透過您的圖書館登入
IP:3.133.159.224
  • 學位論文

資料中心虛擬監測設備位置最佳化

Optimal Placement of Network Security Monitoring Functions in NFV-enabled Data Center Network

指導教授 : 林柏青
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


並列摘要


Infrastructure as a Service (IaaS) is a popular type of cloud services. While allowing users to rent virtual machines (VMs) to save the management and hardware cost, it also blurs the boundary between the internal and external networks, causing security threats such as insider attacks which cannot be observed by traditional firewalls or security devices in the network boundary. Coordination of network function virtualization (NFV) and software-defined network (SDN) is a promising approach to address this issue, and an optimal placement mechanism is necessary to minimize the computing resources and bandwidth cost for network security monitoring. In this work, we present a mechanism of placing virtualized network functions for network security monitoring, abbreviated as NSM-VNF, in a data center network (DCN) to watch communications between pairs of VMs. We model the placement issue as the minimum vertex cover problem and the bin packing problem to optimize the number and position of NSM-VNFs subject to the availability of computing resources and bandwidth. Furthermore, the possible rearrangement due to VM migration is also addressed. Because the complexity of the problems are known to be NP-hard, we design an greedy solution to reduce the complexity. We evaluate the greedy solution with various topology sizes and communication pairs in a DCN by Mininet simulation. The experiments demonstrate that the placement of NSM-VNFs by the solution is close to that of an optimal algorithm, while the execution time is reduced significantly.

並列關鍵字

data center SDN NFV security monitoring

參考文獻


Denial of Service Attacks: Experiments and Analysis,” in IEEE Systems Journal, vol. 7, no. 2, pp. 335-345, June 2013.
Chaining Algorithm in Network Function Virtualization Architecture,” IEEE/ACM International Symposium on Cluster, Cloud and Grid Computing, May 2015.
[7] A. Mohammadkhan, S. Ghapani, G. Liu, W. Zhang, K. K. Ramakrishnan and T. Wood, “Virtual Function Placement and Traffic Steering in Flexible and Dynamic Software Defined Networks,” IEEE International
Workshop on Local and Metropolitan Area Networks (LANMAN), Apr.
Virtualization: From Concept To Prototype,” IEEE Trans. Information Forensics and Security, vol. 10, issue 10, pp. 2236-2249, July 2015.

延伸閱讀