Authors:
Sonia Haddad-Vanier
1
;
Celine Gicquel
2
;
Lila Boukhatem
2
;
Kahina Lazri
3
and
Paul Chaignon
3
Affiliations:
1
SAMM Université Paris I Panthéon Sorbonne and France
;
2
LRI, CNRS - Université Paris Saclay, Université Paris-Sud and France
;
3
Orange Labs Products & Services and France
Keyword(s):
Network Optimization, Distributed Denial of Service (DDos) Attacks, Network Function Virtualizing (NFV), Mathematical Programming, Mixed Integer Linear Program (MILP), Bilevel Programming.
Related
Ontology
Subjects/Areas/Topics:
Applications
;
Linear Programming
;
Methodologies and Technologies
;
Network Optimization
;
Operational Research
;
OR in Telecommunications
;
Pattern Recognition
;
Software Engineering
Abstract:
In this paper, we are interested in the problem of Virtual Network Function (NFV) placement to counter Distributed Denial of Service (DDoS) attacks. A DDoS attack is one of the most common and damaging types of cyberattacks. In Network Function Virtualization (NFV) technology network functions, more specifically security mechanisms, are implemented as software. Such approach significantly reduces the cost of the infrastructure and simplifies the deployment of new services. We propose two new models for this critical and complex problem. The first model is a mixed-integer linear program aiming at eliminating all DDos attacks before they reach their target. As its size grows exponentially with the network size, we propose a constraint generation algorithm to solve it. The numerical results obtained for different realistic network instances show the effectiveness of our approach. The second model is a bilevel programming problem that achieves a tradeoff between NFVs placement costs and
security levels requirements. Our results show that this mechanisms overcomes DDos attacks by effectively filtering attacks while minimizing the total cost of deployed NFV.
(More)