Cost-based placement of virtualized Deep Packet Inspection functions in SDN

被引:40
作者
Bouet, Mathieu [1 ]
Leguay, Jeremie [1 ]
Conan, Vania [1 ]
机构
[1] Thales Commun & Secur, F-92230 Gennevilliers, France
来源
2013 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2013) | 2013年
关键词
D O I
10.1109/MILCOM.2013.172
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In today's IT systems, cyber security requires fine-grained, flexible, adaptable and cost optimized monitoring mechanisms. The emergence of new networking technologies, like Network Function Virtualization (NFV) and Software Defined Networking (SDN), opens up new venues for large scale adoption of these cyber security tools. In particular, Deep Packet Inspection (DPI) engines can be virtualized and dynamically deployed as pieces of software on commodity hardware. Deploying such software DPI engines is costly in terms of license fees and power consumption. Designing cost effective DPI engine deployment strategies that meet the cybersecurity operational constraints is thus mandatory for the adoption of this approach. For this purpose, we propose a method, based on genetic algorithms, that optimizes the cost of DPI engine deployment, minimizing their number, the global network load and the number of unanalyzed flows. We conduct several experiments with different types of traffic and different cost structures. The results show that the method is able to reach a trade-off between the number of DPI engines and network load. Furthermore, the global cost can be reduced up to 58% when relaxing the constraint on the used link capacity, that is the provisioning rate.
引用
收藏
页码:992 / 997
页数:6
相关论文
共 14 条
[1]  
[Anonymous], 2013, NIST SPEC PUBL
[2]  
[Anonymous], 2012, NETWORK FUNCTIONS VI
[3]  
Biran O., 2012, IEEE ACM INT S CLUST
[4]   ALGORITHMS FOR THE CONSTRAINED QUICKEST PATH PROBLEM AND THE ENUMERATION OF QUICKEST PATHS [J].
CHEN, GH ;
HUNG, YC .
COMPUTERS & OPERATIONS RESEARCH, 1994, 21 (02) :113-118
[5]   Scalable Network Virtualization in Software-Defined Networks [J].
Drutskoy, Dmitry ;
Keller, Eric ;
Rexford, Jennifer .
IEEE INTERNET COMPUTING, 2013, 17 (02) :20-27
[6]  
Gringoli F., 2012, IEEE International Conference on Communications (ICC 2012), P1177, DOI 10.1109/ICC.2012.6363806
[7]  
Jiang Joe Wenjie, 2012, INFOCOM 2012 P IEEE
[8]  
Lu Guohan., 2012, Proceedings of the first workshop on Hot topics in software defined networks, P31
[9]  
Maric M, 2010, COMPUT INFORM, V29, P183
[10]   SOFTWARE DEFINED NETWORKING OPPORTUNITIES FOR TRANSPORT [J].
McDysan, Dave .
IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (03) :28-31