大规模公有云中的流量导向

Zhangfeng Hu, Siqing Sun, Ping Yin, Yanjun Li, Qiuzheng Ren, Baozhu Li, Xiong Li
{"title":"大规模公有云中的流量导向","authors":"Zhangfeng Hu, Siqing Sun, Ping Yin, Yanjun Li, Qiuzheng Ren, Baozhu Li, Xiong Li","doi":"10.1145/3571662.3571691","DOIUrl":null,"url":null,"abstract":"More and more complex services composed of a series of sequentially arranged middleboxes which are mainly used to meet the requirements of advanced services such as security services, auditing services, monitoring services, personalized enterprise services, and so forth, are increasingly deployed in cloud data centers of public cloud. SFC (Service Function Chaining) is a technique that facilitates the enforcement of complex services and differentiated traffic forwarding policies, dynamically steering the traffic through an ordered list of service functions. Flow table-based traffic steering scheme is commonly adopted in SDN-enabled scenarios, which consumes too many flow entries and is unsuitable for large-scale public clouds in steering traffic between VNFs (Virtual Network Function) inside of VPC (Virtual Private Cloud). Legacy PBR (Policy-based Routing) based schemes which are widely used in traditional physical networks cannot fulfill the requirements of fully distributed routing architectures of large-scale public clouds. In this paper, we present a PBR and unsymmetrical NAT (Network Address Translation) converged scheme to structure SFC in a fully distributed routing architecture. The scheme uses distributed PBR rules to steer traffic between an ordered list of VNFs located on different nodes while performing NAT on different nodes for ingress/egress traffic of a specific flow to avoid asymmetry of packet headers which may lead to failures of communication. The proposed scheme brings no overhead in data transmission, eliminates extra configurations on each middle box of the chain, and is scalable to support the scenarios of large-scale public cloud.","PeriodicalId":235407,"journal":{"name":"Proceedings of the 8th International Conference on Communication and Information Processing","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2022-11-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Traffic Steering in Large-scale Public Cloud\",\"authors\":\"Zhangfeng Hu, Siqing Sun, Ping Yin, Yanjun Li, Qiuzheng Ren, Baozhu Li, Xiong Li\",\"doi\":\"10.1145/3571662.3571691\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"More and more complex services composed of a series of sequentially arranged middleboxes which are mainly used to meet the requirements of advanced services such as security services, auditing services, monitoring services, personalized enterprise services, and so forth, are increasingly deployed in cloud data centers of public cloud. SFC (Service Function Chaining) is a technique that facilitates the enforcement of complex services and differentiated traffic forwarding policies, dynamically steering the traffic through an ordered list of service functions. Flow table-based traffic steering scheme is commonly adopted in SDN-enabled scenarios, which consumes too many flow entries and is unsuitable for large-scale public clouds in steering traffic between VNFs (Virtual Network Function) inside of VPC (Virtual Private Cloud). Legacy PBR (Policy-based Routing) based schemes which are widely used in traditional physical networks cannot fulfill the requirements of fully distributed routing architectures of large-scale public clouds. In this paper, we present a PBR and unsymmetrical NAT (Network Address Translation) converged scheme to structure SFC in a fully distributed routing architecture. The scheme uses distributed PBR rules to steer traffic between an ordered list of VNFs located on different nodes while performing NAT on different nodes for ingress/egress traffic of a specific flow to avoid asymmetry of packet headers which may lead to failures of communication. The proposed scheme brings no overhead in data transmission, eliminates extra configurations on each middle box of the chain, and is scalable to support the scenarios of large-scale public cloud.\",\"PeriodicalId\":235407,\"journal\":{\"name\":\"Proceedings of the 8th International Conference on Communication and Information Processing\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-11-03\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 8th International Conference on Communication and Information Processing\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3571662.3571691\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 8th International Conference on Communication and Information Processing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3571662.3571691","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

越来越多由一系列顺序排列的中间件组成的复杂服务,主要用于满足安全服务、审计服务、监控服务、个性化企业服务等高级服务的需求,部署在公有云的云数据中心中。SFC (Service Function chains)是一种便于实施复杂业务和差异化流量转发策略的技术,通过有序的业务功能列表对流量进行动态引导。基于流表的流量引导方案一般用于支持sdn的场景,在VPC (Virtual Private Cloud)内部的VNFs (Virtual Network Function)之间进行流量引导时,流表占用的流量过多,不适合大规模公有云使用。传统物理网络中广泛使用的基于策略路由(Policy-based Routing, PBR)的传统路由方案已经不能满足大规模公有云的全分布式路由架构的要求。在本文中,我们提出了一种聚合策略路由和非对称NAT (Network Address Translation)的方案来构建全分布式路由架构下的SFC。该方案使用分布式策略路由规则在不同节点的VNFs有序列表之间引导流量,同时对特定流的进出流量在不同节点上执行NAT,以避免报文头不对称导致通信失败。该方案没有数据传输开销,消除了链中每个中间节点的额外配置,具有可扩展性,可支持大规模公共云场景。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Traffic Steering in Large-scale Public Cloud
More and more complex services composed of a series of sequentially arranged middleboxes which are mainly used to meet the requirements of advanced services such as security services, auditing services, monitoring services, personalized enterprise services, and so forth, are increasingly deployed in cloud data centers of public cloud. SFC (Service Function Chaining) is a technique that facilitates the enforcement of complex services and differentiated traffic forwarding policies, dynamically steering the traffic through an ordered list of service functions. Flow table-based traffic steering scheme is commonly adopted in SDN-enabled scenarios, which consumes too many flow entries and is unsuitable for large-scale public clouds in steering traffic between VNFs (Virtual Network Function) inside of VPC (Virtual Private Cloud). Legacy PBR (Policy-based Routing) based schemes which are widely used in traditional physical networks cannot fulfill the requirements of fully distributed routing architectures of large-scale public clouds. In this paper, we present a PBR and unsymmetrical NAT (Network Address Translation) converged scheme to structure SFC in a fully distributed routing architecture. The scheme uses distributed PBR rules to steer traffic between an ordered list of VNFs located on different nodes while performing NAT on different nodes for ingress/egress traffic of a specific flow to avoid asymmetry of packet headers which may lead to failures of communication. The proposed scheme brings no overhead in data transmission, eliminates extra configurations on each middle box of the chain, and is scalable to support the scenarios of large-scale public cloud.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
MFFNet: Multi-Receptive Field Fusion Net for Microscope Steel Grain Grading An encrypted traffic classification method based on contrastive learning Hybrid Deep Learning CNN-Bidirectional LSTM and Manhattan Distance for Japanese Automated Short Answer Grading: Use case in Japanese Language Studies Distributed Learning based on Asynchronized Discriminator GAN for remote sensing image segmentation Spatial spectrum estimation algorithm of polarization sensitive array based on compensating spatial domain manifold matrix
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1