首页> 外文会议>2017 IEEE 7th International Symposium on Cloud and Service Computing >Optimal Placement of Network Security Monitoring Functions in NFV-Enabled Data Centers
【24h】

Optimal Placement of Network Security Monitoring Functions in NFV-Enabled Data Centers

机译:启用NFV的数据中心中网络安全监视功能的最佳位置

获取原文
获取原文并翻译 | 示例

摘要

While infrastructure as a service (IaaS) provides benefits such as cost reduction, dynamic deployment and high availability for users, it also blurs the boundary between the internal and external networks, causing security threats such as insider attacks which cannot be observed by traditional security devices in the network boundary. Coordination of network function virtualization (NFV) and software-defined networking (SDN) is a promising approach to address this issue, and an optimal placement mechanism is necessary to minimize the computing resources for network security monitoring. In this work, we present a mechanism of placing virtualized network functions (VNFs) for network security monitoring in a data center to watch communications between pairs of virtual machines (VMs) or between VMs and external hosts. The placement issue is modeled as the minimum vertex cover problem and the bin packing problem to optimize the number and positions of VNFs subject to the availability of computing resources and link capacity. We design a greedy algorithm to reduce the time complexity of the problems. A Mininet simulation evaluates this solution for various topology sizes and communication pairs. The experiments demonstrate that the VNF placement planned by this algorithm is close to optimality, but the execution time can be reduced significantly.
机译:虽然基础架构即服务(IaaS)为用户提供了诸如降低成本,动态部署和高可用性等优势,但它也模糊了内部和外部网络之间的边界,从而导致了诸如内部攻击之类的安全威胁,而传统安全设备无法观察到在网络边界。网络功能虚拟化(NFV)和软件定义的网络(SDN)的协调是解决此问题的一种有前途的方法,并且最佳的放置机制对于最大限度地减少用于网络安全监视的计算资源是必需的。在这项工作中,我们提出了一种将虚拟网络功能(VNF)放置在数据中心中以监视网络安全的机制,以监视成对的虚拟机(VM)之间或VM与外部主机之间的通信。将放置问题建模为最小顶点覆盖问题和bin打包问题,以根据计算资源的可用性和链接容量来优化VNF的数量和位置。我们设计了一个贪心算法来减少问题的时间复杂度。 Mininet仿真针对各种拓扑大小和通信对评估了该解决方案。实验表明,该算法规划的VNF布局已接近最优,但执行时间可以大大减少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号