A Monitoring-based Load Balancing Scheme for Network Security Functions

被引:0
|
作者
Hong, Dongjin [1 ]
Kim, Jinyong [1 ]
Hyun, Daeyoung [2 ]
Jeong, Jaehoon [3 ]
机构
[1] Sungkyunkwan Univ, Dept Elect & Comp Engn, Seoul, South Korea
[2] Sungkyunkwan Univ, Dept Software Platform, Seoul, South Korea
[3] Sungkyunkwan Univ, Dept Interact Sci, Seoul, South Korea
关键词
Software Defined Networking; Network Functions Virtualization; Monitoring; Load Balancing; Interface to Network Security Functions;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
This paper proposes an enhanced Interface to Network Security Functions (I2NSF) framework. To improve the whole packet throughput and manage resource of Network Security Functions (NSFs), the enhanced I2NSF framework monitors NSFs and distributes incoming packets to NSFs efficiently. Even if the legacy framework that provides security services using Software-Defined Networking (SDN) and Network Functions Virtualization (NFV) has the similar NSFs, it is inefficient to be unable to distribute the packets to multiple NSFs. Based on the legacy I2NSF framework, therefore, we add two kinds of communication such as (i) communication between NSFs and security controller to monitor NSFs and (ii) communication between Security Function Forwarder (SFF) and security controller to perform the load balance for the packets to multiple NSFs. For the further communications between NSFs with security controller, we present a message format based on the information model proposed by Internet Engineering Task Force (IETF) I2NSF Working Group. We use capability data model proposed by IETF I2NSF WG, which describes the capability of an NSF. In order to show the feasibility of the proposed framework, we implemented the enhanced framework using IETF standards and open sources.
引用
收藏
页码:668 / 672
页数:5
相关论文
共 50 条
  • [1] Cluster-Based Load Balancing for Better Network Security
    Frishman, Gal
    Ben-Itzhak, Yaniv
    Margalit, Oded
    [J]. BIG-DAMA '17: PROCEEDINGS OF THE 2017 WORKSHOP ON BIG DATA ANALYTICS AND MACHINE LEARNING FOR DATA COMMUNICATION NETWORKS, 2017, : 7 - 12
  • [2] A load balancing scheme based on deep learning in blockchain network
    Kim, Hye-Young
    Lee, Ji-Hyun
    [J]. 2021 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI 2021), 2021, : 1821 - 1823
  • [3] Monitoring-Based Certification of Cloud Service Security
    Krotsiani, Maria
    Spanoudakis, George
    Kloukinas, Christos
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2015 CONFERENCES, 2015, 9415 : 644 - 659
  • [4] Resource Utilization based Load Balancing for a Virtualized Security Functions Platform
    Amarasinghe, D. A. H. M.
    Rankothge, W. H.
    Gamage, N. D. U.
    Gamage, T. C. T.
    Uwanpriya, S. D. L. S.
    Jayasinghe, D.
    [J]. 2021 IEEE 12TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2021, : 65 - 68
  • [5] Flow based dynamic load balancing for passive network monitoring
    Lee, U
    Park, JS
    Sanadidi, MY
    Gerla, M
    [J]. PROCEEDINGS OF THE THIRD IASTED INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND COMPUTER NETWORKS, 2005, : 357 - 362
  • [6] A load balancing scheme for cluster-based secure network servers
    Kim, Jin-Ha
    Choi, Gyiu Sang
    Das, Chita R.
    [J]. 2005 IEEE INTERNATIONAL CONFERENCE ON CLUSTER COMPUTING (CLUSTER), 2006, : 225 - +
  • [7] A Survivable Virtual Network Embedding Scheme Based on Load Balancing and Reconfiguration
    Chen, Qingyun
    Wang, Ying
    Qiu, Xuesong
    Li, Wenjing
    Xiao, Ailing
    [J]. 2014 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2014,
  • [8] Online Load Balancing for Network Functions Virtualization
    Tuan-Minh Pham
    Thi-Thuy-Lien Nguyen
    Fdida, Serge
    Huynh Thi Thanh Binh
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [9] A splitting infrastructure for load balancing and security in an MPLS network
    Avallone, Stefano
    Manetti, Vittorio
    Mariano, Marina
    Romano, Simon Pietro
    [J]. 2007 3RD INTERNATIONAL CONFERENCE ON TESTBEDS AND RESEARCH INFRASTRUCTURE FOR THE DEVELOPMENT OF NETWORKS AND COMMUNITIES, 2007, : 183 - 188
  • [10] A Dynamic Load Balancing Scheme Based on Network Sharding in Private Ethereum Blockchain
    Wang, Zicheng
    Cui, Bo
    Hou, Wenhan
    [J]. 2022 IEEE 46TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2022), 2022, : 362 - 367