Theory and implementation of a virtualisation level Future Internet defence in depth architecture

Jerzy Konorski , Piotr Pacyna , Grzegorz Kołaczek , Zbigniew Kotulski , Krzysztof Cabaj , Paweł Szałachowski


An EU Future Internet Engineering project currently underway in Poland defines three parallel internets (PIs). The emerging IIP system (IIPS, abbreviating the project's Polish name), has a four-level architecture, with level 2 responsible for creation of virtual resources of the PIs. This paper proposes a three-tier security architecture to address level 2 threats of unauthorised traffic injection and IIPS traffic manipulation or forging. It is argued that the measures to be taken differ in nature from those ensuring classical security attributes. A combination of hard- and soft-security mechanisms produces node reputation and trust metrics, which permits to eliminate or ostracise misbehaving nodes. Experiments carried out in a small-scale IIPS testbed are briefly discussed.
Journal seriesInternational Journal of Trust Management in Computing and Communications, ISSN 2048-8378, [2048-8386]
Issue year2013
Keywords in Polishwykrywanie incydentów bezpieczeństwa, wykrywanie anomalii, architektura bezpieczeństwa
Keywords in EnglishFuture Internet project; virtualisation; security architecture; HMAC; hash-based message authentication code; anomaly detection; reputation systems; trust management; Poland; parallel internets; virtual resources; node reputation; misbehaving nodes; defence in depth; network security.
