Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Intent-Based Attack Mitigation through Opportunistic Synchronization of Micro-Services
Nguyen, Do Duc Anh; Alain, Pierre; Autrel, Fabien et al.
2024In 2024 IEEE 10th International Conference on Network Softwarization, NetSoft 2024
Peer reviewed
 

Files


Full Text
PhD_Symposium_NetSoft_2024.pdf
Author postprint (592.52 kB) Creative Commons License - Attribution
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Decentralized mitigation; IBN; micro-services; Opportunistic synchronization; Reaction policy; Cyber-attacks; Decentralised; Digital infrastructures; Error prone tasks; Intent-based networking; Micro services; Security management; Computer Networks and Communications; Software; Safety, Risk, Reliability and Quality
Abstract :
[en] The escalating number of cyberattacks poses a significant threat to digital infrastructures. Defining and deploying accurate countermeasures is challenging because of (1) the variety of threats and their possible evolution over time and (2) the need to enforce them as fast as possible, especially for fast-propagating attacks. Intent-Based Networking (IBN) stands for a promising solution for security management, especially to mitigate attacks through the specification of reaction intents, saving time and avoiding error-prone tasks. Nevertheless, most current IBN solutions rely on centralized architectures performing time-consuming operations, which makes them inappropriate to timely deploy countermeasures, especially in the case of fast-propagating attacks spreading large-scale systems. As a solution to shorten the reaction time while supporting scalability, we first consider fast micro-services technologies (e.g., Unikernels) as the substrate of security functions acting as Policy Enforcement Points (PEP). Second, we propose to enable an opportunistic synchronization of those PEPs to react, at least partially but autonomously, against the ongoing attacks in a decentralized fashion. Such a solution raises challenges related to the consistency and performance of the overall enforced reaction policies. This paper presents the early stage of the PhD, outlining the specific challenges, limitations, and research required to leverage decentralized reaction using opportunistic synchronization of micro-services in an IBN framework for security.
Disciplines :
Computer science
Author, co-author :
Nguyen, Do Duc Anh;  IMT Atlantique, SOTERN - IRISA (UMR CNRS 6074), France
Alain, Pierre;  Université de Rennes, SOTERN - IRISA (UMR CNRS 6074), France
Autrel, Fabien;  IMT Atlantique, SOTERN - IRISA (UMR CNRS 6074), France
Bouabdallah, Ahmed;  IMT Atlantique, SOTERN - IRISA (UMR CNRS 6074), France
FRANCOIS, Jérôme  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SEDAN ; Inria Nancy Grand Est, France
External co-authors :
yes
Language :
English
Title :
Intent-Based Attack Mitigation through Opportunistic Synchronization of Micro-Services
Publication date :
2024
Event name :
2024 IEEE 10th International Conference on Network Softwarization (NetSoft) - PhD Symposium
Event place :
Saint Louis, Usa
Event date :
24-06-2024 => 28-06-2024
Audience :
International
Main work title :
2024 IEEE 10th International Conference on Network Softwarization, NetSoft 2024
Publisher :
Institute of Electrical and Electronics Engineers Inc.
ISBN/EAN :
9798350369588
Peer reviewed :
Peer reviewed
Funding text :
This work has been partially supported by the French National Research Agency under the France 2030 label (Superviz ANR-22-PECY-0008). The views reflected herein do not necessarily reflect the opinion of the French government.
Available on ORBilu :
since 19 December 2024

Statistics


Number of views
101 (0 by Unilu)
Number of downloads
74 (0 by Unilu)

Scopus citations®
 
1
Scopus citations®
without self-citations
1
OpenCitations
 
0
OpenAlex citations
 
0

Bibliography


Similar publications



Contact ORBilu