首页 > 最新文献

2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)最新文献

英文 中文
Phased-vCDN Orchestration for flexible and efficient usage of 5G edge infrastructures 分阶段vcdn编排,灵活高效地使用5G边缘基础设施
João Aires, Paulo Duarte, Bruno Parreira, Sérgio Figueiredo
5G networks rely on effective end-to-end management and orchestration of services and resources for reaping the much-desired benefits. The Open Network Automation Platform (ONAP), proposed as a full-fledged, production-oriented framework for next-generation networks, supports the integration with business-oriented components typically found in the Telecom Operators architecture, making it a highly relevant one for R&D purposes. This paper proposes and implements a novel orchestration framework for deep vCDN services, Through phased vCDN deployment, i.e. with split Caching and Streaming components orchestration, the solution targets efficient and flexible resource usage in highly distributed 5G networks. The initial experiments and obtained results demonstrate the approach promises improved deployment and activation times of vCDN nodes, and control over resource usage in edge infrastructures, crucial for future 5G network deployments.
5G网络依赖于有效的端到端服务和资源管理和编排,以获得人们梦寐以求的效益。开放网络自动化平台(ONAP),作为下一代网络的一个成熟的、面向生产的框架,支持与电信运营商架构中典型的面向业务的组件的集成,使其与研发目的高度相关。本文提出并实现了一种新的深度vCDN业务编排框架,通过分阶段部署vCDN,即拆分缓存和流组件编排,以实现5G高分布网络下高效灵活的资源利用。初步实验和获得的结果表明,该方法有望改善vCDN节点的部署和激活时间,并控制边缘基础设施中的资源使用,这对未来的5G网络部署至关重要。
{"title":"Phased-vCDN Orchestration for flexible and efficient usage of 5G edge infrastructures","authors":"João Aires, Paulo Duarte, Bruno Parreira, Sérgio Figueiredo","doi":"10.1109/NFV-SDN47374.2019.9040097","DOIUrl":"https://doi.org/10.1109/NFV-SDN47374.2019.9040097","url":null,"abstract":"5G networks rely on effective end-to-end management and orchestration of services and resources for reaping the much-desired benefits. The Open Network Automation Platform (ONAP), proposed as a full-fledged, production-oriented framework for next-generation networks, supports the integration with business-oriented components typically found in the Telecom Operators architecture, making it a highly relevant one for R&D purposes. This paper proposes and implements a novel orchestration framework for deep vCDN services, Through phased vCDN deployment, i.e. with split Caching and Streaming components orchestration, the solution targets efficient and flexible resource usage in highly distributed 5G networks. The initial experiments and obtained results demonstrate the approach promises improved deployment and activation times of vCDN nodes, and control over resource usage in edge infrastructures, crucial for future 5G network deployments.","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"74 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116703567","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 4
Experimental Demonstration of Live Migration Impact on Virtualized 5G Network using Federated Testbeds 基于联邦试验台的实时迁移对虚拟化5G网络影响的实验演示
Shunmugapriya Ramanathan, K. Kondepu, Behzad Mirkhanzadeh, Tianliang Zhang, M. Razo, M. Tacca, L. Valcarenghi, A. Fumagalli
This demo focuses on live migration of the virtualized network functions (VNFs) in the Cloud-native radio access network (C-RAN) architecture. In C-RAN, the next-generation NodeB (gNB) is split into a radio unit (RU), a distributed unit (DU), and a central unit (CU). The CUs are connected to 5G core, and these functions are likely to be virtualized and distributed in different (micro and macro) data centers of mobile operators. Thus, a failure of VNF, supporting the connectivity among the aforementioned elements, shall be quickly identified and recovered.The demo shows the impact of virtualization technologies on live migration of RAN and Core VNFs among cloud data centers and can be used to measure the user service downtime.
