论文标题
攻击感知的安全函数链重新排序
Attack-aware Security Function Chain Reordering
论文作者
论文摘要
攻击意识认识到对出现攻击的安全系统的自我意识。对云和网络基础架构的更频繁和强烈的攻击正在将安全系统推向极限。随着摩尔定律的终结,仅仅对这些攻击进行扩展不再是经济上是合理的。先前的工作已经处理了安全系统中软件定义的网络和网络功能虚拟化的采用,并使用了两种方法来通过智能放置安全功能来优化性能。但是,这些作品尚未考虑流量通过这些功能的顺序。在这项工作中,我们为需要通过显示其影响来考虑此订单的情况。然后,我们提出一个重新排序框架,并分析建模安全服务功能链并根据这些模型对订单做出决定的必要方面。我们显示了订单的影响,并在评估环境中验证我们的框架。效果可以扩展到多个数量级,该框架的评估证明了我们概念的可行性。
Attack-awareness recognizes self-awareness for security systems regarding the occurring attacks. More frequent and intense attacks on cloud and network infrastructures are pushing security systems to the limit. With the end of Moore's Law, merely scaling against these attacks is no longer economically justified. Previous works have already dealt with the adoption of Software-defined Networking and Network Function Virtualization in security systems and used both approaches to optimize performance by the intelligent placement of security functions. However, these works have not yet considered the sequence in which traffic passes through these functions. In this work, we make a case for the need to take this ordering into account by showing its impact. We then propose a reordering framework and analyze what aspects are necessary for modeling security service function chains and making decisions regarding the order based on those models. We show the impact of the order and validate our framework in an evaluation environment. The effect can extend to multiple orders of magnitude, and the framework's evaluation proves the feasibility of our concept.