Braess Paradox in Network Security: More Firewalls Worsen Performance by 30%
Adding defensive options can increase service costs by 27-31% and risk concentration 6-10x.
Researchers Daniel Commey and Bin Mai from (unknown institution) studied a security-induced Braess paradox in service function chain (SFC) orchestration for NFV/SDN networks. They found that adding defensive options — such as virtual firewalls, IDS/IPS replicas, WAF clusters, zero-trust gateways, and backup inspection paths — can paradoxically degrade network performance and increase risk. This happens because additional security resources concentrate traffic and adversarial value on shared resources, leading to worse equilibrium. The team derived a sufficient condition for the paradox under affine load-dependent VNF delay and proposed a pre-deployment orchestration screen that rejects, caps, or reserves harmful options.
Using a multi-tenant SFC experiment suite across four topologies (fat-tree datacenter, NSFNET-style WAN, GEANT-style WAN, and edge/fog), they showed that naive defensive expansion raises equilibrium service cost by 27.2-30.8% and risk concentration by factors of 6.1-9.7. Their paradox-aware constrained use kept the residual penalty below 1.9%, reduced service cost by 20.0-22.1% relative to naive expansion, and lowered a concentration-sensitive attack-loss proxy by 93.5% on average. This work provides a practical tool for operators to avoid counterproductive security deployments.
- Adding security options (firewalls, IDS, WAF) in NFV/SDN can increase service costs by up to 30.8% due to Braess paradox.
- Risk concentration increases 6.1-9.7x when defensive options are naively added.
- Paradox-aware orchestration reduces cost penalty to under 1.9% and cuts attack-loss proxy by 93.5%.
Why It Matters
Network operators must carefully evaluate security expansions to avoid performance degradation and increased risk concentration.