首页 > 最新文献

2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)最新文献

英文 中文
SFC-Checker: Checking the correct forwarding behavior of Service Function chaining SFC-Checker:检查业务功能链转发行为是否正确
Brendan Tschaen, Y. Zhang, Theophilus A. Benson, S. Banerjee, Jeongkeun Lee, Joon-Myung Kang
Network middleboxes are difficult to manage and troubleshoot, due to their proprietary monolithic design. Moving towards Network Functions Virtualization (NFV), virtualized middlebox appliances can be more flexibly instantiated and dynamically chained, making troubleshooting even more difficult. To guarantee carrier-grade availability and minimize outages, operators need ways to automatically verify that the deployed network and middlebox configurations obey higher level network policies. In this paper, we first define and identify the key challenges for checking the correct forwarding behavior of Service Function Chains (SFC). We then design and develop a network diagnosis framework that aids network administrators in verifying the correctness of SFC policy enforcement. Our prototype - SFC-Checker can verify stateful service chains efficiently, by analyzing the switches' forwarding rules and the middleboxes' stateful forwarding behavior. Built on top of the network function models we proposed, we develop a diagnosis algorithm that is able to check the stateful forwarding behavior of a chain of network service functions.
由于其专有的单片设计,网络中间件很难管理和排除故障。随着网络功能虚拟化(NFV)的发展,虚拟化的中间盒设备可以更灵活地实例化和动态链接,这使得故障排除更加困难。为了保证运营商级的可用性并最大限度地减少中断,运营商需要自动验证部署的网络和中间盒配置是否符合更高级别的网络策略。在本文中,我们首先定义并识别了检查业务功能链(SFC)正确转发行为的关键挑战。然后,我们设计并开发了一个网络诊断框架,帮助网络管理员验证SFC策略执行的正确性。我们的原型SFC-Checker通过分析交换机的转发规则和中间件的有状态转发行为,可以有效地验证有状态的服务链。在我们提出的网络功能模型的基础上,我们开发了一种能够检查网络服务功能链的状态转发行为的诊断算法。
{"title":"SFC-Checker: Checking the correct forwarding behavior of Service Function chaining","authors":"Brendan Tschaen, Y. Zhang, Theophilus A. Benson, S. Banerjee, Jeongkeun Lee, Joon-Myung Kang","doi":"10.1109/NFV-SDN.2016.7919488","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919488","url":null,"abstract":"Network middleboxes are difficult to manage and troubleshoot, due to their proprietary monolithic design. Moving towards Network Functions Virtualization (NFV), virtualized middlebox appliances can be more flexibly instantiated and dynamically chained, making troubleshooting even more difficult. To guarantee carrier-grade availability and minimize outages, operators need ways to automatically verify that the deployed network and middlebox configurations obey higher level network policies. In this paper, we first define and identify the key challenges for checking the correct forwarding behavior of Service Function Chains (SFC). We then design and develop a network diagnosis framework that aids network administrators in verifying the correctness of SFC policy enforcement. Our prototype - SFC-Checker can verify stateful service chains efficiently, by analyzing the switches' forwarding rules and the middleboxes' stateful forwarding behavior. Built on top of the network function models we proposed, we develop a diagnosis algorithm that is able to check the stateful forwarding behavior of a chain of network service functions.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"46 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115507861","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 44
CAR: Cloud-Assisted Routing CAR:云辅助路由
P. K. Dey, M. Yuksel
We propose a new hybrid software-defined networking (SDN) approach, Cloud-Assisted Routing (CAR), that utilizes high computation and memory power of cloud services by splitting both control and data plane functions between a local router and a remote cloud computing platform. Instead of a complete separation of the two planes, our approach maintains most of the control plane at the cloud and the least of it at the local router, and vice versa for the data plane. We present the architectural view of CAR and results from an initial prototype of forwarding table size reduction using CAR. We discuss possible intra- and inter-domain optimizations by highlighting the use-cases of multi-cloud design paradigm and perform a cost comparison between legacy router vs. CAR to identify the break-even points and key components that make CAR monetarily beneficial.
