Customized Network Security for Cloud Service

Customized Network Security for Cloud Service
复制标题

DOI:
10.1109/tsc.2017.2725828
复制
发表时间:
2020-09
影响因子:
8.1
通讯作者:
Jin He;K. Ota;M. Dong;L. Yang;Mingyu Fan;Guangwei Wang;S. Yau
Jin He;K. Ota;M. Dong;L. Yang;Mingyu Fan;Guangwei Wang;S. Yau
中科院分区:
计算机科学2区
文献类型:
--
作者:
Jin He;K. Ota;M. Dong;L. Yang;Mingyu Fan;Guangwei Wang;S. Yau

文献摘要

相似文献

基于虚拟机监视器 (VMM) 的现代云计算平台托管着各种复杂的业务,这些业务存在许多网络安全漏洞。为了保护云计算中这些业务的网络安全,目前云计算前端部署了多个中间盒或者部分中间盒部署在云计算中。但前者成本较高、管理复杂,而且虚拟机之间缺乏网络安全防护,而后者则不能有效防范外部流量的网络攻击。针对上述挑战,我们推出了一种新颖的云服务定制网络安全(CNS),它不仅可以防止来自外部和内部流量的攻击,确保云计算服务的网络安全,还可以为云用户提供定制的网络安全服务。 CNS是通过修改Xen hypervisor来实现的,并通过各种实验证明,表明所提出的解决方案可以直接应用于云计算的广泛实际推广。
Modern cloud computing platforms based on virtual machine monitors (VMMs) host a variety of complex businesses which present many network security vulnerabilities. In order to protect network security for these businesses in cloud computing, nowadays, a number of middleboxes are deployed at front-end of cloud computing or parts of middleboxes are deployed in cloud computing. However, the former is leading to high cost and management complexity, and also lacking of network security protection between virtual machines while the latter does not effectively prevent network attacks from external traffic. To address the above-mentioned challenges, we introduce a novel customized network security for cloud service (CNS), which not only prevents attacks from external and internal traffic to ensure network security of services in cloud computing, but also affords customized network security service for cloud users. CNS is implemented by modifying the Xen hypervisor and proved by various experiments which showing the proposed solution can be directly applied to the extensive practical promotion in cloud computing.