Back to Search
Start Over
Content-based security and protected core networking with software-defined networks
- Source :
- IEEE Communications Magazine. 54:138-144
- Publication Year :
- 2016
- Publisher :
- Institute of Electrical and Electronics Engineers (IEEE), 2016.
-
Abstract
- Successful execution of future network-centric military operations relies on effective enforcement of both need-to-know and responsibility- to-share principles. In modern military missions and coalitions, which have an increasingly agile character, a promising solution is to enforce security policies based on the properties of individual information objects - we call this approach content-based security. This article discusses the enforcement of content-based security policies at the different layers of the TCP/ IP model, and introduces a proof-of-concept implementation of a content-based protection and release mechanism in a software-defined networking environment. Our aim is to provide consistent enforcement of security policies across multiple system layers and multiple security dimensions (confidentiality, integrity, and availability). The results of an analysis of a concrete example of a software-defined network emulated in Mininet are encouraging and confirm the effectiveness of our approach with respect to improving protection of data in transit. The work presented in this article offers a basis for further research in this area.
- Subjects :
- Computer Networks and Communications
Computer science
computer.internet_protocol
Covert channel
Access control
02 engineering and technology
Asset (computer security)
Security policy
Computer security
computer.software_genre
Logical security
Security testing
Security information and event management
Internet protocol suite
0202 electrical engineering, electronic engineering, information engineering
Electrical and Electronic Engineering
Enforcement
Cloud computing security
business.industry
020206 networking & telecommunications
Information security
Computer security model
Computer Science Applications
Security service
Software security assurance
Network Access Control
Security through obscurity
Security convergence
Network security policy
020201 artificial intelligence & image processing
Software-defined networking
business
computer
Subjects
Details
- ISSN :
- 01636804
- Volume :
- 54
- Database :
- OpenAIRE
- Journal :
- IEEE Communications Magazine
- Accession number :
- edsair.doi...........6cc627b9c64031616d1e00914b354943