我们提出了一种新的混合软件定义网络(SDN)方法,云辅助路由(CAR),它通过在本地路由器和远程云计算平台之间分离控制和数据平面功能来利用云服务的高计算和内存能力。我们的方法没有将两个平面完全分离,而是将大部分控制平面维护在云上,而将最少的控制平面维护在本地路由器上,数据平面反之亦然。我们提出了CAR的架构视图和使用CAR减少转发表大小的初始原型的结果。我们通过强调多云设计范例的用例来讨论可能的域内和域间优化,并在传统路由器与CAR之间进行成本比较,以确定使CAR具有经济效益的盈利率点和关键组件。
{"title":"CAR: Cloud-Assisted Routing","authors":"P. K. Dey, M. Yuksel","doi":"10.1109/NFV-SDN.2016.7919483","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919483","url":null,"abstract":"We propose a new hybrid software-defined networking (SDN) approach, Cloud-Assisted Routing (CAR), that utilizes high computation and memory power of cloud services by splitting both control and data plane functions between a local router and a remote cloud computing platform. Instead of a complete separation of the two planes, our approach maintains most of the control plane at the cloud and the least of it at the local router, and vice versa for the data plane. We present the architectural view of CAR and results from an initial prototype of forwarding table size reduction using CAR. We discuss possible intra- and inter-domain optimizations by highlighting the use-cases of multi-cloud design paradigm and perform a cost comparison between legacy router vs. CAR to identify the break-even points and key components that make CAR monetarily beneficial.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"11 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130575056","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 4
Towards a Modular Interactive Management approach for SDN Infrastructure orchestration 面向SDN基础架构编排的模块化交互管理方法
C. S. Gomes, Felipe S. Dantas Silva, Emidio P. Neto, K. Costa, João Batista da Silva
The Software-Defined Networking (SDN) paradigm has introduced a set of resources that can be employed to design new services and applications for the next generation of network technologies. Despite all the benefits provided by the SDN approach, the management of the infrastructure remains an unsolved challenge since it is necessary to provide the appropriate tools to ensure a reliable and effective network service orchestration. In view of this, we introduce the Modular Interactive Management System for SDN Infrastructure (MISSIn), a supportive tool for SDN management, designed to support network operators to deal with complex heterogeneous applications and user requirements, in a dynamic and interactive way.
软件定义网络(SDN)范例引入了一组资源,可用于为下一代网络技术设计新的服务和应用程序。尽管SDN方法提供了所有好处,但基础设施的管理仍然是一个未解决的挑战,因为必须提供适当的工具来确保可靠和有效的网络服务编排。鉴于此,我们推出了SDN基础设施模块化交互管理系统(MISSIn),这是SDN管理的支持工具,旨在支持网络运营商以动态和交互的方式处理复杂的异构应用和用户需求。
{"title":"Towards a Modular Interactive Management approach for SDN Infrastructure orchestration","authors":"C. S. Gomes, Felipe S. Dantas Silva, Emidio P. Neto, K. Costa, João Batista da Silva","doi":"10.1109/NFV-SDN.2016.7919467","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919467","url":null,"abstract":"The Software-Defined Networking (SDN) paradigm has introduced a set of resources that can be employed to design new services and applications for the next generation of network technologies. Despite all the benefits provided by the SDN approach, the management of the infrastructure remains an unsolved challenge since it is necessary to provide the appropriate tools to ensure a reliable and effective network service orchestration. In view of this, we introduce the Modular Interactive Management System for SDN Infrastructure (MISSIn), a supportive tool for SDN management, designed to support network operators to deal with complex heterogeneous applications and user requirements, in a dynamic and interactive way.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"40 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121418900","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 7
An extensible Autoscaling Engine (AE) for Software-based Network Functions 基于软件的网络功能的可扩展自动缩放引擎(AE)
G. Carella, Michael Pauls, L. Grebe, T. Magedanz
With the rapid migration towards Software-based Networks, Telco Operators are modifying their traditional network infrastructures in order to reduce the complexity in managing Network Services (NS). Being able to cope with on-demand traffic increase is one of the key principles taken from the Cloud Computing domain and extended to the Telco one by the ETSI Network Function Virtualization (NFV) initiative. However, due to the novelty of this paradigm in the Telco domain, the landscape of fully-interoperable frameworks is rather limited and even more complex is their extensibility for supporting new functionalities. None of the existing solutions nowadays provide mechanisms for dynamically adapt the NS topology based on their Runtime Key Performance Indicators (KPIs), supporting the requirements requested by the ETSI NFV specification. Therefore, this article presents an Autoscaling Engine (AE) capable of dynamically adapting a NS based on policies provided by the Operator and integrated in the ETSI NFV information model. Its design has been realized considering the NFV requirements, and has been integrated in the ETSI NFV Architecture as additional functional element. Its implementation is part of an existing NFV-compliant framework, Open Baton, and made available to the community as open source. An evaluation of the implemented concept shows that the proposed solution increases the reliability, stability and resource efficiency of NSs.
