 4 more Smart Citations
“…We showed in our previous work [3] an architecture for programmable security mechanisms in cloud infrastructures. It relies on the generation of specific resources based on unikernels, that integrate security mechanisms [4]. However, it should take advantage of orchestration languages, such as TOSCA, to drive the building and configuration of protected virtualized resources.…”
Section: Related Workmentioning
confidence: 99%
“…Applications are capable to run as independent virtual machines [15], contributing to a simplified management as discussed in [16]. We argue in favor of exploiting unikernels to minimize the attack surface and showed how such unikernel-based virtual machines can be generated in an on-the-fly manner in [4].…”
Section: Related Workmentioning
confidence: 99%
See 3 more Smart Citations