Jul 2026· Journal of Network and Systems Management· Vol 34· 0 citations· 42 references
TL;DR
A new virtual Firewall Allocation and Traffic Distribution (vFATD) approach to orchestrate the vFW system that reduces the vFW system costs by optimizing used computing and network resources and relaxes the need for precise vFW provisioning as its performance is continuously adapted to actual traffic demands.
Abstract
The evolution of the 5 G and future 6 G networks into a virtualized infrastructure enables the deployment of virtual firewalls (vFW) to protect the network from undesirable traffic and other threats. The main advantages of the vFW systems come from the flexible deployment of vFW instances across the Telco Cloud-Edge Continuum (TCE) infrastructure and from horizontal scaling of vFW to accommodate daily changes in traffic demand. We propose a new virtual Firewall Allocation and Traffic Distribution (vFATD) approach to orchestrate the vFW system. We formulate the vFATD problem, design a MILP-based optimum orchestration algorithm, and propose k-center-based and genetic-evolution-based heuristic algorithms for practical use. Comprehensive experiments based on actual network topologies and traffic data from a mobile network operator confirmed that the proposed vFATD approach significantly outperforms the current approaches. The results say that the main gain comes from engaging traffic distribution that: i) reduces the vFW system costs by optimizing used computing and network resources, ii) improves its robustness against unexpected traffic changes, e.g., during DDoS attacks, and iii) relaxes the need for precise vFW provisioning as its performance is continuously adapted to actual traffic demands.
This paper presents the design and evaluation of a network slicing implementation in a simulated 5G Standalone (SA) mobile network deployed as a nomadic edge node, where “nomadic” refers to the physical portability and ease of redeployment of a self-contained, containerized 5G testbed suitable for university teaching and experimentation. The platform integrates Open5GS, UERANSIM, Kamailio, and Prometheus/Grafana to emulate a sliced 5G core and access network supporting differentiated service requirements typical of heterogeneous traffic classes and latency-sensitive applications. Slice provisioning is fully configurable, and Docker-based resource constraints are applied to enforce Quality of Service (QoS) differentiation. Performance was assessed through bandwidth and traffic-quality measurements, demonstrating measurable improvements in packet loss and jitter for high-priority slices, with corresponding degradation for lower-priority slices. Although the laboratory environment limits replication of distributed real-world deployments, the results confirm the effectiveness of network slicing for traffic isolation and service prioritization in 5G SA systems. These findings highlight the practical boundaries of container-based slicing enforcement in a single-host nomadic 5G SA node, and inform the design of future multi-host deployments.
Elena-Ramona Modroiu, Jian-Wei Cheng, Damian Atlaß et al.· International Conference on...· 0 citations
Syria’s digital reconstruction offers a unique opportunity to deploy a next-generation distributed computing infrastructure that leverages three strategic international gateways (IGWs): a submarine cable from Cyprus to Tartus (10 Tbps), a terrestrial link from Jordan to Damascus (10 Tbps), and a terrestrial link from Turkey to Aleppo (10 Tbps). This paper proposes and rigorously evaluates a hybrid edge cloud architecture comprising three regional edge nodes (Damascus, Aleppo, and Coastal) and a central cloud in Homs, all interconnected via an ultra-high-speed domestic backbone (10 Tbps). Using analytical models and simulations, researchers demonstrate that edge nodes reduce end-to-end latency to <0.5 ms locally (10–20× improvement over cloud-only), cut backbone traffic by 99% through intelligent preprocessing, and ensure full compliance with the Syrian data residency law (Law No. 12/2016). Furthermore, the integration of 10 Tbps IGWs enables low-latency international peering (RTT ≤ 2.9 ms from the coast to Europe) while preserving data sovereignty. Total cost of ownership (TCO) is reduced by 52% compared to a cloud-only model, even with 10× higher capacity. Researchers provide a comprehensive set of Mermaid-based diagrams and tables quantifying latency, bandwidth, cost, and failover scenarios. The paper concludes with actionable recommendations for the Syrian Ministry of Communications and Technology and international partners.
Jouma Ali Al-Mohamad, M. Paslavskyi, Julio Suárez Albanchez et al.· FMDB Transactions on Sustain...· 0 citations
This work introduces an emulation framework that allows developers and operators to decide how to deploy networks, computing devices, and applications in a Computing Continuum environment, ensuring compliance with established Quality of Service standards.
José Gómez-delaHiz, J. Herrera, S. Laso et al.· Infocommunications journal· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.