Cloud Firewall Under Bursty and Correlated Data Traffic: A Theoretical Analysis

被引:5
|
作者
Carvalho, Glaucio H. S. [1 ]
Woungang, Isaac [1 ]
Anpalagan, Alagan [2 ]
机构
[1] Ryerson Univ, Dept Comp Sci, 350 Victoria St, Toronto, ON M5B 2K3, Canada
[2] Ryerson Univ, Dept Elect & Comp Engn, Toronto, ON M5B 2K3, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Cloud security; DDoS; markov process; firewall; markov-modulated poisson process; PERFORMANCE ANALYSIS; FRAMEWORK; NETWORKS; INTERNET; MODEL;
D O I
10.1109/TCC.2020.3000674
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud firewalls stand as one of the major building blocks of the cloud security framework protecting the Virtual Private Infrastructure against attacks such as the Distributed Denial of Service (DDoS). In order to fully characterize the cloud firewall operation and gain actionable insights on the design of cloud security, performance models for the cloud firewall become imperative. In this article, we propose a multi-dimensional Continuous-Time Markov Chain model for the cloud firewall that takes into account the burstiness and correlation features of the legitimate and malicious data traffic. By adopting the Markov-Modulated Poisson process (MMPP) and the Interrupted Poisson Process (IPP), we identify the workload conditions under which the cloud firewall might be subject to a loss of availability. Furthermore, by comparing the IPP and Poisson attacks, we numerically verify that the cloud firewall is inherently vulnerable to a burstiness-aware attack which might seriously compromise its operation. Additionally, we characterize the joint harmful impact of burstiness and correlation on the cloud firewall that might lead to performance degradation. Finally, we design an elastic doud firewall by proposing a MMPP-driven load balancing procedure that provisions virtual firewalls dynamically while fulfilling a Service Level Agreement (SLA) latency specification.
引用
收藏
页码:1620 / 1633
页数:14
相关论文
共 50 条
  • [41] IMPROVING THE INPUT-QUEUING SWITCH UNDER BURSTY TRAFFIC
    LI, JJ
    ELECTRONICS LETTERS, 1995, 31 (11) : 854 - 855
  • [42] Impact of adaptivity on the behavior of networks of workstations under bursty traffic
    Silla, F
    Malumbres, MP
    Duato, J
    Dai, D
    Panda, DK
    1998 INTERNATIONAL CONFERENCE ON PARALLEL PROCESSING - PROCEEDINGS, 1998, : 88 - 95
  • [43] Modelling an Integrated Scheduling Scheme under Bursty MMPP Traffic
    Liu, Lei
    Jin, Xiaolong
    Min, Geyong
    2009 INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS: WAINA, VOLS 1 AND 2, 2009, : 212 - 217
  • [44] Performance and Data Traffic Analysis of Mobile Cloud Environments
    Pinheiro, Thiago
    Silva, Francisco Airton
    Fe, Iure
    Kosta, Sokol
    Maciel, Paulo
    2018 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2018, : 4100 - 4105
  • [45] Dynamic Resource Management in Virtualized Data Centers with Bursty Traffic
    Valdez-Vivas, Martin
    Bambos, Nicholas
    Apostolopoulos, John
    2014 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2014, : 4287 - 4293
  • [46] Modeling UMTS power saving with bursty packet data traffic
    Yang, Shun-Ren
    Yan, Sheng-Ying
    Hung, Hui-Nien
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2007, 6 (12) : 1398 - 1409
  • [47] Performance analysis of the knockout switch under bursty traffic based on a stochastic activity network model
    Bellcore, Morristown, United States
    Simulation, 1 (19-33):
  • [48] Performance analysis of the knockout switch under bursty traffic based on a stochastic activity network model
    Kant, L
    Sanders, WH
    SIMULATION, 1998, 70 (01) : 19 - 33
  • [49] Modeling and Analysis of Communication Networks in Multicluster Systems under Spatio-Temporal Bursty Traffic
    Wu, Yulei
    Min, Geyong
    Li, Keqiu
    Javadi, Bahman
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2012, 23 (05) : 902 - 912
  • [50] THE DEPARTURE PROCESS OF A FINITE-CAPACITY POLLING SYSTEM WITH BURSTY AND CORRELATED INPUT TRAFFIC
    JOU, YF
    NILSSON, AA
    LAI, FY
    HIGH SPEED NETWORKS AND THEIR PERFORMANCE, 1994, 21 : 83 - 101