Dynamic Defense Provision via Network Functions Virtualization

Dynamic Defense Provision via Network Functions Virtualization
复制标题

DOI:
10.1145/3040992.3041005
复制
发表时间:
2017-03
期刊:
Proceedings of the ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization
影响因子:
--
通讯作者:
Younghee Park;P. Chandaliya;Akshaya Muralidharan;Nikash Kumar;Hongxin Hu
Younghee Park;P. Chandaliya;Akshaya Muralidharan;Nikash Kumar;Hongxin Hu
中科院分区:
其他
文献类型:
--
作者:
Younghee Park;P. Chandaliya;Akshaya Muralidharan;Nikash Kumar;Hongxin Hu

文献摘要

被引文献

相似文献

网络功能虚拟化(NFV)是新防御模式的关键部分,通过基于软件的虚拟实例以较低的成本提供高灵活性。尽管NFV的前景看好,但为NFV设计的原始入侵检测系统(IDS)仍然严重依赖处理能力,并需要大量的CPU资源。在本文中,我们提供了一个框架,通过在NFV上构建轻入侵检测网络功能(NF)来提供动态防御。在不使用现有IDS的情况下,我们的系统通过使用NFV中的一系列网络功能来构建一个轻型入侵检测系统。整个IDS根据不同的协议被分解为单独的轻网络功能。入侵检测NF覆盖从链路层到应用层协议的各种协议栈。它们还包括用于不同应用层协议的不同深度分组检测NF。实验结果表明,该系统在执行有效的入侵检测功能的同时,减少了资源消耗。
Network Function Virtualization (NFV) is a critical part of a new defense paradigm providing high flexibility at a lower cost through software-based virtual instances. Despite the promise of the NFV, the original Intrusion Detection System (IDS) designed for NFV still draws heavily on processing power and requires significant CPU resources. In this paper, we provide a framework for dynamic defense provision by building in light intrusion detection network functions (NFs) over NFV. Without using the existing IDSes, our system constructs a light intrusion detection system by using a chain of network functions in NFV. The entire IDS is broken down into separate light network functions according to different protocols. The intrusion detection NFs cover various protocol stacks from the link layer to the application layer protocols. They also include different deep packet inspection NFs for different application layer protocols. The experimental results show the proposed system reduces resource consumption while performing valid intrusion detection functions.