NFV and NFV-based Security Services 359
These software abstractions can be several magnitudes more scalable than physical
firewalls such that security rules can be applied with very fine granularity. This is
sometimes referred to as micro‐segmentation [12].
Virtual networks and security rules only protect a VNF from other virtual machines
that are sharing the same infrastructure. VNFs must also connect with each other to
collaboratively construct a network service. This is referred to as Service Function
Chaining or SFC [13]. SFC can be realized by the same mechanism using virtual
networks and security rules. It is not very efficient, however, because data packets
must be in and out of processors repeatedly stressing the data path bottlenecks, and the
common packet parsing and classification tasks have to be repeated in each stop of the
pipeline where that information of a packet is needed. An active task in IETF [13] is
defining a new encapsulation scheme for SFC to address some of these issues. SFC does
not provide security protection between different VNFs, however. If security is needed,
a virtual firewall VNF is inserted in the chain to work the same way as a physical firewall
or security gateway.
Some of the VNFs that comprise the service must eventually connect with the outside
world via physical network devices to backbone networks, access networks or devices
that are geographically remote. The VNFs are gateways that must contain access to
physical ports directly or indirectly. These edge VNFs must be protected from threats
just like any other PNF in this case. They do have one advantage compared to the
physical ones: they can scale up and down on demand, and that gives them better ability
to deal with DDoS attacks.
Naturally, networking is the most important aspect of security for VNFs, but not the
only one. Virtualization of computing and storage also exposes new attack surfaces to
VNFs and adds new protection capabilities at the same time. Because VNFs share
a  server’s processors, memory and disk with other virtual machines, the isolation
capability provided by the hypervisor is usually not as strong as physical isolation. These
types of issues have been addressed, however, and more capabilities are being added to
a processor’s architecture to strengthen protections. Other issues include the noisy
neighbor problem, where a less‐restrained virtual machine sharing the same physical
processor resources could intentionally or inadvertently abuse them and cause performance degradation, or more severe issues. To properly address these types of issues,
new generations of processors will add stronger isolation mechanisms, for example,
Intel Xeon’s cache reservation [14]. VIM’s resource management software will develop
schemes to allocate resources and place virtual machines more intelligently.
The virtualization layer, for example the hypervisor, provides a strong level of protection for the VNFs running on the top. Modern hypervisors all have built‐in security
features in addition to the protection provided by the operating systems. VNFs can also
migrate, scaling up and down and in and out, and new security rules or security VNFs
can be added on demand. All these functions substantially enhance the overall ability of
the network services to withstand threats both old and new.
15.6.3 Multi‐Tenancy and XaaS
So far we have assumed that the entire NFV system is private, that is administered by a
single operator. NFV facilitates XaaS models in many different layers that can enable
innovative business and operational approaches. For a given service, the provider must
Précédent

- 401/483

Suivant