Placement Strategies for Virtualized Network Functions in a NFaaS Cloud

Xin He, Tian Guo, E. Nahum, P. Shenoy
{"title":"Placement Strategies for Virtualized Network Functions in a NFaaS Cloud","authors":"Xin He, Tian Guo, E. Nahum, P. Shenoy","doi":"10.1109/HotWeb.2016.17","DOIUrl":null,"url":null,"abstract":"Enterprises that host services in the cloud need to protect their cloud resources using network services such as firewalls and deep packet inspection systems. While middle boxes have typically been used to implement such network functions in traditional enterprise networks, their use in cloud environments by cloud tenants is problematic due to the boundary between cloud providers and cloud tenants. Instead we argue that network function virtualization is a natural fit in cloud environments, where the cloud provider can implement Network Functions as a Service using virtualized network functions running on cloud servers, and enterprise cloud tenants can employ theseservices to implement security and performance optimizations for their cloud resources. In this paper, we focus on placement issues in the design of a NFaaS cloud and present two placement strategies-tenant-centric and service-centric-for deploying virtualized network services in multi-tenant settings. We discuss several tradeoffs of these two strategies. We implement a prototype NFaaS testbed and conduct a series of experiments to quantify the benefits and drawbacks of our two strategies. Our results suggest that the tenant-centric placement provides lower latencies while service-centric approach is more flexible for reconfiguration and capacity scaling.","PeriodicalId":408635,"journal":{"name":"2016 Fourth IEEE Workshop on Hot Topics in Web Systems and Technologies (HotWeb)","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 Fourth IEEE Workshop on Hot Topics in Web Systems and Technologies (HotWeb)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/HotWeb.2016.17","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Enterprises that host services in the cloud need to protect their cloud resources using network services such as firewalls and deep packet inspection systems. While middle boxes have typically been used to implement such network functions in traditional enterprise networks, their use in cloud environments by cloud tenants is problematic due to the boundary between cloud providers and cloud tenants. Instead we argue that network function virtualization is a natural fit in cloud environments, where the cloud provider can implement Network Functions as a Service using virtualized network functions running on cloud servers, and enterprise cloud tenants can employ theseservices to implement security and performance optimizations for their cloud resources. In this paper, we focus on placement issues in the design of a NFaaS cloud and present two placement strategies-tenant-centric and service-centric-for deploying virtualized network services in multi-tenant settings. We discuss several tradeoffs of these two strategies. We implement a prototype NFaaS testbed and conduct a series of experiments to quantify the benefits and drawbacks of our two strategies. Our results suggest that the tenant-centric placement provides lower latencies while service-centric approach is more flexible for reconfiguration and capacity scaling.
NFaaS云中虚拟化网络功能的布局策略
在云中托管业务的企业需要使用防火墙、深度包检测系统等网络服务来保护云资源。虽然中间盒通常用于在传统企业网络中实现此类网络功能,但由于云提供商和云租户之间的边界,它们在云环境中的使用存在问题。相反,我们认为网络功能虚拟化很适合云环境,云提供商可以使用运行在云服务器上的虚拟化网络功能来实现网络功能即服务,企业云租户可以使用这些服务来实现其云资源的安全性和性能优化。在本文中,我们重点关注NFaaS云设计中的放置问题,并提出了两种放置策略——以租户为中心和以服务为中心——用于在多租户设置中部署虚拟化网络服务。我们将讨论这两种策略的几个权衡。我们实现了一个原型NFaaS测试平台,并进行了一系列实验来量化我们两种策略的优缺点。我们的研究结果表明,以租户为中心的布局提供了较低的延迟,而以服务为中心的方法在重新配置和容量扩展方面更加灵活。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信