Detailed Information

Cited 0 time in webofscience Cited 29 time in scopus
Metadata Downloads

GRBC-based Network Security Functions placement scheme in SDS for 5G security

Authors
Guan, JianfengWei, ZhijunYou, Ilsun
Issue Date
15-Jul-2018
Publisher
Academic Press
Keywords
Software Defined Security; Group Routing Betweenness Centrality; Network Security Function; 5G
Citation
Journal of Network and Computer Applications, v.114, pp 48 - 56
Pages
9
Journal Title
Journal of Network and Computer Applications
Volume
114
Start Page
48
End Page
56
URI
https://scholarworks.bwise.kr/sch/handle/2021.sw.sch/5800
DOI
10.1016/j.jnca.2018.03.013
ISSN
1084-8045
1095-8592
Abstract
With the paradigm shift of 5G in terms of computing and infrastructure, 5G security is confronted with new challenges due to the promising introduction of Software Defined Networks (SDN), Network Function Virtualization (NFV) and Cloud Computing. While most of current works on 5G security are focused on high-level analysis of challenges and threats to satisfy the emerging use cases. Software Defined Security (SDS), as a new security paradigm which provides flexible and centralized security protection for varieties of networks especially for SDN and Cloud environment, can be a potential security solution in 5G. Lots of work have focused on the implementations and details of SDS, and most researchers, however, are focusing on the controller design and security policy design. There are few work on the placement strategy of Network Security Functions (NSFs) and devices, which plays a significant role in SDS to improve the optimize defence effects. Most of existing placement schemes are modelled as Integer Linear Programming (ILP) by considering the constrains in terms of resource, time, security and so on, and introduce various heuristic algorithm to reduce its computing complexity. While in this paper, we propose a placement scheme of NSFs and devices in SDS based on underlying routing characteristic and evaluate its performance defending virus attack. The proposed scheme adopts Group Routing Betweenenss Centrality (GRBC) as a metric and introduces a successive algorithm to compute the GRBC. Different to traditional Routing Betweenness Centrality which only considers the importance of single node, the proposed scheme can find the key group of nodes in a SDS underlying network, where the NSFs and security devices should be deployed. In the performance evaluation, we apply our scheme to the scenario of computer virus and worms control in SDS, and the results show that the proposed scheme can improve the performance of security functions in SDS system.
Files in This Item
There are no files associated with this item.
Appears in
Collections
College of Engineering > Department of Information Security Engineering > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Altmetrics

Total Views & Downloads

BROWSE