本演示重点介绍云原生无线接入网(C-RAN)架构中虚拟化网络功能(VNFs)的实时迁移。在C-RAN中,下一代NodeB (gNB)被分为RU (radio unit)、DU (distributed unit)和CU (central unit)。cu连接5G核心,这些功能很可能被虚拟化,分布在移动运营商的不同(微观和宏观)数据中心。因此,支持上述元素之间连接的VNF的故障将被迅速识别和恢复。该演示展示了虚拟化技术对云数据中心之间RAN和Core VNFs实时迁移的影响,并可用于衡量用户服务停机时间。
{"title":"Experimental Demonstration of Live Migration Impact on Virtualized 5G Network using Federated Testbeds","authors":"Shunmugapriya Ramanathan, K. Kondepu, Behzad Mirkhanzadeh, Tianliang Zhang, M. Razo, M. Tacca, L. Valcarenghi, A. Fumagalli","doi":"10.1109/NFV-SDN47374.2019.9040099","DOIUrl":"https://doi.org/10.1109/NFV-SDN47374.2019.9040099","url":null,"abstract":"This demo focuses on live migration of the virtualized network functions (VNFs) in the Cloud-native radio access network (C-RAN) architecture. In C-RAN, the next-generation NodeB (gNB) is split into a radio unit (RU), a distributed unit (DU), and a central unit (CU). The CUs are connected to 5G core, and these functions are likely to be virtualized and distributed in different (micro and macro) data centers of mobile operators. Thus, a failure of VNF, supporting the connectivity among the aforementioned elements, shall be quickly identified and recovered.The demo shows the impact of virtualization technologies on live migration of RAN and Core VNFs among cloud data centers and can be used to measure the user service downtime.","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"9 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"124554715","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
P4ID: P4 Enhanced Intrusion Detection P4ID: P4增强入侵检测
B. Lewis, M. Broadbent, N. Race
The growth in scale and capacity of networks in recent years leads to challenges of positioning and scalability of Intrusion Detection Systems (IDS). With the flexibility afforded by programmable dataplanes, it is now possible to perform a new level of intrusion detection in switches themselves. We present P4ID, combining a rule parser, stateless and stateful packet processing using P4, and evaluate it using publicly available datasets. We show that using this technique, we can achieve a significant reduction in traffic being processed by an IDS.
近年来,网络规模和容量的增长给入侵检测系统的定位和可扩展性带来了挑战。由于可编程数据平面提供的灵活性,现在可以在交换机本身中执行一个新的入侵检测级别。我们提出了P4ID,结合了一个规则解析器,使用P4进行无状态和有状态数据包处理,并使用公开可用的数据集对其进行评估。我们展示了使用这种技术,我们可以显著减少由IDS处理的流量。
{"title":"P4ID: P4 Enhanced Intrusion Detection","authors":"B. Lewis, M. Broadbent, N. Race","doi":"10.1109/NFV-SDN47374.2019.9040044","DOIUrl":"https://doi.org/10.1109/NFV-SDN47374.2019.9040044","url":null,"abstract":"The growth in scale and capacity of networks in recent years leads to challenges of positioning and scalability of Intrusion Detection Systems (IDS). With the flexibility afforded by programmable dataplanes, it is now possible to perform a new level of intrusion detection in switches themselves. We present P4ID, combining a rule parser, stateless and stateful packet processing using P4, and evaluate it using publicly available datasets. We show that using this technique, we can achieve a significant reduction in traffic being processed by an IDS.","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"8 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130323870","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 18
Preprocessing Monitoring Information on the SDN Data-Plane using P4 使用P4对SDN数据平面监控信息进行预处理
Rhaban Hark, Divyashri Bhat, M. Zink, R. Steinmetz, Amr Rizk
Network management applications such as routing, load-balancing, or traffic forecasting, require up-to-date state information about the underlying data-plane. However, it is well known that data-plane measurements contain redundant information. In this work, we propose an approach that estimates how informative data-plane measurements are for control-plane applications that operate on such information. Using programmable data-planes, we present a novel approach on how the decision on forwarding data-plane measurements can be taken at network switches, and how this aids in filtering irrelevant monitoring information to save the controller’s computational and networking resources.
