首页 > 最新文献

2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)最新文献

英文 中文
Network-wide virtual firewall using SDN/OpenFlow 使用SDN/OpenFlow的全网虚拟防火墙
Jarrod N. Bakker, I. Welch, Winston K.G. Seah
Traditional firewalls are used to enforce network security policies at boundaries within a network. However, this can leave hosts vulnerable to attacks that originate from within the network they are part of. We leverage the flexibility of Software Defined Networking to turn the network infrastructure into a virtual firewall thus improving security across an entire network. We present ACLSwitch, a network-wide virtual firewall that utilises the OpenFlow protocol to filter traffic across a network comprised of OpenFlow switches. We also define “policy domains” that allow different filtering configurations to be applied to different switches of the network. The solution allows rules to be distributed across a network without the need for a human operator to send the rules to switches separately, yet it is flexible enough to allow subsets of the switches to enforce different security policies.
传统的防火墙用于在网络边界上实施网络安全策略。然而,这可能使主机容易受到来自其所在网络内部的攻击。我们利用软件定义网络的灵活性,将网络基础设施转变为虚拟防火墙,从而提高整个网络的安全性。我们提出ACLSwitch,一种网络范围的虚拟防火墙,它利用OpenFlow协议过滤由OpenFlow交换机组成的网络中的流量。我们还定义了“策略域”,允许将不同的过滤配置应用于网络的不同交换机。该解决方案允许在整个网络中分发规则,而不需要人工操作员将规则单独发送到交换机,但它足够灵活,可以允许交换机的子集执行不同的安全策略。
{"title":"Network-wide virtual firewall using SDN/OpenFlow","authors":"Jarrod N. Bakker, I. Welch, Winston K.G. Seah","doi":"10.1109/NFV-SDN.2016.7919477","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919477","url":null,"abstract":"Traditional firewalls are used to enforce network security policies at boundaries within a network. However, this can leave hosts vulnerable to attacks that originate from within the network they are part of. We leverage the flexibility of Software Defined Networking to turn the network infrastructure into a virtual firewall thus improving security across an entire network. We present ACLSwitch, a network-wide virtual firewall that utilises the OpenFlow protocol to filter traffic across a network comprised of OpenFlow switches. We also define “policy domains” that allow different filtering configurations to be applied to different switches of the network. The solution allows rules to be distributed across a network without the need for a human operator to send the rules to switches separately, yet it is flexible enough to allow subsets of the switches to enforce different security policies.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130393801","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 14
Statistical-based anomaly detection for NFV services 基于统计的NFV服务异常检测
M. Kourtis, G. Xilouris, G. Gardikis, Ioannis Koutras
Large-scale, carrier-grade Network Functions Virtualisation (NFV) services are expected to involve a significant number of Virtual Network Functions, deployed across multiple Points-of-Presence (PoPs) and possibly in heterogeneous infrastructures. While proper monitoring is crucial for the commercial viability of NFV services, effectively and efficiently monitoring a huge number of VNF instances, promptly detecting any malfunctions or anomalies in order to trigger corrective actions, becomes a real challenge. This paper presents the use of an open-source monitoring system especially tailored for NFV in conjunction with statistical approaches commonly used for anomaly detection, towards the timely detection of anomalies in deployed NFV services.
