Attack-aware Security Function Chain Reordering
Lukas Iffl\"ander, Nishant Rawtani, Lukas Beierlieb, Nicolas Fella,, Klaus-Dieter Lange, Samuel Kounev

TL;DR
This paper emphasizes the importance of the sequence of security functions in service chains, proposing a reordering framework that improves security system performance against attacks.
Contribution
It introduces a novel framework for reordering security functions in service chains, considering attack-awareness and modeling aspects for optimal sequence determination.
Findings
Order of security functions significantly impacts system effectiveness.
The proposed framework can improve security performance by multiple orders of magnitude.
Validation shows the feasibility and potential benefits of reordering security functions.
Abstract
Attack-awareness recognizes self-awareness for security systems regarding the occurring attacks. More frequent and intense attacks on cloud and network infrastructures are pushing security systems to the limit. With the end of Moore's Law, merely scaling against these attacks is no longer economically justified. Previous works have already dealt with the adoption of Software-defined Networking and Network Function Virtualization in security systems and used both approaches to optimize performance by the intelligent placement of security functions. However, these works have not yet considered the sequence in which traffic passes through these functions. In this work, we make a case for the need to take this ordering into account by showing its impact. We then propose a reordering framework and analyze what aspects are necessary for modeling security service function chains and making…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware-Defined Networks and 5G · Network Security and Intrusion Detection · Software System Performance and Reliability
