Secure architecture for Cloud/Fog computing based on firewalls and controllers
Ferdaous Kamoun-Abid, Mouna Rekik, Amel Meddeb-Makhlouf, Faouzi Zarai · Procedia Computer Science · 2021
The concept of distribution in the Cloud and Fog computing makes the network more vulnerable to malicious activities. This requires use of distributed firewalls to stop incoming intrusions, where the Controllers are used to mitigate rules for the purpose of cooperation based on risk analysis. These security components are used in the architecture of Distributed Cloud / Fog with a zoned topology. We propose in this paper to use this topology that implements an access-control based on a set of cooperation levels between user-FN (FN: Node Fog). In addition, we secure the exchange of cooperation messages by guaranteeing integrity, confidentiality and authentication while avoiding replay attacks. This improves the security of the cloud network. As proof, we simulate Cloud/Fog network using the NeSSi² tool. This simulation obtained results are hopeful in term of delay and transmission rate must be a decrease of 1.5 ms. Furthermore, the protocol used in exchange of cooperation messages, is analyzed using Security Protocol Animator (SPAN) for Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The obtained validation results show that the scheme is safe.