大规模的运营商级网络功能虚拟化(NFV)服务预计将涉及大量的虚拟网络功能,部署在多个存在点(pop)上,并可能部署在异构基础设施中。虽然适当的监控对NFV服务的商业可行性至关重要,但有效和高效地监控大量的VNF实例,及时发现任何故障或异常,以便触发纠正措施,成为一个真正的挑战。本文介绍了一个专门为NFV量身定制的开源监控系统的使用,并结合了通常用于异常检测的统计方法,以便及时检测部署的NFV服务中的异常。
{"title":"Statistical-based anomaly detection for NFV services","authors":"M. Kourtis, G. Xilouris, G. Gardikis, Ioannis Koutras","doi":"10.1109/NFV-SDN.2016.7919492","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919492","url":null,"abstract":"Large-scale, carrier-grade Network Functions Virtualisation (NFV) services are expected to involve a significant number of Virtual Network Functions, deployed across multiple Points-of-Presence (PoPs) and possibly in heterogeneous infrastructures. While proper monitoring is crucial for the commercial viability of NFV services, effectively and efficiently monitoring a huge number of VNF instances, promptly detecting any malfunctions or anomalies in order to trigger corrective actions, becomes a real challenge. This paper presents the use of an open-source monitoring system especially tailored for NFV in conjunction with statistical approaches commonly used for anomaly detection, towards the timely detection of anomalies in deployed NFV services.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132988246","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 12
Robust embedding of VNF/service chains with delay bounds 带延迟界的VNF/服务链鲁棒嵌入
Varun S. Reddy, Andreas Baumgartner, T. Bauschert
The efficient and carrier-grade operation of virtualised network infrastructures (Infrastructure as a Service, IaaS) within Cloud Systems requires powerful methods for dynamic resource provisioning, virtual network functions (VNF) placement and interconnection. In the scientific literature, already several contributions related to the virtual network embedding (VNE) problem can be found, see [1] and the references therein as well as our previous contributions [2], [3]. Typically, the physical substrate infrastructure (network nodes with switching, processing and storage resources, and links with defined bandwidth) as well as the traffic demands of the virtual networks are given and the target is to minimise the embedding cost wrt. performance and QoS constraints (e.g. bandwidth guarantees, latency bounds). In this contribution, we propose a novel optimisation model based on the concept of Γ-robustness [4], [5] to deal with uncertainties in the traffic demand and as a consequence in the resource requirements of the VNFs while fulfilling individual average roundtrip delay bounds for each chain of VNFs. The Γ-robust optimisation model is formulated as a mixed-integer linear program (MILP). Moreover, in order to enhance the scalability of the model, a modified MIP-based Variable Neighbourhood Search (VNS) heuristic is proposed. The performance of the novel optimisation model and the heuristic is evaluated for different performance scenarios using a network topology example taken from SNDlib [6].
云系统内虚拟化网络基础设施(基础设施即服务,IaaS)的高效和运营商级运行需要强大的动态资源配置、虚拟网络功能(VNF)放置和互连方法。在科学文献中,已经可以找到一些与虚拟网络嵌入(VNE)问题相关的贡献,参见[1]及其参考文献以及我们之前的贡献[2],[3]。通常,给出了虚拟网络的物理基础设施(具有交换、处理和存储资源的网络节点以及具有定义带宽的链路)以及流量需求,目标是最小化嵌入成本wrt。性能和QoS约束(例如带宽保证,延迟界限)。在这篇文章中,我们提出了一种基于Γ-robustness[4],[5]概念的新型优化模型,以处理交通需求中的不确定性,以及由此导致的vnf资源需求,同时满足每个vnf链的单个平均往返延迟界限。Γ-robust优化模型是一个混合整数线性规划(MILP)。此外,为了增强模型的可扩展性,提出了一种改进的基于mip的变量邻域搜索启发式算法。使用来自SNDlib[6]的网络拓扑示例,对新优化模型和启发式算法的性能进行了不同性能场景的评估。
{"title":"Robust embedding of VNF/service chains with delay bounds","authors":"Varun S. Reddy, Andreas Baumgartner, T. Bauschert","doi":"10.1109/NFV-SDN.2016.7919482","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919482","url":null,"abstract":"The efficient and carrier-grade operation of virtualised network infrastructures (Infrastructure as a Service, IaaS) within Cloud Systems requires powerful methods for dynamic resource provisioning, virtual network functions (VNF) placement and interconnection. In the scientific literature, already several contributions related to the virtual network embedding (VNE) problem can be found, see [1] and the references therein as well as our previous contributions [2], [3]. Typically, the physical substrate infrastructure (network nodes with switching, processing and storage resources, and links with defined bandwidth) as well as the traffic demands of the virtual networks are given and the target is to minimise the embedding cost wrt. performance and QoS