Abstract
In response to the swift evolution of network technologies, traditional security measures centered on perimeter defenses have become inadequate for the needs of present-day distributed systems. Contemporary paradigms, such as Zero Trust Networking (ZTN) and Software Defined Perimeters (SDP), enhance network security by implementing a “never trust, always verify” model. Establishing trust is a crucial part of security policies that govern access to network resources. Automated policy management, continuous monitoring, and data analytics are required to ensure these policies’ reliability. Intent-Based Networking (IBN) can meet these requirements by translating high-level security policies into network configurations, thus bolstering network management and policy enforcement. Integrating IBN with blockchain technology creates a single source of truth (SSoT) for intent translation, providing an immutable, transaction-based ledger to verify each interaction. Our proposed design employs the open-source Hyperledger Besu for a permissioned blockchain implementation, alongside a secure network overlay from NetFoundry (OpenZiti). An IBN system is integrated as a management layer for secure policy creation. These policies, in the form of intents, are stored in the blockchain. Additionally, an event listener mechanism is designed to automatically translate the intents from the blockchain into network overlay configurations. Furthermore, a synchronizer ensures that the state of the network overlay remains aligned with the policy configurations defined by the intents in the blockchain. The overall research aims to achieve a Zero Touch and Trust (ZT&T) network system.
| Original language | English |
|---|---|
| Title of host publication | APNOMS 2023 - 24th Asia-Pacific Network Operations and Management Symposium |
| Subtitle of host publication | Intelligent Management for Enabling the Digital Transformation |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| Pages | 77-82 |
| Number of pages | 6 |
| ISBN (Electronic) | 9788995004395 |
| State | Published - 2023 |
| Externally published | Yes |
| Event | 24th Asia-Pacific Network Operations and Management Symposium, APNOMS 2023 - Sejong, Korea, Republic of Duration: 6 Sep 2023 → 8 Sep 2023 |
Publication series
| Name | APNOMS 2023 - 24th Asia-Pacific Network Operations and Management Symposium: Intelligent Management for Enabling the Digital Transformation |
|---|
Conference
| Conference | 24th Asia-Pacific Network Operations and Management Symposium, APNOMS 2023 |
|---|---|
| Country/Territory | Korea, Republic of |
| City | Sejong |
| Period | 6/09/23 → 8/09/23 |
Bibliographical note
Publisher Copyright:Copyright 2023 KICS.
Keywords
- Blockchain
- IBN
- Security Policies
- Software Defined Perimeter
- Zero Trust Network
ASJC Scopus subject areas
- Artificial Intelligence
- Computer Networks and Communications
- Information Systems
- Information Systems and Management
- Safety, Risk, Reliability and Quality