发明名称 Technologies for scalable security architecture of virtualized networks
摘要 Technologies for performing security monitoring services of a network functions virtualization (NFV) security architecture that includes an NVF security services controller and one or more NFV security services agents. The NFV security services controller is configured to transmit a security monitoring policy to the NFV security services agents and enforce the security monitoring policy at the NFV security services agents. The NFV security services agents are configured to monitor telemetry data and package at least a portion of the telemetry for transmission to an NFV security monitoring analytics system of the NFV security architecture for security threat analysis. Other embodiments are described and claimed.
申请公布号 US9560078(B2) 申请公布日期 2017.01.31
申请号 US201514709168 申请日期 2015.05.11
申请人 Intel Corporation 发明人 Sood Kapil;Young Valerie J.;Venkatachalam Muthaiah;Nedbal Manuel
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Barnes & Thornburg LLP 代理人 Barnes & Thornburg LLP
主权项 1. A network functions virtualization (NFV) security services controller of an NFV security architecture for managing security monitoring services of the NFV security architecture, the NFV security controller comprising: one or more hardware processors; and one or more data storage devices having stored therein a plurality of instructions that, when executed by the one or more hardware processors, cause the NFV security services controller to: transmit a security monitoring policy, via a secure communication channel, to one or more NFV security services agents distributed in a virtual network function (VNF) infrastructure of the NFV security architecture via an NFV security services provider of a virtual infrastructure manager (VIM) of the NFV security architecture, wherein the security monitoring policy comprises a set of monitoring rules usable by the NFV security services agents to monitor telemetry data of the NFV security architecture and adjust configuration settings of the NFV security services agents; andenforce the security monitoring policy transmitted to the one or more security monitoring components of the NFV security architecture; andaudit telemetry data stored at an audit database in network communication with the NFV security services controller, wherein the telemetry data is timestamped by a secure clock corresponding to the NFV security services agent that transmitted the telemetry data to the audit database, and wherein to audit the telemetry data comprises to (i) verify the telemetry data and (ii) sequence the telemetry data.
地址 Santa Clara CA US