A New Paradigm to Address Threats for Virtualized Services
Stefan Covaci 2018
Stefan Covaci; Matteo Repetto; Fulvio Risso;
Seiten 689-694
Jahr 2018
ISBN 978-1-5386-2667-2
ISSN 0730-3157
DOI 10.1109/COMPSAC.2018.10320
Ort Tokyo, Japan
2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC)
Monat July, 23-27
Cloud/NFV security, Situational awareness,
Distributed cyber security frameworks,

cloud computing, computer network security,
Verlag IEEE
Zusammenfassung With the uptaking of virtualization technologies and the growing usage of public cloud infrastructures, an ever larger number of applications run outside of the traditional enterprise's perimeter, and require new security paradigms that fit the typical agility and elasticity of cloud models in service creation and management. Though some recent proposals have integrated security appliances in the logical application topology, we argue that this approach is sub-optimal. Indeed, we believe that embedding security agents in virtualization containers and delegating the control logic to the software orchestrator provides a much more effective, flexible, and scalable solution to the problem. In this paper, we motivate our mindset and outline a novel framework for assessing cyber-threats of virtualized applications and services. We also review existing technologies that build the foundation of our proposal, which we are going to develop in the context of a joint research project.
