PALANTIR: An NFV-Based Security-as-a-Service Approach for Automating Threat Mitigation

Author:

Compastié Maxime1ORCID,López Martínez Antonio2ORCID,Fernández Carolina13ORCID,Gil Pérez Manuel2ORCID,Tsarsitalidis Stylianos4ORCID,Xylouris George5ORCID,Mlakar Izidor67ORCID,Kourtis Michail Alexandros5ORCID,Šafran Valentino6ORCID

Affiliation:

1. Cybersecurity Department, i2CAT Foundation, 08034 Barcelona, Spain

2. Department of Information and Communication Engineering, University of Murcia, 30100 Murcia, Spain

3. Department of Information and Communication Technologies, Universitat Pompeu Fabra, 08018 Barcelona, Spain

4. UBITECH Ubiquitous Solutions, 15231 Athens, Greece

5. ORION Innovations PC, 11744 Athens, Greece

6. Faculty of Electrical Engineering and Computer Science, University of Maribor, 2000 Maribor, Slovenia

7. Sfera IT d.o.o., 2000 Maribor, Slovenia

Abstract

Small and medium enterprises are significantly hampered by cyber-threats as they have inherently limited skills and financial capacities to anticipate, prevent, and handle security incidents. The EU-funded PALANTIR project aims at facilitating the outsourcing of the security supervision to external providers to relieve SMEs/MEs from this burden. However, good practices for the operation of SME/ME assets involve avoiding their exposure to external parties, which requires a tightly defined and timely enforced security policy when resources span across the cloud continuum and need interactions. This paper proposes an innovative architecture extending Network Function Virtualisation to externalise and automate threat mitigation and remediation in cloud, edge, and on-premises environments. Our contributions include an ontology for the decision-making process, a Fault-and-Breach-Management-based remediation policy model, a framework conducting remediation actions, and a set of deployment models adapted to the constraints of cloud, edge, and on-premises environment(s). Finally, we also detail an implementation prototype of the framework serving as evaluation material.

Funder

European Union Horizon 2020 research and innovation programme

Publisher

MDPI AG

Subject

Electrical and Electronic Engineering,Biochemistry,Instrumentation,Atomic and Molecular Physics, and Optics,Analytical Chemistry

Reference63 articles.

1. (2023, January 11). 2022 Global Threat Report. Available online: https://www.crowdstrike.com/global-threat-report.

2. (2023, January 11). SMBs Are Fighting against All Odds in Today’s Cyber Landscape. Available online: https://pages.checkpoint.com/smb-2021-security-report.html.

3. (2023, January 11). Managing the Trend of Growing IT Complexity. Available online: https://mysecuritymarketplace.com/reports/managing-the-trend-of-growing-it-complexity.

4. (2023, January 11). 2021 DBIR Master’s Guide. Available online: https://www.verizon.com/business/resources/reports/dbir/2021/masters-guide/.

5. Technology Pillars in the Architecture of Future 5G Mobile Networks: NFV, MEC and SDN;Blanco;Comput. Stand. Interfaces,2017

Cited by 5 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Knowledge Graphs and Semantic Web Tools in Cyber Threat Intelligence: A Systematic Literature Review;Journal of Cybersecurity and Privacy;2024-08-01

2. Efficient SFC Protection Method against Network Attack Risks in Air Traffic Information Networks;Electronics;2024-07-07

3. Towards Smarter Security Orchestration and Automatic Response for CPS and IoT;2023 IEEE International Conference on Cloud Computing Technology and Science (CloudCom);2023-12-04

4. An Approach for Intelligent Behaviour-Based Threat Modelling with Explanations;2023 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN);2023-11-07

5. 6GENABLERS: A Holistic Approach to Establish Pervasive Trust in 6G Networks;2023 IEEE 28th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks (CAMAD);2023-11-06

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3