SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS

As a rule, certified means of ensuring network security are highly specialized complexes with a constant hardware and software platform. The main disadvantage of this architecture is the impossibility of transparent scaling of devices when the computing power of the network increases. In addition, t...

Full description

Bibliographic Details
Main Authors: Oleg Yu. Guzev, Ivan V. Chizhov
Format: Article
Language:Russian
Published: The Fund for Promotion of Internet media, IT education, human development «League Internet Media» 2019-04-01
Series:Современные информационные технологии и IT-образование
Subjects:
SDN
NFV
Online Access:http://sitito.cs.msu.ru/index.php/SITITO/article/view/495
id doaj-602e7276cddb4318a6cfccc303db655f
record_format Article
spelling doaj-602e7276cddb4318a6cfccc303db655f2020-12-02T11:11:16ZrusThe Fund for Promotion of Internet media, IT education, human development «League Internet Media»Современные информационные технологии и IT-образование2411-14732019-04-0115115416310.25559/SITITO.15.201901.154-163SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMSOleg Yu. Guzev0Ivan V. Chizhov1JSC “InfoTeCS” (Russia)Lomonosov Moscow State University; Federal Research Center «Computer Science and Control» of Russian Academy of Sciences (Russia)As a rule, certified means of ensuring network security are highly specialized complexes with a constant hardware and software platform. The main disadvantage of this architecture is the impossibility of transparent scaling of devices when the computing power of the network increases. In addition, the development and support of such a complex is complicated, as the hardware platform quickly becomes obsolete, which results in the necessity for replacing it, which means that the software components for the support of new equipment need to be improved. The paper describes the scalable architecture of network security systems, allowing manufacturers to simplify the process of updating and developing information security tools. The main feature of the new architecture is the focus on the provision of a set of specialized micro-services. It is based on the principles of virtualization of network functions and it uses the concept of a unified trusted software and hardware platform. Each network function runs on a hardware and software platform running by the hypervisor operating system. It is clear that in the case of certification for the security requirements of the final products, it is necessary to ensure confidence in the hardware platform, operating system and hypervisor. However, the architecture requires unification of the software and hardware platform for all network functions. This makes it easier for developers to support end-products. Thanks to a single trusted platform, the architecture allows simplifying certification procedures for information security requirements in the process of supporting and developing the final product. Load balancing and architecture consistency are provided by means of implementing the technology of decentralized distributed registries (blockchain).http://sitito.cs.msu.ru/index.php/SITITO/article/view/495network functions virtualizationsoftware-configured networkload balancinginforma-tion securitycertificationSDNNFVOpenFlowblockchaininformation security
collection DOAJ
language Russian
format Article
sources DOAJ
author Oleg Yu. Guzev
Ivan V. Chizhov
spellingShingle Oleg Yu. Guzev
Ivan V. Chizhov
SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS
Современные информационные технологии и IT-образование
network functions virtualization
software-configured network
load balancing
informa-tion security
certification
SDN
NFV
OpenFlow
blockchain
information security
author_facet Oleg Yu. Guzev
Ivan V. Chizhov
author_sort Oleg Yu. Guzev
title SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS
title_short SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS
title_full SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS
title_fullStr SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS
title_full_unstemmed SCALABLE ARCHITECTURE OF NETWORK SECURITY SYSTEMS
title_sort scalable architecture of network security systems
publisher The Fund for Promotion of Internet media, IT education, human development «League Internet Media»
series Современные информационные технологии и IT-образование
issn 2411-1473
publishDate 2019-04-01
description As a rule, certified means of ensuring network security are highly specialized complexes with a constant hardware and software platform. The main disadvantage of this architecture is the impossibility of transparent scaling of devices when the computing power of the network increases. In addition, the development and support of such a complex is complicated, as the hardware platform quickly becomes obsolete, which results in the necessity for replacing it, which means that the software components for the support of new equipment need to be improved. The paper describes the scalable architecture of network security systems, allowing manufacturers to simplify the process of updating and developing information security tools. The main feature of the new architecture is the focus on the provision of a set of specialized micro-services. It is based on the principles of virtualization of network functions and it uses the concept of a unified trusted software and hardware platform. Each network function runs on a hardware and software platform running by the hypervisor operating system. It is clear that in the case of certification for the security requirements of the final products, it is necessary to ensure confidence in the hardware platform, operating system and hypervisor. However, the architecture requires unification of the software and hardware platform for all network functions. This makes it easier for developers to support end-products. Thanks to a single trusted platform, the architecture allows simplifying certification procedures for information security requirements in the process of supporting and developing the final product. Load balancing and architecture consistency are provided by means of implementing the technology of decentralized distributed registries (blockchain).
topic network functions virtualization
software-configured network
load balancing
informa-tion security
certification
SDN
NFV
OpenFlow
blockchain
information security
url http://sitito.cs.msu.ru/index.php/SITITO/article/view/495
work_keys_str_mv AT olegyuguzev scalablearchitectureofnetworksecuritysystems
AT ivanvchizhov scalablearchitectureofnetworksecuritysystems
_version_ 1724407041620967424