随着软件网络的快速发展,电信运营商正在对其传统的网络基础设施进行改造,以降低网络服务管理的复杂性。能够应付随需应变的流量增长是来自云计算领域的关键原则之一,并通过ETSI网络功能虚拟化(NFV)计划扩展到电信领域。然而,由于这种范式在电信领域的新颖性,完全可互操作框架的前景相当有限,更复杂的是它们支持新功能的可扩展性。目前,现有的解决方案都没有提供基于运行时关键性能指标(kpi)动态调整NS拓扑的机制,以支持ETSI NFV规范所要求的要求。因此,本文提出了一种自动缩放引擎(AE),该引擎能够根据运营商提供的策略动态调整NS,并集成到ETSI NFV信息模型中。其设计考虑了NFV需求,并作为附加功能元素集成到ETSI NFV架构中。它的实现是现有nfv兼容框架Open Baton的一部分,并作为开源提供给社区。对实现概念的评估表明,提出的解决方案提高了NSs的可靠性、稳定性和资源效率。
{"title":"An extensible Autoscaling Engine (AE) for Software-based Network Functions","authors":"G. Carella, Michael Pauls, L. Grebe, T. Magedanz","doi":"10.1109/NFV-SDN.2016.7919501","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919501","url":null,"abstract":"With the rapid migration towards Software-based Networks, Telco Operators are modifying their traditional network infrastructures in order to reduce the complexity in managing Network Services (NS). Being able to cope with on-demand traffic increase is one of the key principles taken from the Cloud Computing domain and extended to the Telco one by the ETSI Network Function Virtualization (NFV) initiative. However, due to the novelty of this paradigm in the Telco domain, the landscape of fully-interoperable frameworks is rather limited and even more complex is their extensibility for supporting new functionalities. None of the existing solutions nowadays provide mechanisms for dynamically adapt the NS topology based on their Runtime Key Performance Indicators (KPIs), supporting the requirements requested by the ETSI NFV specification. Therefore, this article presents an Autoscaling Engine (AE) capable of dynamically adapting a NS based on policies provided by the Operator and integrated in the ETSI NFV information model. Its design has been realized considering the NFV requirements, and has been integrated in the ETSI NFV Architecture as additional functional element. Its implementation is part of an existing NFV-compliant framework, Open Baton, and made available to the community as open source. An evaluation of the implemented concept shows that the proposed solution increases the reliability, stability and resource efficiency of NSs.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"38 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115588254","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 17
Resilient orchestration of Service Functions Chains in a NFV environment NFV环境中业务功能链的弹性编排
Ahmed Medhat, G. Carella, Michael Pauls, M. Monachesi, M. Corici, T. Magedanz
Service Function Chaining (SFC) defines the concept of linking ordered Service Functions (SFs) through network technologies to support specific application requirements. SFC exploits Software Defined Networking (SDN) and Network Function Virtualization (NFV) technologies to achieve the creation, modification and deletion of SFC in a cost efficient and rapid way. However, during the runtime phase, SFs are exposed to the risk of failures, which results in an end-to-end failure at the application level. For this reason, this paper introduces the concept of a resilient SFC Orchestrator capable of deploying SF Chains following the ETSI NFV architectural model, as well as controlling the runtime phase rerouting the traffic to a different path in case of appearing faults. Furthermore, the concept is exemplified as an addition to the current NFV architecture and evaluated in a NFV environment making use of the Fraunhofer FOKUS Open Baton toolkit in an OpenStack and OpenDayLight based environment. Finally, the measured results show that the Service Function Path (SFP), and therefore their provided services, can be recovered in a few seconds.
