DocumentCode :
2961808
Title :
Optimal placement of sequentially ordered virtual security appliances in the cloud
Author :
Shameli-Sendi, Alireza ; Jarraya, Yosr ; Fekih-Ahmed, Mohamed ; Pourzandi, Makan ; Talhi, Chamseddine ; Cheriet, Mohamed
Author_Institution :
Ecole de Technol. Super. (ETS), Montreal, QC, Canada
fYear :
2015
fDate :
11-15 May 2015
Firstpage :
818
Lastpage :
821
Abstract :
Traditional enterprise network security is based on the deployment of security appliances placed on some specific locations filtering, monitoring the traffic going through them. In this perspective, security appliances are chained in specific order to perform different security functions on the traffic. In the cloud, the same approach is often adopted using virtual security appliances to protect traffic for different virtual applications with the challenge of dealing with the flexible and elastic nature of the cloud. In this paper, we investigate the problem of placing virtual security appliances within the data center in order to minimize network latency and computing costs for security functions while maintaining the required sequential order of traversing virtual security appliances. We propose a new algorithm computing the best place to deploy these virtual security appliances in the data center. We further integrated our placement algorithm in an open source cloud framework, i.e. Openstack, in our test laboratory. The preliminary results show that we are placing the virtual security appliances in the required sequential order while improving the efficiency compared to the current default placement algorithm in Openstack.
Keywords :
cloud computing; computer centres; public domain software; security of data; Openstack; algorithm computing; computing cost; data center; enterprise network security; locations filtering; network latency; open source cloud framework; optimal placement; placement algorithm; security function; sequentially ordered virtual security appliance; traffic monitoring; Algorithm design and analysis; Communication networks; Computers; Home appliances; Middleboxes; Optimization; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Integrated Network Management (IM), 2015 IFIP/IEEE International Symposium on
Conference_Location :
Ottawa, ON
Type :
conf
DOI :
10.1109/INM.2015.7140384
Filename :
7140384
Link To Document :
بازگشت