The priorities of the EC Digital Agenda state that protection against online accidents and crime has become central to consumer confidence and the online economy. This calls for an effective strategy against cyber-attacks that accurately transforms shared knowledge into actionable information while maintaining a global view of the network.
The ambition of SHIELD is to contribute towards addressing these challenges by designing and implementing an integrated framework for next-generation security-as-a-service (SecaaS) offerings.
Towards this aim, the SHIELD approach combines Network Functions Virtualisation (NFV), Big Data Analytics and Trusted Computing (TC), in order to provide an extensible, adaptable, fast, low-cost and trustworthy cybersecurity solution. It aims at delivering cybersecurity as an integrated service of virtual network infrastructures, which can be tailored for Internet Service Providers (ISPs) and enterprise customers - including SMEs - in equal terms. Virtualised Network Security Functions (vNSF) provide software instantiations of security appliances that can be dynamically deployed into a network infrastructure. In line with the NFV concept and going beyond traditional cloud-based SecaaS offers, vNSFs can be distributed within the network infrastructure close to the user/customer. This allows to radically optimize resource allocation, minimize costs and reduce incident response time.
Furthermore, SHIELD envisages that data and logs from vNSFs are aggregated and fed into an information-driven Intrusion Detection and Prevention System (IDPS) platform called Data Analysis and Remediation Engine (DARE), featuring analytical components capable of predicting specific vulnerabilities and attacks. The DARE leverages state-of-the-art Big Data technologies in order to collect, store and process data from vNSFs and translate them into adversarial options, behaviours and intents. By centralising events and logs form multiple vNSFs, the DARE maintains the “big picture” of the network infrastructure status; thus it can infer events which cannot be detected by the individual vNSFs - and dynamically propose actions so as to automatically mitigate them.
Last but not least, in order to address security issues associated with software-based infrastructures, such as SDN/NFV, SHIELD leverages Trusted Computing (TC) aspects and mechanisms in order to attest both the software-defined network infrastructure as well as the virtualised security appliances (vNSFs) and the underlying infrastructure, protecting them against unauthorised modifications.
The SHIELD virtual security infrastructure can either used by the ISP internally for network monitoring and protection, but it can also be offered as-a-service to ISP customers; for this purpose, SHIELD establishes a “vNSF Store”, i.e. a repository of available virtual security functions (firewalls, DPIs, content filters etc.) from which the ISP customers can select the ones which best match their needs and deploy them to protect their infrastructure. This approach promotes openness and interoperability of security functions and offers an affordable, zero-CAPEX security solution for citizens and SMEs.