DocumentCode :
3235727
Title :
Cost-Based Placement of Virtualized Deep Packet Inspection Functions in SDN
Author :
Bouet, Mathieu ; Leguay, Jeremie ; Conan, Vania
Author_Institution :
Thales Commun. & Security, Gennevilliers, France
fYear :
2013
fDate :
18-20 Nov. 2013
Firstpage :
992
Lastpage :
997
Abstract :
In today´s IT systems, cyber security requires fine-grained, flexible, adaptable and cost optimized monitoring mechanisms. The emergence of new networking technologies, like Network Function Virtualization (NFV) and Software Defined Networking (SDN), opens up new venues for large scale adoption of these cyber security tools. In particular, Deep Packet Inspection (DPI) engines can be virtualized and dynamically deployed as pieces of software on commodity hardware. Deploying such software DPI engines is costly in terms of license fees and power consumption. Designing cost effective DPI engine deployment strategies that meet the cybersecurity operational constraints is thus mandatory for the adoption of this approach. For this purpose, we propose a method, based on genetic algorithms, that optimizes the cost of DPI engine deployment, minimizing their number, the global network load and the number of unanalyzed flows. We conduct several experiments with different types of traffic and different cost structures. The results show that the method is able to reach a trade-off between the number of DPI engines and network load. Furthermore, the global cost can be reduced up to 58% when relaxing the constraint on the used link capacity, that is the provisioning rate.
Keywords :
channel capacity; computer network security; costing; genetic algorithms; inspection; packet radio networks; radio links; software radio; telecommunication traffic; virtualisation; IT systems; SDN; adaptable monitoring mechanisms; cost effective DPI engine deployment strategy; cost optimized monitoring mechanism; cost structure; cyber security operational constraint; dynamic DPI engine deployment; fine grained monitoring mechanism; flexible monitoring mechanism; genetic algorithm; global network load; license fee; link capacity; network function virtualization; power consumption; software DPI engine; software defined networking; traffic structure; virtualized DPI engine deployment; virtualized deep packet inspection function; Bandwidth; Biological cells; Cost function; Engines; Genetic algorithms; Hardware; Virtualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Military Communications Conference, MILCOM 2013 - 2013 IEEE
Conference_Location :
San Diego, CA
Type :
conf
DOI :
10.1109/MILCOM.2013.172
Filename :
6735753
Link To Document :
بازگشت