• DocumentCode
    2738921
  • Title

    A novel approach for integrating security policy enforcement with dynamic network virtualization

  • Author

    Basile, Cataldo ; Lioy, Antonio ; Pitscheider, Christian ; Valenza, Fulvio ; Vallini, Marco

  • Author_Institution
    Dip. Autom. e Inf., Politec. di Torino, Turin, Italy
  • fYear
    2015
  • fDate
    13-17 April 2015
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Network function virtualization (NFV) is a new networking paradigm that virtualizes single network functions. NFV introduces several advantages compared to classical approaches, such as the dynamic provisioning of functionality or the implementation of scalable and reliable services (e.g., adding a new instance to support demands). NFV also allows the deployment of security controls, like firewalls or VPN gateways, as virtualized network functions. However, currently there is not an automatic way to select the security functions to enable and to configure the selected ones according to a set of user´s security requirements. This paper presents a first approach towards the integration of network and security policy management into the NFV framework. By adding to the NFV architecture a new software component, the Policy Manager, we provide NFV with an easy and effective way for users to specify their security requirements and a process that hides all the details of the correct deployment and configuration of security functions. To perform its tasks, the Policy Manager uses policy refinement techniques.
  • Keywords
    firewalls; internetworking; virtual private networks; virtualisation; NFV architecture; VPN gateways; dynamic network virtualization; firewalls; policy refinement techniques; security controls; security policy enforcement; security policy management; single network function virtualization; software component; Computer architecture; Concrete; Inspection; Optimization; Security; Unified modeling language; Virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Softwarization (NetSoft), 2015 1st IEEE Conference on
  • Conference_Location
    London
  • Type

    conf

  • DOI
    10.1109/NETSOFT.2015.7116152
  • Filename
    7116152