VNGuard: An NFV/SDN Combination Framework for Provisioning and Managing Virtual Firewalls

被引:0
|
作者
Deng, Juan [1 ]
Hu, Hongxin [1 ]
Li, Hongda [1 ]
Pan, Zhizhong [1 ]
Wang, Kuang-Ching [1 ]
Ahn, Gail-Joon [2 ]
Bi, Jun [3 ]
Park, Younghee [4 ]
机构
[1] Clemson Univ, Clemson, SC 29631 USA
[2] Arizona State Univ, Tempe, AZ 85287 USA
[3] Tsinghua Univ, Beijing, Peoples R China
[4] San Jose State Univ, San Jose, CA 95192 USA
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Network Function Virtualization (NFV) together with cloud technology enables users to request creating flexible virtual networks (VNs). Users also have specific security requirements to protect their VNs. Especially, due to changeable network perimeters, constant VM migrations, and usercentric security needs, VNs require new security features that traditional firewalls fail to provide, because traditional firewalls rely greatly on restricted network topology and entry points to provide effective security protection. To address this challenge, we propose VNGuard, a framework for effective provision and management of virtual firewalls to safeguard VNs, leveraging features provided by NFV and Software Defined Networking (SDN). VNGuard defines a high-level firewall policy language, finds optimal virtual firewall placement, and adapts virtual firewalls to VN changes. To demonstrate the feasibility of our approach, we have implemented core components of VNGuard on top of ClickOS. Our experimental results demonstrate the effectiveness and efficiency of virtual firewalls built on VNGuard.
引用
收藏
页码:107 / 114
页数:8
相关论文
共 50 条
  • [31] A framework for service provisioning in virtual sensor networks
    Lambros Sarakis
    Theodore Zahariadis
    Helen-Catherine Leligou
    Mischa Dohler
    [J]. EURASIP Journal on Wireless Communications and Networking, 2012
  • [32] A framework for service provisioning in virtual sensor networks
    Sarakis, Lambros
    Zahariadis, Theodore
    Leligou, Helen-Catherine
    Dohler, Mischa
    [J]. EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2012,
  • [33] Piecing Together the NFV Provisioning Puzzle: Efficient Placement and Chaining of Virtual Network Functions
    Luizelli, Marcelo Caggiani
    Bays, Leonardo Richter
    Buriol, Luciana Salete
    Barcellos, Marinho Pilla
    Gaspary, Luciano Paschoal
    [J]. PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 98 - 106
  • [34] Enhanced Attack Aware Security Provisioning Scheme in SDN/NFV Enabled over 5G Network
    Abdulqadder, Ihsan H.
    Zou, Deqing
    Aziz, Israa T.
    Yuan, Bin
    [J]. 2018 27TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN), 2018,
  • [35] Virtual IoT HoneyNets to Mitigate Cyberattacks in SDN/NFV-Enabled IoT Networks
    Zarca, Alejandro Molina
    Bernabe, Jorge Bernal
    Skarmeta, Antonio
    Alcaraz Calero, Jose M.
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2020, 38 (06) : 1262 - 1277
  • [36] An Optimized Deployment Mechanism for Virtual Middleboxes in NFV- and SDN-Enabling Network
    Xiong, Gang
    Sun, Penghao
    Hu, Yuxiang
    Lan, Julong
    Li, Kan
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2016, 10 (08): : 3474 - 3497
  • [37] Virtual Network Embedding in SDN/NFV based Fiber-Wireless Access Network
    Han, Pengchao
    Guo, Lei
    Liu, Yejun
    [J]. 2016 INTERNATIONAL CONFERENCE ON SOFTWARE NETWORKING (ICSN), 2016, : 66 - 70
  • [38] An Open NFV and Cloud Architectural Framework for Managing Application Virality Behaviour
    Krishnaswamy, Dilip
    Krishnan, Ram
    Lopez, Diego
    Willis, Peter
    Qamar, Asif
    [J]. 2015 12TH ANNUAL IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, 2015, : 746 - 754
  • [39] VirtRAN: An SDN/NFV-Based Framework for 5G RAN Slicing
    Nayak Manjeshwar, Akshatha
    Jha, Pranav
    Karandikar, Abhay
    Chaporkar, Prasanna
    [J]. JOURNAL OF THE INDIAN INSTITUTE OF SCIENCE, 2020, 100 (02) : 409 - 434
  • [40] A Fine-Grained Multi-Tenant Permission Management Framework for SDN and NFV
    Zou, Deqing
    Lu, Yu
    Yuan, Bin
    Chen, Haoyu
    Jin, Hai
    [J]. IEEE ACCESS, 2018, 6 : 25562 - 25572