VNGuard: An NFV/SDN Combination Framework for Provisioning and Managing Virtual Firewalls

被引:0
|
作者
Deng, Juan [1 ]
Hu, Hongxin [1 ]
Li, Hongda [1 ]
Pan, Zhizhong [1 ]
Wang, Kuang-Ching [1 ]
Ahn, Gail-Joon [2 ]
Bi, Jun [3 ]
Park, Younghee [4 ]
机构
[1] Clemson Univ, Clemson, SC 29631 USA
[2] Arizona State Univ, Tempe, AZ 85287 USA
[3] Tsinghua Univ, Beijing, Peoples R China
[4] San Jose State Univ, San Jose, CA 95192 USA
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Network Function Virtualization (NFV) together with cloud technology enables users to request creating flexible virtual networks (VNs). Users also have specific security requirements to protect their VNs. Especially, due to changeable network perimeters, constant VM migrations, and usercentric security needs, VNs require new security features that traditional firewalls fail to provide, because traditional firewalls rely greatly on restricted network topology and entry points to provide effective security protection. To address this challenge, we propose VNGuard, a framework for effective provision and management of virtual firewalls to safeguard VNs, leveraging features provided by NFV and Software Defined Networking (SDN). VNGuard defines a high-level firewall policy language, finds optimal virtual firewall placement, and adapts virtual firewalls to VN changes. To demonstrate the feasibility of our approach, we have implemented core components of VNGuard on top of ClickOS. Our experimental results demonstrate the effectiveness and efficiency of virtual firewalls built on VNGuard.
引用
收藏
页码:107 / 114
页数:8
相关论文
共 50 条
  • [1] ACLFLOW: An NFV/SDN Security Framework for Provisioning and Managing Access Control Lists
    Mauricio, Leopoldo A. F.
    Rubinstein, Marcelo G.
    Duarte, Otto Carlos M. B.
    [J]. PROCEEDINGS OF THE 2018 9TH INTERNATIONAL CONFERENCE ON THE NETWORK OF THE FUTURE (NOF), 2018, : 44 - 51
  • [2] Exploiting a Virtual Load Balancer with SDN-NFV Framework
    Monir, Md Fahad
    Pan, Dan
    [J]. 2021 IEEE INTERNATIONAL BLACK SEA CONFERENCE ON COMMUNICATIONS AND NETWORKING (IEEE BLACKSEACOM), 2021, : 237 - 242
  • [3] Managing NFV using SDN and Control Theory
    Akhtar, Nabeel
    Matta, Ibrahim
    Wang, Yuefeng
    [J]. NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 1005 - 1006
  • [4] Managing NFV using SDN and Control Theory
    Akhtar, Nabeel
    Matta, Ibrahim
    Wang, Yuefeng
    [J]. NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 1113 - 1118
  • [5] Virtual SDN and NFV Laboratoty - Architecture and Implementation
    Londak, Juraj
    Medvecky, Martin
    Podhradsky, Pavol
    [J]. PROCEEDINGS OF 2017 INTERNATIONAL SYMPOSIUM ELMAR, 2017, : 197 - 200
  • [6] Enabling autonomic provisioning in SDN cloud networks with NFV service chaining
    Cannistra, Robert
    Carle, Benjamin
    Johnson, Matt
    Kapadia, Junaid
    Meath, Zach
    Miller, Mary
    Young, Devin
    DeCusatis, Casimer
    Bundy, Todd
    Zussman, Gil
    Bergman, Keren
    Carranza, Aparicio
    Sher-DeCusatis, Carolyn
    Pletch, Andrew
    Ransom, Raymond
    [J]. 2014 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION (OFC), 2014,
  • [7] SDN control framework for QoS provisioning
    Tomovic, Slavica
    Prasad, Neeli
    Radusinovic, Igor
    [J]. 2014 22ND TELECOMMUNICATIONS FORUM TELFOR (TELFOR), 2014, : 111 - 114
  • [8] Software-Defined Network Virtualization: An Architectural Framework for Integrating SDN and NFV for Service Provisioning in Future Networks
    Duan, Qiang
    Ansari, Nirwan
    Toy, Mehmet
    [J]. IEEE NETWORK, 2016, 30 (05): : 10 - 16
  • [9] Integration of Virtual SDN and NFV Laboratory with NEWTELP Platform
    Medvecky, Martin
    Vargic, Radoslav
    Londak, Juraj
    Podhradsky, Pavol
    Truchly, Peter
    [J]. PROCEEDINGS OF ELMAR-2018: 60TH INTERNATIONAL SYMPOSIUM ELMAR-2018, 2018, : 15 - 18
  • [10] Managing AAA in NFV/SDN-enabled IoT scenarios
    Molina Zarca, Alejandro
    Garcia-Carrillo, Dan
    Bernal Bernabe, Jorge
    Ortiz, Jordi
    Marin-Perez, Rafael
    Skarmeta, Antonio
    [J]. 2018 GLOBAL INTERNET OF THINGS SUMMIT (GIOTS), 2018, : 79 - 85