constraints (e.g. bandwidth guarantees, latency bounds). In this contribution, we propose a novel optimisation model based on the concept of Γ-robustness [4], [5] to deal with uncertainties in the traffic demand and as a consequence in the resource requirements of the VNFs while fulfilling individual average roundtrip delay bounds for each chain of VNFs. The Γ-robust optimisation model is formulated as a mixed-integer linear program (MILP). Moreover, in order to enhance the scalability of the model, a modified MIP-based Variable Neighbourhood Search (VNS) heuristic is proposed. The performance of the novel optimisation model and the heuristic is evaluated for different performance scenarios using a network topology example taken from SNDlib [6].","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"32 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"125090596","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 26
EPLE: An Efficient Passive Lightweight Estimator for SDN packet loss measurement EPLE:一种用于SDN丢包测量的高效被动轻量级估计器
Chunyan Fu, Wolfgang John, C. Meirosu
As Software Defined Networks (SDN) deployments are reaching mainstream, network performance becomes a key concern for success. Service Providers (SPs) rely on network management capabilities, such as packet loss monitoring, to observe the network status and thereby facilitate service-level agreements. On one hand, SPs seek tools providing greater visibility into the status of their networks, but on the other hand, they are keen to limit the overhead of management capabilities in their operational networks. To meet these conflicting requirements, Efficient Passive Lightweight Estimator (EPLE) takes advantage of existing network traffic and SDN signaling, without the need of extra monitoring traffic or facilities. EPLE does not introduce any data plane overhead and the signaling overhead is reduced by locally creating microflow descriptors out of aggregated flow definitions. Our proof-of-concept prototype shows that EPLE can estimate packet loss rates accurately while keeping the processing and signaling overheads small compared to existing active measurement methods.
随着软件定义网络(SDN)部署逐渐成为主流,网络性能成为成功与否的关键因素。服务提供商(Service provider, sp)依靠网络管理能力(如丢包监控)来观察网络状态,从而促进服务水平协议的达成。一方面,服务提供商寻求能够更好地了解其网络状态的工具,但另一方面,他们热衷于限制其运营网络中管理功能的开销。为了满足这些相互冲突的需求,高效被动轻量级估计器(Efficient Passive Lightweight Estimator, EPLE)利用现有的网络流量和SDN信令,而不需要额外的监控流量或设施。EPLE不引入任何数据平面开销,并且通过从聚合流定义中本地创建微流描述符来减少信令开销。我们的概念验证原型表明,与现有的主动测量方法相比,EPLE可以准确地估计丢包率,同时保持较小的处理和信令开销。
{"title":"EPLE: An Efficient Passive Lightweight Estimator for SDN packet loss measurement","authors":"Chunyan Fu, Wolfgang John, C. Meirosu","doi":"10.1109/NFV-SDN.2016.7919497","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919497","url":null,"abstract":"As Software Defined Networks (SDN) deployments are reaching mainstream, network performance becomes a key concern for success. Service Providers (SPs) rely on network management capabilities, such as packet loss monitoring, to observe the network status and thereby facilitate service-level agreements. On one hand, SPs seek tools providing greater visibility into the status of their networks, but on the other hand, they are keen to limit the overhead of management capabilities in their operational networks. To meet these conflicting requirements, Efficient Passive Lightweight Estimator (EPLE) takes advantage of existing network traffic and SDN signaling, without the need of extra monitoring traffic or facilities. EPLE does not introduce any data plane overhead and the signaling overhead is reduced by locally creating microflow descriptors out of aggregated flow definitions. Our proof-of-concept prototype shows that EPLE can estimate packet loss rates accurately while keeping the processing and signaling overheads small compared to existing active measurement methods.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"34 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115305669","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 11
Optimizing Service Chain ID generation for flow rule compression 流规则压缩中服务链ID生成的优化
Om Prakash Nirankari, Prakash Pawar, Kotaro Kataoka
