• DocumentCode
    257223
  • Title

    Tualatin: Towards network security service provision in cloud datacenters

  • Author

    Xiang Wang ; Zhi Liu ; Jun Li ; Baohua Yang ; Yaxuan Qi

  • Author_Institution
    Dept. of Autom., Tsinghua Univ., Beijing, China
  • fYear
    2014
  • fDate
    4-7 Aug. 2014
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Multi-tenant infrastructures deployed in cloud datacenters need network security protection. However, the rigid control mechanism of current security middleboxes induces inflexible orchestration, limiting the agile and on-demand security provision in virtualized datacenters. This paper presents Tualatin, a consolidated framework of delivering security services in multi-tenant datacenters. It meets security requirements of different scenarios by hardware and software co-design. Leveraging Software-Defined Networking (SDN) and OpenFlow techniques, Tualatin provides fine-grained security protection in dynamically changing network topologies, where both switches and security middleboxes are programmatically controlled by logically centralized controllers. With service-level APIs exposed, Tualatin could be easily integrated with other Cloud Management System (CMS). A proof-of-concept system has been deployed in a Tier-IV datacenter, providing customizable network security services for tenant Virtual Private Cloud (VPC) infrastructure.
  • Keywords
    cloud computing; computer centres; security of data; CMS; OpenFlow techniques; SDN; Tualatin; VPC infrastructure; cloud datacenters; cloud management system; customizable network security services; hardware and software codesign; multitenant datacenters; multitenant infrastructures; network security protection; network security service provision; on-demand security provision; proof-of-concept system; rigid control mechanism; service-level API; software-defined networking; virtual private cloud; virtualized datacenters; Cloud computing; Communication networks; Engines; Hardware; Inspection; Middleboxes; Security; Cloud Datacenter; Network Security; Software-Defined Networking;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communication and Networks (ICCCN), 2014 23rd International Conference on
  • Conference_Location
    Shanghai
  • Type

    conf

  • DOI
    10.1109/ICCCN.2014.6911782
  • Filename
    6911782