...
首页> 外文期刊>Computer networks >Verification of firewall reconfiguration for virtual machines migrations in the cloud
【24h】

Verification of firewall reconfiguration for virtual machines migrations in the cloud

机译:验证防火墙重新配置以在云中迁移虚拟机

获取原文
获取原文并翻译 | 示例
           

摘要

While elasticity is valuable to the cloud, it may introduce security flaws due to misconfiguration after virtual machines migration. In this paper, we propose an automated approach to verify distributed firewalls reconfiguration after migration. To this end, we elaborate a language that captures distributed stateless and stateful firewalls with their underlying semantics. Integrated to Cloud Calculus, it allows specifying distributed firewalls topology. We also define semantic equivalence over stateful firewalls that forms the base for our verification approach. Furthermore, we define the property of network access control and state preservation using the concepts of soundness and completeness of firewall configurations. Additionally, we use constraint satisfaction problems to reason about our defined preservation property. Finally, we investigate the correctness and scalability of our approach. (C) 2015 Elsevier B.V. All rights reserved.
机译:尽管弹性对云非常重要,但由于虚拟机迁移后配置错误,它可能会引入安全漏洞。在本文中,我们提出了一种自动方法来验证迁移后分布式防火墙的重新配置。为此,我们精心设计了一种语言,可捕获具有其底层语义的分布式无状态和有状态防火墙。集成到Cloud Calculus中,它允许指定分布式防火墙拓扑。我们还定义了状态防火墙上的语义对等,这构成了我们验证方法的基础。此外,我们使用防火墙配置的健全性和完整性来定义网络访问控制和状态保存的属性。此外,我们使用约束满足问题来推断我们定义的保存属性。最后,我们研究了我们方法的正确性和可扩展性。 (C)2015 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号