SFC (Service Function chains)定义了通过网络技术将有序的服务功能链接起来,以支持特定的应用需求的概念。SFC利用软件定义网络(SDN)和网络功能虚拟化(NFV)技术,以低成本、快速的方式实现SFC的创建、修改和删除。然而,在运行时阶段,sf面临失败的风险,这会导致应用程序级别的端到端失败。出于这个原因,本文介绍了弹性SFC编排器的概念,它能够按照ETSI NFV架构模型部署SF链,并在出现故障时控制运行阶段将流量重新路由到不同的路径。此外,该概念作为当前NFV架构的补充,并在基于OpenStack和OpenDayLight的环境中使用Fraunhofer FOKUS Open Baton工具包在NFV环境中进行了评估。最后,测量结果表明,业务功能路径(SFP)及其提供的业务可以在几秒钟内恢复。
{"title":"Resilient orchestration of Service Functions Chains in a NFV environment","authors":"Ahmed Medhat, G. Carella, Michael Pauls, M. Monachesi, M. Corici, T. Magedanz","doi":"10.1109/NFV-SDN.2016.7919468","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919468","url":null,"abstract":"Service Function Chaining (SFC) defines the concept of linking ordered Service Functions (SFs) through network technologies to support specific application requirements. SFC exploits Software Defined Networking (SDN) and Network Function Virtualization (NFV) technologies to achieve the creation, modification and deletion of SFC in a cost efficient and rapid way. However, during the runtime phase, SFs are exposed to the risk of failures, which results in an end-to-end failure at the application level. For this reason, this paper introduces the concept of a resilient SFC Orchestrator capable of deploying SF Chains following the ETSI NFV architectural model, as well as controlling the runtime phase rerouting the traffic to a different path in case of appearing faults. Furthermore, the concept is exemplified as an addition to the current NFV architecture and evaluated in a NFV environment making use of the Fraunhofer FOKUS Open Baton toolkit in an OpenStack and OpenDayLight based environment. Finally, the measured results show that the Service Function Path (SFP), and therefore their provided services, can be recovered in a few seconds.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"11 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"123035643","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 28
Orchestrating network control functions via comprehensive trade-off exploration 通过综合权衡探索协调网络控制功能
Alan Bairley, G. Xie
SDN orchestration, the problem of integrating and deploying multiple network control functions (NCFs) while minimizing suboptimal network states that can result from competing NCF objectives, is a challenging open problem. In this work, we formulate SDN orchestration as a multiobjective optimization problem, and present an evolutionary approach designed to explore the NCF tradeoff space comprehensively and avoid local optima. For an instance of the VM allocation problem subject to three independent NCFs optimizing network survivability, bandwidth efficiency, and power consumption, respectively, we demonstrate that our approach can enumerate a wider range of, and potentially better solutions than current orchestrators, for data centers with 100s of switches, 1,000s of servers, and 10,000s of VM slots.
SDN编排是一个具有挑战性的开放性问题,即集成和部署多个网络控制功能(NCF),同时最小化NCF目标竞争可能导致的次优网络状态。在这项工作中,我们将SDN编排作为一个多目标优化问题,并提出了一种旨在全面探索NCF权衡空间并避免局部最优的进化方法。对于一个VM分配问题的实例,该问题由三个独立的nfc分别优化网络生存性、带宽效率和功耗,我们证明,对于具有100台交换机、1000台服务器和10,000个VM插槽的数据中心,我们的方法可以列举出比当前编排器更广泛的解决方案,并且可能更好。
{"title":"Orchestrating network control functions via comprehensive trade-off exploration","authors":"Alan Bairley, G. Xie","doi":"10.1109/NFV-SDN.2016.7919485","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919485","url":null,"abstract":"SDN orchestration, the problem of integrating and deploying multiple network control functions (NCFs) while minimizing suboptimal network states that can result from competing NCF objectives, is a challenging open problem. In this work, we formulate SDN orchestration as a multiobjective optimization problem, and present an evolutionary approach designed to explore the NCF tradeoff space comprehensively and avoid local optima. For an instance of the VM allocation problem subject to three independent NCFs optimizing network survivability, bandwidth efficiency, and power consumption, respectively, we demonstrate that our approach can enumerate a wider range of, and potentially better solutions than current orchestrators, for data centers with 100s of switches, 1,000s of servers, and 10,000s of VM slots.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"26 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121794528","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 5
NFVPerf: Online performance monitoring and bottleneck detection for NFV NFVPerf:支持NFV在线性能监控和瓶颈检测
Priyanka Naik, Dilip Kumar Shaw, Mythili Vutukuru
Network Function Virtualization (NFV) is a new trend in networking, where network functions are moving from custom hardware appliances to software implementations running on virtual machines (VMs) hosted on commodity hardware. While the benefits of NFV such as cost reduction and increased agility are well understood, doubts still exist on whether a software implementation can match up to the high performance that hardware appliances deliver. In this context, network operators would benefit from frameworks that monitor performance and identify bottlenecks in Virtual Network Function (VNF) implementations obtained from vendors. While several techniques already exist to identify performance issues in cloud-based applications, most of them either use hardware resource utilizations to identify hot-spots (making them incapable of detecting non-hardware performance bottlenecks) or rely on application specific measurements (which may not be exposed by VNFs to vendors always). This paper describes NFVPerf, a performance monitoring and bottleneck detection tool for NFV. NFVPerf works as part of a cloud that hosts a NFV deployment, and takes a configuration file specifying the basic architecture of the VNF as input. It sniffs packets on all VM-to-VM communication paths, computes per-hop throughputs and delays, and uses these “black-box” measurements alone to identify performance bottlenecks (including software bottlenecks) in real time, without requiring any instrumentation of the VNF. Further, NFVPerf can be customized to any VNF implementations with just configuration changes. Our evaluation of NFVPerf shows that it can monitor performance and identify bottlenecks in an NFV deployment, with high accuracy and minimal overhead. We believe that a system like NFVPerf would form a great addition to cloud management systems in the era of NFV.
