基于轻量级虚拟化的网络边缘安全框架

Abderrahmane Boudi, I. Farris, Miloud Bagaa, T. Taleb
{"title":"基于轻量级虚拟化的网络边缘安全框架","authors":"Abderrahmane Boudi, I. Farris, Miloud Bagaa, T. Taleb","doi":"10.1109/CSCN.2018.8581721","DOIUrl":null,"url":null,"abstract":"The interest towards cybersecurity is fast growing over the last years. Accounting for the tremendous increase of security threats, the need for new defense strategies is acquiring an even growing importance. The widespread adoption of Internet of Things (IoT) devices, ranging from smart industrial appliances to simple domestic sensors, will increase the complexity of managing security requirements in a comprehensive way. The provisioning of on-demand security services according to the SECurity-as-a-Service model is gaining notable attention. Nevertheless, the hosting of security functions in remote data-centers will inevitably introduce long routing detours, thus high latency and traffic overhead. To cope with this, edge computing will prove to be useful to process data locally. But the reduced capabilities of edge nodes can negatively impact the overall performance of SECaaS solutions. This paper focuses on the provisioning of virtualized security functions via lightweight virtualization (i.e., container) technologies running in a resource-constrained environment. Our analysis focuses primarily on the feasibility and the performance evaluation of such scenario.","PeriodicalId":311896,"journal":{"name":"2018 IEEE Conference on Standards for Communications and Networking (CSCN)","volume":"33 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":"{\"title\":\"Lightweight Virtualization Based Security Framework for Network Edge\",\"authors\":\"Abderrahmane Boudi, I. Farris, Miloud Bagaa, T. Taleb\",\"doi\":\"10.1109/CSCN.2018.8581721\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The interest towards cybersecurity is fast growing over the last years. Accounting for the tremendous increase of security threats, the need for new defense strategies is acquiring an even growing importance. The widespread adoption of Internet of Things (IoT) devices, ranging from smart industrial appliances to simple domestic sensors, will increase the complexity of managing security requirements in a comprehensive way. The provisioning of on-demand security services according to the SECurity-as-a-Service model is gaining notable attention. Nevertheless, the hosting of security functions in remote data-centers will inevitably introduce long routing detours, thus high latency and traffic overhead. To cope with this, edge computing will prove to be useful to process data locally. But the reduced capabilities of edge nodes can negatively impact the overall performance of SECaaS solutions. This paper focuses on the provisioning of virtualized security functions via lightweight virtualization (i.e., container) technologies running in a resource-constrained environment. Our analysis focuses primarily on the feasibility and the performance evaluation of such scenario.\",\"PeriodicalId\":311896,\"journal\":{\"name\":\"2018 IEEE Conference on Standards for Communications and Networking (CSCN)\",\"volume\":\"33 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"7\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 IEEE Conference on Standards for Communications and Networking (CSCN)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CSCN.2018.8581721\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE Conference on Standards for Communications and Networking (CSCN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSCN.2018.8581721","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

摘要

在过去的几年里,人们对网络安全的兴趣正在迅速增长。考虑到安全威胁的急剧增加,对新的防御战略的需求变得越来越重要。物联网(IoT)设备的广泛采用,从智能工业设备到简单的家用传感器,将增加全面管理安全需求的复杂性。根据安全即服务(security -as-a- service)模型提供随需应变的安全服务正引起人们的极大关注。然而,在远程数据中心托管安全功能将不可避免地引入漫长的路由弯路,从而导致高延迟和流量开销。为了解决这个问题,边缘计算将被证明对本地处理数据很有用。但是边缘节点能力的降低会对SECaaS解决方案的整体性能产生负面影响。本文的重点是通过在资源受限的环境中运行的轻量级虚拟化(即容器)技术来提供虚拟化安全功能。我们的分析主要集中在该方案的可行性和性能评估上。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Lightweight Virtualization Based Security Framework for Network Edge
The interest towards cybersecurity is fast growing over the last years. Accounting for the tremendous increase of security threats, the need for new defense strategies is acquiring an even growing importance. The widespread adoption of Internet of Things (IoT) devices, ranging from smart industrial appliances to simple domestic sensors, will increase the complexity of managing security requirements in a comprehensive way. The provisioning of on-demand security services according to the SECurity-as-a-Service model is gaining notable attention. Nevertheless, the hosting of security functions in remote data-centers will inevitably introduce long routing detours, thus high latency and traffic overhead. To cope with this, edge computing will prove to be useful to process data locally. But the reduced capabilities of edge nodes can negatively impact the overall performance of SECaaS solutions. This paper focuses on the provisioning of virtualized security functions via lightweight virtualization (i.e., container) technologies running in a resource-constrained environment. Our analysis focuses primarily on the feasibility and the performance evaluation of such scenario.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信