Methods and Techniques for Dynamic Deployability of Software-Defined Security Services

04/04/2020
by   Roberto Doriguzzi-Corin, et al.
0

With the recent trend of "network softwarisation", enabled by emerging technologies such as Software-Defined Networking (SDN) and Network Function Virtualisation (NFV), system administrators of data centres and enterprise networks have started replacing dedicated hardware-based middleboxes with virtualised network functions running on servers and end hosts. This radical change has facilitated the provisioning of advanced and flexible network services, ultimately helping system administrators and network operators to cope with the rapid changes in service requirements and networking workloads. This thesis investigates the challenges of provisioning network security services in "softwarised" networks, where the security of residential and business users can be provided by means of sets of software-based network functions running on high performance servers or on commodity compute devices. The study is approached from the perspective of the telecom operator, whose goal is to protect the customers from network threats and, at the same time, maximize the number of provisioned services, and thereby revenue. Specifically, the overall aim of the research presented in this thesis is proposing novel techniques for optimising the resource usage of software-based security services, hence for increasing the chances for the operator to accommodate more service requests while respecting the desired level of network security of its customers. In this direction, the contributions of this thesis are the following: (i) a solution for the dynamic provisioning of security services that minimises the utilisation of computing and network resources, and (ii) novel methods based on Deep Learning and Linux kernel technologies for reducing the CPU usage of software-based security network functions, with specific focus on the defence against Distributed Denial of Service (DDoS) attacks.

READ FULL TEXT
research
07/10/2020

Improving Software Defined Cognitive and Secure Networking

Traditional communication networks consist of large sets of vendor-speci...
research
04/11/2019

The More the Merrier: Enhancing Reliability of 5G Communication Services with Guaranteed Delay

Although network functions virtualization and software-defined networkin...
research
07/16/2020

A Framework for Threats Analysis Using Software-Defined Networking

The ability to analyze network threats is very important in security res...
research
11/30/2019

Joint Resource and Admission Management for Slice-enabled Networks

Network slicing is a crucial part of the 5G networks that communication ...
research
04/18/2018

SDN-Assisted Network-Based Mitigation of Slow DDoS Attacks

Slow-running attacks against network applications are often not easy to ...
research
12/13/2018

Constraint programming for flexible Service Function Chaining deployment

Network Function Virtualization (NFV) and Software Defined Networking (S...
research
10/24/2018

Leveraging eBPF for programmable network functions with IPv6 Segment Routing

With the advent of Software Defined Networks (SDN), Network Function Vir...

Please sign up or login with your details

Forgot password? Click here to reset