Cloud-Native Threat Detection and Containment for Smart Manufacturing

M. Müller, D. Behnke, Patrick-Benjamin Bök, Stefan Schneider, Manuel Peuster, H. Karl
{"title":"Cloud-Native Threat Detection and Containment for Smart Manufacturing","authors":"M. Müller, D. Behnke, Patrick-Benjamin Bök, Stefan Schneider, Manuel Peuster, H. Karl","doi":"10.1109/NetSoft48620.2020.9165321","DOIUrl":null,"url":null,"abstract":"Softwarization facilitates the introduction of smart manufacturing applications in the industry. Manifold devices such as machine computers, Industrial IoT devices, tablets, smartphones and smart glasses are integrated into factory networks to enable shop floor digitalization and big data analysis. To handle the increasing number of devices and the resulting traffic, a flexible and scalable factory network is necessary which can be realized using softwarization technologies like Network Function Virtualization (NFV). However, the security risks increase with the increasing number of new devices, so that cyber security must also be considered in NFV-based networks. Therefore, extending our previous work, we showcase threat detection using a cloud-native NFV-driven intrusion detection system (IDS) that is integrated in our industrial-specific network services. As a result of the threat detection, the affected network service is put into quarantine via automatic network reconfiguration. We use the 5GTANGO service platform to deploy our developed network services on Kubernetes and to initiate the network reconfiguration. Our focus is on demonstrating the automatic network reconfiguration that is triggered by the IDS.","PeriodicalId":239961,"journal":{"name":"2020 6th IEEE Conference on Network Softwarization (NetSoft)","volume":"49 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 6th IEEE Conference on Network Softwarization (NetSoft)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NetSoft48620.2020.9165321","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Softwarization facilitates the introduction of smart manufacturing applications in the industry. Manifold devices such as machine computers, Industrial IoT devices, tablets, smartphones and smart glasses are integrated into factory networks to enable shop floor digitalization and big data analysis. To handle the increasing number of devices and the resulting traffic, a flexible and scalable factory network is necessary which can be realized using softwarization technologies like Network Function Virtualization (NFV). However, the security risks increase with the increasing number of new devices, so that cyber security must also be considered in NFV-based networks. Therefore, extending our previous work, we showcase threat detection using a cloud-native NFV-driven intrusion detection system (IDS) that is integrated in our industrial-specific network services. As a result of the threat detection, the affected network service is put into quarantine via automatic network reconfiguration. We use the 5GTANGO service platform to deploy our developed network services on Kubernetes and to initiate the network reconfiguration. Our focus is on demonstrating the automatic network reconfiguration that is triggered by the IDS.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
面向智能制造的云原生威胁检测和遏制
软件化有助于在行业中引入智能制造应用。机器计算机、工业物联网设备、平板电脑、智能手机和智能眼镜等多种设备被集成到工厂网络中,以实现车间数字化和大数据分析。为了处理越来越多的设备和由此产生的流量,一个灵活的、可扩展的工厂网络是必要的,这可以使用网络功能虚拟化(NFV)等软件技术来实现。但是,随着新设备数量的增加,安全风险也在增加,因此基于nfv的网络也必须考虑网络安全问题。因此,我们扩展了之前的工作,展示了使用云原生nfv驱动的入侵检测系统(IDS)进行威胁检测,该系统集成在我们的工业特定网络服务中。检测到威胁后,通过自动网络重新配置将受影响的网络服务隔离。我们使用5GTANGO服务平台在Kubernetes上部署我们开发的网络服务,并启动网络重构。我们的重点是演示由IDS触发的自动网络重新配置。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Cloud-native SDN Controller Based on Micro-Services for Transport Networks Techno-economic evaluation of a brokerage role in the context of integrated satellite-5G networks Attack Detection on the Software Defined Networking Switches Linking QoE and Performance Models for DASH-based Video Streaming ANI: Abstracted Network Inventory for Streamlined Service Placement in Distributed Clouds
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1