TY - GEN
T1 - Dynamic defense provision via Network Functions Virtualization
AU - Park, Younghee
AU - Chandaliya, Pritesh
AU - Muralidharan, Akshaya
AU - Kumar, Nikash
AU - Hu, Hongxin
N1 - Publisher Copyright:
© 2017 ACM.
PY - 2017/3/24
Y1 - 2017/3/24
N2 - Network Function Virtualization (NFV) is a critical part of a new defense paradigm providing high flexibility at a lower cost through software-based virtual instances. Despite the promise of the NFV, the original Intrusion Detection System (IDS) designed for NFV still draws heavily on processing power and requires significant CPU resources. In this paper, we provide a framework for dynamic defense provision by building in light intrusion detection network functions (NFs) over NFV. Without using the existing IDSes, our system constructs a light intrusion detection system by using a chain of network functions in NFV. The entire IDS is broken down into separate light network functions according to different protocols. The intrusion detection NFs cover various protocol stacks from the link layer to the application layer protocols. They also include different deep packet inspection NFs for different application layer protocols. The experimental results show the proposed system reduces resource consumption while performing valid intrusion detection functions.
AB - Network Function Virtualization (NFV) is a critical part of a new defense paradigm providing high flexibility at a lower cost through software-based virtual instances. Despite the promise of the NFV, the original Intrusion Detection System (IDS) designed for NFV still draws heavily on processing power and requires significant CPU resources. In this paper, we provide a framework for dynamic defense provision by building in light intrusion detection network functions (NFs) over NFV. Without using the existing IDSes, our system constructs a light intrusion detection system by using a chain of network functions in NFV. The entire IDS is broken down into separate light network functions according to different protocols. The intrusion detection NFs cover various protocol stacks from the link layer to the application layer protocols. They also include different deep packet inspection NFs for different application layer protocols. The experimental results show the proposed system reduces resource consumption while performing valid intrusion detection functions.
KW - Network Functions Virtualization
KW - Network attacks
KW - Security
KW - Software-Defined Networks
UR - https://www.scopus.com/pages/publications/85018354556
U2 - 10.1145/3040992.3041005
DO - 10.1145/3040992.3041005
M3 - Conference contribution
AN - SCOPUS:85018354556
T3 - SDN-NFVSec 2017 - Proceedings of the ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2017
SP - 43
EP - 46
BT - SDN-NFVSec 2017 - Proceedings of the ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2017
PB - Association for Computing Machinery
T2 - 2017 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, SDN-NFVSec 2017, co-located with CODASPY 2017
Y2 - 24 March 2017 through 24 March 2017
ER -