Building a Software Defined Perimeter (SDP) for Network Introspection


연구 분야: Networking



학회: 2021 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)


초록

In this paper, we introduce a novel enhanced Software Defined Perimeter (SDP) architecture that provides defense-in-depth security controls across any network. SDP is a network paradigm that extends traditional perimeter security controls to protect services and systems that exist beyond the physical perimeter of a network. Primarily through authentication, standard SDP enhances security by effectively hiding systems and services on the public Internet from unauthorized packets. Our SDP architecture extends the SDP Specification by enhancing control channel messages to the SDP Controller. Through experiments in AWS, we show that by streaming real-time telemetry about the SDP data channel to the Controller, it can enable defense-in-depth functionality without significant impact to end-user bandwidth.


Author Profile
Michael Lefebvre

AT&T Center for Virtualization Southern Methodist University Dallas TX USA

Austria
Author Profile
Suku Nair

AT&T Center for Virtualization Southern Methodist University Dallas TX USA

Austria
Author Profile
Daniel W. Engels

AT&T Center for Virtualization Southern Methodist University Dallas TX USA

Austria

📄 논문 정보

발행 연도 2021년
인용수 7
출판 국가 Austria
사이트 IEEE
좋아요 수 0

연관 논문 목록 (328건)