Secure and Dependable Virtual Network Embedding
نویسندگان
چکیده
Network virtualization has emerged as a powerful technique to allow multiple heterogeneous networks specified by different users to run on a shared infrastructure. A major challenge is how to make efficient use of the shared resources. Virtual Network Embedding (VNE) addresses this problem by finding an effective mapping of the virtual nodes & links onto the substrate network. For some scenarios, VNE has been studied in some detail in the network virtualization literature [1]. The problem was shown to be computationally intractable, but recent research has explored efficient heuristics to tackle the challenge. Motivation. The VNE problem is traditionally formulated with the objective of maximizing network provider revenue by efficiently embedding incoming virtual network (VN) requests. This objective is subject to constraints, such as processing capacity on the nodes and bandwidth resource on the links. A mostly unexplored perspective on this problem is providing some security assurances, a gap increasingly more acute. With the advent of network virtualization platforms [2], cloud operators now have the ability to extend their cloud computing offerings with virtual networks. To shift their workloads to the cloud, tenants trust their cloud providers to guarantee that their work-loads are secure and available. Unfortunately, there is an increasing number of evidence that problems do occur, of both the malicious kind (e.g., caused by a corrupt cloud insider) or benign (e.g., a cloud outage) [3]. We thus argue that security and dependability is becoming a critical factor that should be considered by virtual network embedding algorithms. To the best of our knowledge the only work that explores VNE security is the recent proposal by Liu et al. [4]. Despite its relevance, the authors fail to respond to the problems mentioned above: they do not contemplate dependability; and consider a single cloud provider, thus the model assumes complete trust in this entity. Contribution. We propose a VN embedding solution that considers security and dependability as first class citizens. For this purpose, we introduce specific security constraints including, for instance, the possibility of a virtual machine attacking another virtual machine (e.g., a side-channel attack) or replay attacks on physical links. As substrate resources may fail, we also take into account dependability constraints, including the ability to tolerate failures, by ensuring that additional computing and communication resources are allocated during the process of embedding. To further extend the resiliency properties of our solution , we assume a multiple cloud provider model …
منابع مشابه
New High Secure Network Steganography Method Based on Packet Length
In network steganography methods based on packet length, the length of the packets is used as a carrier for exchanging secret messages. Existing methods in this area are vulnerable against detections due to abnormal network traffic behaviors. The main goal of this paper is to propose a method which has great resistance to network traffic detections. In the first proposed method, the sender embe...
متن کاملPosition Paper: Secure Virtual Network Embedding
Network virtualization has been recognized as an important technique to overcome the perceived ossification of the current Internet. Several variations of network virtualization have already been discussed in the literature. These approaches use virtualization to partition and/or combine physical network resources into virtual network resources. An actual deployment of virtual networks then req...
متن کاملDeveloping a Framework for E-Manufacturing Based on Wireless Sensor Network
This paper analyzes the current situation of business environment and business intelligence systems integration at first. With emerging applications of internet and wireless communication technologies, emanufacturing is focused on the use of internet, monitoring and communications technologies to make things happen collaboratively on a global basis. A wireless sensor network based data acquisit...
متن کاملLink Prediction using Network Embedding based on Global Similarity
Background: The link prediction issue is one of the most widely used problems in complex network analysis. Link prediction requires knowing the background of previous link connections and combining them with available information. The link prediction local approaches with node structure objectives are fast in case of speed but are not accurate enough. On the other hand, the global link predicti...
متن کاملAuthorization models for secure information sharing: a survey and research agenda
This article presents a survey of authorization models and considers their 'fitness-for-purpose' in facilitating information sharing. Network-supported information sharing is an important technical capability that underpins collaboration in support of dynamic and unpredictable activities such as emergency response, national security, infrastructure protection, supply chain integration and emerg...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1602.02268 شماره
صفحات -
تاریخ انتشار 2016