Abstract : By virtualizing proprietary hardware networking devices, Network Functions Virtualization (NFV) allows agile and cost-effective deployment of diverse network services for multiple tenants on top of the same physical infrastructure. As NFV relies on virtualization, and as an NFV stack typically involves several levels of abstraction and multiple co-resident tenants, this new technology also unavoidably leads to new security threats. In this paper, we take the first step toward modeling and mitigating security threats unique to NFV. Specifically, we model both cross-layer and co-residency attacks on the NFV stack. Additionally, we mitigate such threats through optimizing the virtual machine (VM) placement with respect to given constraints. The simulation results demonstrate the effectiveness of our solution.
https://hal.inria.fr/hal-03243631 Contributor : Hal IfipConnect in order to contact the contributor Submitted on : Monday, May 31, 2021 - 5:59:39 PM Last modification on : Monday, May 31, 2021 - 6:08:47 PM
File
Restricted access
To satisfy the distribution rights of the publisher, the document is embargoed
until : 2023-01-01
Nawaf Alhebaishi, Lingyu Wang, Sushil Jajodia. Modeling and Mitigating Security Threats in Network Functions Virtualization (NFV). 34th IFIP Annual Conference on Data and Applications Security and Privacy (DBSec), Jun 2020, Regensburg, Germany. pp.3-23, ⟨10.1007/978-3-030-49669-2_1⟩. ⟨hal-03243631⟩