Cloud is becoming a dominant computing platform. However, we see few work on how to protect cloud data centers. As a cloud usually hosts many different type of applications, the traditional packet level firewall mechanism is not suitable for cloud platforms in case of complex attacks. It is necessary to perform anomaly detection at the event level. Moreover, protecting objects are more diverse than the traditional firewall. Motivated by this, we propose a general framework of cloud firewall, which features event level detection chain with dynamic resource allocation. We establish a mathematical model for the proposed framework. Moreover, a linear resource investment function is proposed for economical dynamical resource allocation for cloud firewalls. A few conclusions have been extracted for the reference of cloud service providers and designers.
History
Pagination
1941 - 1945
Location
Budapest, Hungary
Start date
2013-06-09
End date
2013-06-13
ISBN-13
9781467331227
Language
eng
Publication classification
E1 Full written paper - refereed; E Conference publication
Copyright notice
2013, IEEE
Editor/Contributor(s)
D Kim, P Mueller
Title of proceedings
Proceedings of the IEEE International Conference on Communications; ICC 2013