首页> 外文会议>IEEE International Scientific-Practical Conference Problems of Infocommunications, Science and Technology >Scenarios for Implementation of Nested Virtualization Technology in Task of Improving Cloud Firewall Fault Tolerance
【24h】

Scenarios for Implementation of Nested Virtualization Technology in Task of Improving Cloud Firewall Fault Tolerance

机译:改进云防火墙容错的任务中嵌套虚拟化技术的情况

获取原文

摘要

Currently, the use of cloud firewalls allows protecting not only individual network resources, but also the entire infrastructure of large data centers. The main requirement for a cloud firewall is high fault tolerance. There are classic ways to increase fault tolerance, which focus on high redundancy of technological solution. Small and medium Internet business cannot always afford the creation of a separate solution to ensure the security of resources. Therefore, it is relevant to implement nested virtualization technology that gives the opportunity to use a cloud server with a hypervisor inside, in which, in turn, virtual machines are launched. Firewall software can be directly implemented on these virtual machines. Improving the fault tolerance of a cloud firewall is possible using of a set of nested virtual machines of the cloud server, which can be instantly restored by its hypervisor. To analyze the impact of the resource allocation plan of the cloud server, to detect a failed or incorrectly running nested virtual machine, the calculation of the virtual machine efficiency indicator is given. The paper proposed three scenarios for the use of nested virtualization technology: nested virtualization of services, nested virtualization of machines and virtualization of the entire infrastructure. For each of them, experimental studies have been carried out in order to identify patterns of time delay values for restoring the full functionality of the cloud firewall after a network attack on its various elements. By conducting experiments, it has been established that the use of nested virtualization technology in the first scenario allows to get a time gain of 7 times; in the second scenario there is a gain of 1.5 times; in the third one, it has been allowed to fully restart the cloud firewall infrastructure in a new cloud.
机译:目前,使用云防火墙的使用允许保护各个网络资源,也可以保护大型数据中心的整个基础设施。云防火墙的主要要求是高容错的容错。有经典的方法可以提高容错,专注于技术解决方案的高冗余。中小型互联网业务不能总是负担于创建一个单独的解决方案,以确保资源的安全性。因此,它与实现嵌套虚拟化技术有关,它赋予内部虚拟机管理程序使用云服务器的机会,其中,依次启动虚拟机。防火墙软件可以直接在这些虚拟机上实现。使用云服务器的一组嵌套虚拟机可以提高云防火墙的容错,可以通过其管理程序立即恢复。要分析云服务器资源分配计划的影响,检测失败或不正确的嵌套虚拟机,给出了虚拟机效率指示符的计算。本文提出了使用嵌套虚拟化技术的三种方案:嵌套虚拟化服务,嵌套虚拟化的机器和整个基础架构的虚拟化。对于它们中的每一个,已经执行了实验研究,以识别在网络攻击对其各种元素的网络攻击之后恢复云防火墙的完整功能的时间延迟值模式。通过进行实验,已经确定,在第一场景中使用嵌套虚拟化技术允许获得7次的时间增益;在第二个情景中,有1.5倍的增长;在第三,它已被允许在新云中完全重新启动云防火墙基础架构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号