Skip to main navigation Skip to search Skip to main content

A monitoring-based load balancing scheme for network security functions

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper proposes an enhanced Interface to Network Security Functions (I2NSF) framework. To improve the whole packet throughput and manage resource of Network Security Functions (NSFs), the enhanced I2NSF framework monitors NSFs and distributes incoming packets to NSFs efficiently. Even if the legacy framework that provides security services using Software-Defined Networking (SDN) and Network Functions Virtualization (NFV) has the similar NSFs, it is inefficient to be unable to distribute the packets to multiple NSFs. Based on the legacy I2NSF framework, therefore, we add two kinds of communication such as (i) communication between NSFs and security controller to monitor NSFs and (ii) communication between Security Function Forwarder (SFF) and security controller to perform the load balance for the packets to multiple NSFs. For the further communications between NSFs with security controller, we present a message format based on the information model proposed by Internet Engineering Task Force (IETF) I2NSF Working Group. We use capability data model proposed by IETF I2NSF WG, which describes the capability of an NSF. In order to show the feasibility of the proposed framework, we implemented the enhanced framework using IETF standards and open sources.

Original languageEnglish
Title of host publicationInternational Conference on Information and Communication Technology Convergence
Subtitle of host publicationICT Convergence Technologies Leading the Fourth Industrial Revolution, ICTC 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages668-672
Number of pages5
ISBN (Electronic)9781509040315
DOIs
StatePublished - 12 Dec 2017
Event8th International Conference on Information and Communication Technology Convergence, ICTC 2017 - Jeju Island, Korea, Republic of
Duration: 18 Oct 201720 Oct 2017

Publication series

NameInternational Conference on Information and Communication Technology Convergence: ICT Convergence Technologies Leading the Fourth Industrial Revolution, ICTC 2017
Volume2017-December

Conference

Conference8th International Conference on Information and Communication Technology Convergence, ICTC 2017
Country/TerritoryKorea, Republic of
CityJeju Island
Period18/10/1720/10/17

Keywords

  • Interface to Network Security Functions
  • Load Balancing
  • Monitoring
  • Network Functions Virtualization
  • Software Defined Networking

Fingerprint

Dive into the research topics of 'A monitoring-based load balancing scheme for network security functions'. Together they form a unique fingerprint.

Cite this