Dynamic Network Security Function Enforcement via Joint Flow and Function Scheduling

Dynamic Network Security Function Enforcement via Joint Flow and Function Scheduling
复制标题

通过联合流程和功能调度执行动态网络安全功能

DOI:
10.1109/tifs.2022.3142995
复制
发表时间:
2022
期刊:
IEEE Transactions on Information Forensics and Security (TIFS)
影响因子:
--
通讯作者:
Jianping Wu
Jianping Wu
中科院分区:
其他
文献类型:
--
作者:
Qi Li;Xinhao Deng;Zhuotao Liu;Yuan Yang;Xiaoyue Zou;Qian Wang;Mingwei Xu;Jianping Wu

文献摘要

相似文献

网络功能虚拟化(Network Function Virtualization, NFV)是一种实现网络功能动态部署的新型组网模式。现有的研究主要集中在NFV的优化功能部署和管理上。不幸的是,这些研究并没有很好地解决网络中安全功能的有效执行问题,这是部署网络功能(NFs)的目标,即对流量进行实时安全功能执行,因为最优的功能部署并不意味着对网络流量进行有效的安全功能执行。特别是,它们产生了重大的NF执行成本。为了解决这一问题,本文提出了<inline-formula> < text -math notation="LaTeX">${\textsf {FuncE}}$ </ text -math></inline-formula>,旨在通过开发统一的动态流程和功能调度来解决高效的实时安全功能执行问题。我们将这个问题表述为一个整数线性规划问题,并证明了它是np困难的。我们通过分解和开发启发式方法来解决问题,以获得接近最优的解决方案。我们利用实际拓扑进行了全面的实验,验证了<inline-formula> < text -math符号="LaTeX">${\textsf {FuncE}}$ </ text -math></inline-formula>设计的有效性。实验结果表明,<inline-formula> < text -math notation="LaTeX">${\textsf {FuncE}}$ </ text -math></inline-formula>实现了近乎最优的网络函数执行,其延迟比现有最优求解器减少了100倍以上。特别是,与最先进的防御相比,<inline-formula> < text -math notation="LaTeX">${\textsf {FuncE}}$ </ text -math></inline-formula>使用超过50%的vnf处理相同数量的候选流,同时确保相同级别的函数实施。
Network Function Virtualization (NFV) is a new networking paradigm to enable dynamic network function deployment in networks. Existing studies focused on optimized function deployment and management in NFV. Unfortunately, these studies did not well address the problem of efficient security function enforcement in networks, which is the goal of deploying network functions (NFs), i.e., for real-time security function enforcement on the traffic, since optimal function deployment does not mean efficient security function enforcement on network traffic. In particular, they incurred significant NF enforcement cost. In order to address this issue, in this paper, we propose <inline-formula> <tex-math notation="LaTeX">${\textsf {FuncE}}$ </tex-math></inline-formula> that aims to solve the efficient real-time security function enforcement problem by developing unified dynamic flow and function scheduling. We formulate the problem as an integer linear programming problem and prove that it is NP-hard. We tackle the problem by decomposing it and developing heuristics to achieve near-optimal solutions. We conduct comprehensive experiments by using real topologies to demonstrate the effectiveness of the <inline-formula> <tex-math notation="LaTeX">${\textsf {FuncE}}$ </tex-math></inline-formula> design. The experimental results demonstrate that <inline-formula> <tex-math notation="LaTeX">${\textsf {FuncE}}$ </tex-math></inline-formula> achieves near-optimal network function enforcement, which incurs over 100 times less latency than the existing the optimal solver. In particular, compared to the state-of-art defenses, <inline-formula> <tex-math notation="LaTeX">${\textsf {FuncE}}$ </tex-math></inline-formula> processes the same number of candidate flows using over 50% less VNFs, while ensuring the same level of function enforcement.