The Experts below are selected from a list of 24 Experts worldwide ranked by ideXlab platform
Saeed Sharifian - One of the best experts on this subject based on the ideXlab platform.
-
Learning-based dynamic scalable load-balanced Firewall as a Service in network function-virtualized cloud computing environments
The Journal of Supercomputing, 2018Co-Authors: Naghmeh Dezhabad, Saeed SharifianAbstract:Network function virtualization (NFV) is a network architecture which tries to provide communication Services in clouds through virtualization techniques. Actually, NFV combines server and Service and replaces a lot of network devices. NFV deploys software applications instead of hardware devices and therefore reduces network provider’s financial costs and facilities manageability. One of the Services that NFVs present is virtualized Firewalls in clouds. As other Services in clouds, Firewalls should be dynamically scaled to the needs of any business and adapt as demands increase. In this paper, a method is proposed for dynamic auto-scalability of the Firewall Service in cloud environments. The proposed method also balances incoming load among different virtualized Firewalls which are installed as a software on virtual machines and are located in one pool. We consider a queuing model for each virtual machine. The goal here is to determine the number of active virtualized Firewalls required in different time steps according to the intensity of incoming load and the proportion of total requests that goes to each Firewall. Decisions are made regarding the utilization of Firewall virtual machines so that QoS requirements can be met; at the same time, the resources will be saved in order to balance the performance with the cost of allocated Firewall virtual machines. To solve the problem, we propose a hybrid genetic algorithm and reinforcement learning-based approach, namely GARLAS (genetic algorithm and reinforcement learning-based autonomic scaling), implemented in a cloud manager. The results of simulation with MATLAB on different realistic workloads demonstrate that the approach is able to find an optimal policy in both scalability and load balancing aspects. Also, it leads to 87.91 and 85.15% of lower average response time and 9.93 and 11.77% of improvement in utilization in comparison with static and threshold-based approaches, respectively.
Anwar Mahwish - One of the best experts on this subject based on the ideXlab platform.
-
Virtual Firewalling For Migrating Virtual Machines In Cloud Computing
Blekinge Tekniska Högskola Sektionen för datavetenskap och kommunikation, 2013Co-Authors: Anwar MahwishAbstract:Context. Cloud Computing (CC) uses virtualization to provide computing resources on demand via Internet. Small and large organizations benefit from CC because of reduced operating costs and increase in business agility. The migrating Virtual Machine (VM) is vulnerable from attacks such as fake migration initiations, Service interruptions, manipulation of data or other network attacks. During live migration any security lax in VM Firewall policy can put the VM data, OS and the applications on it at risk. A malicious VM can pose threat to other VMs in its host and consequently for VMs in LAN. Hardware Firewalls only protect VM before and after migration. Plus, they are blind to virtual traffic. Hence, virtual Firewalls (VFs) are used to secure VMs. Mostly; they are deployed at Virtual Machine Monitor-level (VMM) under Cloud provider’s control. Source VMM-level VF provides security to VM before the migration incurs and the destination VMM-level VF starts securing VM after migration is completed. It thus, becomes possible for attacker to use the intermediate migrating window to launch attacks on VM. Considering the potential of VFs there should be a great value in using open source VFs at VM-level for protecting VMs during migration, thereby, reducing the attacker’s slot to gain access to VM. It would enable hardened security for overall VM migration. Objectives. The aim is to investigate VM-level Firewalling using open source Firewall as a complementary security layer to VMM-level Firewalling, to secure migrating VM in the CC domain. The first objective is to identify how virtual Firewalls secure migrating VM in CC and to propose VM-level open-source virtual Firewalling for protecting VM during migration. Later the VF is implemented to validate and evaluate its intactness or activeness during migration in real Cloud data center. Methods. In the literary review 9 electronic libraries are used, which include IEEE Xplore, ACM Digital Library, SCOPUS, Engineering Village and Web of Knowledge. Studies are selected after querying libraries for 2 key terms ‘virtual machine’ and ‘migration’ (along with other variations/synonyms), in the abstract. Relevant papers on the subject are read and analyzed. Finally, the information gaps are identified. Using a lacuna the experimental solution is designed. To test the potential of VF at VM-level for migrating VM’s security the experimental validation is performed using stratification samples of Firewall rules. The VF evaluation is done using continuous ICMP echo packet transmission. The packets are analyzed to determine Firewall behavior during migration. To evaluate the validity, the VM migration is performed 8 times in City Network data center. Results. The literary review identified the widespread use of VMM-level Firewalling for migrating VM’s security in CC. The VM-level VFs were not researched nor evaluated for intactness during migration. The experiment performed at City Network demonstrated that the VM-level VF secures VM during migration (on average) for 96% of migration time, thereby reducing attack window for attacker during VM mobility. According to the results the average total migration time (TMT) was 16.6 s and average downtime (DT) of Firewall was as low as 0.47 s, which means that VF at VM-level protects VM during entire migration span except when VM’s down (4% of migration time). Conclusions. The research concludes that VM-level Firewalling using open source VF as an additional security layer in CC for VM migrations is feasible to employ and will enhance the migrating machine’s security by providing hardened Firewall Service during migration process, thus, reducing the potential attack window. VMM-level VF provides security in post and pre migration phase. Using VM-level VF as a complementary measure to VMM-level VF enables additional protection for VM migration process, thereby reducing the chances for attacker to attack VM during transition.Email: mahwish.anwar@gmail.com Twitter: Mah__WishORCID ID: 0000-0001-7486-5216
Naghmeh Dezhabad - One of the best experts on this subject based on the ideXlab platform.
