Dergiler / Gazi University Journal of Science / 2019 / Cilt: 32 - Sayı: 3

Virtual Security Functions and Their Placement in Software Defined Networks: A Survey

Virtual Security Functions and Their Placement in Software Defined Networks: A Survey

Sayfa
833–851
DOI
—

Abstract

Software Defined Networking (SDN) and Network Functions Virtualization (NFV) are twoimportant technologies gaining prominence thanks to their benefits for improving the flexibilityand cost efficiency in networks. These technologies have been utilized extensively for providingnew age security solutions in recent years. Through the use of SDN and NFV, network securityfunctions are virtualized and deployed in a hardware-independent manner, thus reducing costs aswell as enabling faster innovations and developments. Functions virtualized with NFV such asfirewall, deep packet inspection, intrusion detection systems etc. can reside as applications in theSDN architecture. The issue of where to place these functions in the network is an importantproblem discussed in the literature. When placing these functions, objectives such as efficient useof network resources, energy consumption, cost, network load, delay etc. must be considered foreach function, in addition to ensuring that network security requirements are met. This paperprovides a critical survey on the placement of virtualized network security functions in softwaredefined networks and identifies open problems in this field. We briefly describe SDN and NFVtechnologies, touch upon the relationship between them, exemplify and review the most commonvirtual security functions in SDN. We also examine and compare the studies on the optimalplacement of virtual security functions. Finally, we identify several open research challenges inthis area and suggest potential future directions to be considered by researchers.