Review

Virtual Security Functions and Their Placement in Software Defined Networks: A Survey

Volume: 32 Number: 3 September 1, 2019
EN

Virtual Security Functions and Their Placement in Software Defined Networks: A Survey

Abstract

Software Defined Networking (SDN) and Network Functions Virtualization (NFV) are two important technologies gaining prominence thanks to their benefits for improving the flexibility and cost efficiency in networks. These technologies have been utilized extensively for providing new age security solutions in recent years. Through the use of SDN and NFV, network security functions are virtualized and deployed in a hardware-independent manner, thus reducing costs as well as enabling faster innovations and developments. Functions virtualized with NFV such as firewall, deep packet inspection, intrusion detection systems etc. can reside as applications in the SDN architecture. The issue of where to place these functions in the network is an important problem discussed in the literature. When placing these functions, objectives such as efficient use of network resources, energy consumption, cost, network load, delay etc. must be considered for each function, in addition to ensuring that network security requirements are met. This paper provides a critical survey on the placement of virtualized network security functions in software defined networks and identifies open problems in this field. We briefly describe SDN and NFV technologies, touch upon the relationship between them, exemplify and review the most common virtual security functions in SDN. We also examine and compare the studies on the optimal placement of virtual security functions. Finally, we identify several open research challenges in this area and suggest potential future directions to be considered by researchers.

Keywords

References

  1. 1. Kreutz, D., Ramos, F. M., Verissimo, P. E., Rothenberg, C. E., Azodolmolky, S., Uhlig, S. “Software-defined networking: A comprehensive survey”, Proceedings of the IEEE, 103(1):14-76, (2015).
  2. 2. Feamster, N., Rexford, J., Zegura, E. T”he road to sdn: an intellectual history of programmable networks”, ACM SIGCOMM Computer Communication Review, 44(2):87-98, (2014).
  3. 3. Nunes, B. A. A., Mendonca, M., Nguyen, X.N., Obraczka, K., Turletti, T. “A survey of software-defined networking: Past, present, and future of programmable networks”. IEEE Communication Surveys and Tutorials, 16(3):1617-1634, (2014).
  4. 4. Han, B., Gopalakrishnan, V., Ji, L., Lee, S. “Network function virtualization: Challenges and opportunities for innovations”, IEEE Communications Magazine, 53(2):90-97, (2015).
  5. 5. Internet: ETSI-NFV. http://www.etsi.org/technologies-clusters/technologies/nfv, [Online, accessed 2-April-2018].
  6. 6. Hu, H., Ahn, G.-J. “Virtualizing and utilizing network security functions for securing software defined infrastructure”.
  7. 7. Bouet, M., Leguay, J., Combe, T., Conan, V. “Cost-based placement of vdpi functions in nfv infrastructures”, International Journal of Network Management, 25(6):490-506, (2015).
  8. 8. Internet: Software-Defined Networking (SDN) Definition. https://www.opennetworking.org/sdn-definition/, [Online, accessed 2-April-2018].

Details

Primary Language

English

Subjects

Engineering

Journal Section

Review

Authors

Sedef Demırcı This is me
Türkiye

Publication Date

September 1, 2019

Submission Date

May 8, 2018

Acceptance Date

April 8, 2019

Published in Issue

Year 2019 Volume: 32 Number: 3

APA
Demırcı, S., Demırcı, M., & Sagıroglu, S. (2019). Virtual Security Functions and Their Placement in Software Defined Networks: A Survey. Gazi University Journal of Science, 32(3), 833-851. https://doi.org/10.35378/gujs.422000
AMA
1.Demırcı S, Demırcı M, Sagıroglu S. Virtual Security Functions and Their Placement in Software Defined Networks: A Survey. Gazi University Journal of Science. 2019;32(3):833-851. doi:10.35378/gujs.422000
Chicago
Demırcı, Sedef, Mehmet Demırcı, and Seref Sagıroglu. 2019. “Virtual Security Functions and Their Placement in Software Defined Networks: A Survey”. Gazi University Journal of Science 32 (3): 833-51. https://doi.org/10.35378/gujs.422000.
EndNote
Demırcı S, Demırcı M, Sagıroglu S (September 1, 2019) Virtual Security Functions and Their Placement in Software Defined Networks: A Survey. Gazi University Journal of Science 32 3 833–851.
IEEE
[1]S. Demırcı, M. Demırcı, and S. Sagıroglu, “Virtual Security Functions and Their Placement in Software Defined Networks: A Survey”, Gazi University Journal of Science, vol. 32, no. 3, pp. 833–851, Sept. 2019, doi: 10.35378/gujs.422000.
ISNAD
Demırcı, Sedef - Demırcı, Mehmet - Sagıroglu, Seref. “Virtual Security Functions and Their Placement in Software Defined Networks: A Survey”. Gazi University Journal of Science 32/3 (September 1, 2019): 833-851. https://doi.org/10.35378/gujs.422000.
JAMA
1.Demırcı S, Demırcı M, Sagıroglu S. Virtual Security Functions and Their Placement in Software Defined Networks: A Survey. Gazi University Journal of Science. 2019;32:833–851.
MLA
Demırcı, Sedef, et al. “Virtual Security Functions and Their Placement in Software Defined Networks: A Survey”. Gazi University Journal of Science, vol. 32, no. 3, Sept. 2019, pp. 833-51, doi:10.35378/gujs.422000.
Vancouver
1.Sedef Demırcı, Mehmet Demırcı, Seref Sagıroglu. Virtual Security Functions and Their Placement in Software Defined Networks: A Survey. Gazi University Journal of Science. 2019 Sep. 1;32(3):833-51. doi:10.35378/gujs.422000

Cited By