Eidolon - A System for Dynamically Generating Secure Network Environments to Isolate Compromised Nodes

Lombardi, Luca (2025) Eidolon - A System for Dynamically Generating Secure Network Environments to Isolate Compromised Nodes. [Laurea magistrale], Università di Bologna, Corso di Studio in Ingegneria informatica [LM-DM270], Documento ad accesso riservato.
Documenti full-text disponibili:
[thumbnail of Thesis] Documento PDF (Thesis)
Full-text non accessibile fino al 18 Marzo 2027.
Disponibile con Licenza: Creative Commons: Attribuzione - Non commerciale - Condividi allo stesso modo 4.0 (CC BY-NC-SA 4.0)

Download (5MB) | Contatta l'autore

Abstract

In recent years the increasing complexity of enterprise network management, with the adoption of cloud computing, IoT, hybrid work environments, and globalized business operations, has increased the attack surface of modern companies and critical infrastructures showing the limitations of traditional perimeter-based network security models. This work explores a host-based micro-segmentation approach based on Zero-Trust principles to enhance network security, scalability, and resilience while offering tools to aid in the management of wide area network. This research introduces Eidolon, a system for dynamically creating and deploying secure overlay networks using Software Defined Networking (SDN), built from Nebula and the previously developed NEST project. Eidolon enables automated isolation of compromised nodes from the network while ensuring seamless network management through declarative configuration using the Dhall language and high security with advanced certificate automation. This research focuses on developing a new framework for secure, adaptable, and reliable enterprise networking, contributing to the advancement of Zero Trust architectures. Eidolon's performance, scalability, and usability are assessed in this research, highlighting its potential as a powerful and adaptable solution for contemporary enterprise networking. This system serves as a base for future projects, such as real-time threat analysis, network simulations, and AI-powered security solutions.

Abstract
Tipologia del documento
Tesi di laurea (Laurea magistrale)
Autore della tesi
Lombardi, Luca
Relatore della tesi
Correlatore della tesi
Scuola
Corso di studio
Indirizzo
CURRICULUM INGEGNERIA INFORMATICA
Ordinamento Cds
DM270
Parole chiave
Zero Trust, Software Defined Network, Infrastructure as Code, Nebula, Cloud Provisioning
Data di discussione della Tesi
25 Marzo 2025
URI

Altri metadati

Gestione del documento: Visualizza il documento

^