A Cost-based Placement Algorithm for Multiple Virtual Security Appliances in Cloud using SDN: MO-UFLP(Multi-Ordered Uncapacitated Facility Location Problem)

Prajeesh Murukan,Dana Jamaluddine,Shalaka Kolhapure,Fady Mikhael,Shiva Nouzari
DOI: https://doi.org/10.48550/arXiv.1602.08155
2016-02-26
Abstract:Software Defined Networking (SDN), has introduced many advanced platforms for managing networks and adopting different security tools with them, but the cost of these platforms should be considered as well. In this paper, we present an extension of the existing approach to the optimal placement of virtual security appliances in a pre-defined network setting. The approach proposed by Bouet [1] only considered one security appliance, we extended his approach to several virtual security appliances. We conducted several simulation tests showing good performances of our approach. To show the feasibility, we implemented our approach using SDN and virtual security appliances and integrated it into OpenStack. This extension adapts UFLP algorithm to real world situations where several middle boxes need to be deployed to satisfy security needs for the applications deployed in the cloud. We realized this approach by implementing "OpenStack on top of OpenStack" , a nested OpenStack implementation with OpenDayLight as the SDN controller .
Cryptography and Security
What problem does this paper attempt to address?