网络功能虚拟化(NFV)是网络中的一种新趋势,其中网络功能正在从定制硬件设备转移到运行在托管在商品硬件上的虚拟机(vm)上的软件实现。虽然NFV的好处,如降低成本和提高敏捷性是众所周知的,但软件实现是否能与硬件设备提供的高性能相匹配,仍然存在疑问。在这种情况下,网络运营商将受益于从供应商那里获得的监控性能和识别虚拟网络功能(VNF)实现瓶颈的框架。虽然已经有几种技术可以识别基于云的应用程序中的性能问题,但大多数技术要么使用硬件资源利用率来识别热点(使它们无法检测非硬件性能瓶颈),要么依赖于特定于应用程序的测量(vnf可能并不总是向供应商公开这些测量)。本文介绍了NFVPerf——一种面向NFV的性能监控和瓶颈检测工具。NFVPerf作为承载NFV部署的云的一部分,并将指定VNF基本架构的配置文件作为输入。它嗅探所有vm到vm通信路径上的数据包,计算每跳吞吐量和延迟,并单独使用这些“黑盒”测量来实时识别性能瓶颈(包括软件瓶颈),而不需要任何VNF检测。此外,NFVPerf可以定制为任何VNF实现,只需更改配置。我们对NFVPerf的评估表明,它可以监控性能并识别NFV部署中的瓶颈,具有高精度和最小的开销。我们相信NFVPerf这样的系统将会成为NFV时代云管理系统的一个很好的补充。
{"title":"NFVPerf: Online performance monitoring and bottleneck detection for NFV","authors":"Priyanka Naik, Dilip Kumar Shaw, Mythili Vutukuru","doi":"10.1109/NFV-SDN.2016.7919491","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919491","url":null,"abstract":"Network Function Virtualization (NFV) is a new trend in networking, where network functions are moving from custom hardware appliances to software implementations running on virtual machines (VMs) hosted on commodity hardware. While the benefits of NFV such as cost reduction and increased agility are well understood, doubts still exist on whether a software implementation can match up to the high performance that hardware appliances deliver. In this context, network operators would benefit from frameworks that monitor performance and identify bottlenecks in Virtual Network Function (VNF) implementations obtained from vendors. While several techniques already exist to identify performance issues in cloud-based applications, most of them either use hardware resource utilizations to identify hot-spots (making them incapable of detecting non-hardware performance bottlenecks) or rely on application specific measurements (which may not be exposed by VNFs to vendors always). This paper describes NFVPerf, a performance monitoring and bottleneck detection tool for NFV. NFVPerf works as part of a cloud that hosts a NFV deployment, and takes a configuration file specifying the basic architecture of the VNF as input. It sniffs packets on all VM-to-VM communication paths, computes per-hop throughputs and delays, and uses these “black-box” measurements alone to identify performance bottlenecks (including software bottlenecks) in real time, without requiring any instrumentation of the VNF. Further, NFVPerf can be customized to any VNF implementations with just configuration changes. Our evaluation of NFVPerf shows that it can monitor performance and identify bottlenecks in an NFV deployment, with high accuracy and minimal overhead. We believe that a system like NFVPerf would form a great addition to cloud management systems in the era of NFV.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"391 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"125148797","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 53
Efficient service graph embedding: A practical approach 高效的服务图嵌入:一种实用的方法
Balázs Németh, Balázs Sonkoly, Matthias Rost, S. Schmid
Future network services and applications, such as coordinated remote driving or remote surgery, pose serious challenges on the underlying networks. In order to fulfill the extremely low latency requirement in combination with ultrahigh availability and reliability, we need novel approaches, for example to dynamically move network “capabilities” close to the users. This requires more flexibility, automation and adaptability to be added to the networks at different levels and operation planes. The key enabler of the novel features is network softwarization provided by NFV and SDN techniques. In this paper, we focus on a central component of the orchestration plane which is responsible for mapping the building blocks of services to available resources. Our main contribution is twofold. First, we propose a novel service graph embedding algorithm which is able to jointly control and optimize the usage of compute and network resources efficiently based on greedy heuristics. Besides, the algorithm can be configured extensively to obtain different optimization goals and trade-off running time with the search space. Second, we report on our implementation and integration with our proof-of-concept orchestration framework ESCAPE. Several experiments confirmed its practical applicability.
