Chang Chen, Xiaohe Hu, et al.
Tsinghua Science and Technology
Multi-tenant infrastructures deployed in cloud datacenters need network security protection. However, the rigid control mechanism of current security middleboxes induces inflexible orchestration, limiting the agile and on-demand security provision in virtualized datacenters. This paper presents Tualatin, a consolidated framework of delivering security services in multi-tenant datacenters. It meets security requirements of different scenarios by hardware and software co-design. Leveraging Software-Defined Networking (SDN) and OpenFlow techniques, Tualatin provides fine-grained security protection in dynamically changing network topologies, where both switches and security middleboxes are programmatically controlled by logically centralized controllers. With service-level APIs exposed, Tualatin could be easily integrated with other Cloud Management System (CMS). A proof-of-concept system has been deployed in a Tier-IV datacenter, providing customizable network security services for tenant Virtual Private Cloud (VPC) infrastructure.
Chang Chen, Xiaohe Hu, et al.
Tsinghua Science and Technology
Zhi Liu, Xiang Wang, et al.
ICNC 2015
Zhi Liu, Xiang Wang, et al.
SIGCOMM 2015
Baohua Yang, Junda Liu, et al.
INFOCOM 2014