Cloud Firewall Under Bursty and Correlated Data Traffic: A Theoretical Analysis

被引:5
|
作者
Carvalho, Glaucio H. S. [1 ]
Woungang, Isaac [1 ]
Anpalagan, Alagan [2 ]
机构
[1] Ryerson Univ, Dept Comp Sci, 350 Victoria St, Toronto, ON M5B 2K3, Canada
[2] Ryerson Univ, Dept Elect & Comp Engn, Toronto, ON M5B 2K3, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Cloud security; DDoS; markov process; firewall; markov-modulated poisson process; PERFORMANCE ANALYSIS; FRAMEWORK; NETWORKS; INTERNET; MODEL;
D O I
10.1109/TCC.2020.3000674
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud firewalls stand as one of the major building blocks of the cloud security framework protecting the Virtual Private Infrastructure against attacks such as the Distributed Denial of Service (DDoS). In order to fully characterize the cloud firewall operation and gain actionable insights on the design of cloud security, performance models for the cloud firewall become imperative. In this article, we propose a multi-dimensional Continuous-Time Markov Chain model for the cloud firewall that takes into account the burstiness and correlation features of the legitimate and malicious data traffic. By adopting the Markov-Modulated Poisson process (MMPP) and the Interrupted Poisson Process (IPP), we identify the workload conditions under which the cloud firewall might be subject to a loss of availability. Furthermore, by comparing the IPP and Poisson attacks, we numerically verify that the cloud firewall is inherently vulnerable to a burstiness-aware attack which might seriously compromise its operation. Additionally, we characterize the joint harmful impact of burstiness and correlation on the cloud firewall that might lead to performance degradation. Finally, we design an elastic doud firewall by proposing a MMPP-driven load balancing procedure that provisions virtual firewalls dynamically while fulfilling a Service Level Agreement (SLA) latency specification.
引用
收藏
页码:1620 / 1633
页数:14
相关论文
共 50 条
  • [1] Performance Analysis of WLANs under Bursty and Correlated Video Traffic
    Najjari, Noushin
    Min, Geyong
    Hu, Jia
    Miao, Wang
    2017 14TH INTERNATIONAL SYMPOSIUM ON PERVASIVE SYSTEMS, ALGORITHMS AND NETWORKS & 2017 11TH INTERNATIONAL CONFERENCE ON FRONTIER OF COMPUTER SCIENCE AND TECHNOLOGY & 2017 THIRD INTERNATIONAL SYMPOSIUM OF CREATIVE COMPUTING (ISPAN-FCST-ISCC), 2017, : 250 - 256
  • [2] Performance Analysis of Hybrid Wireless Networks Under Bursty and Correlated Traffic
    Wu, Yulei
    Min, Geyong
    Yang, Laurence T.
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2013, 62 (01) : 449 - 454
  • [3] A Theoretical Model for Analysis of Firewalls Under Bursty Traffic Flows
    Shahsavari, Yahya
    Shahhoseini, HadiShahriar
    Zhang, Kaiwen
    Elbiaze, Halima
    IEEE ACCESS, 2019, 7 : 183311 - 183321
  • [4] Controlling mean queuing delay under multi-class bursty and correlated traffic
    Lim, L. B.
    Guan, L.
    Grigg, A.
    Phillips, I. W.
    Wang, X. G.
    Awan, I. U.
    JOURNAL OF COMPUTER AND SYSTEM SCIENCES, 2011, 77 (05) : 898 - 916
  • [5] Adaptive protocols for optical LANs with bursty and correlated traffic
    Papadimitriou, GI
    Obaidat, MS
    Pomportsis, AS
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2002, 15 (2-3) : 115 - 125
  • [6] Theoretical Analysis of PF Scheduling with Bursty Traffic Model in OFDMA Systems
    Zhang, Guowei
    Xu, Jing
    Liu, Ligang
    Yang, Yang
    Li, Qiang
    Hamalainen, Matti
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [7] On improving service differentiation under Bursty data traffic in wireless networks
    Zhu, H
    Cao, GH
    IEEE INFOCOM 2004: THE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-4, PROCEEDINGS, 2004, : 871 - 881
  • [8] Performance analysis of optical burst switching under bursty traffic
    陈春汉
    曹明翠
    罗志详
    ChineseOpticsLetters, 2004, (01) : 21 - 23
  • [9] Performances of the data vortex switch architecture under nonuniform and bursty traffic
    Yang, QM
    Bergman, K
    JOURNAL OF LIGHTWAVE TECHNOLOGY, 2002, 20 (08) : 1242 - 1247
  • [10] ANALYSIS OF AN OUTPUT-BUFFERED ATM SWITCH WITH SPEED-UP CONSTRAINTS UNDER CORRELATED AND IMBALANCED BURSTY TRAFFIC
    MAKHAMREH, II
    GEORGANAS, ND
    MCDONALD, D
    IEE PROCEEDINGS-COMMUNICATIONS, 1995, 142 (02): : 61 - 66