On the Safety and Efficiency of Virtual Firewall Elasticity Control
Juan Deng, Hongda Li, Hongxin Hu, Kuang-Ching Wang, Gail-Joon Ahn, Ziming Zhao, Wonkyu Han
Abstract
Traditional hardware-based firewall appliances are placed at fixed locations with fixed capacity. Such nature makes them difficult to protect today's prevailing virtualized environments. Two emerging networking paradigms, Network Function Virtualization (NFV) and Software-Defined Networking (SDN), offer the potential to address these limitations. NFV envisions to implement firewall function as software instance (a.k.a virtual firewall). Virtual firewalls provide great flexibility and elasticity, which are necessary to protect virtualized environments. In this paper, we propose to build an innovative virtual firewall controller, VFW Controller, to enable safe, efficient and costeffective virtual firewall elasticity control. VFW Controller addresses four key challenges with respect to semantic consistency, correct flow update, buffer overflow avoidance, and optimal scaling in virtual firewall scaling. To demonstrate the feasibility of our approach, we implement the core components of VFW Controller on top of NFV and SDN environments. Our experimental results demonstrate that VFW Controller is efficient to provide safe elasticity control of virtual firewalls. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 919b11e8-e9a4-4b2f-85c9-7fb746a12b23Cited by top-tier papers2
- The CrossPath Attack: Disrupting the SDN Control Channel via Shared LinksJiahao Cao, Qi Li, Renjie Xie, Kun Sun et al.USENIX Security 2019 · 68 citations
- vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection SystemsHongda Li, Hongxin Hu, Guofei Gu, Gail-Joon Ahn et al.CCS 2018 · 47 citations
Related papers
- PSI: Precise Security Instrumentation for Enterprise NetworksTianlong Yu, Seyed Kaveh Fayaz, Michael P. Collins, Vyas Sekar et al.NDSS 2017 · 64 citations
- Modeling the Cost of Flexibility in Communication NetworksAlberto Martínez Alba, Péter Babarczi, Andreas Blenk, Mu He et al.INFOCOM 2021 · 7 citations
- Incremental Server Deployment for Scalable NFV-enabled NetworksJianchun Liu, Hongli Xu, Gongming Zhao, Chen Qian et al.INFOCOM 2020 · 23 citations
- NFlow and MVT Abstractions for NFV ScalingZiyan Wu, Yang Zhang, Wendi Feng, Zhi-Li ZhangINFOCOM 2022 · 6 citations
- Network Monitoring for SDN Virtual NetworksGyeongsik Yang, Heesang Jin, Minkoo Kang, Gi Jun Moon et al.INFOCOM 2020 · 15 citations
