DocumentCode :
2843269
Title :
On-Demand VPC Topology Construction for Virtual Perimeter Defense in Public Clouds
Author :
Wu, Xiaoxin ; Wang, Donghui
fYear :
2012
fDate :
18-21 June 2012
Firstpage :
427
Lastpage :
435
Abstract :
This paper targets at building efficient perimeter defense for virtual private cloud (VPC) in public cloud that provides infrastructure as a service (IaaS). Because topology information can help both cloud and cloud user to better manage VPC infrastructure, we propose topology oriented VPC deployment to 1) reduce the security threats caused by transparency/virtualization, 2) to facilitate perimeter defense, and 3) to make better network routing within data center (DC). An isomorphism algorithm called Ullmann algorithm is introduced and justified for searching and assigning cloud resources, which are used to construct a VPC with a required topology. Constructing VPC in this way makes underlying physical resources more visible to VPC and cloud management, and therefore can more efficiently fulfil security solutions and policies. In case when an exactly the same topology as user requests cannot be found, a minor loose of topology requirement through using partially virtual topology is allowed to improve the successful mapping rate. The use of security set helps to reduce cloud decision time. The algorithm is evaluated through simulation. The successful rate and decision time tested in a middle-sized cloud environment prove algorithm feasibility.
Keywords :
Cloud computing; Home appliances; Logic gates; Network topology; Routing; Security; Topology;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Distributed Computing Systems Workshops (ICDCSW), 2012 32nd International Conference on
Conference_Location :
Macau, China
ISSN :
1545-0678
Print_ISBN :
978-1-4673-1423-7
Type :
conf
DOI :
10.1109/ICDCSW.2012.73
Filename :
6258189
Link To Document :
بازگشت