Chu
366
Sometimes new attacks may be deployed that no one has seen before, and existing
system software may not have a ready configuration we can use to fix the problem. NFV
enables developers to rapidly prototype a new network gateway using programmable
SDN, and to deploy it inline in the front end, via SFC, without interrupting the existing
DNS system. This third method can be an important tool to deal with ever‐more
sophisticated zero‐day attacks that we cannot foresee.
15.7.1.2 Distributed Network Security Services
Network security can also be distributed, either implemented within the hypervisor or
as a hardened distributed service of the NFVI. Since the enforcement of security rules
is dispersed to all servers, their load is distributed and scaled naturally, because a percentage of each server’s computing resources are allocated to security. The network
security “device” only exists virtually in a management system’s abstraction. This allows
users to use security gateways pervasively, since they basically have no material cost.
This last point is very important. Once the cost of adding a network security device is
eliminated, we can abstract many security solutions to general policies, and the
management system can automatically provision the necessary rules without human
intervention – and the associated inevitable human errors.
This fine‐grained abstraction of security also allows automated gathering logs for compliance audit and monitoring. It paves the way for further uniformed policy enforcement
and audit.
15.7.1.3 Network Security as a Service
Many network security functions can be abstracted and delivered as a service. One of
the common network security functions is VPN access. A corporation may deploy
VPN gateways in its HQ or offices around the country or the world. Its employees from
home or remote locations can safely access information and computing resources
located in the HQ and data centers. This pattern is very common and ubiquitous. The
same pattern exists for many systems, for example healthcare, or geographically
dispersed IoT sensors.
This usage pattern can be abstracted and delivered as a service by one global operator
to all its customers around the world, with much lower cost and higher ease of use.
In the healthcare setting, for example, hospitals and other care providers do not wish
to spend the time and money to deal with IT systems, communication systems, and
security and patient privacy law compliance. An operator can supply much better solutions, including certified compliance to regulations through an API‐based service. Not
only security and related regulations, but mobile healthcare services can be integrated
seamlessly by software on top of a shared operator infrastructure based on NFV.
This XaaS pattern can be applied to many industries and market segments that are
expected to become major use cases of 5G.
15.7.2 Policy‐based Security Services
The second area we will look into is that of policy‐based security services. Policy refers to
a higher‐level notion of what we want from our systems, as compared to a lower‐level
procedure of how. Policy‐based management shows up in all areas of IT and non‐IT human
endeavors, from IT security, human resources and financials, to government and law.
366
Sometimes new attacks may be deployed that no one has seen before, and existing
system software may not have a ready configuration we can use to fix the problem. NFV
enables developers to rapidly prototype a new network gateway using programmable
SDN, and to deploy it inline in the front end, via SFC, without interrupting the existing
DNS system. This third method can be an important tool to deal with ever‐more
sophisticated zero‐day attacks that we cannot foresee.
15.7.1.2 Distributed Network Security Services
Network security can also be distributed, either implemented within the hypervisor or
as a hardened distributed service of the NFVI. Since the enforcement of security rules
is dispersed to all servers, their load is distributed and scaled naturally, because a percentage of each server’s computing resources are allocated to security. The network
security “device” only exists virtually in a management system’s abstraction. This allows
users to use security gateways pervasively, since they basically have no material cost.
This last point is very important. Once the cost of adding a network security device is
eliminated, we can abstract many security solutions to general policies, and the
management system can automatically provision the necessary rules without human
intervention – and the associated inevitable human errors.
This fine‐grained abstraction of security also allows automated gathering logs for compliance audit and monitoring. It paves the way for further uniformed policy enforcement
and audit.
15.7.1.3 Network Security as a Service
Many network security functions can be abstracted and delivered as a service. One of
the common network security functions is VPN access. A corporation may deploy
VPN gateways in its HQ or offices around the country or the world. Its employees from
home or remote locations can safely access information and computing resources
located in the HQ and data centers. This pattern is very common and ubiquitous. The
same pattern exists for many systems, for example healthcare, or geographically
dispersed IoT sensors.
This usage pattern can be abstracted and delivered as a service by one global operator
to all its customers around the world, with much lower cost and higher ease of use.
In the healthcare setting, for example, hospitals and other care providers do not wish
to spend the time and money to deal with IT systems, communication systems, and
security and patient privacy law compliance. An operator can supply much better solutions, including certified compliance to regulations through an API‐based service. Not
only security and related regulations, but mobile healthcare services can be integrated
seamlessly by software on top of a shared operator infrastructure based on NFV.
This XaaS pattern can be applied to many industries and market segments that are
expected to become major use cases of 5G.
15.7.2 Policy‐based Security Services
The second area we will look into is that of policy‐based security services. Policy refers to
a higher‐level notion of what we want from our systems, as compared to a lower‐level
procedure of how. Policy‐based management shows up in all areas of IT and non‐IT human
endeavors, from IT security, human resources and financials, to government and law.
