Dependable Policy Enforcement in Traditional Non-SDN Networks

被引:2
|
作者
Odegbile, Olufemi [1 ]
Chen, Shigang [1 ]
Wang, Yuanda [1 ]
机构
[1] Univ Florida, Dept Comp & Informat Sci & Engn, Gainesville, FL 32611 USA
基金
美国国家科学基金会;
关键词
PACKET CLASSIFICATION;
D O I
10.1109/ICDCS.2019.00061
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Middleboxes are widely used in modern networks for a variety of network functions in cybersecurity, performance enhancement, and monitoring. Middlebox policy enforcement is however complex and tedious with unreliable manual re-configuration of legacy routers. The existing solution on automated policy enforcement relies on software-defined networking and does not apply to the traditional non-SDN networks, which remain popular today in enterprise deployment and core networks. This paper proposes a new architecture based entirely on software-defined middleboxes (instead of using software-defined switches in the prior art) to enable dependable and automated policy enforcement in non-SDN networks whose routers forward packets based on traditional routing protocols that are not policy-sensitive. We present a hot-potato enforcement strategy, which is then enhanced with two optimizations for load-balanced policy enforcement. Further enhancements are made to relieve middlebox processing overhead and avoid packet fragmentation due to policy enforcement.
引用
收藏
页码:545 / 554
页数:10
相关论文
共 50 条
  • [1] Policy enforcement in traditional non-SDN networks
    Odegbile, Olufemi
    Ma, Chaoyi
    Chen, Shigang
    Wang, Yuanda
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2023, 177 (39-52) : 39 - 52
  • [2] QoS Guarantee over Hybrid SDN/non-SDN Networks
    Salman, Ola
    Elhajj, Imad H.
    Chehab, Ali
    Kayssi, Ayman
    PROCEEDINGS OF THE 2017 8TH INTERNATIONAL CONFERENCE ON THE NETWORK OF THE FUTURE (NOF), 2017, : 141 - 143
  • [3] LoCoSDN: A Local Controller for Operation of OF Switches in non-SDN Networks
    Schmidt, Mark
    Hauser, Frederik
    Germann, Bastian
    Menth, Michael
    2018 FIFTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2018, : 80 - 86
  • [4] Online assignment of non-SDN virtual network nodes to a physical SDN
    Osgouei, Amin Ghalami
    Koohanestani, Amir Khorsandi
    Saidi, Hossein
    Fanian, Ali
    COMPUTER NETWORKS, 2017, 129 : 105 - 116
  • [5] An efficient architecture for dynamic middlebox policy enforcement in SDN networks
    Pinheiro, Antonio J.
    Gondim, Ethel B.
    Campelo, Divanilson R.
    COMPUTER NETWORKS, 2017, 122 : 153 - 162
  • [6] Extension Knowledge on the Correlation of Managed Objects for Unified Management of SDN and non-SDN
    Xu, Hui
    Chen, Hongwei
    PROCEEDINGS OF THE 38TH CHINESE CONTROL CONFERENCE (CCC), 2019, : 5177 - 5181
  • [7] Securing middlebox policy enforcement in SDN
    Bu, Kai
    Yang, Yutian
    Guo, Zixuan
    Yang, Yuanyuan
    Li, Xing
    Zhang, Shigeng
    COMPUTER NETWORKS, 2021, 193
  • [8] Integration of Legacy Non-SDN Optical ROADMs in a Software Defined Network
    Alawe, Imad
    Cousin, Bernard
    Thorey, Olivier
    Legouable, Rodolphe
    2016 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING WORKSHOP (IC2EW), 2016, : 60 - 64
  • [9] Security network policy enforcement through a SDN framework
    Berardi, Davide
    Callegati, Franco
    Melis, Andrea
    Prandini, Marco
    2018 28TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2018, : 97 - 100
  • [10] eHDDP: Enhanced Hybrid Domain Discovery Protocol for network topologies with both wired/wireless and SDN/non-SDN devices
    Martinez-Yelmo, Isaias
    Alvarez-Horcajo, Joaquin
    Antonio Carral, Juan
    Lopez-Pajares, Diego
    COMPUTER NETWORKS, 2021, 191