NFV-based protection: the SHIELD approach

Autor/a

Gardikis, Georgios

Gaston, Bernat

Jacquin, Ludovic

Lioy, Antonio

Data de publicació

2017-11



Resum

This demo showcases some of the capabilities foreseen for the security infrastructure designed by the H2020 SHIELD project. SHIELD exploits NFV for adaptive monitoring of an IT infrastructure and for feeding the data to an analytics engine to detect attacks in real time. An intelligent reaction system is then activated to reconfigure the SDN/NFV infrastructure so that the attacks are thwarted. The SDN/NFV infrastructure itself is protected from attacks thanks to trusted computing techniques, that permit to quickly identify misbehaving nodes. The proposed demo will present detection and reaction to a DDoS attack (by on-the-fly deployment of new virtual network security functions and/or change of network paths), as well as detection of software attacks against virtual network functions (executed in Docker containers) and unauthorized modification of the SDN switching tables and NFV configurations.

Tipus de document

Objecte de conferència

Llengua

Anglès

Matèries CDU

621.3 - Enginyeria elèctrica. Electrotècnia. Telecomunicacions

Paraules clau

Xarxes d'àrea extensa (Ordinadors); Distributed Artificial Intelligence; Security; 5G & Internet of Things; Cybersecurity; Software Defined Networking

Pàgines

3 p.

Publicat per

IEEE

És versió de

IEEE Conference on Network Function Virtualization and Software Defined Networks (IEEE NFV SDN), Berlin, 2017.

Documents

main.pdf

252.3Kb

 

Drets

© 2017 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.

Aquest element apareix en la col·lecció o col·leccions següent(s)