NFV and NFV-based Security Services 365
15.7.1 NFV‐based Network Security
Network security services are typically provided by a gateway device. They are
ubiquitous today in our computing and networking infrastructures in the forms
of firewalls, DPI (deep packet inspection), IDS/IPS (intrusion detection systems or
intrusion prevention systems), and many more. They can be stand‐alone appliances or
can be embedded into other network devices. These gateways are inline devices,
meaning that they must be inserted into the network data path and handle the full load
of traffic in order to be most effective. They are therefore prime candidates for virtualization. We look at different ways in an NFV system in which this can be achieved,
and their benefits.
15.7.1.1 Virtual Security Appliances
Virtual security appliances are easy to adopt with NFV. The virtual appliance is a VNF
that has equivalent security function as its PNF counterpart. The virtual appliance also
has several fundamental advantages:
● The VNF can be created on‐demand within seconds, anywhere in the NFV
infrastructure resource pool;
● The VNF can easily scale up or down on demand;
● The VNF can be virtually dropped in to an existing network function chain;
● If the VNF is designed in a modern way, or cloud native, then it can also easily scale
out horizontally in many cases;
● The VNF can be managed remotely and automatically by applying uniform security
policies.
How can these properties of the VNF improve security? We can look at one recent
security incident: the DDoS attack against DNS service provider Dyn.com. By Dyn’s
statement [33], the attack was the work of “tens of millions” IoT devices infected by the
Mirai botnet. With the deployment of 5G and future IoT use explosion, we should
expect similar incidents, with several orders of higher‐scale magnitude. How can a NFV
system better defend against such an attack?
First, NFV’s dynamic scaling feature will be able to absorb the first wave of attack
much more effectively. In a physical appliance deployment, the system’s capability is
static. Let us say the Dyn engineers foresaw an attack that may spike the load of the
system by up to 10× of the normal load. That is the system capacity that they would have
installed, and the malicious party only needs to generate 11× the load to cause a problem. In a NFV system, the entire data center’s resources are a shared pool among many
work loads. When the DNS system is under attack, the DNS system can scale up
dynamically (including by shifting resource allocation from less critical system services)
and give the system much more flexibility and time to absorb the attack wave, detect
DDoS activities, analyze behaviors and even figure out remedies.
Second, even if the attacker can muster a large enough load to drain the extra capacity
of the entire data center, Dyn’s NAC operators would have much better MANO tools to
deploy a solution quickly. The Dyn’s official statement said that it took them a heroic
“two hours” to recover from the first wave of the attack. A better MANO may reduce
the deployment of the remedy in minutes or even seconds, and therefore practically
render the attack a non‐event.
15.7.1 NFV‐based Network Security
Network security services are typically provided by a gateway device. They are
ubiquitous today in our computing and networking infrastructures in the forms
of firewalls, DPI (deep packet inspection), IDS/IPS (intrusion detection systems or
intrusion prevention systems), and many more. They can be stand‐alone appliances or
can be embedded into other network devices. These gateways are inline devices,
meaning that they must be inserted into the network data path and handle the full load
of traffic in order to be most effective. They are therefore prime candidates for virtualization. We look at different ways in an NFV system in which this can be achieved,
and their benefits.
15.7.1.1 Virtual Security Appliances
Virtual security appliances are easy to adopt with NFV. The virtual appliance is a VNF
that has equivalent security function as its PNF counterpart. The virtual appliance also
has several fundamental advantages:
● The VNF can be created on‐demand within seconds, anywhere in the NFV
infrastructure resource pool;
● The VNF can easily scale up or down on demand;
● The VNF can be virtually dropped in to an existing network function chain;
● If the VNF is designed in a modern way, or cloud native, then it can also easily scale
out horizontally in many cases;
● The VNF can be managed remotely and automatically by applying uniform security
policies.
How can these properties of the VNF improve security? We can look at one recent
security incident: the DDoS attack against DNS service provider Dyn.com. By Dyn’s
statement [33], the attack was the work of “tens of millions” IoT devices infected by the
Mirai botnet. With the deployment of 5G and future IoT use explosion, we should
expect similar incidents, with several orders of higher‐scale magnitude. How can a NFV
system better defend against such an attack?
First, NFV’s dynamic scaling feature will be able to absorb the first wave of attack
much more effectively. In a physical appliance deployment, the system’s capability is
static. Let us say the Dyn engineers foresaw an attack that may spike the load of the
system by up to 10× of the normal load. That is the system capacity that they would have
installed, and the malicious party only needs to generate 11× the load to cause a problem. In a NFV system, the entire data center’s resources are a shared pool among many
work loads. When the DNS system is under attack, the DNS system can scale up
dynamically (including by shifting resource allocation from less critical system services)
and give the system much more flexibility and time to absorb the attack wave, detect
DDoS activities, analyze behaviors and even figure out remedies.
Second, even if the attacker can muster a large enough load to drain the extra capacity
of the entire data center, Dyn’s NAC operators would have much better MANO tools to
deploy a solution quickly. The Dyn’s official statement said that it took them a heroic
“two hours” to recover from the first wave of the attack. A better MANO may reduce
the deployment of the remedy in minutes or even seconds, and therefore practically
render the attack a non‐event.