Service Chaining provides opportunities for network and service providers to implement their services and policies with finer granularity of an individual user or an application. However, the increasing number of Service Chains and middleboxes will introduce a larger number of flow rules and more consumption of Ternary Content Addressable Memory (TCAM), whose capacity is limited due to high cost and power consumption. This paper proposes to compress the flow rules for service chaining by optimizing the generation of Service Chain IDs that are widely used in packet tagging techniques for the Service Chaining. Our solution 1) makes service chain IDs aggregatable based on Common Forwarding Actions (CFAs) among the service chains, and 2) reduces the number of flow rules at each SDN switch to execute a larger number of forwarding actions for service chaining. The evaluation results showed that the proposed algorithm can reduce up to 76% of the flow rules using the randomly generated networks and service chains. Because the generation of Service Chain ID does not interfere the other flow rule compression techniques, our algorithm can also be used as a plug-in to the other Service Chaining mechanisms to optimize their ID generation.
服务链为网络和服务提供商提供了机会,使其能够以更细的单个用户或应用程序粒度实现其服务和策略。然而,越来越多的服务链和中间盒将引入更多的流规则和更多的三元内容可寻址存储器(Ternary Content Addressable Memory, TCAM)的消耗,其容量受到高成本和功耗的限制。本文提出通过优化服务链id的生成来压缩服务链的流规则,服务链id在信息包标记技术中被广泛使用。我们的解决方案是:1)基于业务链之间的共同转发动作(Common Forwarding Actions, CFAs)实现业务链id的聚合;2)减少每个SDN交换机上的流规则数量,为业务链执行更多的转发动作。评估结果表明,该算法使用随机生成的网络和服务链可以减少多达76%的流规则。由于服务链ID的生成不会干扰其他流规则压缩技术,因此我们的算法也可以作为其他服务链机制的插件来优化它们的ID生成。
{"title":"Optimizing Service Chain ID generation for flow rule compression","authors":"Om Prakash Nirankari, Prakash Pawar, Kotaro Kataoka","doi":"10.1109/NFV-SDN.2016.7919502","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919502","url":null,"abstract":"Service Chaining provides opportunities for network and service providers to implement their services and policies with finer granularity of an individual user or an application. However, the increasing number of Service Chains and middleboxes will introduce a larger number of flow rules and more consumption of Ternary Content Addressable Memory (TCAM), whose capacity is limited due to high cost and power consumption. This paper proposes to compress the flow rules for service chaining by optimizing the generation of Service Chain IDs that are widely used in packet tagging techniques for the Service Chaining. Our solution 1) makes service chain IDs aggregatable based on Common Forwarding Actions (CFAs) among the service chains, and 2) reduces the number of flow rules at each SDN switch to execute a larger number of forwarding actions for service chaining. The evaluation results showed that the proposed algorithm can reduce up to 76% of the flow rules using the randomly generated networks and service chains. Because the generation of Service Chain ID does not interfere the other flow rule compression techniques, our algorithm can also be used as a plug-in to the other Service Chaining mechanisms to optimize their ID generation.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"37 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"131873591","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Performance evaluation and tuning of Virtual Infrastructure Managers for (Micro) Virtual Network Functions (微)虚拟网络功能的虚拟基础设施管理器的性能评估与调优
Pier Luigi Ventre, Claudio Pisa, S. Salsano, G. Siracusano, Florian Schmidt, Paolo Lungaroni, N. Blefari-Melazzi
Virtualized Network Functions (VNFs) are emerging as the keystone of 5G network architectures: flexibility, agility, fast instantiation times, consolidation, Commercial Off The Shelf (COTS) hardware support and significant cost savings are fundamental for meeting the requirements of the new generation of mobile networks. In this paper we deal with the management of the virtual computing resources for the execution of Micro VNFs. This functionality is performed by the Virtual Infrastructure Manager (VIM) in the NFV MANagement and Orchestration (MANO) reference architecture.We discuss the VIM instantiation process and propose a generic reference model, starting from the analysis of two Open Source VIMs, namely OpenStack Nova and Nomad. We implemented a tuned version of the VIMs with the specific goal of reducing the duration of the instantiation process. We realized a performance comparison of the two VIMs, both considering the plain and the tuned versions. The tuned VIMs and the performance evaluation tools that we have employed are provided openly and can be downloaded from our repository.
虚拟化网络功能(vnf)正在成为5G网络架构的基石:灵活性、敏捷性、快速实例化时间、整合、商用现货(COTS)硬件支持和显著的成本节约是满足新一代移动网络需求的基础。在本文中,我们讨论了执行微型VNFs所需的虚拟计算资源的管理。此功能由NFV管理和编排参考体系结构中的虚拟基础设施管理器(VIM)执行。本文从分析OpenStack Nova和Nomad这两个开源VIM开始,讨论了VIM的实例化过程,并提出了一个通用的参考模型。我们实现了VIMs的调优版本,其特定目标是缩短实例化过程的持续时间。我们实现了两个vm的性能比较,都考虑了普通版本和调优版本。我们所使用的调优vm和性能评估工具是公开提供的,可以从我们的存储库下载。
{"title":"Performance evaluation and tuning of Virtual Infrastructure Managers for (Micro) Virtual Network Functions","authors":"Pier Luigi Ventre, Claudio Pisa, S. Salsano, G. Siracusano, Florian Schmidt, Paolo Lungaroni, N. Blefari-Melazzi","doi":"10.1109/NFV-SDN.2016.7919489","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919489","url":null,"abstract":"Virtualized Network Functions (VNFs) are emerging as the keystone of 5G network architectures: flexibility, agility, fast instantiation times, consolidation, Commercial Off The Shelf (COTS) hardware support and significant cost savings are fundamental for meeting the requirements of the new generation of mobile networks. In this paper we deal with the management of the virtual computing resources for the execution of Micro VNFs. This functionality is performed by the Virtual Infrastructure Manager (VIM) in the NFV MANagement and Orchestration (MANO) reference architecture.We discuss the VIM instantiation process and propose a generic reference model, starting from the analysis of two Open Source VIMs, namely OpenStack Nova and Nomad. We implemented a tuned version of the VIMs with the specific goal of reducing the duration of the instantiation process. We realized a performance comparison of the two VIMs, both considering the plain and the tuned versions. The tuned VIMs and the performance evaluation tools that we have employed are provided openly and can be downloaded from our repository.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"64 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116436145","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 13
The role of inter-controller traffic in SDN controllers placement 控制器间流量在SDN控制器放置中的作用
Tianzhu Zhang, A. Bianco, P. Giaccone
We consider a distributed Software Defined Networking (SDN) architecture adopting a cluster of multiple controllers to improve network performance and reliability. Differently from previous work, we focus on the control traffic exchanged among the controllers, in addition to the Openflow control traffic exchanged between controllers and switches. We develop an analytical model to estimate the reaction time perceived at the switches due to the inter-controller communications, based on the data-ownership model adopted in the cluster. We advocate a careful placement of the controllers, taking into account the two above kinds of control traffic. We evaluate, for some real ISP network topologies, the possible delay tradeoffs for the controllers placement problem.
