SHIN, WANG AND GU: A FIRST STEP TOWARDS NETWORK SECURITY VIRTUALIZATION: FROM CONCEPT TO PROTOTYPE 1 A First Step Towards Network Security Virtualization: From Concept To Prototype
نویسندگان
چکیده
Network security management is becoming more and more complicated in recent years, considering the need of deploying more and more network security devices/middle-boxes at various locations inside the already complicated networks. A grand challenge in this situation is that current management is inflexible and the security resource utilization is not efficient. The flexible deployment and utilization of proper security devices at reasonable places at needed time with low management cost is extremely difficult. In this paper we present a new concept of Network Security Virtualization (NSV), which virtualizes security resources/functions to network administrators/users, and thus maximally utilizing existing security devices/middle-boxes. In addition, it enables security protection to desirable networks with minimal management cost. To verify this concept, we further design and implement a prototype system, NETSECVISOR, which can utilize existing pre-installed (fixed-location) security devices and leverage software-defined networking (SDN) technology to virtualize network security functions. At its core, NETSECVISOR contains (i) a simple script language to register security services and policies, (ii) a set of routing algorithms to determine optimal routing paths for different security policies based on different needs, and (iii) a set of security response functions/strategies to handle security incidents. We deploy NETSECVISOR in both virtual test networks and a commercial switch environment to evaluate its performance and feasibility. The evaluation results show that our prototype only adds a very small overhead while providing desired network security virtualization to network users/administrators.
منابع مشابه
Poisoning Network Visibility in Software-Defined Networks: New Attacks and Countermeasures
Software-Defined Networking (SDN) is a new networking paradigm that grants a controller and its applications an omnipotent power to have holistic network visibility and flexible network programmability, thus enabling new innovations in network protocols and applications. One of the core advantages of SDN is its logically centralized control plane to provide the entire network visibility, on whi...
متن کاملExploring Cross-Site Scripting Botnet Detection and simulation
Nowadays, with increasing number of Internet users and its commercial character subsequently bring in proportionate number of criminal minded network security threats. Among various of malicious programs, the botnet is considered as one of the most critical issue for the current worldwide Internet users. Unfortunately, existing techniques for detecting botnetsespecially cross-site scripting (XS...
متن کاملSPHysics Simulation of Experimental Spillway Hydraulics
In this paper, we use the parallel open source code parallelSPHysics based on the weakly compressible Smoothed Particle Hydrodynamics (WCSPH) approach to study a spillway flow over stepped stairs. SPH is a robust mesh-free particle modelling technique and has great potential in treating the free surfaces in spillway hydraulics. A laboratory experiment is carried out for the different flow disch...
متن کاملLearning to Segment Instances in Videos with Spatial Propagation Network
We propose a deep learning-based framework for instance-level object segmentation. Our method mainly consists of three steps. First, We train a generic model based on ResNet-101 for foreground/background segmentations. Second, based on this generic model, we fine-tune it to learn instance-level models and segment individual objects by using augmented object annotations in first frames of test v...
متن کاملMulti - step iterations with errors for common fixed points of a finite family of nonself asymptotically nonexpansive mappings ∗
In this paper we established strong and weak convergence theorems for a multi-step iterative scheme with errors for nonself asymptotically nonexpansive mappings in the real uniformly convex Banach space. Our results extend and improve the ones announced by Lin Wang [Lin Wang, Strong and weak convergence theorems for common fixed points of nonself asymptotically nonexpansive mappings, J. Math. A...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2015