DocumentCode :
2843331
Title :
LiveSec: Towards Effective Security Management in Large-Scale Production Networks
Author :
Wang, Kai ; Qi, Yaxuan ; Yang, Baohua ; Xue, Yibo ; Li, Jun
Author_Institution :
Dept. of Autom., Tsinghua Univ., Beijing, China
fYear :
2012
fDate :
18-21 June 2012
Firstpage :
451
Lastpage :
460
Abstract :
Network security has become an increasingly important yet challenging issue in present production networks. State-of-the-art solutions cannot meet the overall requirements of high-efficiency security, due to the complicated configuration demands, heavy network traffic and ever-increasing network scale. In this paper, we present Live Sec, a scalable and flexible security management architecture, which achieves holistic security protection with good scalability and flexibility in large-scale networks. Live Sec employs a new Access-Switching layer to provide: 1) interactive policy-enforcement that enables fine-grain control for the end-to-end traffic of network tenants or users, 2) distributed load-balancing that dynamically dispatches security workload over incrementally-deployed security service elements, 3) application-aware network visualization that helps to identify and locate security events, via live traffic monitoring and historical traffic replay. Live Sec has been deployed in Tsinghua University since December 2010. Currently, we are successfully supporting more than 50 users simultaneously (wireless and wired), and over 200 VM-based service elements.
Keywords :
telecommunication network management; telecommunication security; telecommunication traffic; LiveSec; access-switching layer; application-aware network visualization; distributed load-balancing; end-to-end traffic; flexible security management architecture; historical traffic replay; holistic security protection; interactive policy-enforcement; large-scale production network; live traffic monitoring; network security; scalable security management architecture; security service element; Middleboxes; Production; Protocols; Routing; Security; Switches; OpenFlow; network architecture; network management; security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Distributed Computing Systems Workshops (ICDCSW), 2012 32nd International Conference on
Conference_Location :
Macau
ISSN :
1545-0678
Print_ISBN :
978-1-4673-1423-7
Type :
conf
DOI :
10.1109/ICDCSW.2012.87
Filename :
6258192
Link To Document :
بازگشت