我们考虑采用多控制器集群的分布式软件定义网络(SDN)架构来提高网络性能和可靠性。与以往工作不同的是,除了Openflow控制器和交换机之间交换的控制流量外,我们还关注控制器之间交换的控制流量。基于集群中采用的数据所有权模型,我们开发了一个分析模型来估计由于控制器间通信而在开关处感知到的反应时间。考虑到上述两种类型的控制流量,我们建议仔细放置控制器。对于一些真实的ISP网络拓扑,我们评估了控制器放置问题可能的延迟权衡。
{"title":"The role of inter-controller traffic in SDN controllers placement","authors":"Tianzhu Zhang, A. Bianco, P. Giaccone","doi":"10.1109/NFV-SDN.2016.7919481","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919481","url":null,"abstract":"We consider a distributed Software Defined Networking (SDN) architecture adopting a cluster of multiple controllers to improve network performance and reliability. Differently from previous work, we focus on the control traffic exchanged among the controllers, in addition to the Openflow control traffic exchanged between controllers and switches. We develop an analytical model to estimate the reaction time perceived at the switches due to the inter-controller communications, based on the data-ownership model adopted in the cluster. We advocate a careful placement of the controllers, taking into account the two above kinds of control traffic. We evaluate, for some real ISP network topologies, the possible delay tradeoffs for the controllers placement problem.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"39 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"124671225","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 50
An empirical case for container-driven fine-grained VNF resource flexing 容器驱动的细粒度VNF资源灵活的经验案例
Amit Sheoran, Xiangyu Bu, Lianjie Cao, P. Sharma, S. Fahmy
In this paper, we make a case for using lightweight containers for fine-grained resource flexing for Virtualized Network Functions (VNFs) to meet the demands of varying workloads. We quantitatively compare the VNF performance and infrastructure resource usage of three instantiations (bare metal, virtual machine, and container) of three selected VNFs. The three VNFs we experiment with are the Mobility Management Entity (MME) of the Evolved packet core (EPC) architecture for cellular networks, the Suricata multi-threaded Intrusion Detection System (IDS), and the Snort single-threaded IDS. Our results show that container-based instantiations not only incur lower resource usage but also have shorter boot time. This makes containers an attractive choice for fine-grained VNF resource flexing. The lessons learned from our empirical case studies with EPC and IDS provide important guidelines for building an elastic micro-service architecture for NFV deployments.
在本文中,我们将为虚拟化网络功能(virtual Network Functions, VNFs)使用轻量级容器来实现细粒度的资源弹性,以满足不同工作负载的需求。我们定量地比较了三个选定VNFs的三个实例(裸机、虚拟机和容器)的VNF性能和基础设施资源使用情况。我们试验的三个VNFs是用于蜂窝网络的演进分组核心(EPC)体系结构的移动性管理实体(MME)、Suricata多线程入侵检测系统(IDS)和Snort单线程入侵检测系统。我们的结果表明,基于容器的实例化不仅减少了资源使用,而且缩短了引导时间。这使得容器成为细粒度VNF资源灵活化的一个有吸引力的选择。我们从EPC和IDS的经验案例研究中吸取的经验教训为NFV部署构建弹性微服务架构提供了重要的指导方针。
{"title":"An empirical case for container-driven fine-grained VNF resource flexing","authors":"Amit Sheoran, Xiangyu Bu, Lianjie Cao, P. Sharma, S. Fahmy","doi":"10.1109/NFV-SDN.2016.7919486","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919486","url":null,"abstract":"In this paper, we make a case for using lightweight containers for fine-grained resource flexing for Virtualized Network Functions (VNFs) to meet the demands of varying workloads. We quantitatively compare the VNF performance and infrastructure resource usage of three instantiations (bare metal, virtual machine, and container) of three selected VNFs. The three VNFs we experiment with are the Mobility Management Entity (MME) of the Evolved packet core (EPC) architecture for cellular networks, the Suricata multi-threaded Intrusion Detection System (IDS), and the Snort single-threaded IDS. Our results show that container-based instantiations not only incur lower resource usage but also have shorter boot time. This makes containers an attractive choice for fine-grained VNF resource flexing. The lessons learned from our empirical case studies with EPC and IDS provide important guidelines for building an elastic micro-service architecture for NFV deployments.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"8 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"133013397","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 24
BotD: A scalable anomaly-based Bot Detection Architecture for securing web services BotD:用于保护web服务的可扩展的基于异常的Bot检测体系结构
Krishna Teja Yadavalli, Shatrunjay Rawat
The significance of anomaly detection is increasing as a result of the rapid increase in unknown attacks. With the increase in deployment of scalable web services, there is a need for developing a scalable anomaly detection mechanisms. In this paper, we propose a scalable anomaly-based Bot Detection Architecture (BotD) in which different anomaly-based bot detection algorithms can be implemented. Our architecture leverages NF scalability provided by Network Function Virtualization (NFV), and network programmability provided by Software Defined Networking (SDN). We have also proposed a loss-free state transfer technique across NFs. We have simulated our architecture using Mininet and Ryu controller, and tested the functioning of the architecture.
