SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS
As a rule, certified means of ensuring network security are highly specialized complexes with a constant hardware and software platform. The main disadvantage of this architecture is the impossibility of transparent scaling of devices when the computing power of the network increases. In addition, t...
Main Authors: | , |
---|---|
Format: | Article |
Language: | Russian |
Published: |
The Fund for Promotion of Internet media, IT education, human development «League Internet Media»
2019-04-01
|
Series: | Современные информационные технологии и IT-образование |
Subjects: | |
Online Access: | http://sitito.cs.msu.ru/index.php/SITITO/article/view/495 |
id |
doaj-602e7276cddb4318a6cfccc303db655f |
---|---|
record_format |
Article |
spelling |
doaj-602e7276cddb4318a6cfccc303db655f2020-12-02T11:11:16ZrusThe Fund for Promotion of Internet media, IT education, human development «League Internet Media»Современные информационные технологии и IT-образование2411-14732019-04-0115115416310.25559/SITITO.15.201901.154-163SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMSOleg Yu. Guzev0Ivan V. Chizhov1JSC “InfoTeCS” (Russia)Lomonosov Moscow State University; Federal Research Center «Computer Science and Control» of Russian Academy of Sciences (Russia)As a rule, certified means of ensuring network security are highly specialized complexes with a constant hardware and software platform. The main disadvantage of this architecture is the impossibility of transparent scaling of devices when the computing power of the network increases. In addition, the development and support of such a complex is complicated, as the hardware platform quickly becomes obsolete, which results in the necessity for replacing it, which means that the software components for the support of new equipment need to be improved. The paper describes the scalable architecture of network security systems, allowing manufacturers to simplify the process of updating and developing information security tools. The main feature of the new architecture is the focus on the provision of a set of specialized micro-services. It is based on the principles of virtualization of network functions and it uses the concept of a unified trusted software and hardware platform. Each network function runs on a hardware and software platform running by the hypervisor operating system. It is clear that in the case of certification for the security requirements of the final products, it is necessary to ensure confidence in the hardware platform, operating system and hypervisor. However, the architecture requires unification of the software and hardware platform for all network functions. This makes it easier for developers to support end-products. Thanks to a single trusted platform, the architecture allows simplifying certification procedures for information security requirements in the process of supporting and developing the final product. Load balancing and architecture consistency are provided by means of implementing the technology of decentralized distributed registries (blockchain).http://sitito.cs.msu.ru/index.php/SITITO/article/view/495network functions virtualizationsoftware-configured networkload balancinginforma-tion securitycertificationSDNNFVOpenFlowblockchaininformation security |
collection |
DOAJ |
language |
Russian |
format |
Article |
sources |
DOAJ |
author |
Oleg Yu. Guzev Ivan V. Chizhov |
spellingShingle |
Oleg Yu. Guzev Ivan V. Chizhov SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS Современные информационные технологии и IT-образование network functions virtualization software-configured network load balancing informa-tion security certification SDN NFV OpenFlow blockchain information security |
author_facet |
Oleg Yu. Guzev Ivan V. Chizhov |
author_sort |
Oleg Yu. Guzev |
title |
SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS |
title_short |
SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS |
title_full |
SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS |
title_fullStr |
SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS |
title_full_unstemmed |
SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS |
title_sort |
scalable architecture of network security systems |
publisher |
The Fund for Promotion of Internet media, IT education, human development «League Internet Media» |
series |
Современные информационные технологии и IT-образование |
issn |
2411-1473 |
publishDate |
2019-04-01 |
description |
As a rule, certified means of ensuring network security are highly specialized complexes with a constant hardware and software platform. The main disadvantage of this architecture is the impossibility of transparent scaling of devices when the computing power of the network increases. In addition, the development and support of such a complex is complicated, as the hardware platform quickly becomes obsolete, which results in the necessity for replacing it, which means that the software components for the support of new equipment need to be improved. The paper describes the scalable architecture of network security systems, allowing manufacturers to simplify the process of updating and developing information security tools. The main feature of the new architecture is the focus on the provision of a set of specialized micro-services. It is based on the principles of virtualization of network functions and it uses the concept of a unified trusted software and hardware platform. Each network function runs on a hardware and software platform running by the hypervisor operating system. It is clear that in the case of certification for the security requirements of the final products, it is necessary to ensure confidence in the hardware platform, operating system and hypervisor. However, the architecture requires unification of the software and hardware platform for all network functions. This makes it easier for developers to support end-products. Thanks to a single trusted platform, the architecture allows simplifying certification procedures for information security requirements in the process of supporting and developing the final product. Load balancing and architecture consistency are provided by means of implementing the technology of decentralized distributed registries (blockchain). |
topic |
network functions virtualization software-configured network load balancing informa-tion security certification SDN NFV OpenFlow blockchain information security |
url |
http://sitito.cs.msu.ru/index.php/SITITO/article/view/495 |
work_keys_str_mv |
AT olegyuguzev scalablearchitectureofnetworksecuritysystems AT ivanvchizhov scalablearchitectureofnetworksecuritysystems |
_version_ |
1724407041620967424 |