José Manuel Bernabé Murcia , Alejandro M. Zarca , Antonio Skármeta
{"title":"BASTION:超越下一代网络的自动化服务和安全编排","authors":"José Manuel Bernabé Murcia , Alejandro M. Zarca , Antonio Skármeta","doi":"10.1016/j.comnet.2025.111352","DOIUrl":null,"url":null,"abstract":"<div><div>The adoption of 5G technology and beyond introduces advanced capabilities, such as dynamic resource coordination and allocation tailored to specific service and security requirements. To achieve efficient security and network management, service automation and orchestration are essential. This paper presents BASTION, a ZSM-aligned framework for enhanced service and security (meta) orchestration. By leveraging an intent-based, policy-driven approach, it enables the orchestration and enforcement of service and security policies across B5G infrastructures, dynamically adapting to real-time infrastructure conditions. While meta-orchestration capabilities focus on selecting the most suitable orchestration algorithm based on the system’s current status and the received requirements, orchestration capabilities primarily determine what, where, when, and how to enforce services and security policies. Additionally, the modular design and implementation allow for the seamless integration of new security capabilities through plugins, drivers, and managers. This advancement represents a significant step towards building resilient, adaptable, and secure B5G networks capable of meeting the complex demands of modern network environments. The implementation details showcase the full range of capabilities offered by the BASTION framework, highlighting its effectiveness through successful European and national projects. Furthermore, the performance evaluation section provides a comprehensive analysis of orchestration efficiency, breaking down execution times across different phases. In particular, BASTION demonstrates exceptional performance, achieving decision times as low as 1.3 ms and deploying services and security policies, including fully operational dynamic VNFs in less than 30 s, underscoring its ability to deliver fast, scalable, and efficient orchestration in complex environments.</div></div>","PeriodicalId":50637,"journal":{"name":"Computer Networks","volume":"267 ","pages":"Article 111352"},"PeriodicalIF":4.4000,"publicationDate":"2025-05-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"BASTION: Beyond automated service and security orchestration for next-generation networks\",\"authors\":\"José Manuel Bernabé Murcia , Alejandro M. Zarca , Antonio Skármeta\",\"doi\":\"10.1016/j.comnet.2025.111352\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>The adoption of 5G technology and beyond introduces advanced capabilities, such as dynamic resource coordination and allocation tailored to specific service and security requirements. To achieve efficient security and network management, service automation and orchestration are essential. This paper presents BASTION, a ZSM-aligned framework for enhanced service and security (meta) orchestration. By leveraging an intent-based, policy-driven approach, it enables the orchestration and enforcement of service and security policies across B5G infrastructures, dynamically adapting to real-time infrastructure conditions. While meta-orchestration capabilities focus on selecting the most suitable orchestration algorithm based on the system’s current status and the received requirements, orchestration capabilities primarily determine what, where, when, and how to enforce services and security policies. Additionally, the modular design and implementation allow for the seamless integration of new security capabilities through plugins, drivers, and managers. This advancement represents a significant step towards building resilient, adaptable, and secure B5G networks capable of meeting the complex demands of modern network environments. The implementation details showcase the full range of capabilities offered by the BASTION framework, highlighting its effectiveness through successful European and national projects. Furthermore, the performance evaluation section provides a comprehensive analysis of orchestration efficiency, breaking down execution times across different phases. In particular, BASTION demonstrates exceptional performance, achieving decision times as low as 1.3 ms and deploying services and security policies, including fully operational dynamic VNFs in less than 30 s, underscoring its ability to deliver fast, scalable, and efficient orchestration in complex environments.</div></div>\",\"PeriodicalId\":50637,\"journal\":{\"name\":\"Computer Networks\",\"volume\":\"267 \",\"pages\":\"Article 111352\"},\"PeriodicalIF\":4.4000,\"publicationDate\":\"2025-05-17\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Computer Networks\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S1389128625003196\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, HARDWARE & ARCHITECTURE\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computer Networks","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S1389128625003196","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, HARDWARE & ARCHITECTURE","Score":null,"Total":0}
BASTION: Beyond automated service and security orchestration for next-generation networks
The adoption of 5G technology and beyond introduces advanced capabilities, such as dynamic resource coordination and allocation tailored to specific service and security requirements. To achieve efficient security and network management, service automation and orchestration are essential. This paper presents BASTION, a ZSM-aligned framework for enhanced service and security (meta) orchestration. By leveraging an intent-based, policy-driven approach, it enables the orchestration and enforcement of service and security policies across B5G infrastructures, dynamically adapting to real-time infrastructure conditions. While meta-orchestration capabilities focus on selecting the most suitable orchestration algorithm based on the system’s current status and the received requirements, orchestration capabilities primarily determine what, where, when, and how to enforce services and security policies. Additionally, the modular design and implementation allow for the seamless integration of new security capabilities through plugins, drivers, and managers. This advancement represents a significant step towards building resilient, adaptable, and secure B5G networks capable of meeting the complex demands of modern network environments. The implementation details showcase the full range of capabilities offered by the BASTION framework, highlighting its effectiveness through successful European and national projects. Furthermore, the performance evaluation section provides a comprehensive analysis of orchestration efficiency, breaking down execution times across different phases. In particular, BASTION demonstrates exceptional performance, achieving decision times as low as 1.3 ms and deploying services and security policies, including fully operational dynamic VNFs in less than 30 s, underscoring its ability to deliver fast, scalable, and efficient orchestration in complex environments.
期刊介绍:
Computer Networks is an international, archival journal providing a publication vehicle for complete coverage of all topics of interest to those involved in the computer communications networking area. The audience includes researchers, managers and operators of networks as well as designers and implementors. The Editorial Board will consider any material for publication that is of interest to those groups.