Optimal Access Control Deployment in Network Function Virtualization

被引:1
|
作者
Smine, Manel [1 ]
Espes, David [2 ]
Pahl, Marc-Oliver [1 ]
机构
[1] IMT Atlantique, Rennes, France
[2] Univ Western Brittany, Brest, France
关键词
Network Function Virtualization (NFV); access control policy deployment; optimization; GENETIC ALGORITHM;
D O I
10.1109/NOMS54207.2022.9789911
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network function virtualization (NFV) yields numerous advantages, specifically the ability to provide a cost-efficient alternative to hardware-based functionalities on software platforms to break the vendor lock-in problem. However, these advantages come at the cost of several security issues. These threats can be leveraged by controlling the information that flows between the different components that compose NFV services. We propose an approach allowing an optimal deployment of access control policies on NFV services. The proposed approach allows to find the best possible trade-offs between the impact in terms of latency resulting from the deployment of the access control policy and the used resources. In contrast to existing approaches, our solution prevents an insider adversary who compromises one or more unknown VNF(s) to go around the access control policy. We experimentally evaluate the return solutions according to the size of the NFV service, the size of the policy to be deployed and the number of physical servers that host the VNF service.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Service Deployment Aspects in the Systems with Network Function Virtualization
    Mariia, Skulysh
    Svitlana, Sulima
    [J]. 2016 INTERNATIONAL CONFERENCE RADIO ELECTRONICS & INFO COMMUNICATIONS (UKRMICO), 2016,
  • [2] Enhancement of Network Access Control Architecture With Virtualization
    Annuar, Hairil
    Shanmugam, Bharanidharan
    Ahmad, Azuan
    Idris, Norbik Bashah
    AlBakri, Sameer Hasan
    Samy, Ganthan Nayarana
    [J]. 2013 INTERNATIONAL CONFERENCE ON INFORMATICS AND CREATIVE MULTIMEDIA (ICICM), 2013, : 314 - 320
  • [3] Resources Allocation at the Physical Layer for Network Function Virtualization Deployment
    Xie, Ning
    Luo, Jianping
    [J]. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2020, 69 (03) : 2771 - 2784
  • [4] Network Functions Virtualization Access Control as a Service
    Smine, Manel
    Espes, David
    Cuppens-Boulahia, Nora
    Cuppens, Frederic
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXXIV, DBSEC 2020, 2020, 12122 : 100 - 117
  • [5] Optimal Network Function Virtualization and Service Function Chaining:A Survey
    MIRJALILY Ghasem
    LUO Zhiquan
    [J]. Chinese Journal of Electronics, 2018, 27 (04) : 704 - 717
  • [6] Optimal Network Function Virtualization and Service Function Chaining: A Survey
    Mirjalily, Ghasem
    Luo Zhiquan
    [J]. CHINESE JOURNAL OF ELECTRONICS, 2018, 27 (04) : 704 - 717
  • [7] Network Functions Virtualization for Flexible Deployment of Converged Optical -Wireless Access Infrastructure
    Krasko, Olena
    Al-Zayadi, Haider
    Pashkevych, Volodymyr
    Kopets, Halyna
    Humeniuk, Bohdan
    [J]. 2018 14TH INTERNATIONAL CONFERENCE ON ADVANCED TRENDS IN RADIOELECTRONICS, TELECOMMUNICATIONS AND COMPUTER ENGINEERING (TCSET), 2018, : 1135 - 1138
  • [8] Service Deployment With Priority Queueing for Traffic Processing and Transmission in Network Function Virtualization
    He, Fujun
    Oki, Eiji
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (04): : 4861 - 4874
  • [9] A model-driven approach for deployment descriptor design in network function virtualization
    Atoui, Wassim Sellil
    Assy, Nour
    Gaaloul, Walid
    Ben Yahia, Imen Grida
    [J]. INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2022, 32 (01)
  • [10] Fiber Access Network Architecture Featuring Distributed Processing and Function Virtualization
    Orphanoudakis, Theofanis
    Kosmatos, Evangelos
    Matrakidis, Chris
    Stavdas, Alexandros
    [J]. 2015 IEEE INTERNATIONAL BLACK SEA CONFERENCE ON COMMUNICATIONS AND NETWORKING (BLACKSEACOM), 2015, : 147 - 151