路由、负载平衡或流量预测等网络管理应用程序需要有关底层数据平面的最新状态信息。然而,众所周知,数据平面测量包含冗余信息。在这项工作中,我们提出了一种方法来估计对这些信息进行操作的控制平面应用程序的数据平面测量的信息量。利用可编程数据平面,我们提出了一种新颖的方法,说明如何在网络交换机上进行转发数据平面测量的决策,以及如何帮助过滤无关的监控信息以节省控制器的计算和网络资源。
{"title":"Preprocessing Monitoring Information on the SDN Data-Plane using P4","authors":"Rhaban Hark, Divyashri Bhat, M. Zink, R. Steinmetz, Amr Rizk","doi":"10.1109/NFV-SDN47374.2019.9040030","DOIUrl":"https://doi.org/10.1109/NFV-SDN47374.2019.9040030","url":null,"abstract":"Network management applications such as routing, load-balancing, or traffic forecasting, require up-to-date state information about the underlying data-plane. However, it is well known that data-plane measurements contain redundant information. In this work, we propose an approach that estimates how informative data-plane measurements are for control-plane applications that operate on such information. Using programmable data-planes, we present a novel approach on how the decision on forwarding data-plane measurements can be taken at network switches, and how this aids in filtering irrelevant monitoring information to save the controller’s computational and networking resources.","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"35 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"126472030","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 6
FOP4: Function Offloading Prototyping in Heterogeneous and Programmable Network Scenarios FOP4:异构和可编程网络场景下的功能卸载原型
Daniele Moro, Manuel Peuster, H. Karl, A. Capone
Offloading packet processing tasks to programmable switches and/or to programmable network interfaces, so called “SmartNICs”, is one of the key concepts to prepare softwarized networks for the high traffic demands of the future. However, implementing network functions that make use of those offloading technologies is still challenging and usually requires the availability of specialized hardware. It becomes even harder if heterogeneous services, making use of different offloading and network virtualization technologies, should be developed. In this paper, we introduce FOP4 (Function Offloading Prototyping with P4), a novel prototyping platform that allows to prototype heterogeneous software network scenarios, including container-based, P4-switch-based, and SmartNIC-based network functions. The presented work substantially extends our existing Containernet platform with the means to prototype offloading scenarios. Besides presenting the platform’s system design, we evaluate its scalability and show that it can run scenarios with more than 64 P4 switch or SmartNIC nodes on a single laptop. Finally, we presented a case study in which we use the presented platform to prototype an extended in-band network telemetry use case.
将数据包处理任务卸载到可编程交换机和/或可编程网络接口,即所谓的“智能网卡”,是为未来高流量需求准备软件网络的关键概念之一。然而,实现利用这些卸载技术的网络功能仍然具有挑战性,并且通常需要专用硬件的可用性。如果要开发异构服务(使用不同的卸载和网络虚拟化技术),这将变得更加困难。在本文中,我们介绍了FOP4(功能卸载原型与P4),一个新颖的原型平台,允许原型异构软件网络场景,包括基于容器,基于P4交换机和基于smartnic的网络功能。所提出的工作实质上扩展了我们现有的Containernet平台,实现了卸载场景的原型。除了展示平台的系统设计外,我们还评估了其可扩展性,并表明它可以在一台笔记本电脑上运行超过64个P4交换机或SmartNIC节点的场景。最后,我们提出了一个案例研究,其中我们使用所提出的平台原型扩展带内网络遥测用例。
{"title":"FOP4: Function Offloading Prototyping in Heterogeneous and Programmable Network Scenarios","authors":"Daniele Moro, Manuel Peuster, H. Karl, A. Capone","doi":"10.1109/NFV-SDN47374.2019.9040052","DOIUrl":"https://doi.org/10.1109/NFV-SDN47374.2019.9040052","url":null,"abstract":"Offloading packet processing tasks to programmable switches and/or to programmable network interfaces, so called “SmartNICs”, is one of the key concepts to prepare softwarized networks for the high traffic demands of the future. However, implementing network functions that make use of those offloading technologies is still challenging and usually requires the availability of specialized hardware. It becomes even harder if heterogeneous services, making use of different offloading and network virtualization technologies, should be developed. In this paper, we introduce FOP4 (Function Offloading Prototyping with P4), a novel prototyping platform that allows to prototype heterogeneous software network scenarios, including container-based, P4-switch-based, and SmartNIC-based network functions. The presented work substantially extends our existing Containernet platform with the means to prototype offloading scenarios. Besides presenting the platform’s system design, we evaluate its scalability and show that it can run scenarios with more than 64 P4 switch or SmartNIC nodes on a single laptop. Finally, we presented a case study in which we use the presented platform to prototype an extended in-band network telemetry use case.","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"24 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"114513999","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 9
P4NFV: P4 Enabled NFV Systems with SmartNICs P4NFV:带smartnic的P4使能NFV系统
Ali Mohammadkhan, Sourav Panda, Sameer G. Kulkarni, K. Ramakrishnan, L. Bhuyan
Software Defined Networking (SDN) and Network Function Virtualization (NFV) are transforming Data Center (DC), Telecom, and enterprise networking. The programmability offered by P4 enables SDN to be more protocol-independent and flexible. Data Centers are increasingly adopting SmartNICs (sNICs) to accelerate packet processing that can be leveraged to support packet processing pipelines and custom Network Functions (NFs). However, there are several challenges in integrating and deploying P4 based SDN control as well as host and sNIC-based programmable NFs. These include configuration and management of the data plane components (Host and sNIC P4 switches) for the SDN control plane and effective utilization of data plane resources. P4NFV addresses these concerns and provides a unified P4 switch abstraction framework to simplify the SDN control plane, reducing management complexities, and leveraging a host-local SDN Agent to improve the overall resource utilization. The SDN agent considers the network-wide, host, and sNIC specific capabilities and constraints. Based on workload and traffic characteristics, P4NFV determines the partitioning of the P4 tables and optimal placement of NFs (P4 actions) to minimize the overall delay and maximize resource utilization. P4NFV uses Mixed Integer Linear Programming (MILP) based optimization formulation and achieves up to 2. 5X increase in system capacity while minimizing the delay experienced by flows. P4NFV considers the number of packet exchanges, flow size, and state dependency to minimize the delay imposed by data transmission over PCI Express interface.
软件定义网络(SDN)和网络功能虚拟化(NFV)正在改变数据中心(DC)、电信和企业网络。P4提供的可编程性使SDN具有更大的协议独立性和灵活性。数据中心越来越多地采用snic (smartnic)来加速数据包处理,从而支持数据包处理管道和自定义NFs (Network Functions)。然而,在集成和部署基于P4的SDN控制以及基于主机和snic的可编程NFs方面存在一些挑战。包括SDN控制平面的数据平面组件(主机和sNIC P4交换机)的配置和管理,以及数据平面资源的有效利用。P4NFV解决了这些问题,并提供了统一的P4交换机抽象框架来简化SDN控制平面,降低管理复杂性,并利用主机本地SDN代理来提高整体资源利用率。SDN代理考虑网络范围、主机和sNIC特定的能力和约束。基于工作负载和流量特征,P4NFV确定P4表的分区和NFs (P4动作)的最佳放置,以最小化总体延迟并最大化资源利用率。P4NFV采用基于混合整数线性规划(MILP)的优化公式,最大可达2。系统容量增加5倍,同时最大限度地减少流量的延迟。P4NFV考虑了分组交换的数量、流大小和状态依赖性,以最大限度地减少通过PCI Express接口传输数据所带来的延迟。
{"title":"P4NFV: P4 Enabled NFV Systems with SmartNICs","authors":"Ali Mohammadkhan, Sourav Panda, Sameer G. Kulkarni, K. Ramakrishnan, L. Bhuyan","doi":"10.1109/NFV-SDN47374.2019.9040000","DOIUrl":"https://doi.org/10.1109/NFV-SDN47374.2019.9040000","url":null,"abstract":"Software Defined Networking (SDN) and Network Function Virtualization (NFV) are transforming Data Center (DC), Telecom, and enterprise networking. The programmability offered by P4 enables SDN to be more protocol-independent and flexible. Data Centers are increasingly adopting SmartNICs (sNICs) to accelerate packet processing that can be leveraged to support packet processing pipelines and custom Network Functions (NFs). However, there are several challenges in integrating and deploying P4 based SDN control as well as host and sNIC-based programmable NFs. These include configuration and management of the data plane components (Host and sNIC P4 switches) for the SDN control plane and effective utilization of data plane resources. P4NFV addresses these concerns and provides a unified P4 switch abstraction framework to simplify the SDN control plane, reducing management complexities, and leveraging a host-local SDN Agent to improve the overall resource utilization. The SDN agent considers the network-wide, host, and sNIC specific capabilities and constraints. Based on workload and traffic characteristics, P4NFV determines the partitioning of the P4 tables and optimal placement of NFs (P4 actions) to minimize the overall delay and maximize resource utilization. P4NFV uses Mixed Integer Linear Programming (MILP) based optimization formulation and achieves up to 2. 5X increase in system capacity while minimizing the delay experienced by flows. P4NFV considers the number of packet exchanges, flow size, and state dependency to minimize the delay imposed by data transmission over PCI Express interface.","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"169 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"122061462","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 7
