Graduate School and Research Center in Digital Sciences

Offloading security services to the cloud infrastructure

Chaignon, Paul; Adjavon, Diane; Lazri, Kahina; François, Jérôme; Festor, Olivier

SECSON 2018, Workshop on Security in Softwarized Networks: Prospects and Challenges, 24 August 2018, Budapest, Hungary

Cloud applications rely on a diverse set of security services from application-layer rate-limiting to TCP SYN cookies and application firewalls. Some of these services are implemented at the infrastructure layer, on the host or in the NIC, to filter attacks closer to their source and free CPU cycles for the tenants' applications. Most security services, however, remain difficult to implement at the infrastructure layer because they are closely tied to the applications they protect. In this paper, we propose to allow tenants to offload small filtering programs to the infrastructure. We design a mechanism to ensure fairness in resource consumption among tenants and show that, by carefully probing specific points of the infrastructure, all resource consumption can be accounted for. We prototype our solution over the new high-performance datapath of Linux. Our preliminary experiments show that an offload to the host's CPU can bring a 4-6x performance improvement. In addition, fairness among tenants introduces an overhead of only 14% in the worst case and approximately 3% for realistic applications.

Document Doi Hal Bibtex

Title:Offloading security services to the cloud infrastructure
Type:Conference
Language:English
City:Budapest
Country:HUNGARY
Date:
Department:Digital Security
Eurecom ref:5756
Copyright: © ACM, 2018. This is the author's version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in SECSON 2018, Workshop on Security in Softwarized Networks: Prospects and Challenges, 24 August 2018, Budapest, Hungary http://dx.doi.org/10.1145/3229616.3229624
Bibtex: @inproceedings{EURECOM+5756, doi = {http://dx.doi.org/10.1145/3229616.3229624}, year = {2018}, title = {{O}ffloading security services to the cloud infrastructure}, author = {{C}haignon, {P}aul and {A}djavon, {D}iane and {L}azri, {K}ahina and {F}ran{\'c}ois, {J}{\'e}r{\^o}me and {F}estor, {O}livier}, booktitle = {{SECSON} 2018, {W}orkshop on {S}ecurity in {S}oftwarized {N}etworks: {P}rospects and {C}hallenges, 24 {A}ugust 2018, {B}udapest, {H}ungary}, address = {{B}udapest, {HUNGARY}}, month = {08}, url = {http://www.eurecom.fr/publication/5756} }