SD-WAN架构中网络安全机制的比较分析:初步结果

Jorge Rodríguez Bustamante, D. Avila-Pesantez
{"title":"SD-WAN架构中网络安全机制的比较分析:初步结果","authors":"Jorge Rodríguez Bustamante, D. Avila-Pesantez","doi":"10.1109/EIRCON52903.2021.9613418","DOIUrl":null,"url":null,"abstract":"Software-defined network in a wide area network (SD-WAN) has become a trend applied by large companies with geographically separated branches. The primary objective is based on a software solution that provides a cost-benefit balance, given the high cost of WAN connections. The growth of SD-WAN has brought numerous solutions by various vendors, but that has also increased the number of threats and vulnerabilities to this technology. This article aims to compare the commercial mechanisms versus opensource solutions implement within a specific architecture. It describes the cyber-attack vectors within SD-WAN and how to respond them within a simulation using the GNS3 software. The topology presented is based on a design with two branches and a headquarters, connected by two links that provide redundancy, one by MPLS and the other by broadband internet. The results of this research report that the commercial solution (Fortigate) provides better security mechanisms that focus on confidentiality, integrity, and availability. However, the open-source solution (Flexiwan) offers tools for adaptability to future threats thanks to the community's efforts.","PeriodicalId":403519,"journal":{"name":"2021 IEEE Engineering International Research Conference (EIRCON)","volume":"72 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Comparative analysis of Cybersecurity mechanisms in SD-WAN architectures: A preliminary results\",\"authors\":\"Jorge Rodríguez Bustamante, D. Avila-Pesantez\",\"doi\":\"10.1109/EIRCON52903.2021.9613418\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Software-defined network in a wide area network (SD-WAN) has become a trend applied by large companies with geographically separated branches. The primary objective is based on a software solution that provides a cost-benefit balance, given the high cost of WAN connections. The growth of SD-WAN has brought numerous solutions by various vendors, but that has also increased the number of threats and vulnerabilities to this technology. This article aims to compare the commercial mechanisms versus opensource solutions implement within a specific architecture. It describes the cyber-attack vectors within SD-WAN and how to respond them within a simulation using the GNS3 software. The topology presented is based on a design with two branches and a headquarters, connected by two links that provide redundancy, one by MPLS and the other by broadband internet. The results of this research report that the commercial solution (Fortigate) provides better security mechanisms that focus on confidentiality, integrity, and availability. However, the open-source solution (Flexiwan) offers tools for adaptability to future threats thanks to the community's efforts.\",\"PeriodicalId\":403519,\"journal\":{\"name\":\"2021 IEEE Engineering International Research Conference (EIRCON)\",\"volume\":\"72 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-10-27\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 IEEE Engineering International Research Conference (EIRCON)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EIRCON52903.2021.9613418\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE Engineering International Research Conference (EIRCON)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EIRCON52903.2021.9613418","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

广域网中的软件定义网络(SD-WAN)已经成为地域分散的大公司应用的一种趋势。考虑到WAN连接的高成本,主要目标是基于提供成本效益平衡的软件解决方案。SD-WAN的发展带来了各种供应商的众多解决方案,但这也增加了该技术的威胁和漏洞的数量。本文旨在比较在特定体系结构中实现的商业机制与开源解决方案。它描述了SD-WAN中的网络攻击向量以及如何在使用GNS3软件的模拟中响应它们。所提出的拓扑结构是基于两个分支机构和一个总部的设计,通过两条链路连接,一条通过MPLS,另一条通过宽带互联网提供冗余。这项研究的结果表明,商业解决方案(Fortigate)提供了更好的安全机制,重点关注机密性、完整性和可用性。然而,由于社区的努力,开源解决方案(Flexiwan)提供了适应未来威胁的工具。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Comparative analysis of Cybersecurity mechanisms in SD-WAN architectures: A preliminary results
Software-defined network in a wide area network (SD-WAN) has become a trend applied by large companies with geographically separated branches. The primary objective is based on a software solution that provides a cost-benefit balance, given the high cost of WAN connections. The growth of SD-WAN has brought numerous solutions by various vendors, but that has also increased the number of threats and vulnerabilities to this technology. This article aims to compare the commercial mechanisms versus opensource solutions implement within a specific architecture. It describes the cyber-attack vectors within SD-WAN and how to respond them within a simulation using the GNS3 software. The topology presented is based on a design with two branches and a headquarters, connected by two links that provide redundancy, one by MPLS and the other by broadband internet. The results of this research report that the commercial solution (Fortigate) provides better security mechanisms that focus on confidentiality, integrity, and availability. However, the open-source solution (Flexiwan) offers tools for adaptability to future threats thanks to the community's efforts.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信