NFV-SDN 2019 Technical Program Committee NFV-SDN 2019技术计划委员会
{"title":"NFV-SDN 2019 Technical Program Committee","authors":"","doi":"10.1109/nfv-sdn47374.2019.9040123","DOIUrl":"https://doi.org/10.1109/nfv-sdn47374.2019.9040123","url":null,"abstract":"","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"73 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"124673428","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Protecting OpenFlow using Intel SGX 使用英特尔SGX保护OpenFlow
Jorge Medina, Nicolae Paladi, P. Arlos
OpenFlow flow tables in Open vSwitch contain valuable information about installed flows, priorities, packet actions and routing policies. Their importance is emphasized when collocated tenants compete for the limited entries available to install flow rules. OpenFlow flow tables are a security asset that requires confidentiality and integrity guarantees. However, commodity software switch implementations - such as Open vSwitch - do not implement protection mechanisms capable to prevent attackers from obtaining information about the installed flows or modifying flow tables. We adopt a novel approach to enabling OpenFlow flow table protection through decomposition. We identify core assets requiring security guarantees, isolate OpenFlow flow tables through decomposition and implement a prototype using Open vSwitch and Software Guard Extensions enclaves. An evaluation of the prototype on a distributed testbed both demonstrates that the approach is practical and indicates directions for further improvements.
Open vSwitch中的OpenFlow流表包含有关已安装流、优先级、数据包动作和路由策略的宝贵信息。当分配的租户竞争可用于安装流规则的有限条目时,它们的重要性得到了强调。OpenFlow流表是一种安全资产,需要保密性和完整性保证。然而,商品软件交换机实现(例如Open vSwitch)没有实现能够阻止攻击者获取有关已安装流或修改流表的信息的保护机制。我们采用一种新颖的方法通过分解实现OpenFlow流表保护。我们确定需要安全保证的核心资产,通过分解隔离OpenFlow流表,并使用Open vSwitch和Software Guard Extensions enclaves实现原型。在分布式测试平台上对原型进行了评估,既证明了该方法的实用性,又指出了进一步改进的方向。
{"title":"Protecting OpenFlow using Intel SGX","authors":"Jorge Medina, Nicolae Paladi, P. Arlos","doi":"10.1109/NFV-SDN47374.2019.9039980","DOIUrl":"https://doi.org/10.1109/NFV-SDN47374.2019.9039980","url":null,"abstract":"OpenFlow flow tables in Open vSwitch contain valuable information about installed flows, priorities, packet actions and routing policies. Their importance is emphasized when collocated tenants compete for the limited entries available to install flow rules. OpenFlow flow tables are a security asset that requires confidentiality and integrity guarantees. However, commodity software switch implementations - such as Open vSwitch - do not implement protection mechanisms capable to prevent attackers from obtaining information about the installed flows or modifying flow tables. We adopt a novel approach to enabling OpenFlow flow table protection through decomposition. We identify core assets requiring security guarantees, isolate OpenFlow flow tables through decomposition and implement a prototype using Open vSwitch and Software Guard Extensions enclaves. An evaluation of the prototype on a distributed testbed both demonstrates that the approach is practical and indicates directions for further improvements.","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"40 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"129399267","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 7
NFV-SDN 2019 Table of Contents NFV-SDN 2019目录
{"title":"NFV-SDN 2019 Table of Contents","authors":"","doi":"10.1109/nfv-sdn47374.2019.9039954","DOIUrl":"https://doi.org/10.1109/nfv-sdn47374.2019.9039954","url":null,"abstract":"","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"41 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"131340610","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
NFV-SDN 2019 Organizing Committee NFV-SDN 2019组委会
{"title":"NFV-SDN 2019 Organizing Committee","authors":"","doi":"10.1109/nfv-sdn47374.2019.9040156","DOIUrl":"https://doi.org/10.1109/nfv-sdn47374.2019.9040156","url":null,"abstract":"","PeriodicalId":394933,"journal":{"name":"2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"16 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"123015909","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
期刊
2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1