DocumentCode :
594626
Title :
To cloud or not to cloud: A study of trade-offs between in-house and outsourced virtual private network
Author :
Arshad, Fahad A. ; Modelo-Howard, G. ; Bagchi, Saurabh
Author_Institution :
Sch. of Electr. & Comput. Eng., Purdue Univ., West Lafayette, IN, USA
fYear :
2012
fDate :
Oct. 30 2012-Nov. 2 2012
Firstpage :
1
Lastpage :
6
Abstract :
The question of whether to migrate IT services to a cloud computing infrastructure arises before most IT decision makers today. To enable secure access to sensitive resources a virtual private network (VPN) is almost a required piece of technology. Setting up and managing a VPN server is a non-trivial task-there are a variety of modes in which VPN can be used (IPSec, SSL/TLS, PPTP), there are a variety of software-only and software-hardware solutions, and each comes with a rich set of configuration options. Therefore, it is a perplexing question to practitioners what option to choose, with an understanding of the performance and the security implications of each choice. In this paper, we consider the various factors that should go into such decision making and exemplify this by choosing among two competitive options for protecting access to IT resources of our NSF center which has a significant number of external (i.e., non-Purdue) users. The two options are an open-source software-only VPN (pfSense) and a commercial appliance, i.e., an integrated hardware-software solution. Further, the first is managed by us while the latter is outsourced to an entity that provides VPN services to multiple consumer organizations, and hence, referred by us as the cloud-based service. We follow up with conducting a post-deployment study of the VPN users which reveals that despite a two-fold reduction in throughput, the cloud-based service is considered satisfactory due to its non-intrusiveness with respect to other network activities and ease of configuration.
Keywords :
cloud computing; computer network security; decision making; information technology; public domain software; virtual private networks; IPSec; IT decision making; IT resource; IT service; NSF center; PPTP; SSL; TLS; VPN server; cloud computing infrastructure; cloud-based service; consumer organization; in-house virtual private network; network activities; open-source software; outsourced virtual private network; secure access; security implication; sensitive resources; software-hardware solution; Linux; Loss measurement; Protocols; Security; Servers; Throughput; Virtual private networks; Cloud Computing; Configurability; Security; Virtual Private Network;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Protocols (ICNP), 2012 20th IEEE International Conference on
Conference_Location :
Austin, TX
Print_ISBN :
978-1-4673-2445-8
Electronic_ISBN :
978-1-4673-2446-5
Type :
conf
DOI :
10.1109/ICNP.2012.6459949
Filename :
6459949
Link To Document :
بازگشت