• DocumentCode
    58257
  • Title

    A Decentralized Cloud Firewall Framework with Resources Provisioning Cost Optimization

  • Author

    Meng Liu ; Wanchun Dou ; Shui Yu ; Zhensheng Zhang

  • Author_Institution
    Dept. of Comput. Sci. & Technol., Nanjing Univ., Nanjing, China
  • Volume
    26
  • Issue
    3
  • fYear
    2015
  • fDate
    March 1 2015
  • Firstpage
    621
  • Lastpage
    631
  • Abstract
    Cloud computing is becoming popular as the next infrastructure of computing platform. Despite the promising model and hype surrounding, security has become the major concern that people hesitate to transfer their applications to clouds. Concretely, cloud platform is under numerous attacks. As a result, it is definitely expected to establish a firewall to protect cloud from these attacks. However, setting up a centralized firewall for a whole cloud data center is infeasible from both performance and financial aspects. In this paper, we propose a decentralized cloud firewall framework for individual cloud customers. We investigate how to dynamically allocate resources to optimize resources provisioning cost, while satisfying QoS requirement specified by individual customers simultaneously. Moreover, we establish novel queuing theory based model M/Geo/1 and M/Geo/m for quantitative system analysis, where the service times follow a geometric distribution. By employing Z-transform and embedded Markov chain techniques, we obtain a closed-form expression of mean packet response time. Through extensive simulations and experiments, we conclude that an M/Geo/1 model reflects the cloud firewall real system much better than a traditional M/M/1 model. Our numerical results also indicate that we are able to set up cloud firewall with affordable cost to cloud customers.
  • Keywords
    Markov processes; cloud computing; computer centres; customer services; financial management; firewalls; geometry; optimisation; quality of service; queueing theory; resource allocation; transforms; M/Geo/1; M/Geo/m; QoS requirement; Z-transform; cloud computing; cloud data center; decentralized cloud firewall framework; embedded Markov chain techniques; financial aspects; geometric distribution; individual cloud customers; queuing theory; resource allocation; resources provisioning cost optimization; Analytical models; Cloud computing; Markov processes; Mathematical model; Quality of service; Servers; Time factors; Cloud computing; firewall; resources allocation; system modeling;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2014.2314672
  • Filename
    6781636