随着未知攻击的迅速增加,异常检测的重要性也在不断提高。随着可伸缩web服务部署的增加,需要开发可伸缩的异常检测机制。在本文中,我们提出了一个可扩展的基于异常的Bot检测架构(BotD),其中可以实现不同的基于异常的Bot检测算法。我们的架构利用了网络功能虚拟化(NFV)提供的NF可扩展性和软件定义网络(SDN)提供的网络可编程性。我们还提出了一种跨NFs的无损耗状态转移技术。我们使用Mininet和Ryu控制器模拟了我们的体系结构,并测试了体系结构的功能。
{"title":"BotD: A scalable anomaly-based Bot Detection Architecture for securing web services","authors":"Krishna Teja Yadavalli, Shatrunjay Rawat","doi":"10.1109/NFV-SDN.2016.7919478","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919478","url":null,"abstract":"The significance of anomaly detection is increasing as a result of the rapid increase in unknown attacks. With the increase in deployment of scalable web services, there is a need for developing a scalable anomaly detection mechanisms. In this paper, we propose a scalable anomaly-based Bot Detection Architecture (BotD) in which different anomaly-based bot detection algorithms can be implemented. Our architecture leverages NF scalability provided by Network Function Virtualization (NFV), and network programmability provided by Software Defined Networking (SDN). We have also proposed a loss-free state transfer technique across NFs. We have simulated our architecture using Mininet and Ryu controller, and tested the functioning of the architecture.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132703157","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 1
A comparison of SDN and NFV for re-designing the LTE Packet Core 重新设计LTE分组核心的SDN和NFV的比较
Aman Jain, S. SadagopanN., S. Lohani, Mythili Vutukuru
With an increase in the number of mobile users and traffic, mobile network operators are finding it difficult to scale their radio and core networks. Further, hardware network appliances are expensive to procure and upgrade, and are difficult to adapt and program for new services. These trends have recently spurred several efforts to redesign various components of mobile networks, including the LTE Evolved Packet Core (EPC). Software Defined Networking (SDN) and Network Functions Virtualization (NFV) are two popular emerging networking paradigms that aim to increase network flexibility and scalability, while reducing the overall cost. With SDN, the control and data planes of the packet core can be separated, enabling cheaper packet gateways in the data plane, and an intelligent core network controller to handle the signaling and management functions. With NFV, the various hardware components that comprise the packet core can be virtualized and run as software on a cloud, enabling benefits such as elastic scaling and quick innovation. While several proposals exist to use SDN and NFV to redesign the EPC, there is no common framework to compare the new designs on various performance metrics. This paper presents the design and evaluation of two open-source implementations of the LTE EPC, one based on SDN principles and the other based on NFV, and presents a performance comparison of the two approaches. Experiments with our prototype show that an NFV-based implementation is better suited for networks with high signaling traffic, because handling the communication with the SDN controller quickly becomes the bottleneck at the switches in the SDN-based EPC. On the other hand, an SDN-based design of the EPC is better suited for networks with high data plane traffic, because SDN switches are often more optimized for packet forwarding than virtualized software appliances. We believe that our framework can be used to develop and compare several such design alternatives, and can serve as a guide for future redesigns of mobile data packet core networks.
