SDN-based Runtime Security Enforcement Approach for Privacy Preservation of Dynamic Web Service Composition
Yunfei Meng, Zhiqiu Huang, Guohua Shen, Changbo Ke

TL;DR
This paper presents an SDN-based runtime security enforcement approach that enhances privacy preservation in dynamic Web service composition by controlling access at the network level, effectively preventing illegal access and attacks.
Contribution
It introduces a novel security policy transformation and runtime monitoring method using SDN controllers for privacy preservation in dynamic Web service environments.
Findings
Effective prevention of illegal network access and service leakage.
The approach maintains high accuracy and performance with increasing policy complexity.
Experimental validation confirms the method's feasibility and efficiency.
Abstract
Aiming at the privacy preservation of dynamic Web service composition, this paper proposes a SDN-based runtime security enforcement approach for privacy preservation of dynamic Web service composition. The main idea of this approach is that the owner of service composition leverages the security policy model (SPM) to define the access control relationships that service composition must comply with in the application plane, then SPM model is transformed into the low-level security policy model (RSPM) containing the information of SDN data plane, and RSPM model is uploaded into the SDN controller. After uploading, the virtual machine access control algorithm integrated in the SDN controller monitors all of access requests towards service composition at runtime. Only the access requests that meet the definition of RSPM model can be forwarded to the target terminal. Any access requests that…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware-Defined Networks and 5G · Network Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting
