首页 > 最新文献

10th International Conference on Network and Service Management (CNSM) and Workshop最新文献

英文 中文
Tag-In-Tag: Efficient flow table management in SDN switches Tag-In-Tag: SDN交换机中高效的流表管理
Subhasish Banerjee, Kalapriya Kannan
Ternary Content Addressable Memory (TCAM) with O(1) look up performance has become the obvious and irreplaceable choice of high performance switching hardware. However, emerging network paradigm, especially Software Defined Networking (SDN), has changed the nature of operations and the rate of access in this memory subsystem. These conditions are expected to adversely impact TCAM power consumption, increase the silicon area and hence are likely to bring down the expected performance. In this paper we propose Tag-In-Tag an approach that exploits SDN features and replaces the flow entries with two layers of simpler and shorter tags. One level of tagging exploits the availability of unique path for individual flows from the ingress switch to egress switch that can be computed a-priori. Second level of tagging allows finer identification of the flows to enable flow specific actions. Double tagging helps in preserving the finer benefits of the SDNs while providing highest level of compaction to the flow entries in the flow tables. Through various experiments using real world and synthetic data we show that our approach can accommodate 15 times more flow entries in a fixed size TCAM whereas power consumption per-flow is reduced by 80% compared to an unoptimized SDN enabled switch.
具有0(1)查找性能的三元内容可寻址存储器(TCAM)已成为高性能交换硬件的明显和不可替代的选择。然而,新兴的网络范例,特别是软件定义网络(SDN),已经改变了这个内存子系统的操作性质和访问速率。这些条件预计会对TCAM功耗产生不利影响,增加硅面积,因此可能会降低预期性能。在本文中,我们提出了Tag-In-Tag一种利用SDN特征并用两层更简单和更短的标签取代流条目的方法。标记的一个级别利用了从入口交换机到出口交换机的单个流的唯一路径的可用性,该路径可以先验地计算。第二级标记允许对流进行更精细的标识,以启用特定于流的操作。双重标签有助于保留sdn的优点,同时为流表中的流项提供最高级别的压缩。通过使用真实世界和合成数据的各种实验,我们表明,我们的方法可以在固定大小的TCAM中容纳15倍的流条目,而与未优化的SDN启用交换机相比,每流功耗降低了80%。
{"title":"Tag-In-Tag: Efficient flow table management in SDN switches","authors":"Subhasish Banerjee, Kalapriya Kannan","doi":"10.1109/CNSM.2014.7014147","DOIUrl":"https://doi.org/10.1109/CNSM.2014.7014147","url":null,"abstract":"Ternary Content Addressable Memory (TCAM) with O(1) look up performance has become the obvious and irreplaceable choice of high performance switching hardware. However, emerging network paradigm, especially Software Defined Networking (SDN), has changed the nature of operations and the rate of access in this memory subsystem. These conditions are expected to adversely impact TCAM power consumption, increase the silicon area and hence are likely to bring down the expected performance. In this paper we propose Tag-In-Tag an approach that exploits SDN features and replaces the flow entries with two layers of simpler and shorter tags. One level of tagging exploits the availability of unique path for individual flows from the ingress switch to egress switch that can be computed a-priori. Second level of tagging allows finer identification of the flows to enable flow specific actions. Double tagging helps in preserving the finer benefits of the SDNs while providing highest level of compaction to the flow entries in the flow tables. Through various experiments using real world and synthetic data we show that our approach can accommodate 15 times more flow entries in a fixed size TCAM whereas power consumption per-flow is reduced by 80% compared to an unoptimized SDN enabled switch.","PeriodicalId":268334,"journal":{"name":"10th International Conference on Network and Service Management (CNSM) and Workshop","volume":"59 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2014-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"127082821","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 56
Software defined enterprise passive optical network 软件定义的企业无源光网络
A. Amokrane, Jinho Hwang, Jin Xiao, Nikos Anerousis
In the last few years, changing infrastructure and business requirements are forcing enterprises to rethink their networks. Enterprises look to passive optical networks (PON) for increased network efficiency, flexibility, and cost reduction. At the same time, the emergence of Cloud and mobile in enterprise networks calls for dynamic network control and management following a centralized and software-defined paradigm. In this context, we propose a software-defined edge network (SDEN) design that operates on top of PON. SDEN leverages PON benefits while overcoming its lack of dynamic control. This paper is a work-in-progress focusing on enabling key flow control functions over PON: dynamic traffic steering, service dimensioning and realtime re-dimensioning. We also discuss how SDEN edge network can integrate with core SDN solutions to achieve end-to-end manageability. Through case experiment studies conducted on a live PON testbed deployment, we show the practical benefits and potentials that SDEN can offer to enterprise networks redesign.
在过去的几年里,不断变化的基础设施和业务需求迫使企业重新考虑他们的网络。企业希望通过无源光网络(PON)来提高网络效率、灵活性和降低成本。与此同时,云计算和移动网络在企业网络中的出现,要求遵循集中式和软件定义范式的动态网络控制和管理。在这种情况下,我们提出了一种基于PON的软件定义边缘网络(SDEN)设计。SDEN利用PON的优点,同时克服了其缺乏动态控制。本文是一项正在进行的工作,重点是在PON上实现关键流控制功能:动态流量转向、服务维度和实时重新维度。我们还讨论了SDEN边缘网络如何与核心SDN解决方案集成以实现端到端可管理性。通过在实时PON测试平台上进行的案例实验研究,我们展示了SDEN可以为企业网络重新设计提供的实际优势和潜力。
{"title":"Software defined enterprise passive optical network","authors":"A. Amokrane, Jinho Hwang, Jin Xiao, Nikos Anerousis","doi":"10.1109/CNSM.2014.7014203","DOIUrl":"https://doi.org/10.1109/CNSM.2014.7014203","url":null,"abstract":"In the last few years, changing infrastructure and business requirements are forcing enterprises to rethink their networks. Enterprises look to passive optical networks (PON) for increased network efficiency, flexibility, and cost reduction. At the same time, the emergence of Cloud and mobile in enterprise networks calls for dynamic network control and management following a centralized and software-defined paradigm. In this context, we propose a software-defined edge network (SDEN) design that operates on top of PON. SDEN leverages PON benefits while overcoming its lack of dynamic control. This paper is a work-in-progress focusing on enabling key flow control functions over PON: dynamic traffic steering, service dimensioning and realtime re-dimensioning. We also discuss how SDEN edge network can integrate with core SDN solutions to achieve end-to-end manageability. Through case experiment studies conducted on a live PON testbed deployment, we show the practical benefits and potentials that SDEN can offer to enterprise networks redesign.","PeriodicalId":268334,"journal":{"name":"10th International Conference on Network and Service Management (CNSM) and Workshop","volume":"24 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2014-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116497191","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 13
DEWS: A decentralized engine for Web search DEWS:一个分散的网络搜索引擎
Reaz Ahmed, Md. Faizul Bari, Md. Rakibul Haque, R. Boutaba, B. Mathieu
Contemporary Web search is governed by centrally controlled search engines, which is not healthy for our online freedom and privacy. A better solution is to enable the Web to index itself in a decentralized manner. In this work we propose a decentralized Web search mechanism, named DEWS, which enables existing webservers to collaborate with each other to build a distributed index of the Web. DEWS can rank search results based on query keyword relevance and relative importance of webpages. DEWS also supports approximate matching of query keywords in web documents. Simulation results show that the ranking accuracy of DEWS is very close to the centralized case, while network overhead for collaborative search and indexing is logarithmic on network size.
当代网络搜索由中央控制的搜索引擎控制,这对我们的网络自由和隐私是不健康的。一个更好的解决方案是使Web能够以分散的方式对自身进行索引。在这项工作中,我们提出了一种分散的Web搜索机制,称为DEWS,它使现有的Web服务器能够相互协作以构建Web的分布式索引。DEWS可以根据查询关键字的相关性和网页的相对重要性对搜索结果进行排名。DEWS还支持web文档中查询关键字的近似匹配。仿真结果表明,DEWS的排序精度非常接近集中式情况,而协同搜索和索引的网络开销与网络规模成对数关系。
{"title":"DEWS: A decentralized engine for Web search","authors":"Reaz Ahmed, Md. Faizul Bari, Md. Rakibul Haque, R. Boutaba, B. Mathieu","doi":"10.1109/CNSM.2014.7014168","DOIUrl":"https://doi.org/10.1109/CNSM.2014.7014168","url":null,"abstract":"Contemporary Web search is governed by centrally controlled search engines, which is not healthy for our online freedom and privacy. A better solution is to enable the Web to index itself in a decentralized manner. In this work we propose a decentralized Web search mechanism, named DEWS, which enables existing webservers to collaborate with each other to build a distributed index of the Web. DEWS can rank search results based on query keyword relevance and relative importance of webpages. DEWS also supports approximate matching of query keywords in web documents. Simulation results show that the ranking accuracy of DEWS is very close to the centralized case, while network overhead for collaborative search and indexing is logarithmic on network size.","PeriodicalId":268334,"journal":{"name":"10th International Conference on Network and Service Management (CNSM) and Workshop","volume":"130 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2014-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"124492960","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
On satisfying green SLAs in distributed clouds 关于在分布式云中满足绿色sla
A. Amokrane, M. Zhani, Qi Zhang, R. Langar, R. Boutaba, G. Pujolle
With the massive adoption of cloud-based services, high energy consumption and carbon footprint of cloud infrastructures have become a major concern in IT industry. Consequently, many governments and IT advisory organizations have urged IT stakeholders (i.e., cloud provider and cloud customers) to embrace green IT and regularly monitor and report their carbon emissions and put in place efficient strategies and techniques to control the environmental impact of their infrastructures and/or applications. Motivated by this growing trend, we investigate, in this paper, how cloud providers can meet Service Level Agreements (SLAs) with green requirements. In such SLAs, a cloud customer requires from cloud providers that carbon emissions generated by the leased resources should not exceed a fixed bound. We hence propose a resource management framework allowing cloud providers to provision resources in the form of Virtual Data Centers (VDCs) (i.e., a set of virtual machines and virtual links with guaranteed bandwidth) across a geo-distributed infrastructure with the aim of reducing operational costs and green SLA violation penalties. Extensive simulations show that the proposed solution maximizes the cloud provider's profit and minimizes the violation of green SLAs.
随着基于云的服务的大量采用,云基础设施的高能耗和碳足迹已成为IT行业关注的主要问题。因此,许多政府和IT咨询组织敦促IT利益相关者(即云提供商和云客户)接受绿色IT,定期监测和报告其碳排放,并实施有效的战略和技术来控制其基础设施和/或应用程序对环境的影响。在这种增长趋势的推动下,我们在本文中调查了云提供商如何满足绿色需求的服务水平协议(sla)。在这样的sla中,云客户要求云提供商租用资源产生的碳排放不应超过固定的范围。因此,我们提出了一种资源管理框架,允许云提供商以虚拟数据中心(vdc)的形式(即一组虚拟机和具有保证带宽的虚拟链路)跨地理分布式基础设施提供资源,目的是降低运营成本和绿色SLA违规处罚。大量的模拟表明,所提出的解决方案最大限度地提高了云提供商的利润,并最大限度地减少了对绿色sla的违反。
{"title":"On satisfying green SLAs in distributed clouds","authors":"A. Amokrane, M. Zhani, Qi Zhang, R. Langar, R. Boutaba, G. Pujolle","doi":"10.1109/CNSM.2014.7014142","DOIUrl":"https://doi.org/10.1109/CNSM.2014.7014142","url":null,"abstract":"With the massive adoption of cloud-based services, high energy consumption and carbon footprint of cloud infrastructures have become a major concern in IT industry. Consequently, many governments and IT advisory organizations have urged IT stakeholders (i.e., cloud provider and cloud customers) to embrace green IT and regularly monitor and report their carbon emissions and put in place efficient strategies and techniques to control the environmental impact of their infrastructures and/or applications. Motivated by this growing trend, we investigate, in this paper, how cloud providers can meet Service Level Agreements (SLAs) with green requirements. In such SLAs, a cloud customer requires from cloud providers that carbon emissions generated by the leased resources should not exceed a fixed bound. We hence propose a resource management framework allowing cloud providers to provision resources in the form of Virtual Data Centers (VDCs) (i.e., a set of virtual machines and virtual links with guaranteed bandwidth) across a geo-distributed infrastructure with the aim of reducing operational costs and green SLA violation penalties. Extensive simulations show that the proposed solution maximizes the cloud provider's profit and minimizes the violation of green SLAs.","PeriodicalId":268334,"journal":{"name":"10th International Conference on Network and Service Management (CNSM) and Workshop","volume":"46 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2014-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"122591612","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 25
A NovaGenesis proxy/gateway/controller for OpenFlow software defined networks 用于OpenFlow软件定义网络的NovaGenesis代理/网关/控制器
A. Alberti, Victor H. de O. Fernandes, M. A. F. Casaroli, Lucio H. de Oliveira, Frederico M. Pedroso Junior, Dhananjay Singh
Software-defined networking (SDN) is a promising approach to deal with complexity in new generation networks. The idea is to “extract simplicity” from what we have learned in the last decades while “mastering complexity” at designing and deploying network infrastructures. The idea is to decouple control and data planes. In this sense, OpenFlow is a protocol for remote control of switches' forwarding tables, replacing the traditional distributed network control model by a centralized one. An open problem in OpenFlow, and more generally on SDN, is how to integrate network control with services orchestration, i.e. to enable service frameworks to negotiate with network representatives in order to create service-aware networks. In this paper, we employ the design principles of a new architecture called NovaGenesis to implement a proxy/gateway/controller for Open- Flow networks. This service represents, interoperates, and controls a Python OpenFlow controller (POX) in order to expose its resources directly to NovaGenesis services. The POX Agent (POXA), as it is called, innovates on exposing OpenFlow resources to NovaGenesis name-oriented service orchestration, enabling the direct establishment of service level agreements among POX and NovaGenesis services.
软件定义网络(SDN)是处理新一代网络复杂性的一种很有前途的方法。其理念是从我们过去几十年所学到的东西中“提取简单性”,同时在设计和部署网络基础设施时“掌握复杂性”。其思想是分离控制平面和数据平面。从这个意义上说,OpenFlow是一种远程控制交换机转发表的协议,用集中式网络控制模型取代了传统的分布式网络控制模型。OpenFlow中的一个开放问题,以及更普遍的SDN上的一个问题,是如何将网络控制与服务编排集成在一起,即使服务框架能够与网络代表进行协商,以创建服务感知网络。在本文中,我们采用一种称为NovaGenesis的新架构的设计原则来实现开放流网络的代理/网关/控制器。该服务表示、互操作和控制Python OpenFlow控制器(POX),以便将其资源直接公开给NovaGenesis服务。POX代理(POXA)在将OpenFlow资源公开给NovaGenesis面向名称的服务编排方面进行了创新,从而能够在POX和NovaGenesis服务之间直接建立服务水平协议。
{"title":"A NovaGenesis proxy/gateway/controller for OpenFlow software defined networks","authors":"A. Alberti, Victor H. de O. Fernandes, M. A. F. Casaroli, Lucio H. de Oliveira, Frederico M. Pedroso Junior, Dhananjay Singh","doi":"10.1109/CNSM.2014.7014201","DOIUrl":"https://doi.org/10.1109/CNSM.2014.7014201","url":null,"abstract":"Software-defined networking (SDN) is a promising approach to deal with complexity in new generation networks. The idea is to “extract simplicity” from what we have learned in the last decades while “mastering complexity” at designing and deploying network infrastructures. The idea is to decouple control and data planes. In this sense, OpenFlow is a protocol for remote control of switches' forwarding tables, replacing the traditional distributed network control model by a centralized one. An open problem in OpenFlow, and more generally on SDN, is how to integrate network control with services orchestration, i.e. to enable service frameworks to negotiate with network representatives in order to create service-aware networks. In this paper, we employ the design principles of a new architecture called NovaGenesis to implement a proxy/gateway/controller for Open- Flow networks. This service represents, interoperates, and controls a Python OpenFlow controller (POX) in order to expose its resources directly to NovaGenesis services. The POX Agent (POXA), as it is called, innovates on exposing OpenFlow resources to NovaGenesis name-oriented service orchestration, enabling the direct establishment of service level agreements among POX and NovaGenesis services.","PeriodicalId":268334,"journal":{"name":"10th International Conference on Network and Service Management (CNSM) and Workshop","volume":"22 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2014-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"125249459","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 10
Programming Software-Defined wireless networks 编程软件定义无线网络
R. Riggio, K. Gomez, T. Rasheed, Julius Schulz-Zander, S. Kukliński, M. Marina
Programming a mobile network requires to account for multiple complex operations, such as allocating radio resources and monitoring interference. Nevertheless, the current Software-Defined Networking ecosystem provides little support for mobile networks in term of radio data-plane abstractions, controllers, and programming primitives. Starting from the consideration that WiFi is becoming an integral part of the 5G architecture, we present a set of programming abstractions modeling three fundamental aspects of a WiFi network, namely state management of wireless clients, resource provisioning, and network state collection. The proposed abstractions hide away the implementation details of the underlying wireless technology providing programmers with expressive tools to control the state of the network. We also describe a proof-of-concept implementation of a Software-Defined Radio Access Network controller for WiFi networks and a Python-based Software Development Kit leveraging the proposed abstractions. The resulting platform can be effectively leveraged in order to implement typical control tasks such as mobility management and traffic engineering as well as applications and services such as multicast video delivery and/or dynamic content caching.
对移动网络进行编程需要考虑多种复杂的操作,如分配无线电资源和监测干扰。然而,当前的软件定义网络生态系统在无线电数据平面抽象、控制器和编程原语方面对移动网络提供的支持很少。考虑到WiFi正在成为5G架构不可或缺的一部分,我们提出了一组编程抽象,对WiFi网络的三个基本方面进行建模,即无线客户端状态管理、资源供应和网络状态收集。提出的抽象隐藏了底层无线技术的实现细节,为程序员提供了控制网络状态的表达工具。我们还描述了用于WiFi网络的软件定义无线接入网控制器的概念验证实现,以及利用所提出的抽象的基于python的软件开发工具包。由此产生的平台可以有效地利用,以实现典型的控制任务,如移动性管理和流量工程,以及应用程序和服务,如多播视频传输和/或动态内容缓存。
{"title":"Programming Software-Defined wireless networks","authors":"R. Riggio, K. Gomez, T. Rasheed, Julius Schulz-Zander, S. Kukliński, M. Marina","doi":"10.1145/2639108.2642897","DOIUrl":"https://doi.org/10.1145/2639108.2642897","url":null,"abstract":"Programming a mobile network requires to account for multiple complex operations, such as allocating radio resources and monitoring interference. Nevertheless, the current Software-Defined Networking ecosystem provides little support for mobile networks in term of radio data-plane abstractions, controllers, and programming primitives. Starting from the consideration that WiFi is becoming an integral part of the 5G architecture, we present a set of programming abstractions modeling three fundamental aspects of a WiFi network, namely state management of wireless clients, resource provisioning, and network state collection. The proposed abstractions hide away the implementation details of the underlying wireless technology providing programmers with expressive tools to control the state of the network. We also describe a proof-of-concept implementation of a Software-Defined Radio Access Network controller for WiFi networks and a Python-based Software Development Kit leveraging the proposed abstractions. The resulting platform can be effectively leveraged in order to implement typical control tasks such as mobility management and traffic engineering as well as applications and services such as multicast video delivery and/or dynamic content caching.","PeriodicalId":268334,"journal":{"name":"10th International Conference on Network and Service Management (CNSM) and Workshop","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2014-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"125839767","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 31
SDNIPS: Enabling Software-Defined Networking based intrusion prevention system in clouds SDNIPS:支持基于软件定义网络的云入侵防御系统
Tianyi Xing, Zhengyang Xiong, Dijiang Huang, D. Medhi
Security has been considered as one of the top concerns in clouds. Intrusion Detection and Prevention Systems (IDPS) have been widely deployed to enhance the cloud security. Using Software-Defined Networking (SDN) approaches to enhance the system security in clouds has been recently presented in [1], [2]. However, none of existing works established a comprehensive IPS solution to reconfigure the cloud networking environment on-the-fly to counter malicious attacks. In this paper, we present an SDN-based IPS solution called SDNIPS that is a full lifecycle solution including detection and prevention in the cloud. We propose a new IDPS architecture based on Snort-based IDS and Open vSwitch (OVS). We also compare the SDN-based IPS solution with the traditional IPS approach from both mechanism analysis and evaluation. Network Reconfiguration (NR) features are designed and implemented based on the POX controller to enhance the prevention flexibility. Finally, evaluations of SDNIPS demonstrate its feasibility and efficiency over traditional approaches.
安全性一直被认为是云计算的首要关注点之一。入侵检测和防御系统(IDPS)已被广泛部署,以增强云安全。最近在[1],[2]中提出了使用软件定义网络(SDN)方法来增强云中的系统安全性。但是,目前还没有建立全面的IPS解决方案,对云网络环境进行动态重新配置,以应对恶意攻击。在本文中,我们提出了一个基于sdn的IPS解决方案,称为SDNIPS,这是一个完整的生命周期解决方案,包括云中的检测和预防。我们提出了一种基于snort的IDS和Open vSwitch (OVS)的IDPS架构。我们还从机理分析和评价两方面对基于sdn的入侵防御方案与传统入侵防御方案进行了比较。在POX控制器的基础上设计并实现了网络重构(NR)特性,增强了预防的灵活性。最后,通过对SDNIPS方法的评价,证明了该方法的可行性和有效性。
{"title":"SDNIPS: Enabling Software-Defined Networking based intrusion prevention system in clouds","authors":"Tianyi Xing, Zhengyang Xiong, Dijiang Huang, D. Medhi","doi":"10.1109/CNSM.2014.7014181","DOIUrl":"https://doi.org/10.1109/CNSM.2014.7014181","url":null,"abstract":"Security has been considered as one of the top concerns in clouds. Intrusion Detection and Prevention Systems (IDPS) have been widely deployed to enhance the cloud security. Using Software-Defined Networking (SDN) approaches to enhance the system security in clouds has been recently presented in [1], [2]. However, none of existing works established a comprehensive IPS solution to reconfigure the cloud networking environment on-the-fly to counter malicious attacks. In this paper, we present an SDN-based IPS solution called SDNIPS that is a full lifecycle solution including detection and prevention in the cloud. We propose a new IDPS architecture based on Snort-based IDS and Open vSwitch (OVS). We also compare the SDN-based IPS solution with the traditional IPS approach from both mechanism analysis and evaluation. Network Reconfiguration (NR) features are designed and implemented based on the POX controller to enhance the prevention flexibility. Finally, evaluations of SDNIPS demonstrate its feasibility and efficiency over traditional approaches.","PeriodicalId":268334,"journal":{"name":"10th International Conference on Network and Service Management (CNSM) and Workshop","volume":"26 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2014-01-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115949015","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 72
期刊
10th International Conference on Network and Service Management (CNSM) and Workshop
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1