BigMaC: Reactive Network-Wide Policy Caching for SDN Policy Enforcement

被引:10
|
作者
Yan, Bo [1 ]
Xu, Yang [1 ]
Chao, H. Jonathan [1 ]
机构
[1] NYU, Tandon Sch Engn, Dept Elect & Comp Engn, Brooklyn, NY 11201 USA
基金
美国国家科学基金会;
关键词
SDN; network-wide policy caching; policy enforcement; MANAGEMENT;
D O I
10.1109/JSAC.2018.2871296
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Enforcing network policies is critical for service deployments over software-defined networks (SDN). Most existing studies suggest proactively compiling policies into flow entries in the data plane and updating the installed entries when necessary. With a growing amount of applications, taking a proactive approach may overflow underlying switch memory. Meanwhile, certain policies can be frequently updated. Such updates may propagate across configurations in the network, leading to a long time for correctness validation. To improve both the scalability and the flexibility of SDN policy enforcement, we advocate reactively deploying network policies in the data plane. To this end, we propose a network-wide policy enforcement framework named BigMaC. BigMaC advertises a neat policy model for network managers to specify various network policies as rules. It then caches the rules as flow entries in the switches reactively on demand. One major challenge for the BigMaC design is to guarantee the consistency of defined policies and cached entries in the network. To maintain consistency with efficient table usage and simple updates, we group rules into buckets and perform rule caching in the unit of buckets. With trace-driven simulations, we verify that BigMaC can significantly save table space and reduce update complexity compared to prior proposals.
引用
收藏
页码:2675 / 2687
页数:13
相关论文
共 50 条
  • [31] Reinforcement Learning Policy for Adaptive Edge Caching in Heterogeneous Vehicular Network
    Chen, Jiayin
    Xu, Wenchao
    Cheng, Nan
    Wu, Huaqing
    Zhang, Shan
    Shen, Xuemin
    2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [32] A SDN-based Deployment Framework for Computer Network Defense Policy
    Gao, Jinghua
    Xia, Chunhe
    Wang, Shuguang
    Zhang, Huajun
    PROCEEDINGS OF 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2015), 2015, : 1253 - 1258
  • [33] Providing Optical Network as a Service with Policy-based Transport SDN
    Marcos Antonio de Siqueira
    Fabian Nicolaas Christiaan van ’t Hooft
    Juliano Rodrigues Fernandes de Oliveira
    Edmundo Roberto Mauro Madeira
    Christian Esteve Rothenberg
    Journal of Network and Systems Management, 2015, 23 : 360 - 373
  • [34] Providing Optical Network as a Service with Policy-based Transport SDN
    de Siqueira, Marcos Antonio
    Christiaan van 't Hooft, Fabian Nicolaas
    Fernandes de Oliveira, Juliano Rodrigues
    Mauro Madeira, Edmundo Roberto
    Rothenberg, Christian Esteve
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2015, 23 (02) : 360 - 373
  • [35] CloudFlow: Cloud-wide policy enforcement using fast VM introspection
    Baig, Mirza Basim
    Fitzsimons, Connor
    Balasubramanian, Suryanarayanan
    Sion, Radu
    Porter, Donald E.
    2014 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E), 2014, : 159 - 164
  • [36] A Policy-Aware Enforcement Logic for Appropriately Invoking Network Coding
    Atya, Ahmed Osama Fathy
    Broustis, Ioannis
    Singh, Shailendra
    Syrivelis, Dimitris
    Krishnamurthy, Srikanth V.
    La Porta, Thomas F.
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2016, 24 (04) : 2005 - 2018
  • [37] Network Controlled Mobility Management with Policy Enforcement Towards IMT-A
    Klockar, Annika
    Mihovska, Albena
    Luo, Jijun
    Mino, Emilio
    Tragos, Elias
    2008 INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CIRCUITS AND SYSTEMS PROCEEDINGS, VOLS 1 AND 2: VOL 1: COMMUNICATION THEORY AND SYSTEM, 2008, : 145 - 149
  • [38] Learning a Hybrid Proactive and Reactive Caching Policy in Wireless Edge Under Dynamic Popularity
    Qi, Kaiqiang
    Han, Shengqian
    Yang, Chenyang
    IEEE ACCESS, 2019, 7 : 120788 - 120801
  • [39] Network Policy Enforcement With Commodity Multiqueue NICs for Multitenant Data Centers
    Kim, Gyuyeong
    Lee, Wonjun
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (08) : 6252 - 6263
  • [40] A novel approach for integrating security policy enforcement with dynamic network virtualization
    Basile, Cataldo
    Lioy, Antonio
    Pitscheider, Christian
    Valenza, Fulvio
    Vallini, Marco
    2015 1ST IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT), 2015,