未来的网络服务和应用,如协同远程驾驶或远程手术,对底层网络提出了严峻的挑战。为了在超高可用性和可靠性的同时满足极低延迟的需求,我们需要新的方法,例如动态地将网络“功能”移动到接近用户的位置。这就要求在不同层次和操作平面的网络中增加更多的灵活性、自动化和适应性。这些新特性的关键促成因素是NFV和SDN技术提供的网络软件化。在本文中,我们将重点关注编排平面的一个中心组件,该组件负责将服务的构建块映射到可用资源。我们的主要贡献是双重的。首先,我们提出了一种基于贪婪启发式的服务图嵌入算法,该算法能够有效地联合控制和优化计算资源和网络资源的使用。此外,该算法可以广泛配置,以获得不同的优化目标,并在运行时间与搜索空间之间进行权衡。其次,我们报告了我们与概念验证编排框架ESCAPE的实现和集成。几个实验证实了它的实用性。
{"title":"Efficient service graph embedding: A practical approach","authors":"Balázs Németh, Balázs Sonkoly, Matthias Rost, S. Schmid","doi":"10.1109/NFV-SDN.2016.7919470","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919470","url":null,"abstract":"Future network services and applications, such as coordinated remote driving or remote surgery, pose serious challenges on the underlying networks. In order to fulfill the extremely low latency requirement in combination with ultrahigh availability and reliability, we need novel approaches, for example to dynamically move network “capabilities” close to the users. This requires more flexibility, automation and adaptability to be added to the networks at different levels and operation planes. The key enabler of the novel features is network softwarization provided by NFV and SDN techniques. In this paper, we focus on a central component of the orchestration plane which is responsible for mapping the building blocks of services to available resources. Our main contribution is twofold. First, we propose a novel service graph embedding algorithm which is able to jointly control and optimize the usage of compute and network resources efficiently based on greedy heuristics. Besides, the algorithm can be configured extensively to obtain different optimization goals and trade-off running time with the search space. Second, we report on our implementation and integration with our proof-of-concept orchestration framework ESCAPE. Several experiments confirmed its practical applicability.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"165 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"126735267","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 17
Policy based virtualised security architecture for SDN/NFV enabled 5G access networks 基于策略的虚拟化安全架构,支持SDN/NFV的5G接入网络
M. S. Siddiqui, E. Escalona, Eleni Trouva, M. Kourtis, D. Kritharidis, K. Katsaros, S. Spirou, C. Canales, M. Lorenzo
The challenging traits of 5G networks to support novel and diverse business requirements of vertical sectors have rendered current network security approaches impotent. To address various security requirements of 5G networks and services, a holistic and robust security architecture mindful of 5G technical and business features becomes vital. This paper describes a holistic security architecture for a multi-tenant NFV/SDN enabled 5G access network based on policy-based security management and monitoring & smart analytics.
