Analytical Model for Elastic Scaling of Cloud-Based Firewalls

Analytical Model for Elastic Scaling of Cloud-Based Firewalls
复制标题

基于云的防火墙弹性扩展的分析模型

DOI:
--
复制
发表时间:
2017
影响因子:
5.3
通讯作者:
R. Boutaba
R. Boutaba
中科院分区:
计算机科学2区
文献类型:
--
作者:
K. Salah;P. Calyam;R. Boutaba

文献摘要

被引文献

相似文献

本文介绍了如何在云环境中适当地实现网络防火墙的弹性。弹性是通过以自主方式配置和取消配置资源来适应工作负载变化的能力,以便在每个时间点可用资源与当前需求尽可能匹配。基于云的防火墙的灵活性旨在仅使用最少的云防火墙实例来满足商定的性能衡量标准。我们的贡献在于确定应该根据传入流量负载和防火墙规则库中的目标规则动态调整的防火墙实例数量。为此,我们建立了一个基于马尔可夫链和排队论原理的分析模型。该模型捕获基于云的防火墙服务的行为,该服务包括负载均衡器和可变数量的虚拟防火墙。然后,我们从分析模型中推导出封闭形式的公式,以确定满足服务级别协议中指定的响应时间所需的最小虚拟防火墙数量。该模型以负载、负载均衡器和虚拟机的处理能力以及目标防火墙规则的深度等关键系统参数作为输入。我们使用离散事件仿真和在Amazon Web Services云上进行的真实世界实验来验证我们的模型。我们还提供了数值例子来展示我们的模型如何用于云性能/安全工程师的实践中,以便在流量负载波动和目标防火墙规则深度可变的情况下获得适当的弹性。
This paper shows how to properly achieve elasticity for network firewalls deployed in a cloud environment. Elasticity is the ability to adapt to workload changes by provisioning and de-provisioning resources in an autonomic manner, such that at each point in time the available resources match the current demand as closely as possible. Elasticity for cloud-based firewalls aims to satisfy an agreed-upon performance measure using only the minimal number of cloud firewall instances. Our contribution lies in determining the number of firewall instances that should be dynamically adjusted in accordance with the incoming traffic load and the targeted rules within the firewall rulebase. To do so, we develop an analytical model based on the principles of Markov chains and queueing theory. The model captures the behavior of a cloud-based firewall service comprising a load balancer and a variable number of virtual firewalls. From the analytical model, we then derive closed-form formulas to determine the minimal number of virtual firewalls required to meet the response time specified in the service level agreement. The model takes as input key system parameters including workload, processing capacity of load balancer and virtual machines, as well as the depth of the targeted firewall rules. We validate our model using discrete-event simulation, and real-world experiments conducted on Amazon Web Services cloud. We also provide numerical examples to show how our model can be used in practice by cloud performance/security engineers to achieve proper elasticity under fluctuating traffic load and variable depth of targeted firewall rules.