期刊文献+
共找到1篇文章
< 1 >
每页显示 20 50 100
Research and Practice of Dynamic Network Security Architecture for IaaS Platforms 被引量:7
1
作者 Lin Chen Xingshu Chen +2 位作者 junfang jiang Xueyuan Yin Guolin Shao 《Tsinghua Science and Technology》 SCIE EI CAS 2014年第5期496-507,共12页
Network security requirements based on virtual network technologies in laaS platforms and corresponding solutions were reviewed. A dynamic network security architecture was proposed, which was built on the technologie... Network security requirements based on virtual network technologies in laaS platforms and corresponding solutions were reviewed. A dynamic network security architecture was proposed, which was built on the technologies of software defined networking, Virtual Machine (VM) traffic redirection, network policy unified management, software defined isolation networks, vulnerability scanning, and software updates. The proposed architecture was able to obtain the capacity for detection and access control for VM traffic by redirecting it to configurable security appliances, and ensured the effectiveness of network policies in the total life cycle of the VM by configuring the policies to the right place at the appropriate time, according to the impacts of VM state transitions. The virtual isolation domains for tenants' VMs could be built flexibly based on VLAN policies or Netfilter/Iptables firewall appliances, and vulnerability scanning as a service and software update as a service were both provided as security supports. Through cooperation with IDS appliances and automatic alarm mechanisms, the proposed architecture could dynamically mitigate a wide range of network-based attacks. The experimental results demonstrate the effectiveness of the proposed architecture. 展开更多
关键词 cloud computing network security LAAS life cycle network policy
原文传递
上一页 1 下一页 到第
使用帮助 返回顶部