随着移动用户数量和流量的增加,移动网络运营商发现很难扩展其无线和核心网络。此外,硬件网络设备的采购和升级成本很高,而且难以适应和编写新服务。这些趋势最近促使人们努力重新设计移动网络的各种组件,包括LTE演进分组核心(EPC)。软件定义网络(SDN)和网络功能虚拟化(NFV)是两种流行的新兴网络范例,旨在提高网络的灵活性和可扩展性,同时降低总体成本。通过SDN,报文核心的控制平面和数据平面可以分离,数据平面的报文网关可以更便宜,核心网的智能控制器可以处理信令和管理功能。通过NFV,组成包核心的各种硬件组件可以虚拟化,并作为软件在云上运行,从而实现弹性扩展和快速创新等优势。虽然有一些建议使用SDN和NFV来重新设计EPC,但没有一个通用的框架来比较各种性能指标的新设计。本文介绍了基于SDN原理和基于NFV原理的两种LTE EPC的开源实现方案的设计和评估,并对两种方案进行了性能比较。我们的原型实验表明,基于nfv的实现更适合具有高信令流量的网络,因为处理与SDN控制器的通信很快成为基于SDN的EPC交换机的瓶颈。另一方面,基于SDN的EPC设计更适合具有高数据平面流量的网络,因为SDN交换机通常比虚拟化软件设备更适合数据包转发。我们相信我们的框架可以用来开发和比较几个这样的设计方案,并可以作为未来重新设计移动数据包核心网的指南。
{"title":"A comparison of SDN and NFV for re-designing the LTE Packet Core","authors":"Aman Jain, S. SadagopanN., S. Lohani, Mythili Vutukuru","doi":"10.1109/NFV-SDN.2016.7919479","DOIUrl":"https://doi.org/10.1109/NFV-SDN.2016.7919479","url":null,"abstract":"With an increase in the number of mobile users and traffic, mobile network operators are finding it difficult to scale their radio and core networks. Further, hardware network appliances are expensive to procure and upgrade, and are difficult to adapt and program for new services. These trends have recently spurred several efforts to redesign various components of mobile networks, including the LTE Evolved Packet Core (EPC). Software Defined Networking (SDN) and Network Functions Virtualization (NFV) are two popular emerging networking paradigms that aim to increase network flexibility and scalability, while reducing the overall cost. With SDN, the control and data planes of the packet core can be separated, enabling cheaper packet gateways in the data plane, and an intelligent core network controller to handle the signaling and management functions. With NFV, the various hardware components that comprise the packet core can be virtualized and run as software on a cloud, enabling benefits such as elastic scaling and quick innovation. While several proposals exist to use SDN and NFV to redesign the EPC, there is no common framework to compare the new designs on various performance metrics. This paper presents the design and evaluation of two open-source implementations of the LTE EPC, one based on SDN principles and the other based on NFV, and presents a performance comparison of the two approaches. Experiments with our prototype show that an NFV-based implementation is better suited for networks with high signaling traffic, because handling the communication with the SDN controller quickly becomes the bottleneck at the switches in the SDN-based EPC. On the other hand, an SDN-based design of the EPC is better suited for networks with high data plane traffic, because SDN switches are often more optimized for packet forwarding than virtualized software appliances. We believe that our framework can be used to develop and compare several such design alternatives, and can serve as a guide for future redesigns of mobile data packet core networks.","PeriodicalId":448203,"journal":{"name":"2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"40 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121274142","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 56
期刊
2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1