FlowSNAC: Improving FlowNAC with Secure Scaling and Resiliency
Title | FlowSNAC: Improving FlowNAC with Secure Scaling and Resiliency |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Matias, J., Garay, J., Jacob, E., Sköldström, P., Ghafoor, A. |
Conference Name | 2016 Fifth European Workshop on Software-Defined Networks (EWSDN) |
Keywords | authentication, Degradation, FlowNAC, FlowSNAC, life-cycle management, Load management, Monitoring, network function virtualization, NFV, orchestration systems, process control, product life cycle management, pubcrawl, Resiliency, Resilient Security Architectures, resource allocation, resource allocations, Resource management, SDN, SDN/NFV management, secure scaling, Secure State Migration, secure state transfer, security, service degradation, software defined networking, stateless components, traffic steering, VNF services |
Abstract | Life-cycle management of stateful VNF services is a complicated task, especially when automated resiliency and scaling should be handled in a secure manner, without service degradation. We present FlowSNAC, a resilient and scalable VNF service for user authentication and service deployment. FlowSNAC consists of both stateful and stateless components, some of that are SDN-based and others that are NFVs. We describe how it adapts to changing conditions by automatically updating resource allocations through a series of intermediate steps of traffic steering, resource allocation, and secure state transfer. We conclude by highlighting some of the lessons learned during implementation, and their wider consequences for the architecture of SDN/NFV management and orchestration systems. |
URL | http://ieeexplore.ieee.org/document/7956055/ |
DOI | 10.1109/EWSDN.2016.21 |
Citation Key | matias_flowsnac:_2016 |
- VNF services
- secure scaling
- Secure State Migration
- process control
- secure state transfer
- security
- service degradation
- Load management
- product life cycle management
- pubcrawl
- Resiliency
- Monitoring
- software defined networking
- stateless components
- traffic steering
- FlowNAC
- FlowSNAC
- Resilient Security Architectures
- resource allocation
- resource allocations
- resource management
- life-cycle management
- network function virtualization
- NFV
- orchestration systems
- SDN
- SDN/NFV management
- authentication
- Degradation