Virtual Firewalls Scaling and Placement with Traffic Distribution in Telco Cloud-Edge Continuum
摘要
The evolution of the 5 G and future 6 G networks into a virtualized infrastructure enables the deployment of virtual firewalls (vFW) to protect the network from undesirable traffic and other threats. The main advantages of the vFW systems come from the flexible deployment of vFW instances across the Telco Cloud-Edge Continuum (TCE) infrastructure and from horizontal scaling of vFW to accommodate daily changes in traffic demand. We propose a new virtual Firewall Allocation and Traffic Distribution (vFATD) approach to orchestrate the vFW system. We formulate the vFATD problem, design a MILP-based optimum orchestration algorithm, and propose k-center-based and genetic-evolution-based heuristic algorithms for practical use. Comprehensive experiments based on actual network topologies and traffic data from a mobile network operator confirmed that the proposed vFATD approach significantly outperforms the current approaches. The results say that the main gain comes from engaging traffic distribution that: i) reduces the vFW system costs by optimizing used computing and network resources, ii) improves its robustness against unexpected traffic changes, e.g., during DDoS attacks, and iii) relaxes the need for precise vFW provisioning as its performance is continuously adapted to actual traffic demands.