Recent management paradigms for software-defined infrastructures bring more agility in the creation and operation of digital services, but also introduce new cyber-security issues due to fast-changing environments and dynamic topologies. Rigid and statically-configured architectures are no more suitable for managing cyber-security functions in mixed cloud/6G/IoT environments, since the number, capabilities, and providers of such functions are expected to change at run-time. In this paper, we propose a context discovery protocol based on the OpenC2 language. It recursively queries Context Providers that describe services, relationships, and cyber-security functions, in order to build the whole service context graph, also encompassing multiple networks and domains. We provide a working implementation that covers OpenStack and Kubernetes environments, and we validate it in a software-defined 5 G testbed. Our approach provides a more general context and uniform interface than existing service discovery protocols; furthermore, the domain-specific language enables seamless integration in cyber-security frameworks.

Context Discovery for Digital Service Chain with OpenC2

Repetto, Matteo
Ultimo
Conceptualization
2025

Abstract

Recent management paradigms for software-defined infrastructures bring more agility in the creation and operation of digital services, but also introduce new cyber-security issues due to fast-changing environments and dynamic topologies. Rigid and statically-configured architectures are no more suitable for managing cyber-security functions in mixed cloud/6G/IoT environments, since the number, capabilities, and providers of such functions are expected to change at run-time. In this paper, we propose a context discovery protocol based on the OpenC2 language. It recursively queries Context Providers that describe services, relationships, and cyber-security functions, in order to build the whole service context graph, also encompassing multiple networks and domains. We provide a working implementation that covers OpenStack and Kubernetes environments, and we validate it in a software-defined 5 G testbed. Our approach provides a more general context and uniform interface than existing service discovery protocols; furthermore, the domain-specific language enables seamless integration in cyber-security frameworks.
2025
Istituto di Matematica Applicata e Tecnologie Informatiche - IMATI - Sede Secondaria Genova
979-8-3315-4345-7
Context discovery; OpenC2; situational awareness
File in questo prodotto:
File Dimensione Formato  
ctxd.pdf

accesso aperto

Descrizione: Preprint
Tipologia: Documento in Pre-print
Licenza: Creative commons
Dimensione 528.72 kB
Formato Adobe PDF
528.72 kB Adobe PDF Visualizza/Apri
Context_Discovery_for_Digital_Service_Chain_with_OpenC2.pdf

solo utenti autorizzati

Descrizione: Versione pubblicata
Tipologia: Versione Editoriale (PDF)
Licenza: NON PUBBLICO - Accesso privato/ristretto
Dimensione 613.8 kB
Formato Adobe PDF
613.8 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/550522
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
social impact