On the Optimality of Virtualized Security Function Placement in Multi-Tenant Data Centers

Ali, A., Anagnostopoulos, C. and Pezaros, D. P. (2018) On the Optimality of Virtualized Security Function Placement in Multi-Tenant Data Centers. In: IEEE International Conference on Communications (ICC 2018), Kansas City, MO, USA, 20-24 May 2018, ISBN 9781538631805 (doi: 10.1109/ICC.2018.8422426)

[img]
Preview
Text
157223.pdf - Accepted Version

486kB

Abstract

Security and service protection against cyber attacks remain among the primary challenges for virtualized, multi-tenant Data Centres (DCs), for reasons that vary from lack of resource isolation to the monolithic nature of legacy middleboxes. Although security is currently considered a property of the underlying infrastructure, diverse services require protection against different threats and at timescales which are on par with those of service deployment and elastic resource provisioning. We address the resource allocation problem of deploying customised security services over a virtualized, multi-tenant DC. We formulate the problem in Integral Linear Programming (ILP) as an instance of the NP-hard variable size variable cost bin packing problem with the objective of maximising the residual resources after allocation. We propose a modified version of the Best Fit Decreasing algorithm (BFD) to solve the problem in polynomial time and we show that BFD optimises the objective function up to 80% more than other algorithms.

Item Type:Conference Proceedings
Status:Published
Refereed:Yes
Glasgow Author(s) Enlighten ID:Ali, Ms Abeer and Anagnostopoulos, Dr Christos and Pezaros, Professor Dimitrios
Authors: Ali, A., Anagnostopoulos, C., and Pezaros, D. P.
College/School:College of Science and Engineering > School of Computing Science
ISSN:1938-1883
ISBN:9781538631805
Copyright Holders:Copyright © 2018 IEEE
Publisher Policy:Reproduced in accordance with the copyright policy of the publisher

University Staff: Request a correction | Enlighten Editors: Update this record

Project CodeAward NoProject NamePrincipal InvestigatorFunder's NameFunder RefLead Dept
643481A Situation-aware information infrastructureDimitrios PezarosEngineering and Physical Sciences Research Council (EPSRC)EP/L026015/1COM - COMPUTING SCIENCE
709131Network Measurement as a Service (MaaS)Dimitrios PezarosEngineering and Physical Sciences Research Council (EPSRC)EP/N033957/1COM - COMPUTING SCIENCE
722161FRuIT: The Federated RaspberryPi Micro-Infrastructure TestbedJeremy SingerEngineering and Physical Sciences Research Council (EPSRC)EP/P004024/1COM - COMPUTING SCIENCE