课题基金 / 基金详情

Resilience as a Service: Optimisation of Middlebox placement

Resilience as a Service: Optimisation of Middlebox placement
弹性即服务:中间盒布局的优化
批准号:
1802322
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2016
资助国家:
英国
项目状态:
已结题
起止时间:
2016 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
这项研究的目的是提出一种在网络中以分布式方式虚拟化、部署和协调多个安全应用程序的方法,以提高整体性能和弹性。我们最初的目标列表包含以下内容:研究并实施可在各种网络系统(包括节点和交换机)上运行,并可为安全应用程序提供所需的网络数据访问权限的轻量级虚拟环境。这类虚拟环境目前受到诸如Docker[11]等底层操作系统的限制,或者为嵌入式设备带来不必要的复杂性,例如网络交换机,Java VirtualMachine[15][14]就是这种情况。通过流分析、虚拟机迁移技术和拓扑覆盖分析,研究能够最大化性能和弹性的各种部署策略。研究表明,大型数据中心网络中来宾虚拟机的迁移和最佳放置提高了总体资源利用率[16][4],我们希望利用这项技术,以便在发生故障或攻击时还能提供更强的网络弹性。建议对SDN南向协议进行扩展,允许以编程方式管理这些设备。遵循与SDN相同的设计原则,这可以提高大型网络的可扩展性和灵活性;此外,它还提供网络安全状态的全局视图,使管理员和开发人员能够轻松管理安全应用程序。目前使用SDN实现这一点的尝试显示出严重的局限性[8],所涉及的协议在设计时没有考虑到这一用例。分析、实施和部署概念验证应用程序,这些应用程序将利用现有的局部性在网络中实现弹性。为了验证正确的功能并证明我们声称的中间盒本地化(提供整体提高的性能并允许按需扩展)和增强的弹性,需要执行众所周知的网络功能的应用程序(例如防火墙、代理、入侵检测系统)。这些应用程序必须利用上面提到的轻量级环境来展示可移植性和在嵌入式设备上的执行。
英文摘要
The aim of this research is to propose an approach for virtualising, deployingand orchestrating multiple security applications in a distributed fashion withina network, to boost overall performance and resilience. Our initial list of objectivescontains the following:Investigate and implement lightweight virtual environments that can runon a variety of network systems, including nodes and switches, and canprovide the required access to network data for security applications. Suchvirtual environments are currently limited by underlying operating systems,such as Docker[11], or present unnecessary complexity for embeddeddevices, e.g. network switches, as is the case with the Java VirtualMachine[15][14].Investigate various deployment strategies that can maximise performance4and resilience through flow analysis, virtual machine migration techniquesand topology coverage analysis. Research has shown that the migrationand optimal placement of guest virtual machines within large data centrenetworks improves overall resource usage[16][4], a technique we want toleverage in order to also offer increased network resilience in the case offaults or attacks.Propose an extension to SDN southbound protocols that would allow managementof these devices in a programmatic manner. Following the samedesign principles as SDN, this allows for increased scalability and flexibilityof a large network; furthermore it provides a global view of the securitystatus of the network, allowing administrators and developers to managesecurity applications with ease. Current attempts of using SDN for thisshow severe limitations[8], the protocols involved not being designed withthis use case in mind.Analyse, implement and deploy proof of concept applications that wouldleverage existing locality for resilience within a network. In order to verifythe correct functionality and prove our claims for middlebox localisation(which provides overall increased performance and allows for scaling ondemand) and enhanced resilience, applications that perform well knownnetwork functions (e.g. Firewalls, Proxies, Intrusion Detection Systems)are required. These applications must leverage the lightweight environmentmentioned above to also demonstrate portability and execution onembedded devices.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Distributed, multi-level network anomaly detection for datacentre networks
数据中心网络的分布式、多级网络异常检测
DOI: 10.1109/icc.2017.7996569
发表时间: 2017
期刊:
影响因子: --
作者: [Iordache M]
通讯作者: Iordache M
国内基金
海外基金
基于Service Chain的数据中心网络资源调度问题研究
  • 批准号:
    61772235
  • 项目类别:
    面上项目
  • 资助金额:
    59.0万元
  • 批准年份:
    2017
  • 负责人:
    崔林
  • 依托单位:
面向Web Service的服务质量预测技术研究
  • 批准号:
    61003072
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    7.0万元
  • 批准年份:
    2010
  • 负责人:
    邵凌霜
  • 依托单位:
Web Service QoS的多维多尺度模型及评估、预测方法的研究
  • 批准号:
    60803011
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    19.0万元
  • 批准年份:
    2008
  • 负责人:
    赵俊峰
  • 依托单位:
SOA中面向业务的Service识别与设计方法研究
  • 批准号:
    70871032
  • 项目类别:
    面上项目
  • 资助金额:
    18.0万元
  • 批准年份:
    2008
  • 负责人:
    任明仑
  • 依托单位: