AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (2.5 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Open Access

Collaborative Network Security in Multi-Tenant Data Center for Cloud Computing

Zhen Chen( )Wenyu DongHang LiPeng ZhangXinming ChenJunwei Cao( )
Research Institute of Information Technology and Tsinghua National Lab for Information Science and Technology, Tsinghua University, Beijing 100084, China
Department of Computer Science and Technology, Tsinghua University, Beijing 100084, China
Department of Computer Science and Technology, PLA Univ. of Info. & Eng., Zhengzhou 450001, China
Department of Electronic and Information Engineering, Xi’an Jiaotong University, Xi’an 710049, China
Department of Electrical and Computer Engineering, University of Massachusetts, MA 01003, USA
Show Author Information

Abstract

A data center is an infrastructure that supports Internet service. Cloud computing is rapidly changing the face of the Internet service infrastructure, enabling even small organizations to quickly build Web and mobile applications for millions of users by taking advantage of the scale and flexibility of shared physical infrastructures provided by cloud computing. In this scenario, multiple tenants save their data and applications in shared data centers, blurring the network boundaries between each tenant in the cloud. In addition, different tenants have different security requirements, while different security policies are necessary for different tenants. Network virtualization is used to meet a diverse set of tenant-specific requirements with the underlying physical network, enabling multi-tenant datacenters to automatically address a large and diverse set of tenants requirements. In this paper, we propose the system implementation of vCNSMS, a collaborative network security prototype system used in a multi-tenant data center. We demonstrate vCNSMS with a centralized collaborative scheme and deep packet inspection with an open source UTM system. A security level based protection policy is proposed for simplifying the security rule management for vCNSMS. Different security levels have different packet inspection schemes and are enforced with different security plugins. A smart packet verdict scheme is also integrated into vCNSMS for intelligence flow processing to protect from possible network attacks inside a data center network.

References

【1】
【1】
 
 
Tsinghua Science and Technology
Pages 82-94

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Chen Z, Dong W, Li H, et al. Collaborative Network Security in Multi-Tenant Data Center for Cloud Computing. Tsinghua Science and Technology, 2014, 19(1): 82-94. https://doi.org/10.1109/TST.2014.6733211

1405

Views

166

Downloads

41

Crossref

N/A

Web of Science

54

Scopus

0

CSCD

Received: 18 December 2013
Accepted: 24 December 2013
Published: 07 February 2014
© The author(s) 2014