Collaborative Network Security in Multi-Tenant Data Center for Cloud Computing

来源 :Tsinghua Science and Technology | 被引量 : 0次 | 上传用户:suli115296303
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
A data center is an infrastructure that supports Internet service. Cloud computing is rapidly changing the face of the Internet service infrastructure, enabling even small organizations to quickly build Web and mobile applications for millions of users by taking advantage of the scale and flexibility of shared physical infrastructures provided by cloud computing. In this scenario, multiple tenants save their data and applications in shared data centers, blurring the network boundaries between each tenant in the cloud. In addition, different tenants have different security requirements, while different security policies are necessary for different tenants. Network virtualization is used to meet a diverse set of tenant-specific requirements with the underlying physical network, enabling multi-tenant datacenters to automatically address a large and diverse set of tenants requirements. In this paper, we propose the system implementation of vCNSMS, a collaborative network security prototype system used in a multi-tenant data center. We demonstrate vCNSMS with a centralized collaborative scheme and deep packet inspection with an open source UTM system. A security level based protection policy is proposed for simplifying the security rule management for vCNSMS. Different security levels have different packet inspection schemes and are enforced with different security plugins. A smart packet verdict scheme is also integrated into vCNSMS for intelligence flow processing to protect from possible network attacks inside a data center network. A data center is an infrastructure that supports Internet service. Cloud computing is rapidly changing the face of the Internet service infrastructure, enabling even small organizations to quickly build web and mobile applications for millions of users by taking advantage of the scale and flexibility of shared physical infastructures provided by cloud computing. In this scenario, multiple tenants save their data and applications in shared data centers, blurring the network boundaries between each tenant in the cloud. different tenants. Network virtualization is used to meet a diverse set of tenant-specific requirements with the underlying physical network, enabling multi-tenant datacenters to automatically address a large and diverse set of ten requirements requirements. In this paper, we propose the system implementation of vCNSMS, a collaborative network security prototype system used in a multi-tenant data center. We demonstrate vCNSMS with a centralized collaborative scheme and deep packet inspection with an open source UTM system. A security level based protection policy is proposed for simplifying the security rule management for vCNSMS. Different security levels have different packet inspection schemes and are enforced with different security plugins. A smart packet verdict scheme is also integrated into vCNSMS for intelligence flow processing to protect from possible network attacks inside a data center network.
其他文献
The concept of deep learning has been applied to many domains, but the definition of a suitable problem depth has not been sufficiently explored. In this study,
党的十八大以来,以习近平同志为核心的中央领导集体,以极大的政治勇气和智慧深入推进改革,新一轮治国理政改革大潮涌起.党的十九大以来,一系列治国理政新理念、新思想、新战
科研管理的内部制约因素是影响科研管理水平的内因,而科研管理的外部制约因素是影响科研管理实效的外因,本文认为,外部体制的改革创新是促进科研管理的重要平台.文章在借鉴历
孔子的教育思想不仅在古代产生了深远的影响,对于现代教育也有着深刻的启示,孔子教育的核心思想主要表现在为仁由己、因材施教、学思结合等多个方面。本文主要针对孔子教育思想
当前,国有企业的改革与改制,正在向纵深推进,而混合所有制改革是国企改革的重要突破口.如何做好混合所有制企业思想政治工作,关系到企业的长远发展和职工的切身利益.本文分析
小学语文教学的目的是指导学生正确地理解和运用祖国的语言文字,使学生具有初步的听说读写的能力。指导学生正确地理解和运用语言文字,使学生形成能力,是当前我们阅读教学急需探
习近平同志在党的十九大报告中指出:“中国特色社会主义进入了新时代”.准确把握习近平新时代中国特色社会主义思想的历史起点和逻辑前提,协调人与人、人与工作、人与环境之
为探究吕家坨井田地质构造格局,根据钻孔勘探资料,采用分形理论和趋势面分析方法,研究了井田7
随着互联网的高速发展,家园沟通的方式越来越多。但在幼儿园,为促幼儿健康成长,教师与家长之间有效的沟通是十分有必要的,有效沟通不仅可以使家园双方建立良好的合作关系,促进幼儿
思想政治工作是国有企业成长和发展的生命线,深化企业文化视角下的国有企业思想政治工作研究,是探索国有企业思想政治工作与现代企业管理相融合的有效方式,是创新国有企业思