Virtual network functions placement for defense against distributed denial of service attacks - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

Virtual network functions placement for defense against distributed denial of service attacks

Résumé

In this paper, we are interested in the problem of Virtual Network Function (VNF) placement to counter Distributed Denial of Service (DDoS) attacks. A DDoS attack is one of the most common and damaging types of cyberattacks. Network Function Virtualization (NFV) technology in which network functions and more specifically security mechanisms are implemented as software. Such approach significantly reduces the cost of the infrastructure and simplifies the deployment of new services. We propose two new models for this critical and complex problem. The first model is a mixed-integer linear program aiming at eliminating all DDos attacks before they reach their target. As its size grows exponentially with the network size, we propose a constraint generation algorithm to solve it. The numerical results obtained for different realistic network instances show the effectiveness of our approach. The second model is a bilevel programming problem that achieves a tradeoff between VNFs placement costs and security levels requirements. Our results show that this mechanisms overcomes DDos attacks by effectively filtering attacks while minimizing the total cost of deployed NFV.

Dates et versions

hal-02421693 , version 1 (20-12-2019)

Identifiants

Citer

Sonia Haddad-Vanier, Céline Gicquel, Lila Boukhatem, Kahina Lazri, Paul Chaignon. Virtual network functions placement for defense against distributed denial of service attacks. ICORES 2019 - 8th International Conference on Operations Research and Enterprise Systems, Feb 2019, Prague, Czech Republic. ⟨10.5220/0007397601420150⟩. ⟨hal-02421693⟩
81 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More