CPFirewall: A Novel Parallel Firewall Scheme for FWaaS in the Cloud Environment.

Zhenfang Wang,ZhiHui Lu,Jie Wu,Kang Fan
DOI: https://doi.org/10.1007/978-3-319-26979-5_9
2015-01-01
Abstract:In cloud, resources are virtualized and the software delivery way is becoming something like a \"service\" to provide end user and operator benefits including on-demand self-service, resource pooling, rapid elasticity and service metering capability. As a part of network function virtualization, firewall virtualization can greatly increase the firewall configuration flexibility for the cloud environment. In this paper, we focus on FWaaS Firewall as a Service and we design a parallel firewall system called CPFirewall Cloud Parallel Firewall System. In CPFirewall, the firewall resources are virtualized and multiple tenants can build up their own parallel firewall by renting virtual firewalls. This needs solve some challenges. We adopt a rule-splitting algorithm to build a rule anomaly set We call it Wrapset. for detecting rule anomaly. We design the rule-allocation algorithm to achieve the cloud-native features, including load balance and dynamic scale. And we also improve the system performance using Exponential Smoothing ES forecasting method. Experiment results have verified that CPFirewall has a higher efficiency than other firewall schemes and is much more suitable for the Cloud network environment.
What problem does this paper attempt to address?