以提高云防火墙容错能力为任务的嵌套虚拟化技术实现场景

Vitalii Tkachov, Mykhailo Hunko, Vadym Volotka
{"title":"以提高云防火墙容错能力为任务的嵌套虚拟化技术实现场景","authors":"Vitalii Tkachov, Mykhailo Hunko, Vadym Volotka","doi":"10.1109/PICST47496.2019.9061473","DOIUrl":null,"url":null,"abstract":"Currently, the use of cloud firewalls allows protecting not only individual network resources, but also the entire infrastructure of large data centers. The main requirement for a cloud firewall is high fault tolerance. There are classic ways to increase fault tolerance, which focus on high redundancy of technological solution. Small and medium Internet business cannot always afford the creation of a separate solution to ensure the security of resources. Therefore, it is relevant to implement nested virtualization technology that gives the opportunity to use a cloud server with a hypervisor inside, in which, in turn, virtual machines are launched. Firewall software can be directly implemented on these virtual machines. Improving the fault tolerance of a cloud firewall is possible using of a set of nested virtual machines of the cloud server, which can be instantly restored by its hypervisor. To analyze the impact of the resource allocation plan of the cloud server, to detect a failed or incorrectly running nested virtual machine, the calculation of the virtual machine efficiency indicator is given. The paper proposed three scenarios for the use of nested virtualization technology: nested virtualization of services, nested virtualization of machines and virtualization of the entire infrastructure. For each of them, experimental studies have been carried out in order to identify patterns of time delay values for restoring the full functionality of the cloud firewall after a network attack on its various elements. By conducting experiments, it has been established that the use of nested virtualization technology in the first scenario allows to get a time gain of 7 times; in the second scenario there is a gain of 1.5 times; in the third one, it has been allowed to fully restart the cloud firewall infrastructure in a new cloud.","PeriodicalId":6764,"journal":{"name":"2019 IEEE International Scientific-Practical Conference Problems of Infocommunications, Science and Technology (PIC S&T)","volume":"34 1","pages":"759-763"},"PeriodicalIF":0.0000,"publicationDate":"2019-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":"{\"title\":\"Scenarios for Implementation of Nested Virtualization Technology in Task of Improving Cloud Firewall Fault Tolerance\",\"authors\":\"Vitalii Tkachov, Mykhailo Hunko, Vadym Volotka\",\"doi\":\"10.1109/PICST47496.2019.9061473\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Currently, the use of cloud firewalls allows protecting not only individual network resources, but also the entire infrastructure of large data centers. The main requirement for a cloud firewall is high fault tolerance. There are classic ways to increase fault tolerance, which focus on high redundancy of technological solution. Small and medium Internet business cannot always afford the creation of a separate solution to ensure the security of resources. Therefore, it is relevant to implement nested virtualization technology that gives the opportunity to use a cloud server with a hypervisor inside, in which, in turn, virtual machines are launched. Firewall software can be directly implemented on these virtual machines. Improving the fault tolerance of a cloud firewall is possible using of a set of nested virtual machines of the cloud server, which can be instantly restored by its hypervisor. To analyze the impact of the resource allocation plan of the cloud server, to detect a failed or incorrectly running nested virtual machine, the calculation of the virtual machine efficiency indicator is given. The paper proposed three scenarios for the use of nested virtualization technology: nested virtualization of services, nested virtualization of machines and virtualization of the entire infrastructure. For each of them, experimental studies have been carried out in order to identify patterns of time delay values for restoring the full functionality of the cloud firewall after a network attack on its various elements. By conducting experiments, it has been established that the use of nested virtualization technology in the first scenario allows to get a time gain of 7 times; in the second scenario there is a gain of 1.5 times; in the third one, it has been allowed to fully restart the cloud firewall infrastructure in a new cloud.\",\"PeriodicalId\":6764,\"journal\":{\"name\":\"2019 IEEE International Scientific-Practical Conference Problems of Infocommunications, Science and Technology (PIC S&T)\",\"volume\":\"34 1\",\"pages\":\"759-763\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"9\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 IEEE International Scientific-Practical Conference Problems of Infocommunications, Science and Technology (PIC S&T)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/PICST47496.2019.9061473\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 IEEE International Scientific-Practical Conference Problems of Infocommunications, Science and Technology (PIC S&T)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/PICST47496.2019.9061473","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

摘要

目前,使用云防火墙不仅可以保护单个网络资源,还可以保护大型数据中心的整个基础设施。对云防火墙的主要要求是高容错性。提高容错能力的经典方法主要集中在技术方案的高冗余性上。中小型互联网企业不能总是负担得起创建一个单独的解决方案,以确保资源的安全。因此,实现嵌套虚拟化技术是相关的,这种技术提供了使用内部有管理程序的云服务器的机会,而虚拟机又在其中启动。防火墙软件可以直接在这些虚拟机上实现。使用云服务器的一组嵌套虚拟机可以提高云防火墙的容错性,这些虚拟机可以由其管理程序立即恢复。为了分析云服务器资源分配计划的影响,检测嵌套虚拟机失败或不正确运行,给出了虚拟机效率指标的计算。本文提出了使用嵌套虚拟化技术的三种场景:服务的嵌套虚拟化、机器的嵌套虚拟化和整个基础设施的虚拟化。对于它们中的每一个,都进行了实验研究,以确定在网络攻击其各种元素后恢复云防火墙全部功能的时间延迟值模式。通过实验确定,在第一种场景中使用嵌套虚拟化技术可以获得7倍的时间增益;在第二种情况下,增益是1.5倍;在第三个版本中,允许在新的云中完全重新启动云防火墙基础设施。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Scenarios for Implementation of Nested Virtualization Technology in Task of Improving Cloud Firewall Fault Tolerance
Currently, the use of cloud firewalls allows protecting not only individual network resources, but also the entire infrastructure of large data centers. The main requirement for a cloud firewall is high fault tolerance. There are classic ways to increase fault tolerance, which focus on high redundancy of technological solution. Small and medium Internet business cannot always afford the creation of a separate solution to ensure the security of resources. Therefore, it is relevant to implement nested virtualization technology that gives the opportunity to use a cloud server with a hypervisor inside, in which, in turn, virtual machines are launched. Firewall software can be directly implemented on these virtual machines. Improving the fault tolerance of a cloud firewall is possible using of a set of nested virtual machines of the cloud server, which can be instantly restored by its hypervisor. To analyze the impact of the resource allocation plan of the cloud server, to detect a failed or incorrectly running nested virtual machine, the calculation of the virtual machine efficiency indicator is given. The paper proposed three scenarios for the use of nested virtualization technology: nested virtualization of services, nested virtualization of machines and virtualization of the entire infrastructure. For each of them, experimental studies have been carried out in order to identify patterns of time delay values for restoring the full functionality of the cloud firewall after a network attack on its various elements. By conducting experiments, it has been established that the use of nested virtualization technology in the first scenario allows to get a time gain of 7 times; in the second scenario there is a gain of 1.5 times; in the third one, it has been allowed to fully restart the cloud firewall infrastructure in a new cloud.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信