Design and implementation of the data plane for provisioning high-performance security services in a dynamic network environment동적 네트워크 환경에서의 고성능 보안 서비스 제공을 위한 데이터 평면의 설계 및 구현에 관한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 208
  • Download : 0
Modern network environments are constantly changing due to various reasons such as migration of virtualized hosts, movements of mobile devices, and changes in application / service lifecycle. In order to provide appropriate network security for these environments, security services must also be able to accommodate such changes in the network. To achieve this, security services typically adopt software-defined networking (SDN) and network function virtualization (NFV) techniques. Unfortunately, these approaches result in significant performance losses as follows. First, network bandwidth is greatly wasted due to redundant traffic routing. Second, since security services are processed in software, their performance is insufficient for handling advanced features such as DPI. Third, traffic is concentrated on specific nodes or links where security services are located, resulting in performance loss due to processing overhead and resource imbalance. This dissertation focuses on such performance issues found in the provision of security services in a dynamic network environment. As a solution to each problem, we propose 1) an architecture that integrates security services into a data plane (DPX), 2) a real-time programmable hardware regular expression processor (Reinhardt), and 3) a system for network resource and traffic distribution by traffic engineering (QoSE), and present their implementation and design. We expect this dissertation to contribute to the establishment of more secure and improved network infrastructure by presenting practical solutions for high-performance security services with modern network characteristics and increasing network traffic in mind.
Advisors
Shin, Seunwonresearcher신승원researcher
Description
한국과학기술원 :정보보호대학원,
Publisher
한국과학기술원
Issue Date
2021
Identifier
325007
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 정보보호대학원, 2021.2,[vi, 93 p. :]

Keywords

Dynamic network▼aSecurity▼aPerformance▼aData plane▼aArchitecture; 동적 네트워크▼a보안▼a성능▼a데이터 평면▼a아키텍쳐

URI
http://hdl.handle.net/10203/295751
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=956572&flag=dissertation
Appears in Collection
IS-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0