5G网络在支持垂直行业新颖多样的业务需求方面具有挑战性,这使得现有的网络安全方法无能为力。为满足5G网络和业务的各种安全需求,考虑到5G技术和业务特点的整体、稳健的安全架构至关重要。本文描述了基于策略安全管理和监控与智能分析的多租户NFV/SDN 5G接入网的整体安全架构。
{"title":"Policy based virtualised security architecture for SDN/NFV enabled 5G access networks","authors":"M. S. Siddiqui, E. Escalona, Eleni Trouva, M. Kourtis, D. Kritharidis, K. Katsaros, S. Spirou, C. Canales, M. Lorenzo","doi":"10.1109/NFV-SDN.2016.7919474","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919474","url":null,"abstract":"The challenging traits of 5G networks to support novel and diverse business requirements of vertical sectors have rendered current network security approaches impotent. To address various security requirements of 5G networks and services, a holistic and robust security architecture mindful of 5G technical and business features becomes vital. This paper describes a holistic security architecture for a multi-tenant NFV/SDN enabled 5G access network based on policy-based security management and monitoring & smart analytics.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"116 10","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132289179","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 18
Predicting network attack patterns in SDN using machine learning approach 使用机器学习方法预测SDN中的网络攻击模式
Saurav Nanda, Faheem Zafari, C. DeCusatis, Eric Wedaa, B. Yang
An experimental setup of 32 honeypots reported 17M login attempts originating from 112 different countries and over 6000 distinct source IP addresses. Due to decoupled control and data plane, Software Defined Networks (SDN) can handle these increasing number of attacks by blocking those network connections at the switch level. However, the challenge lies in defining the set of rules on the SDN controller to block malicious network connections. Historical network attack data can be used to automatically identify and block the malicious connections. There are a few existing open-source software tools to monitor and limit the number of login attempts per source IP address one-by-one. However, these solutions cannot efficiently act against a chain of attacks that comprises multiple IP addresses used by each attacker. In this paper, we propose using machine learning algorithms, trained on historical network attack data, to identify the potential malicious connections and potential attack destinations. We use four widely-known machine learning algorithms: C4.5, Bayesian Network (BayesNet), Decision Table (DT), and Naive-Bayes to predict the host that will be attacked based on the historical data. Experimental results show that average prediction accuracy of 91.68% is attained using Bayesian Networks.
一个包含32个蜜罐的实验装置报告了来自112个不同国家和6000多个不同源IP地址的17M次登录尝试。由于控制和数据平面的解耦,软件定义网络(SDN)可以通过在交换机级别阻止这些网络连接来处理这些越来越多的攻击。然而,挑战在于在SDN控制器上定义一组规则来阻止恶意网络连接。利用历史网络攻击数据,可以自动识别和阻断恶意连接。有一些现有的开源软件工具可以逐个监控和限制每个源IP地址的登录尝试次数。然而,这些解决方案不能有效地应对由每个攻击者使用的多个IP地址组成的攻击链。在本文中,我们建议使用经过历史网络攻击数据训练的机器学习算法来识别潜在的恶意连接和潜在的攻击目的地。我们使用四种广为人知的机器学习算法:C4.5、贝叶斯网络(BayesNet)、决策表(DT)和朴素贝叶斯(Naive-Bayes),根据历史数据预测将被攻击的主机。实验结果表明,贝叶斯网络的平均预测准确率为91.68%。
{"title":"Predicting network attack patterns in SDN using machine learning approach","authors":"Saurav Nanda, Faheem Zafari, C. DeCusatis, Eric Wedaa, B. Yang","doi":"10.1109/NFV-SDN.2016.7919493","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919493","url":null,"abstract":"An experimental setup of 32 honeypots reported 17M login attempts originating from 112 different countries and over 6000 distinct source IP addresses. Due to decoupled control and data plane, Software Defined Networks (SDN) can handle these increasing number of attacks by blocking those network connections at the switch level. However, the challenge lies in defining the set of rules on the SDN controller to block malicious network connections. Historical network attack data can be used to automatically identify and block the malicious connections. There are a few existing open-source software tools to monitor and limit the number of login attempts per source IP address one-by-one. However, these solutions cannot efficiently act against a chain of attacks that comprises multiple IP addresses used by each attacker. In this paper, we propose using machine learning algorithms, trained on historical network attack data, to identify the potential malicious connections and potential attack destinations. We use four widely-known machine learning algorithms: C4.5, Bayesian Network (BayesNet), Decision Table (DT), and Naive-Bayes to predict the host that will be attacked based on the historical data. Experimental results show that average prediction accuracy of 91.68% is attained using Bayesian Networks.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"32 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"127989862","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 106
期刊
2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1