Analytical Model for Elastic Scaling of Cloud-Based Firewalls

被引:29
|
作者
Salah, Khaled [1 ]
Calyam, Prasad [2 ]
Boutaba, Raouf [3 ,4 ]
机构
[1] Khalifa Univ Sci Technol & Res, Sharjah 573, U Arab Emirates
[2] Univ Missouri, Columbia, MO 65211 USA
[3] Univ Waterloo, Waterloo, ON N2L 3G1, Canada
[4] POSTECH, Div IT Convergence Engn, Pohang, South Korea
关键词
Cloud computing; firewalls; cloud firewalls; scalability; elasticity; resource management;
D O I
10.1109/TNSM.2016.2640297
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper shows how to properly achieve elasticity for network firewalls deployed in a cloud environment. Elasticity is the ability to adapt to workload changes by provisioning and de-provisioning resources in an autonomic manner, such that at each point in time the available resources match the current demand as closely as possible. Elasticity for cloud-based firewalls aims to satisfy an agreed-upon performance measure using only the minimal number of cloud firewall instances. Our contribution lies in determining the number of firewall instances that should be dynamically adjusted in accordance with the incoming traffic load and the targeted rules within the firewall rulebase. To do so, we develop an analytical model based on the principles of Markov chains and queueing theory. The model captures the behavior of a cloud-based firewall service comprising a load balancer and a variable number of virtual firewalls. From the analytical model, we then derive closed-form formulas to determine the minimal number of virtual firewalls required to meet the response time specified in the service level agreement. The model takes as input key system parameters including workload, processing capacity of load balancer and virtual machines, as well as the depth of the targeted firewall rules. We validate our model using discrete-event simulation, and real-world experiments conducted on Amazon Web Services cloud. We also provide numerical examples to show how our model can be used in practice by cloud performance/security engineers to achieve proper elasticity under fluctuating traffic load and variable depth of targeted firewall rules.
引用
收藏
页码:136 / 146
页数:11
相关论文
共 50 条
  • [1] An Analytical Model to Achieve Elasticity for Cloud-based Firewalls
    Salah, Khaled
    [J]. 40TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2015), 2015, : 173 - 176
  • [2] A Multiparameter Analytical Model of the Physical Infrastructure of a Cloud-Based System
    Hanczewski, Slawomir
    Stasiak, Maciej
    Weissenberg, Michal
    [J]. IEEE ACCESS, 2021, 9 (100981-100990) : 100981 - 100990
  • [3] CIRUS: an elastic cloud-based framework for Ubilytics
    Linh Manh Pham
    El-Rheddane, Ahmed
    Donsez, Didier
    de Palma, Noel
    [J]. ANNALS OF TELECOMMUNICATIONS-ANNALES DES TELECOMMUNICATIONS, 2016, 71 (3-4): : 133 - 140
  • [4] CIRUS: an elastic cloud-based framework for Ubilytics
    Linh Manh Pham
    Ahmed El-Rheddane
    Didier Donsez
    Noel de Palma
    [J]. Annals of Telecommunications, 2016, 71 : 133 - 140
  • [5] An auto-scaling mechanism for cloud-based multimedia storage systems: a fuzzy-based elastic controller
    Mostafa Ghobaei-Arani
    Maryam Rezaei
    Alireza Souri
    [J]. Multimedia Tools and Applications, 2022, 81 : 34501 - 34523
  • [6] An auto-scaling mechanism for cloud-based multimedia storage systems: a fuzzy-based elastic controller
    Ghobaei-Arani, Mostafa
    Rezaei, Maryam
    Souri, Alireza
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (24) : 34501 - 34523
  • [7] Considering an Elastic Scaling Model for Cloud Security
    MacDermott, Aine
    Shi, Qi
    Merabti, Madjid
    Kifiyat, Kashif
    [J]. 2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 150 - 155
  • [8] A Pattern-Based Formalization of Cloud-Based Elastic Systems
    Dustdar, Schahram
    Gambi, Alessio
    Krenn, Willibald
    Nickovic, Dejan
    [J]. 7TH INTERNATIONAL WORKSHOP ON PRINCIPLES OF ENGINEERING SERVICE-ORIENTED AND CLOUD SYSTEMS PESOS 2015, 2015, : 31 - 37
  • [9] Automated Testing of Cloud-Based Elastic Systems with AUToCLES
    Gambi, Alessio
    Hummer, Waldemar
    Dustdar, Schahram
    [J]. 2013 28TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE), 2013, : 714 - 717
  • [10] Elastic and effective cloud-based solution in online education
    Jin, Yi
    Huang, Jianhua
    Li, Cheng
    Ye, Qi
    Yao, Jun
    [J]. PROCEEDINGS OF THE 2016 2ND WORKSHOP ON ADVANCED RESEARCH AND TECHNOLOGY IN INDUSTRY APPLICATIONS, 2016, 81 : 1828 - 1832