NFVGuard: Verifying the Security of Multilevel Network Functions Virtualization (NFV) Stack

Alaa Oqaily, L.T. Sudershan, Yosr Jarraya, Suryadipta Majumdar, Mengyuan Zhang, Makan Pourzandi, Lingyu Wang, Mourad Debbabi

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

Network Functions Virtualization (NFV) enables agile and cost-effective deployment of multi-tenant network services on top of a cloud infrastructure. However, the multi-tenant and multilevel nature of NFV may lead to novel security challenges, such as stealthy attacks exploiting potential inconsistencies between different levels of the NFV stacks. Consequently, the security compliance of a multilevel NFV stack cannot be sufficiently established using existing solutions, which typically focus on one level. Moreover, the naive approach of separately verifying every level could be expensive or even infeasible. In this paper, we propose, NFVGuard, the first multilevel approach to the formal security verification of NFV stacks. Our key idea is to conduct the security verification at only one level, and then assure that verification result for other levels by verifying the consistency between adjacent levels. We integrate NFVGuard with OpenStack/Tacker, a popular platform for the NFV deployment, and experimentally evaluate its effectiveness.
Original languageEnglish
Title of host publicationProceedings - 2020 IEEE International Conference on Cloud Computing Technology and Science, CloudCom 2020
PublisherIEEE Computer Society
Pages33-40
ISBN (Electronic)9780738143767
DOIs
Publication statusPublished - 1 Dec 2020
Externally publishedYes
Event12th IEEE International Conference on Cloud Computing Technology and Science, CloudCom 2020 - Bangkok, Thailand
Duration: 14 Dec 202017 Dec 2020

Publication series

NameProceedings of the International Conference on Cloud Computing Technology and Science, CloudCom
ISSN (Print)2330-2194
ISSN (Electronic)2330-2186

Conference

Conference12th IEEE International Conference on Cloud Computing Technology and Science, CloudCom 2020
Country/TerritoryThailand
CityBangkok
Period14/12/2017/12/20

Fingerprint

Dive into the research topics of 'NFVGuard: Verifying the Security of Multilevel Network Functions Virtualization (NFV) Stack'. Together they form a unique fingerprint.

Cite this