首页> 外文期刊>Parallel and Distributed Systems, IEEE Transactions on >A Decentralized Cloud Firewall Framework with Resources Provisioning Cost Optimization
【24h】

A Decentralized Cloud Firewall Framework with Resources Provisioning Cost Optimization

机译:具有资源调配成本优化的分散式云防火墙框架

获取原文
获取原文并翻译 | 示例

摘要

Cloud computing is becoming popular as the next infrastructure of computing platform. Despite the promising model and hype surrounding, security has become the major concern that people hesitate to transfer their applications to clouds. Concretely, cloud platform is under numerous attacks. As a result, it is definitely expected to establish a firewall to protect cloud from these attacks. However, setting up a centralized firewall for a whole cloud data center is infeasible from both performance and financial aspects. In this paper, we propose a decentralized cloud firewall framework for individual cloud customers. We investigate how to dynamically allocate resources to optimize resources provisioning cost, while satisfying QoS requirement specified by individual customers simultaneously. Moreover, we establish novel queuing theory based model M/Geo/1 and M/Geo/m for quantitative system analysis, where the service times follow a geometric distribution. By employing Z-transform and embedded Markov chain techniques, we obtain a closed-form expression of mean packet response time. Through extensive simulations and experiments, we conclude that an M/Geo/1 model reflects the cloud firewall real system much better than a traditional M/M/1 model. Our numerical results also indicate that we are able to set up cloud firewall with affordable cost to cloud customers.
机译:云计算作为计算平台的下一个基础架构正变得越来越流行。尽管存在令人鼓舞的模型和大肆宣传,但安全性已成为人们不愿将其应用程序转移到云的主要问题。具体而言,云平台受到了无数攻击。因此,绝对希望建立防火墙来保护云免受这些攻击。但是,从性能和财务角度来看,为整个云数据中心设置集中式防火墙是不可行的。在本文中,我们为个人云客户提出了一个分散的云防火墙框架。我们研究如何动态分配资源以优化资源供应成本,同时满足各个客户指定的QoS要求。此外,我们建立了基于模型M / Geo / 1和M / Geo / m的新颖排队理论,用于定量系统分析,其中服务时间遵循几何分布。通过使用Z变换和嵌入式Markov链技术,我们可以获得平均数据包响应时间的闭式表达式。通过广泛的仿真和实验,我们得出的结论是,M / Geo / 1模型比传统的M / M / 1模型更好地反映了云防火墙的实际系统。我们的数值结果还表明,我们能够以对云客户而言可承受的成本建立云防火墙。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号