Flexible Data Plane for Zero Trust Security in Data Centers and Its Instantiation using ONOS Intent Framework

  • Chang H.
  • Lakshman T.
  • Mukherjee S.
  • Wang L.

Zero Trust security in a data center requires that every entity (VMs, hosts, users, etc.) within the data center is protected from one another through strict traffic scrutiny. Current solutions enforce this by controlling the reachability of traffic in and out of any entity. However, the security functions must be more stringent with stateful operations to enforce zero trust. This paper addresses this issue by enforcing application of stateful security operations to entities in an automated fashion. The control plane is realized by extending the Intent Framework of Open Network Operating System (ONOS) to handle security policies that go beyond reachability checks. Stateful data plane operations are realized via elastic data plane services (DPS) running alongside the software switch in the hotst's hypervisor. We implement a prototype based on our extended ONOS and the Open vSwitch (OVS) as a software switch. We choose the Snort intrusion detection as an example DPS since it cannot be instantiated as simple flow rules.

Recent Publications

August 09, 2017

A Cloud Native Approach to 5G Network Slicing

  • Francini A.
  • Miller R.
  • Sharma S.

5G networks will have to support a set of very diverse and often extreme requirements. Network slicing offers an effective way to unlock the full potential of 5G networks and meet those requirements on a shared network infrastructure. This paper presents a cloud native approach to network slicing. The cloud ...

August 01, 2017

Modeling and simulation of RSOA with a dual-electrode configuration

  • De Valicourt G.
  • Liu Z.
  • Violas M.
  • Wang H.
  • Wu Q.

Based on the physical model of a bulk reflective semiconductor optical amplifier (RSOA) used as a modulator in radio over fiber (RoF) links, the distributions of carrier density, signal photon density, and amplified spontaneous emission photon density are demonstrated. One of limits in the use of RSOA is the lower ...

July 12, 2017

PrivApprox: Privacy-Preserving Stream Analytics

  • Chen R.
  • Christof Fetzer
  • Le D.
  • Martin Beck
  • Pramod Bhatotia
  • Thorsten Strufe

How to preserve users' privacy while supporting high-utility analytics for low-latency stream processing? To answer this question: we describe the design, implementation and evaluation of PRIVAPPROX, a data analytics system for privacy-preserving stream processing. PRIVAPPROX provides three properties: (i) Privacy: zero-knowledge privacy (ezk) guarantees for users, a privacy bound tighter ...