-
Learning-based dynamic scalable load-balanced Firewall as a Service in network function-virtualized cloud computing environments
The Journal of Supercomputing, 2018Co-Authors: Naghmeh Dezhabad, Saeed SharifianAbstract:Network function virtualization (NFV) is a network architecture which tries to provide communication Services in clouds through virtualization techniques. Actually, NFV combines server and Service and replaces a lot of network devices. NFV deploys software applications instead of hardware devices and therefore reduces network provider’s financial costs and facilities manageability. One of the Services that NFVs present is virtualized Firewalls in clouds. As other Services in clouds, Firewalls should be dynamically scaled to the needs of any business and adapt as demands increase. In this paper, a method is proposed for dynamic auto-scalability of the Firewall Service in cloud environments. The proposed method also balances incoming load among different virtualized Firewalls which are installed as a software on virtual machines and are located in one pool. We consider a queuing model for each virtual machine. The goal here is to determine the number of active virtualized Firewalls required in different time steps according to the intensity of incoming load and the proportion of total requests that goes to each Firewall. Decisions are made regarding the utilization of Firewall virtual machines so that QoS requirements can be met; at the same time, the resources will be saved in order to balance the performance with the cost of allocated Firewall virtual machines. To solve the problem, we propose a hybrid genetic algorithm and reinforcement learning-based approach, namely GARLAS (genetic algorithm and reinforcement learning-based autonomic scaling), implemented in a cloud manager. The results of simulation with MATLAB on different realistic workloads demonstrate that the approach is able to find an optimal policy in both scalability and load balancing aspects. Also, it leads to 87.91 and 85.15% of lower average response time and 9.93 and 11.77% of improvement in utilization in comparison with static and threshold-based approaches, respectively.
Chienchao Tseng - One of the best experts on this subject based on the ideXlab platform.
-
an autoblocking mechanism for Firewall Service
IEEE Conference Dependable and Secure Computing, 2017Co-Authors: Huaiwen Hsu, Yichih Kao, Shichun Tsai, Chienchao TsengAbstract:A distributed denial-of-Service (DDoS) attack could cause the incoming connections per second exceeding the capacity of the Firewall device and the network system might be paralyzed. By analyzing the syslog of Firewall, we design an effective mechanism to block malicious source IPs automatically from the router. We have undergone a field trial on campus for two years. The collected data shows that our approach significantly reduces suspicious traffic and improve the stability of overall network Service.
Urho Tomi - One of the best experts on this subject based on the ideXlab platform.
-
Keskitetty palomuurijärjestelmä
Vaasan ammattikorkeakoulu, 2013Co-Authors: Urho TomiAbstract:Tämä opinnäytetyö on tehty Anvia Yrityspalvelut Oy:n Tuotehallintayksikön Tietoliikenneosastolle. Anvia Yrityspalveluiden tarjoama palomuuripalvelu oli toteutettu erillisillä palomuurilaitteilla, joiden toimitukseen ja ylläpitoon haluttiin helpotusta. Lisäksi haluttiin tuottaa uusia yritysasiakkaille tarjottavia palveluita. Ratkaisuksi valittiin keskitetty palomuurijärjestelmä, joka mahdollistaa palomuuripalveluiden tuottamisen keskitetysti. Hankittu palomuurijärjestelmä mahdollistaa ´myös UTM-toiminnot, joiden avulla uusia palveluja voidaan tuottaa. Palomuurilaitevalmistajan valinnassa tehtiin vertailuja monen valmistajan välillä. Laitevalinta perustui valmistajan kykyyn toteuttaa UTM-ratkaisuja sekä laitevalmistajan hyvään maineeseen. Varsinainen palomuuriklusterin kytkentä operaattoriverkkoon suunniteltiin ja kytkettiin siten, että siinä otettiin huomioon mahdollisimman suuri vikasietoisuus. Palomuurilaitteen mahdollistamat UTM-toiminnot todettiin toimivan hyvin ja ne pystyttiin toteuttamaan Anvian tarjoamiin yritysliittymiin.This thesis is done to Anvia Yrityspalvelut Oy’s product management of telecommunication department. Anvia Yrityspalvelut offers Firewall Services based on distributed Firewalls. New centralized Firewall system is going to replace the old Firewall Service and with the new Firewall Service Anvia is looking more cost efficient model starting with installing and maintenance times. With new Firewall system there is also possible to offer new Services to the customers. Firewall system is capable of next generation Firewall, UTM features. The Firewall manufacturer selection was done after the comparison between man of the Firewall manufacturers. Selection was based on the ability to execute UTM functions and on a good reputation of the manufacturer. Actual connecting of the Firewall cluster to the operator’s core network was planned and connected so that there is considered great fault tolerance. Firewall systems UTM functions where tested and stated to function very well and able to implement existing enterprise connections